
Certified Information Systems Auditor
Domain 5Objective 1
Security Frameworks and Governance CISA Practice Questions (Page 5)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
24questions here
5free pages
4concepts
26%of the exam
Questions 21–24
- 21
A security manager wants to evaluate whether a new security awareness program is effective. Which combination of metrics would provide the most comprehensive assessment?
Select an answer first - 22
A company is required to comply with a new regulation that mandates specific security controls. The company already follows the NIST Cybersecurity Framework. The compliance team wants to avoid duplicating efforts and create a single set of controls that satisfies both the regulation and the framework. What is the most efficient approach?
Select an answer first - 23
A government contractor must implement a set of security controls to protect controlled unclassified information (CUI) in its IT systems. The contract specifies compliance with a framework that is mandatory for federal agencies and their contractors. Which framework is the contractor most likely required to follow?
Select an answer first - 24
A security manager is designing a security awareness program for a company with a highly diverse workforce, including remote workers, office staff, and executives. The program must be effective across all groups while respecting the fact that executives have very limited time. Which strategy best addresses these competing constraints?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.