What's more, part of that Exams4Collection CISA dumps now are free: https://drive.google.com/open?id=15VvNZMW3oPezFOhKxNI2qsdK3B5wcRyi
With the rapid market development, there are more and more companies and websites to sell CISA guide question for learners to help them prepare for exam, but many study materials have very low quality and low pass rate, this has resulting in many candidates failed the exam, some of them even loss confidence of their exam. As for the safe environment and effective product, why don’t you have a try for our CISA Test Question, never let you down! Before your purchase, there is a free demo for you. You can know the quality of our CISA guide question earlier.
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Information Systems Acquisition, Development and Implementation | 12% | - Information Systems Implementation
|
| Topic 2: Protection of Information Assets | 26% | - Information Asset Security and Control
|
| Topic 3: Governance and Management of IT | 18% | - IT Management
|
| Topic 4: Information Systems Auditing Process | 18% | - Execution
|
| Topic 5: Information Systems Operations and Business Resilience | 26% | - Information Systems Operations
|
We are a team of IT professionals that provide our customers with the up-to-date CISA study guide and the current certification exam information. Our exam collection contains the latest questions, accurate CISA Exam Answers and some detailed explanations. You will find everything you want to overcome the difficulties of CISA practice exam and questions. You will get high mark followed by our materials.
NEW QUESTION # 1209
IS management has decided to install a level 1 Redundant Array of Inexpensive Disks (RAID) system in all servers to compensate for the elimination of offsite backups. The IS auditor should recommend:
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
A RAID system, at any level, will not protect against a natural disaster. The problem will not be alleviated without offsite backups, more frequent onsite backups or even setting up a cold site. Choices A, B and D do not compensate for the lack of offsite backup.
NEW QUESTION # 1210
An organization is within a jurisdiction where new regulations have recently been announced to restrict cross-border data transfer of personally identifiable information (PIl). Which of the following IT decisions will MOST likely need to be assessed in the context of this?
Answer: D
NEW QUESTION # 1211
An investment advisor e-mails periodic newsletters to clients and wants reasonable assurance that no one has modified the newsletter. This objective can be achieved by:
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
There is no attempt on the part of the investment advisor to prove their identity or to keep the newsletter confidential. The objective is to assure the receivers that it came to them without any modification, i.e., it has message integrity. Choice A is correct because the hash is encrypted using the advisor's private key.
The recipients can open the newsletter, recompute the hash and decrypt the received hash using the advisor's public key. If the two hashes are equal, the newsletter was not modified in transit. Choice B is not feasible, for no one other than the investment advisor can open it. Choice C addresses sender authentication but not message integrity. Choice D addresses confidentiality, but not message integrity, because anyone can obtain the investment advisor's public key, decrypt the newsletter, modify it and send it to others. The interceptor will not be able to use the advisor's private key, because they do not have it.
Anything encrypted using the interceptor's private key can be decrypted by the receiver only by using their public key.
NEW QUESTION # 1212
IS auditors are MOST likely to perform compliance tests of internal controls if, after their initial evaluation of
the controls, they conclude that control risks are within the acceptable limits. True or false?
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
IS auditors are most likely to perform compliance tests of internal controls if, after their initial evaluation of
the controls, they conclude that control risks are within the acceptable limits. Think of it this way: If any
reliance is placed on internal controls, that reliance must be validated through compliance testing. High
control risk results in little reliance on internal controls, which results in additional substantive testing.
NEW QUESTION # 1213
Which of the following layer of an enterprise data flow architecture represents subsets of information from the core data warehouse?
Answer: A
Explanation:
Section: Information System Acquisition, Development and Implementation Explanation:
Data Mart layer - Data mart represents subset of information from the core DW selected and organized to meet the needs of a particular business unit or business line. Data mart can be relational databases or some form on-line analytical processing (OLAP) data structure.
For CISA exam you should know below information about business intelligence:
Business intelligence(BI) is a broad field of IT encompasses the collection and analysis of information to assist decision making and assess organizational performance. To deliver effective BI, organizations need to design and implement a data architecture. The complete data architecture consists of two components The enterprise data flow architecture (EDFA) A logical data architecture Various layers/components of this data flow architecture are as follows:
Presentation/desktop access layer - This is where end users directly deal with information. This layer includes familiar desktop tools such as spreadsheets, direct querying tools, reporting and analysis suits offered by vendors such as Congas and business objects, and purpose built application such as balanced source cards and digital dashboards.
Data Source Layer - Enterprise information derives from number of sources:
Operational data - Data captured and maintained by an organization's existing systems, and usually held in system-specific database or flat files.
External Data - Data provided to an organization by external sources. This could include data such as customer demographic and market share information.
Nonoperational data - Information needed by end user that is not currently maintained in a computer accessible format.
Core data warehouse - This is where all the data of interest to an organization is captured and organized to assist reporting and analysis. DWs are normally instituted as large relational databases. A property constituted DW should support three basic form of an inquiry.
Drilling up and drilling down - Using dimension of interest to the business, it should be possible to aggregate data as well as drill down. Attributes available at the more granular levels of the warehouse can also be used to refine the analysis.
Drill across - Use common attributes to access a cross section of information in the warehouse such as sum sales across all product lines by customer and group of customers according to length of association with the company.
Historical Analysis - The warehouse should support this by holding historical, time variant data. An example of historical analysis would be to report monthly store sales and then repeat the analysis using only customer who were preexisting at the start of the year in order to separate the effective new customer from the ability to generate repeat business with existing customers.
Data Mart Layer - Data mart represents subset of information from the core DW selected and organized to meet the needs of a particular business unit or business line. Data mart can be relational databases or some form on-line analytical processing (OLAP) data structure.
Data Staging and quality layer - This layer is responsible for data copying, transformation into DW format and quality control. It is particularly important that only reliable data into core DW. This layer needs to be able to deal with problems periodically thrown by operational systems such as change to account number format and reuse of old accounts and customer numbers.
Data Access Layer - This layer operates to connect the data storage and quality layer with data stores in the data source layer and, in the process, avoiding the need to know to know exactly how these data stores are organized. Technology now permits SQL access to data even if it is not stored in a relational database.
Data Preparation layer - This layer is concerned with the assembly and preparation of data for loading into data marts. The usual practice is to per-calculate the values that are loaded into OLAP data repositories to increase access speed. Data mining is concern with exploring large volume of data to determine patterns and trends of information. Data mining often identifies patterns that are counterintuitive due to number and complexity of data relationships. Data quality needs to be very high to not corrupt the result.
Metadata repository layer - Metadata are data about data. The information held in metadata layer needs to extend beyond data structure names and formats to provide detail on business purpose and context. The metadata layer should be comprehensive in scope, covering data as they flow between the various layers, including documenting transformation and validation rules.
Warehouse Management Layer - The function of this layer is the scheduling of the tasks necessary to build and maintain the DW and populate data marts. This layer is also involved in administration of security.
Application messaging layer - This layer is concerned with transporting information between the various layers. In addition to business data, this layer encompasses generation, storage and targeted communication of control messages.
Internet/Intranet layer - This layer is concerned with basic data communication. Included here are browser based user interface and TCP/IP networking.
Various analysis models used by data architects/ analysis follows:
Activity or swim-lane diagram - De-construct business processes.
Entity relationship diagram - Depict data entities and how they relate. These data analysis methods obviously play an important part in developing an enterprise data model. However, it is also crucial that knowledgeable business operative is involved in the process. This way proper understanding can be obtained of the business purpose and context of the data. This also mitigates the risk of replication of suboptimal data configuration from existing systems and database into DW.
The following were incorrect answers:
Desktop access layer or presentation layer is where end users directly deal with information. This layer includes familiar desktop tools such as spreadsheets, direct querying tools, reporting and analysis suits offered by vendors such as Congas and business objects, and purpose built application such as balanced source cards and digital dashboards.
Data access layer - his layer operates to connect the data storage and quality layer with data stores in the data source layer and, in the process, avoiding the need to know to know exactly how these data stores are organized. Technology now permits SQL access to data even if it is not stored in a relational database.
Reference:
CISA review manual 2014 Page number 188
NEW QUESTION # 1214
......
All CISA learning materials fall within the scope of this exam for your information. The content is written promptly and helpfully because we hired the most professional experts in this area to compile the CISA Preparation quiz. And our experts are professional in this career for over ten years. Our CISA practice materials will be worthy of purchase, and you will get manifest improvement.
Valid CISA Exam Simulator: https://www.exams4collection.com/CISA-latest-braindumps.html
P.S. Free 2026 ISACA CISA dumps are available on Google Drive shared by Exams4Collection: https://drive.google.com/open?id=15VvNZMW3oPezFOhKxNI2qsdK3B5wcRyi