Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 2Objective 2

Risk and Compliance Management CISA Practice Questions (Page 4)

Part of the Governance and Management of IT domain, which accounts for 18% of the CISA exam.

31questions here
7free pages
8concepts
18%of the exam

Questions 16–20

  1. 16application · medium

    A healthcare organization is conducting its annual IT risk assessment. The risk team has identified a legacy patient records system that is no longer patched by the vendor. The system contains sensitive personal health information (PHI). The team is now analyzing the likelihood and impact of a data breach. Which of the following steps should the team perform NEXT in the risk assessment process?

    Select an answer first
  2. 17foundation · easy

    What is the primary role of a data protection officer (DPO) in a privacy program?

    Select an answer first
  3. 18application · medium

    A multinational bank is adopting an enterprise risk management (ERM) framework. The board has approved a risk appetite statement that permits a maximum of 0.5% annualized loss from cyber incidents across the entire loan portfolio. During the annual risk assessment, the IT risk team identifies a new third-party payment processor vulnerability that could cause a 1.2% loss if exploited. The team calculates that implementing an additional compensating control would reduce the exposure to 0.4%. Which of the following is the MOST appropriate initial action for the IT risk team?

    Select an answer first
  4. 19foundation · easy

    In the IT risk assessment process, which step involves determining the likelihood and impact of identified risks?

    Select an answer first
  5. 20application · medium

    A government agency classifies its data into four levels: Public, Internal, Confidential, and Secret. A new cloud-based collaboration tool is being deployed, and the agency wants to ensure that data is handled appropriately. Which of the following is the MOST important control to implement for Confidential and Secret data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.