
Certified Information Systems Auditor
Domain 5Objective 1
Security Frameworks and Governance CISA Practice Questions (Page 1)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
24questions here
5free pages
4concepts
26%of the exam
Questions 1–5
- 1
A security manager has been running a security awareness program for a year. To determine whether the program should be continued, modified, or discontinued, which action provides the most reliable basis for this decision?
Select an answer first - 2
A financial services firm is launching a security awareness program. The compliance officer insists that the program must be tailored to different roles within the organization. Which approach best satisfies this requirement?
Select an answer first - 3
Which framework is primarily designed to provide a comprehensive set of controls and best practices for establishing, implementing, maintaining, and continually improving an organization's information security management system?
Select an answer first - 4
Which metric is most commonly used to evaluate the effectiveness of a security awareness program?
Select an answer first - 5
A global company has offices in regions with very different threat landscapes. The headquarters mandates a single, uniform security awareness program for all employees. The regional security leads argue that the program is not effective because it does not address local risks. The CISO wants to improve effectiveness while maintaining a consistent corporate message. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.