
Certified Information Systems Auditor
Domain 5Objective 1
Security Frameworks and Governance CISA Practice Questions (Page 3)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
24questions here
5free pages
4concepts
26%of the exam
Questions 11–15
- 11
A retail company has a high rate of employees writing down passwords on sticky notes. The security team wants to implement a training program to address this behavior. Which training objective is most directly aligned with this issue?
Select an answer first - 12
Which of the following is a key element of an effective security awareness training program?
Select an answer first - 13
An organization is implementing a new access control system. The security team has written a document that specifies the exact steps an administrator must follow to grant a new user access. Which type of document is this?
Select an answer first - 14
A company has a security policy that states 'all employees must complete security awareness training annually.' The training department has created a detailed, step-by-step guide on how to enroll in and complete the training. The security team has also published a document recommending that employees use a password manager. Which three types of documents are represented in this scenario?
Select an answer first - 15
An organization wants to adopt a framework that provides a structured approach for aligning IT governance with business objectives while also incorporating security and risk management. Which framework is most appropriate for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.