
Certified Information Systems Auditor
Domain 2Objective 2
Risk and Compliance Management CISA Practice Questions (Page 5)
Part of the Governance and Management of IT domain, which accounts for 18% of the CISA exam.
31questions here
7free pages
8concepts
18%of the exam
Questions 21–25
- 21
A mid-sized organization is establishing a privacy program to comply with new data protection regulations. The organization has limited resources and has not previously had a formal privacy function. Which of the following is the MOST effective first step for the organization to take?
Select an answer first - 22
An organization decides to purchase cyber insurance to cover potential losses from a data breach. Which risk response option does this represent?
Select an answer first - 23
A multinational organization is subject to both GDPR and the California Consumer Privacy Act (CCPA). The organization is designing a new customer data platform that will collect personal data from EU and California residents. The privacy team is evaluating the requirements. Which of the following is the MOST appropriate approach to ensure compliance with both regulations?
Select an answer first - 24
Which role is typically responsible for the day-to-day management of data quality and metadata for a specific data domain?
Select an answer first - 25
Under the GDPR, which of the following is a legal basis for processing personal data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.