显示标签为“ISACA”的博文。显示所有博文
显示标签为“ISACA”的博文。显示所有博文

2014年4月10日星期四

どのようにISACA CGEIT認定試験の準備をしているか

JPexamがISACAのCGEITのサンプルの問題のダウンロードを提供して、あなはリスクフリーの購入のプロセスを体験することができます。これは試用の練習問題で、あなたにインタフェースの友好、問題の質と購入する前の価値を見せます。弊社はJPexamのISACAのCGEITのサンプルは製品の性質を確かめるに足りて、あなたに満足させると信じております。あなたの権利と利益を保障するために、JPexamは一回で合格しなかったら、全額で返金することを約束します。弊社の目的はあなたが試験に合格することに助けを差し上げるだけでなく、あなたが本物のIT認証の専門家になることを願っています。あなたが仕事を求める競争力を高めて、自分の技術レベルに合わせている技術職を取って、気楽にホワイトカラー労働者になって高い給料を取ることをお祈りします。

CGEIT認定試験は専門知識と情報技術を検査する試験で、JPexamが一日早くISACAのCGEIT認定試験に合格させるのサイトで試験の前に弊社が提供する訓練練習問題をテストして、短い時間であなたの収穫が大きいです。

IT業種は急激に発展しているこの時代で、IT専門家を称賛しなければならないです。彼らは自身が持っている先端技術で色々な便利を作ってくれます。それに、会社に大量な人的·物的資源を節約させると同時に、案外のうまい効果を取得しました。彼らの給料は言うまでもなく高いです。そのような人になりたいのですか。羨ましいですか。心配することはないです。JPexamのISACAのCGEITトレーニング資料はあなたに期待するものを与えますから。JPexamを選ぶのは、成功を選ぶということになります。

JPexamはISACAのCGEIT認定試験に便利なサービスを提供するサイトで、従来の試験によってJPexam が今年のISACAのCGEIT認定試験を予測してもっとも真実に近い問題集を研究し続けます。

JPexamは正確な選択を与えて、君の悩みを減らして、もし早くてISACA CGEIT認証をとりたければ、早くてJPexamをショッピングカートに入れましょう。あなたにとても良い指導を確保できて、試験に合格するのを助けって、JPexamからすぐにあなたの通行証をとります。

試験番号:CGEIT問題集
試験科目:ISACA CGEIT Certification Practice Test
最近更新時間:2014-04-10
問題と解答:全279問
100%の返金保証。1年間の無料アップデート。

購入前にお試し,私たちの試験の質問と回答のいずれかの無料サンプルをダウンロード:http://www.jpexam.com/CGEIT_exam.html

NO.1 DRAG DROP
Val IT is a suite of documents that provide a framework for the governance of IT investments, produced by
the IT Governance Institute (ITGI). It is a formal statement of principles and processes for IT portfolio
management. Drag and drop the correct domain ('Portfolio management') next to the IT processes
defined by Val IT.
Answer:

NO.2 Benchmarking is a continuous process that can be time consuming to do correctly.
Which of the following guidelines for performing benchmarking identifies the critical processes and
creates measurement techniques to grade the process?
A. Research
B. Adapt
C. Plan
D. Improve
Answer: C

ISACA認証試験   CGEIT   CGEIT   CGEIT過去問

NO.3 Jenny is the project manager for the NBT projects. She is working with the project team and several
subject matter experts to perform the quantitative risk analysis process.
During this process she and the project team uncover several risks events that were not previously
identified. What should Jenny do with these risk events?
A. The events should be determined if they need to be accepted or responded to.
B. The events should be entered into the risk register.
C. The events should continue on with quantitative risk analysis.
D. The events should be entered into qualitative risk analysis.
Answer: B

ISACA認証試験   CGEIT   CGEIT過去問   CGEIT過去問   CGEIT

NO.4 CORRECT TEXT
Fill in the blank with an appropriate phrase.
_________models address specifications, requirements, design, verification and validation, and
maintenance activities.
Answer: Life cycle

ISACA過去問   CGEIT認定資格   CGEIT   CGEIT練習問題

NO.5 You are the project manager for your organization and you are working with Thomas, a project team
member. You and Thomas have been working on a specific risk response for a probable risk event in the
project. Thomas is empowered with a risk response and will control all aspects of the identified risk
response in which a particular risk event will happen within the project. What title, in regard to risk, is
bestowed on Thomas?
A. Risk coordinator
B. Risk expeditor
C. Risk owner
D. Risk team leader
Answer: C

ISACA認定資格   CGEIT過去問   CGEIT過去問   CGEIT過去問   CGEIT問題集

NO.6 You are the project manager for your organization. You are preparing for the quantitative risk analysis.
Mark, a project team member, wants to know why you need to do quantitative risk analysis when you just
completed qualitative risk analysis. Which one of the following statements best defines what quantitative
risk analysis is.?
A. Quantitative risk analysis is the process of prioritizing risks for further analysis or action by assessing
and combining their probability of occurrence and impact.
B. Quantitative risk analysis is the planning and quantification of risk responses based on
probability and impact of each risk event.
C. Quantitative risk analysis is the review of the risk events with the high probability and the highest
impact on the project objectives.
D. Quantitative risk analysis is the process of numerically analyzing the effect of identified risks on overall
project objectives.
Answer: D

ISACA過去問   CGEIT認定資格   CGEIT認定証   CGEIT参考書

NO.7 You are the project manager of the NHQ project for your company. You are working with your project
team to complete a risk audit. A recent issue that your project team responded to, and management
approved, was to increase the project schedule because there was risk surrounding the installation time
of a new material. Your logic was that with the expanded schedule there would be time to complete the
installation without affecting downstream project activities. What type of risk response is being audited in
this scenario?
A. Avoidance
B. Mitigation
C. Parkinson's Law
D. Lag Time
Answer: A

ISACA   CGEIT認証試験   CGEIT過去問   CGEIT参考書   CGEIT

NO.8 Mary is the business analyst for your organization. She asks you what the purpose of the assess
capability gaps task is. Which of the following is the best response to give Mary?
A. It identifies the causal factors that are contributing to an effect the solution will solve.
B. It identifies new capabilities required by the organization to meet the business need.
C. It describes the ends that the organization wants to improve.
D. It identifies the skill gaps in the existing resources.
Answer: B

ISACA認定資格   CGEIT練習問題   CGEIT練習問題   CGEIT認定証

NO.9 You work as a project manager for TYU project. You are planning for risk mitigation.
You need to identify the risks that will need a more in-depth analysis. Which of the following activities will
help you in this?
A. Estimate activity duration
B. Quantitative analysis
C. Qualitative analysis
D. Risk identification
Answer: C

ISACA問題集   CGEIT   CGEIT   CGEIT

NO.10 Mark is the project manager of the BFL project for his organization. He and the project team are
creating a probability and impact matrix using RAG rating. There is some confusion and disagreement
among the project team as to how a certain risk is important and priority for attention should be managed.
Where can Mark determine the priority of a risk given its probability and impact?
A. Risk response plan
B. Look-up table
C. Project sponsor
D. Risk management plan
Answer: B

ISACA参考書   CGEIT問題集   CGEIT認定試験   CGEIT

NO.11 Which of the following is a process that occurs due to mergers, outsourcing or changing business
needs?
A. Voluntary exit
B. Plant closing
C. Involuntary exit
D. Outplacement
Answer: C

ISACA認定試験   CGEIT過去問   CGEIT   CGEIT   CGEIT認定試験

NO.12 Beth is a project team member on the JHG Project. Beth has added extra features to the project and
this has introduced new risks to the project work. The project manager of the JHG project elects to
remove the features Beth has added. The process of removing the extra features to remove the risks is
called what?
A. Corrective action
B. Preventive action
C. Scope creep
D. Defect repair
Answer: B

ISACA   CGEIT   CGEIT

NO.13 Which of the following are the roles of a CEO in the Resource management framework?
Each correct answer represents a complete solution. Choose all that apply.
A. Organizing and facilitating IT strategic implementations
B. Establishment of business priorities & allocation of resources for IT performance
C. Overseeing the aggregate IT funding
D. Capitalization on knowledge & information
Answer: A,B,D

ISACA認定証   CGEIT   CGEIT認定試験   CGEIT   CGEIT認定試験

NO.14 Which of the following elements of planning gap measures the gap between the total potential for the
market and the actual current usage by all the consumers in the market?
A. Project gap
B. Competitive gap
C. Usage gap
D. Product gap
Answer: C

ISACA過去問   CGEIT   CGEIT   CGEIT

NO.15 You are the project manager of a large project that will last four years. In this project, you would like to
model the risk based on its distribution, impact, and other factors.
There are three modeling techniques that a project manager can use to include both event-oriented and
project oriented analysis. Which modeling technique does NOT provide event-oriented and project
oriented analysis for identified risks?
A. Modeling and simulation
B. Expected monetary value
C. Sensitivity analysis
D. Jo-Hari Window
Answer: D

ISACA認定証   CGEIT認定証   CGEIT認定証

NO.16 Which of the following essential elements of IT Portfolio Investment Management drives better
decisions by providing real-time portfolio performance information in personalized views, such as
cost/benefit summary, risk versus reward, ROI versus alignment, and balance bubble charts?
A. Workflow, Process Management, Tracking and Authorization
B. Portfolio Management
C. Integrated Dashboards and Scorecards
D. Portfolio What-If Planning
Answer: C

ISACA認定試験   CGEIT   CGEIT認定証   CGEIT練習問題   CGEIT

NO.17 Which of the following is the process of comparing the business processes and performance metrics
including cost, cycle time, productivity, or quality?
A. Agreement
B. COBIT
C. Service Improvement Plan
D. Benchmarking
Answer: D

ISACA問題集   CGEIT認定試験   CGEIT認定資格   CGEIT   CGEIT認定試験   CGEIT

NO.18 Your project spans the entire organization. You would like to assess the risk of the project but are
worried that some of the managers involved in the project could affect the outcome of any risk
identification meeting. Your worry is based on the fact that some employees would not want to publicly
identify risk events that could make their supervisors look bad. You would like a method that would allow
participants to anonymously identify risk events. What risk identification method could you use?
A. Delphi technique
B. Isolated pilot groups
C. SWOT analysis
D. Root cause analysis
Answer: A

ISACA   CGEIT   CGEIT   CGEIT   CGEIT

NO.19 Which of the following processes is described in the statement below?
"This is the process of numerically analyzing the effect of identified risks on overall project
objectives."
A. Identify Risks
B. Perform Qualitative Risk Analysis
C. Perform Quantitative Risk Analysis
D. Monitor and Control Risks
Answer: C

ISACA認定証   CGEIT   CGEIT   CGEIT問題集   CGEIT

NO.20 CORRECT TEXT
Fill in the blank with an appropriate phrase.
_________is the study of how the variation (uncertainty) in the output of a mathematical model can be
apportioned, qualitatively or quantitatively, to different sources of variation in the input of a model
Answer: Sensitivity analysis

ISACA過去問   CGEIT認定資格   CGEIT認定証

NO.21 Which of the following is NOT a sub-process of Service Portfolio Management?
A. Service Portfolio Update
B. Business Planning Data
C. Strategic Planning
D. Strategic Service Assessment
E. Service Strategy Definition
Answer: B

ISACA   CGEIT認定証   CGEIT認証試験   CGEIT問題集

NO.22 You are the business analyst for your organization and are preparing to conduct stakeholder analysis.
As part of this process you realize that you'll need several inputs.
Which one of the following is NOT an input you'll use for the conduct stakeholder analysis task?
A. Organizational process assets
B. Enterprise architecture
C. Business need
D. Enterprise environmental factors
Answer: D

ISACA   CGEIT認定試験   CGEIT   CGEIT   CGEIT

NO.23 You work as a project manager for BlueWell Inc. You are working on a project and the
management wants a rapid and cost-effective means for establishing priorities for planning risk responses
in your project. Which risk management process can satisfy management's objective for your project?
A. Quantitative analysis
B. Qualitative risk analysis
C. Historical information
D. Rolling wave planning
Answer: B

ISACA練習問題   CGEIT過去問   CGEIT過去問   CGEIT問題集

NO.24 CORRECT TEXT
Fill in the blank with an appropriate word.
________is also referred to as corporate governance, and covers issues such as board structures, roles
and executive remuneration.
Answer: Conformance

ISACA   CGEIT   CGEIT   CGEIT

NO.25 You are a management consultant. WebTech Inc., an e-commerce organization, hires you to analyze
its SWOT. Which of the following factors will you not consider for the SWOT analysis?
A. Bandwidth
B. Pricing
C. Product
D. Promotion
Answer: A

ISACA   CGEIT認定試験   CGEIT参考書   CGEIT   CGEIT   CGEIT問題集

NO.26 An organization supports both programs and projects for various industries. What is a portfolio?
A. A portfolio describes all of the monies that are invested in the organization.
B. A portfolio is the total amount of funds that have been invested in programs, projects, and operations.
C. A portfolio describes any project or program within one industry or application area.
D. A portfolio describes the organization of related projects, programs, and operations.
Answer: D

ISACA過去問   CGEIT認定試験   CGEIT参考書   CGEIT

NO.27 Your organization mainly focuses on the production of bicycles for selling it around the world. In
addition to this, the organization also produces scooters. Management wants to restrict its line of
production to bicycles. Therefore, it decides to sell the scooter production department to another
competitor. Which of the following terms best describes the sale of the scooter production department to
your competitor?
A. Corporate restructure
B. Divestiture
C. Rightsizing
D. Outsourcing
Answer: B

ISACA認定資格   CGEIT   CGEIT

NO.28 What are the various phases of the Software Assurance Acquisition process according to the U.S.
Department of Defense (DoD) and Department of Homeland Security (DHS) Acquisition and Outsourcing
Working Group?
A. Implementing, contracting, auditing, monitoring
B. Requirements, planning, monitoring, auditing
C. Designing, implementing, contracting, monitoring
D. Planning, contracting, monitoring and acceptance, follow-on
Answer: D

ISACA   CGEIT練習問題   CGEIT認証試験

NO.29 Which of the following processes is responsible for low risk, frequently occurring low cost changes?
A. Incident Management
B. IT Facilities Management
C. Release Management
D. Request Fulfillment
Answer: D

ISACA   CGEIT認定試験   CGEIT   CGEIT練習問題   CGEIT認定資格

NO.30 CORRECT TEXT
Fill in the blank with the appropriate word. An ___________ is a resource, process, product, computing
infrastructure, and so forth that an organization has determined must be protected.
Answer: asset

ISACA   CGEIT認定資格   CGEIT   CGEIT   CGEIT   CGEIT認定試験

JPexamは最新の1z0-481問題集と高品質の648-385問題と回答を提供します。JPexamのMB2-866 VCEテストエンジンとHP2-W100試験ガイドはあなたが一回で試験に合格するのを助けることができます。高品質のVCAW510 PDFトレーニング教材は、あなたがより迅速かつ簡単に試験に合格することを100%保証します。試験に合格して認証資格を取るのはそのような簡単なことです。

記事のリンク:http://www.jpexam.com/CGEIT_exam.html

2014年4月5日星期六

ISACA CISM認定試験を受験したいならこの問題集を推奨

IT職員としてのあなたは昇進したいのですか。プロなIT技術専門家になりたいのですか。速くISACAのCISM認定試験を申し込みましょう。この認証がどんなに重要するかあなたもよく知っています。試験に合格できないなんて心配しないで、あなたの能力を疑わないでください。ISACAのCISM認定試験を受けたいのなら、試験の準備に関する全ての質問がJPexamは解決して差し上げます。JPexamはIT認証に対するプロなサイトです。JPexamがそばのいてあげたら、全ての難問が解決できます。JPexamに助けられた受験生は数え切れないです。JPexamをクロックしたら、100パーセントの成功を差し上げます。

CISMはISACAの一つ認証試験として、もしISACA認証試験に合格してIT業界にとても人気があってので、ますます多くの人がCISM試験に申し込んで、CISM試験は簡単ではなくて、時間とエネルギーがかかって用意しなければなりません。

IT業界で仕事している皆さんはIT認定試験の資格の重要性をよく知っていているでしょう。IT認定試験には多くの種類があります。現在最も人気がある試験もいろいろあります。例えばCISM認定試験などです。その中の試験、どちらを受験しましたか。もし一つの認証資格を持っていないなら、IT認定試験を申し込んで試験の資格を取得する必要があります。試験を受ける予定があれば、急いでJPexamへ来て必要な情報を見つけましょう。JPexamはあなたがCISM認定試験に合格する保障ですから。

試験番号:CISM問題集
試験科目:Certified Information Security Manager
最近更新時間:2014-04-05
問題と解答:全633問
100%の返金保証。1年間の無料アップデート。

JPexamのIT認証試験問題集は長年のトレーニング経験を持っています。JPexam ISACAのCISM試験トレーニング資料は信頼できる製品です。当社のスタッフ は受験生の皆様が試験で高い点数を取ることを保証できるように、巨大な努力をして皆様に最新版のCISM試験トレーニング資料を提供しています。JPexam ISACAのCISM試験材料は最も実用的なIT認定材料を提供することを確認することができます。

購入前にお試し,私たちの試験の質問と回答のいずれかの無料サンプルをダウンロード:http://www.jpexam.com/CISM_exam.html

NO.1 Which of the following results from the risk assessment process would BEST assist risk management
decision making?
A. Control risk
B. Inherent risk
C. Risk exposure
D. Residual risk
Answer: D

ISACA練習問題   CISM参考書   CISM練習問題   CISM

NO.2 Which of the following BEST describes an information security manager's role in a multidisciplinary
team that will address a new regulatory requirement regarding operational risk?
A. Ensure that all IT risks are identified
B. Evaluate the impact of information security risks
C. Demonstrate that IT mitigating controls are in place
D. Suggest new IT controls to mitigate operational risk
Answer: B

ISACA認定証   CISM   CISM   CISM

NO.3 Which of the following is characteristic of centralized information security management?
A. More expensive to administer
B. Better adherence to policies
C. More aligned with business unit needs
D. Faster turnaround of requests
Answer: B

ISACA問題集   CISM   CISM認定資格   CISM   CISM練習問題   CISM

NO.4 It is MOST important that information security architecture be aligned with which of the following?
A. Industry best practices
B. Information technology plans
C. Information security best practices
D. Business objectives and goals
Answer: D

ISACA   CISM   CISM   CISM   CISM

NO.5 What will have the HIGHEST impact on standard information security governance models?
A. Number of employees
B. Distance between physical locations
C. Complexity of organizational structure
D. Organizational budget
Answer: C

ISACA   CISM参考書   CISM参考書

NO.6 A security manager meeting the requirements for the international flow of personal data will need to
ensure:
A. a data processing agreement.
B. a data protection registration.
C. the agreement of the data subjects.
D. subject access procedures.
Answer: C

ISACA問題集   CISM   CISM   CISM参考書

NO.7 Which of the following will BEST protect an organization from internal security attacks?
A. Static IP addressing
B. Internal address translation
C. Prospective employee background checks
D. Employee awareness certification program
Answer: C

ISACA参考書   CISM   CISM問題集   CISM   CISM問題集

NO.8 The MOST important component of a privacy policy is:
A. notifications
B. warranties
C. liabilities
D. geographic coverage
Answer: A

ISACA   CISM認定資格   CISM認証試験

NO.9 What would a security manager PRIMARILY utilize when proposing the implementation of a security
solution?
A. Risk assessment report
B. Technical evaluation report
C. Business case
D. Budgetary requirements
Answer: C

ISACA   CISM   CISM認定証   CISM認証試験   CISM

NO.10 The PRIMARY goal in developing an information security strategy is to:
A. establish security metrics and performance monitoring.
B. educate business process owners regarding their duties.
C. ensure that legal and regulatory requirements are met.
D. support the business objectives of the organization.
Answer: D

ISACA認定証   CISM   CISM   CISM認定証

NO.11 Security technologies should be selected PRIMARILY on the basis of their:
A. ability to mitigate business risks
B. evaluations in trade publications
C. use of new and emerging technologies
D. benefits in comparison to their costs
Answer: A

ISACA   CISM   CISM問題集

NO.12 Senior management commitment and support for information security can BEST be obtained through
presentations that:
A. use illustrative examples of successful attacks.
B. explain the technical risks to the organization.
C. evaluate the organization against best security practices.
D. tie security risks to key business objectives.
Answer: D

ISACA   CISM参考書   CISM問題集   CISM

NO.13 What is the PRIMARY role of the information security manager in the process of information
classification within an organization?
A. Defining and ratifying the classification structure of information assets
B. Deciding the classification levels applied to the organization's information assets
C. Securing information assets in accordance with their classification
D. Checking if information assets have been classified properly
Answer: A

ISACA   CISM   CISM認定試験   CISM

NO.14 Temporarily deactivating some monitoring processes, even if supported by an acceptance of
operational risk, may not be acceptable to the information security manager if:
A. it implies compliance risks.
B. short-term impact cannot be determined.
C. it violates industry security practices.
D. changes in the roles matrix cannot be detected.
Answer: A

ISACA   CISM   CISM   CISM   CISM   CISM認証試験

NO.15 Identification and prioritization of business risk enables project managers to:
A. establish implementation milestones.
B. reduce the overall amount of slack time.
C. address areas with most significance.
D. accelerate completion of critical paths.
Answer: C

ISACA認定証   CISM   CISM認定証   CISM

NO.16 In order to highlight to management the importance of integrating information security in the business
processes, a newly hired information security officer should FIRST:
A. prepare a security budget.
B. conduct a risk assessment.
C. develop an information security policy.
D. obtain benchmarking information.
Answer: B

ISACA   CISM   CISM認定試験   CISM問題集

NO.17 Which of the following is responsible for legal and regulatory liability?
A. Chief security officer (CSO)
B. Chief legal counsel (CLC)
C. Board and senior management
D. Information security steering group
Answer: C

ISACA認定証   CISM   CISM認証試験

NO.18 Based on the information provided, which of the following situations presents the GREATEST
information security risk for an organization with multiple, but small, domestic processing locations?
A. Systems operation procedures are not enforced
B. Change management procedures are poor
C. Systems development is outsourced
D. Systems capacity management is not performed
Answer: B

ISACA認定証   CISM参考書   CISM

NO.19 How would an information security manager balance the potentially conflicting requirements of an
international organization's security standards and local regulation?
A. Give organization standards preference over local regulations
B. Follow local regulations only
C. Make the organization aware of those standards where local regulations causes conflicts
D. Negotiate a local version of the organization standards
Answer: D

ISACA   CISM認定証   CISM認定資格   CISM過去問   CISM練習問題

NO.20 A risk assessment should be conducted:
A. once a year for each business process andsubprocess.
B. every three-to-six months for critical business processes.
C. by external parties to maintain objectivity.
D. annually or whenever there is a significant change.
Answer: D

ISACA認定資格   CISM問題集   CISM

NO.21 An information security manager at a global organization that is subject to regulation by multiple
governmental jurisdictions with differing requirements should:
A. bring all locations into conformity with the aggregate requirements of all governmental jurisdictions.
B. establish baseline standards for all locations and add supplemental standards as required.
C. bring all locations into conformity with a generally accepted set of industry best practices.
D. establish a baseline standard incorporating those requirements that all jurisdictions have in common.
Answer: B

ISACA   CISM認証試験   CISM   CISM

NO.22 Logging is an example of which type of defense against systems compromise?
A. Containment
B. Detection
C. Reaction
D. Recovery
Answer: B

ISACA   CISM   CISM   CISM

NO.23 Which of the following factors is a primary driver for information security governance that does not
require any further justification?
A. Alignment with industry best practices
B. Business continuity investment
C. Business benefits
D. Regulatory compliance
Answer: D

ISACA参考書   CISM   CISM参考書   CISM

NO.24 From an information security manager perspective, what is the immediate benefit of clearly-defined
roles and responsibilities?
A. Enhanced policy compliance
B. Improved procedure flows
C. Segregation of duties
D. Better accountability
Answer: D

ISACA練習問題   CISM   CISM過去問   CISM認定資格   CISM

NO.25 Acceptable risk is achieved when:
A. residual risk is minimized.
B. transferred risk is minimized.
C. control risk is minimized.
D. inherent risk is minimized.
Answer: A

ISACA   CISM練習問題   CISM   CISM

NO.26 Which of the following is MOST important in developing a security strategy?
A. Creating a positive business security environment
B. Understanding key business objectives
C. Having a reporting line to senior management
D. Allocating sufficient resources to information security
Answer: B

ISACA   CISM参考書   CISM認定資格   CISM   CISM認定資格

NO.27 Who in an organization has the responsibility for classifying information?
A. Data custodian
B. Database administrator
C. Information security officer
D. Data owner
Answer: D

ISACA認証試験   CISM   CISM   CISM   CISM認証試験   CISM認定証

NO.28 To achieve effective strategic alignment of security initiatives, it is important that:
A. steering committee leadershipbe selected by rotation.
B. inputs be obtained and consensus achieved between the major organizational units.
C. the business strategybe updated periodically.
D. procedures and standardsbe approved by all departmental heads.
Answer: B

ISACA   CISM   CISM   CISM参考書   CISM認定試験

NO.29 Risk management programs are designed to reduce risk to:
A. a level that is too small to be measurable.
B. the point at which the benefit exceeds the expense.
C. a level that the organization is willing to accept.
D. a rate of return that equals the current cost of capital.
Answer: C

ISACA   CISM   CISM   CISM認定証

NO.30 An internal audit has identified major weaknesses over IT processing. Which of the following should an
information security manager use to BEST convey a sense of urgency to management?
A. Security metrics reports
B. Risk assessment reports
C. Business impact analysis (BIA)
D. Return on security investment report
Answer: B

ISACA過去問   CISM   CISM過去問   CISM認定資格

JPexamは最新の000-129問題集と高品質のC_TFIN52_64問題と回答を提供します。JPexamの1Z0-033 VCEテストエンジンとC4040-224試験ガイドはあなたが一回で試験に合格するのを助けることができます。高品質の1z0-457 PDFトレーニング教材は、あなたがより迅速かつ簡単に試験に合格することを100%保証します。試験に合格して認証資格を取るのはそのような簡単なことです。

記事のリンク:http://www.jpexam.com/CISM_exam.html

2014年3月31日星期一

ISACA CRISC認定試験の最高の問題集の一部を無料で捧げる

JPexamあなたに 最高のISACAのCRISC試験問題集を提供して差し上げます。あなたを成功への道に引率します。JPexamのISACAのCRISC試験トレーニング資料は試験の準備をしているあなたにヘルプを与えます。当社の資料はあなたがIT専門家になるように特別に受験生の皆さんのために作成したものです。JPexamのISACAのCRISC試験トレーニング資料はあなたに最も適用して、あなたのニーズを満たす資料です。はやくJPexamのサイトを登録してくだい。きっと棚ぼたがありますよ。

JPexamは100%の合格率を保証するだけでなく、1年間の無料なオンラインの更新を提供しております。最新の資源と最新の動態が第一時間にお客様に知らせいたします。何の問題があったらお気軽に聞いてください。

JPexamは正確な選択を与えて、君の悩みを減らして、もし早くてISACA CRISC認証をとりたければ、早くてJPexamをショッピングカートに入れましょう。あなたにとても良い指導を確保できて、試験に合格するのを助けって、JPexamからすぐにあなたの通行証をとります。

試験番号:CRISC問題集
試験科目:Certified in Risk and Information Systems Control
最近更新時間:2014-03-31
問題と解答:全395問
100%の返金保証。1年間の無料アップデート。

JPexamのCRISC問題集は実際のCRISC認定試験と同じです。この問題集は実際試験の問題をすべて含めることができるだけでなく、問題集のソフト版はCRISC試験の雰囲気を完全にシミュレートすることもできます。JPexamの問題集を利用してから、試験を受けるときに簡単に対処し、楽に高い点数を取ることができます。

JPexamのISACAのCRISC試験資料は同じシラバスに従って研究されたのです。それに、資料もずっとアップグレードしていますから、実際の試験問題とよく似ています。JPexamの試験合格率も非常に高いことは否定することができない事実です。JPexamのISACAのCRISC試験トレーニング資料の値段は手頃で、IT認証の受験生のみなさんによく適用します。

ISACAのCRISC認定試験を受験したいですか。試験がたいへん難しいですから悩んでいるのですか。試験を申し込みたいですが、合格できないことが心配します。いまこのような気持ちを持っていますか。大丈夫ですよ。安心にCRISC試験を申し込みましょう。JPexamの試験参考書を使用する限り、どんなに難しい試験でも問題にならないです。試験に合格する自信を全然持っていなくても、JPexamのCRISC問題集はあなたが一度簡単に成功することを保証できます。不思議と思っていますか。では、JPexamのウェブサイトへ来てもっと多くの情報をブラウズすることもできます。それに、CRISC問題集の一部を試用することもできます。そうすると、この参考書が確かにあなたが楽に試験に合格する保障ということをきっと知るようになります。

購入前にお試し,私たちの試験の質問と回答のいずれかの無料サンプルをダウンロード:http://www.jpexam.com/CRISC_exam.html

JPexamは最新の74-325問題集と高品質の74-353問題と回答を提供します。JPexamの646-365 VCEテストエンジンと70-341試験ガイドはあなたが一回で試験に合格するのを助けることができます。高品質の642-832 PDFトレーニング教材は、あなたがより迅速かつ簡単に試験に合格することを100%保証します。試験に合格して認証資格を取るのはそのような簡単なことです。

記事のリンク:http://www.jpexam.com/CRISC_exam.html

2013年12月6日星期五

Latest ISACA CRISC of exam practice questions and answers free download

The person who has been able to succeed is because that he believed he can do it. IT-Tests.com is able to help each IT person, because it has the capability. IT-Tests.com ISACA CRISC exam training materials can help you to pass the exam. Any restrictions start from your own heart, if you want to pass the ISACA CRISC examination, you will choose the IT-Tests.com.

Through the ISACA certification CRISC exam method has a lot of kinds, spend a lot of time and energy to review the ISACA certification CRISC exam related professional knowledge is a kind of method, through a small amount of time and money IT-Tests.com choose to use the pertinence training and exercises is also a kind of method.

IT-Tests.com is an excellent IT certification examination information website. In IT-Tests.com you can find exam tips and materials about ISACA certification CRISC exam. You can also free download part of examination questions and answers about ISACA CRISC in IT-Tests. IT-Tests.com will timely provide you free updates about ISACA CRISC exam materials. Besides, the exam materials we sold are to provide the answers. Our IT experts team will continue to take advantage of professional experience to come up with accurate and detailed exam practice questions to help you pass the exam. In short, we will provide you with everything you need about ISACA certification CRISC exam.

IT-Tests.com provide you with a clear and excellent choice and reduce your troubles. Do you want early success? Do you want to quickly get ISACA certification CRISC exam certificate? Hurry to add IT-Tests.com to your Shopping Cart. IT-Tests.com will give you a good guide to ensure you pass the exam. Using IT-Tests.com can quickly help you get the certificate you want.

You can free download part of IT-Tests's exercises and answers about ISACA certification CRISC exam as a try, then you will be more confident to choose our IT-Tests's products to prepare your ISACA certification CRISC exam. Please add IT-Tests's products in you cart quickly.

Exam Code: CRISC
Exam Name: ISACA (Certified in Risk and Information Systems Control)
Free One year updates to match real exam scenarios, 100% pass and refund Warranty.
Total Q&A: 395 Questions and Answers
Last Update: 2013-12-06

CRISC (Certified in Risk and Information Systems Control) Free Demo Download: http://www.it-tests.com/CRISC.html

IT-Tests.com offer the latest MSC-431 Questions & Answers and high-quality 00M-620 PDF Practice Test. Our BAS-004 VCE testing engine and 000-123 study guide can help you pass the real exam. High-quality C-TSCM62-65 Real Exam Questions can 100% guarantee you pass the exam faster and easier. Pass the exam to obtain certification is so simple.

Article Link: http://www.it-tests.com/CRISC.html

2013年9月19日星期四

ISACA certification CGEIT exam targeted exercises

IT-Tests.com senior experts have developed exercises and answers about ISACA certification CGEIT exam with their knowledge and experience, which have 95% similarity with the real exam. I believe that you will be very confident of our products. If you choose to use IT-Tests's products, IT-Tests.com can help you 100% pass your first time to attend ISACA certification CGEIT exam. If you fail the exam, we will give a full refund to you.

IT-Tests.com's ISACA CGEIT exam training materials are the best training materials of all the Internet training resources. Our visibility is very high, which are results that obtained through many candidates who have used the IT-Tests.com's ISACA CGEIT exam training materials. If you also use IT-Tests.com's ISACA CGEIT exam training materials, we can give you 100% guarantee of success. If you do not pass the exam, we will refund the full purchase cost to you . For the vital interests of the majority of candidates, IT-Tests.com is absolutely trustworthy.

CGEIT exam is a new turning point in the IT industry. Get this examination certification, you will become the IT industry's professional high-end person. With the spread and progress of information technology, you will see hundreds of online resources which provide ISACA CGEIT questions and answers. While IT-Tests.com ahead. The reason people choose IT-Tests.com ISACA CGEIT exam training materials is that it can really bring benefits to them, and to help you come true your dreams as soon as possible!

A lot of my friends from IT industry in order to pass ISACA certification CGEIT exam have spend a lot of time and effort, but they did not choose training courses or online training, so passing the exam is so difficult for them and generally, the disposable passing rate is very low. Fortunately, IT-Tests.com can provide you the most reliable training tool for you. IT-Tests.com provide training resource that include simulation test software, simulation test, practice questions and answers about ISACA certification CGEIT exam. We can provide the best and latest practice questions and answers of ISACA certification CGEIT exam to meet your need.

God wants me to be a person who have strength, rather than a good-looking doll. When I chose the IT industry I have proven to God my strength. But God forced me to keep moving. ISACA CGEIT exam is a major challenge in my life, so I am desperately trying to learn. But it does not matter, because I purchased IT-Tests.com's ISACA CGEIT exam training materials. With it, I can pass the ISACA CGEIT exam easily. Road is under our feet, only you can decide its direction. To choose IT-Tests.com's ISACA CGEIT exam training materials, and it is equivalent to have a better future.

IT-Tests.com IT Certification has years of training experience. IT-Tests.com ISACA CGEIT exam training materials is a reliable product. IT elite team continue to provide our candidates with the latest version of the CGEIT exam training materials. Our staff made ​​great efforts to ensure that you always get good grades in examinations. To be sure, IT-Tests.com ISACA CGEIT exam materials can provide you with the most practical IT certification material.

Exam Code: CGEIT
Exam Name: ISACA (ISACA CGEIT Certification Practice Test)
Free One year updates to match real exam scenarios, 100% pass and refund Warranty.
Total Q&A: 279 Questions and Answers
Last Update: 2013-09-19

IT-Tests.com ISACA CGEIT Training Kit is designed and ready by IT-Tests.com IT experts. Its design is closely linked to today's rapidly changing IT market. . IT-Tests.com training to help you take advantage of the continuous development of technology to improve the ability to solve problems, and improve your job satisfaction. The coverage IT-Tests.com ISACA CGEIT questions can reach 100% , as long as you use our questions and answers, we guarantee you pass the exam the first time!

CGEIT (ISACA CGEIT Certification Practice Test) Free Demo Download: http://www.it-tests.com/CGEIT.html

NO.1 An organization supports both programs and projects for various industries. What is a portfolio?
A. A portfolio describes all of the monies that are invested in the organization.
B. A portfolio is the total amount of funds that have been invested in programs, projects, and operations.
C. A portfolio describes any project or program within one industry or application area.
D. A portfolio describes the organization of related projects, programs, and operations.
Answer: D

ISACA demo   CGEIT answers real questions   CGEIT   CGEIT test answers   CGEIT study guide   CGEIT dumps

NO.2 What are the various phases of the Software Assurance Acquisition process according to the U.S.
Department of Defense (DoD) and Department of Homeland Security (DHS) Acquisition and Outsourcing
Working Group?
A. Implementing, contracting, auditing, monitoring
B. Requirements, planning, monitoring, auditing
C. Designing, implementing, contracting, monitoring
D. Planning, contracting, monitoring and acceptance, follow-on
Answer: D

ISACA   CGEIT   CGEIT study guide   CGEIT original questions   CGEIT

NO.3 You work as a project manager for BlueWell Inc. You are working on a project and the
management wants a rapid and cost-effective means for establishing priorities for planning risk responses
in your project. Which risk management process can satisfy management's objective for your project?
A. Quantitative analysis
B. Qualitative risk analysis
C. Historical information
D. Rolling wave planning
Answer: B

ISACA   CGEIT exam prep   CGEIT   CGEIT

NO.4 You are the project manager of the NHQ project for your company. You are working with your project
team to complete a risk audit. A recent issue that your project team responded to, and management
approved, was to increase the project schedule because there was risk surrounding the installation time
of a new material. Your logic was that with the expanded schedule there would be time to complete the
installation without affecting downstream project activities. What type of risk response is being audited in
this scenario?
A. Avoidance
B. Mitigation
C. Parkinson's Law
D. Lag Time
Answer: A

ISACA   CGEIT   CGEIT   CGEIT

NO.5 Mark is the project manager of the BFL project for his organization. He and the project team are
creating a probability and impact matrix using RAG rating. There is some confusion and disagreement
among the project team as to how a certain risk is important and priority for attention should be managed.
Where can Mark determine the priority of a risk given its probability and impact?
A. Risk response plan
B. Look-up table
C. Project sponsor
D. Risk management plan
Answer: B

ISACA answers real questions   CGEIT test   CGEIT exam   CGEIT study guide   CGEIT

NO.6 Which of the following is NOT a sub-process of Service Portfolio Management?
A. Service Portfolio Update
B. Business Planning Data
C. Strategic Planning
D. Strategic Service Assessment
E. Service Strategy Definition
Answer: B

ISACA practice test   CGEIT answers real questions   CGEIT pdf   CGEIT

NO.7 Mary is the business analyst for your organization. She asks you what the purpose of the assess
capability gaps task is. Which of the following is the best response to give Mary?
A. It identifies the causal factors that are contributing to an effect the solution will solve.
B. It identifies new capabilities required by the organization to meet the business need.
C. It describes the ends that the organization wants to improve.
D. It identifies the skill gaps in the existing resources.
Answer: B

ISACA test   CGEIT   CGEIT   CGEIT

NO.8 Beth is a project team member on the JHG Project. Beth has added extra features to the project and
this has introduced new risks to the project work. The project manager of the JHG project elects to
remove the features Beth has added. The process of removing the extra features to remove the risks is
called what?
A. Corrective action
B. Preventive action
C. Scope creep
D. Defect repair
Answer: B

ISACA answers real questions   CGEIT   CGEIT   CGEIT

NO.9 Which of the following elements of planning gap measures the gap between the total potential for the
market and the actual current usage by all the consumers in the market?
A. Project gap
B. Competitive gap
C. Usage gap
D. Product gap
Answer: C

ISACA   CGEIT dumps   CGEIT exam simulations   CGEIT   CGEIT

NO.10 Benchmarking is a continuous process that can be time consuming to do correctly.
Which of the following guidelines for performing benchmarking identifies the critical processes and
creates measurement techniques to grade the process?
A. Research
B. Adapt
C. Plan
D. Improve
Answer: C

ISACA study guide   CGEIT   CGEIT

NO.11 You are the project manager for your organization. You are preparing for the quantitative risk analysis.
Mark, a project team member, wants to know why you need to do quantitative risk analysis when you just
completed qualitative risk analysis. Which one of the following statements best defines what quantitative
risk analysis is.?
A. Quantitative risk analysis is the process of prioritizing risks for further analysis or action by assessing
and combining their probability of occurrence and impact.
B. Quantitative risk analysis is the planning and quantification of risk responses based on
probability and impact of each risk event.
C. Quantitative risk analysis is the review of the risk events with the high probability and the highest
impact on the project objectives.
D. Quantitative risk analysis is the process of numerically analyzing the effect of identified risks on overall
project objectives.
Answer: D

ISACA original questions   CGEIT   CGEIT practice test   CGEIT

NO.12 Your organization mainly focuses on the production of bicycles for selling it around the world. In
addition to this, the organization also produces scooters. Management wants to restrict its line of
production to bicycles. Therefore, it decides to sell the scooter production department to another
competitor. Which of the following terms best describes the sale of the scooter production department to
your competitor?
A. Corporate restructure
B. Divestiture
C. Rightsizing
D. Outsourcing
Answer: B

ISACA test   CGEIT dumps   CGEIT study guide   CGEIT   CGEIT

NO.13 You work as a project manager for TYU project. You are planning for risk mitigation.
You need to identify the risks that will need a more in-depth analysis. Which of the following activities will
help you in this?
A. Estimate activity duration
B. Quantitative analysis
C. Qualitative analysis
D. Risk identification
Answer: C

ISACA   CGEIT   CGEIT certification training   CGEIT

NO.14 You are a management consultant. WebTech Inc., an e-commerce organization, hires you to analyze
its SWOT. Which of the following factors will you not consider for the SWOT analysis?
A. Bandwidth
B. Pricing
C. Product
D. Promotion
Answer: A

ISACA dumps   CGEIT test answers   CGEIT   CGEIT certification training   CGEIT practice test

NO.15 Which of the following processes is responsible for low risk, frequently occurring low cost changes?
A. Incident Management
B. IT Facilities Management
C. Release Management
D. Request Fulfillment
Answer: D

ISACA certification   CGEIT   CGEIT demo   CGEIT

NO.16 CORRECT TEXT
Fill in the blank with an appropriate phrase.
_________is the study of how the variation (uncertainty) in the output of a mathematical model can be
apportioned, qualitatively or quantitatively, to different sources of variation in the input of a model
Answer: Sensitivity analysis

ISACA demo   CGEIT   CGEIT practice test   CGEIT test   CGEIT

NO.17 CORRECT TEXT
Fill in the blank with an appropriate phrase.
_________models address specifications, requirements, design, verification and validation, and
maintenance activities.
Answer: Life cycle

ISACA practice test   CGEIT   CGEIT   CGEIT test   CGEIT

NO.18 Which of the following processes is described in the statement below?
"This is the process of numerically analyzing the effect of identified risks on overall project
objectives."
A. Identify Risks
B. Perform Qualitative Risk Analysis
C. Perform Quantitative Risk Analysis
D. Monitor and Control Risks
Answer: C

ISACA   CGEIT   CGEIT   CGEIT practice test

NO.19 Which of the following are the roles of a CEO in the Resource management framework?
Each correct answer represents a complete solution. Choose all that apply.
A. Organizing and facilitating IT strategic implementations
B. Establishment of business priorities & allocation of resources for IT performance
C. Overseeing the aggregate IT funding
D. Capitalization on knowledge & information
Answer: A,B,D

ISACA   CGEIT   CGEIT demo

NO.20 Jenny is the project manager for the NBT projects. She is working with the project team and several
subject matter experts to perform the quantitative risk analysis process.
During this process she and the project team uncover several risks events that were not previously
identified. What should Jenny do with these risk events?
A. The events should be determined if they need to be accepted or responded to.
B. The events should be entered into the risk register.
C. The events should continue on with quantitative risk analysis.
D. The events should be entered into qualitative risk analysis.
Answer: B

ISACA practice test   CGEIT   CGEIT

NO.21 You are the project manager for your organization and you are working with Thomas, a project team
member. You and Thomas have been working on a specific risk response for a probable risk event in the
project. Thomas is empowered with a risk response and will control all aspects of the identified risk
response in which a particular risk event will happen within the project. What title, in regard to risk, is
bestowed on Thomas?
A. Risk coordinator
B. Risk expeditor
C. Risk owner
D. Risk team leader
Answer: C

ISACA   CGEIT   CGEIT

NO.22 CORRECT TEXT
Fill in the blank with an appropriate word.
________is also referred to as corporate governance, and covers issues such as board structures, roles
and executive remuneration.
Answer: Conformance

ISACA braindump   CGEIT   CGEIT test questions   CGEIT   CGEIT

NO.23 Which of the following essential elements of IT Portfolio Investment Management drives better
decisions by providing real-time portfolio performance information in personalized views, such as
cost/benefit summary, risk versus reward, ROI versus alignment, and balance bubble charts?
A. Workflow, Process Management, Tracking and Authorization
B. Portfolio Management
C. Integrated Dashboards and Scorecards
D. Portfolio What-If Planning
Answer: C

ISACA   CGEIT exam   CGEIT exam

NO.24 Which of the following is the process of comparing the business processes and performance metrics
including cost, cycle time, productivity, or quality?
A. Agreement
B. COBIT
C. Service Improvement Plan
D. Benchmarking
Answer: D

ISACA dumps   CGEIT   CGEIT   CGEIT study guide   CGEIT dumps

NO.25 Your project spans the entire organization. You would like to assess the risk of the project but are
worried that some of the managers involved in the project could affect the outcome of any risk
identification meeting. Your worry is based on the fact that some employees would not want to publicly
identify risk events that could make their supervisors look bad. You would like a method that would allow
participants to anonymously identify risk events. What risk identification method could you use?
A. Delphi technique
B. Isolated pilot groups
C. SWOT analysis
D. Root cause analysis
Answer: A

ISACA braindump   CGEIT   CGEIT questions   CGEIT   CGEIT

NO.26 Which of the following is a process that occurs due to mergers, outsourcing or changing business
needs?
A. Voluntary exit
B. Plant closing
C. Involuntary exit
D. Outplacement
Answer: C

ISACA   CGEIT   CGEIT

NO.27 You are the business analyst for your organization and are preparing to conduct stakeholder analysis.
As part of this process you realize that you'll need several inputs.
Which one of the following is NOT an input you'll use for the conduct stakeholder analysis task?
A. Organizational process assets
B. Enterprise architecture
C. Business need
D. Enterprise environmental factors
Answer: D

ISACA braindump   CGEIT answers real questions   CGEIT exam   CGEIT

NO.28 DRAG DROP
Val IT is a suite of documents that provide a framework for the governance of IT investments, produced by
the IT Governance Institute (ITGI). It is a formal statement of principles and processes for IT portfolio
management. Drag and drop the correct domain ('Portfolio management') next to the IT processes
defined by Val IT.
Answer:

NO.29 CORRECT TEXT
Fill in the blank with the appropriate word. An ___________ is a resource, process, product, computing
infrastructure, and so forth that an organization has determined must be protected.
Answer: asset

ISACA answers real questions   CGEIT demo   CGEIT   CGEIT   CGEIT

NO.30 You are the project manager of a large project that will last four years. In this project, you would like to
model the risk based on its distribution, impact, and other factors.
There are three modeling techniques that a project manager can use to include both event-oriented and
project oriented analysis. Which modeling technique does NOT provide event-oriented and project
oriented analysis for identified risks?
A. Modeling and simulation
B. Expected monetary value
C. Sensitivity analysis
D. Jo-Hari Window
Answer: D

ISACA   CGEIT test answers   CGEIT

IT-Tests.com offer the latest JN0-533 Questions & Answers and high-quality MB5-854 PDF Practice Test. Our JN0-690 VCE testing engine and LOT-958 study guide can help you pass the real exam. High-quality 000-540 Real Exam Questions can 100% guarantee you pass the exam faster and easier. Pass the exam to obtain certification is so simple.

Article Link: http://www.it-tests.com/CGEIT.html

2013年8月29日星期四

ISACA certification CISA exam training methods

Feedbacks of many IT professionals who have passed ISACA certification CISA exam prove that their successes benefit from IT-Tests's help. IT-Tests's targeted test practice questions and answers to gave them great help, which save their valuable time and energy, and allow them to easily and smoothly pass their first ISACA certification CISA exam. So IT-Tests.com a website worthy of your trust. Please select IT-Tests, you will be the next successful IT person. IT-Tests.com will help you achieve your dream.

You choosing IT-Tests.com to help you pass ISACA certification CISA exam is a wise choice. You can first online free download IT-Tests's trial version of exercises and answers about ISACA certification CISA exam as a try, then you will be more confident to choose IT-Tests's product to prepare for ISACA certification CISA exam. If you fail the exam, we will give you a full refund.

IT exam become more important than ever in today's highly competitive world, these things mean a different future. ISACA CISA exam will be a milestone in your career, and may dig into new opportunities, but how do you pass ISACA CISA exam? Do not worry, help is at hand, with IT-Tests.com you no longer need to be afraid. IT-Tests.com ISACA CISA exam questions and answers is the pioneer in exam preparation.

Exam Code: CISA
Exam Name: ISACA Isaca CISA CISA
Free One year updates to match real exam scenarios, 100% pass and refund Warranty.
Updated: 2013-08-29

Each IT person is working hard for promotion and salary increases. It is also a reflection of the pressure of modern society. We should use the strength to prove ourselves. Participate in the ISACA CISA exam please. In fact, this examination is not so difficult as what you are thinking. You only need to select the appropriate training materials. IT-Tests.com's ISACA CISA exam training materials is the best training materials. Select the materials is to choose what you want. In order to enhance your own, do it quickly.

CISA (Isaca CISA ) Free Demo Download: http://www.it-tests.com/CISA.html

NO.1 Which of the following devices extends the network and has the capacity to store frames and act as a
storage and forward device?
A. Router
B. Bridge
C. Repeater
D. Gateway
Answer: B

ISACA study guide   CISA certification   CISA exam simulations
Explanation:
A bridge connects two separate networks to form a logical network (e.g., joining an ethernet and token
network) and has the storage capacity to store frames and act as a storage and forward device. Bridges
operate at the OSI data link layer by examining the media access control header of a data packet.
Incorrect answers:
A. Routers are switching devices that operate at the OSI network layer by examining network addresses
(i.e., routing information encoded in an IP packet). The router, by examining the IP address, can make
intelligent decisions in directing the packet to its destination.
C. Repeaters amplify transmission signals to reach remote devices by taking a signal from a LAN,
reconditioning and retiming it, and sending it to another. This functionality is hardware encoded and
occurs at the OSI physical layer.
D. Gateways provide access paths to foreign networks.

NO.2 A critical function of a firewall is to act as a:
A. special router that connects the Internet to a LAN.
B. device for preventing authorized users from accessing the LAN.
C. server used to connect authorized users to private trusted network resources.
D. proxy server to increase the speed of access to authorized users.
Answer: B

ISACA   CISA   CISA   CISA pdf
Explanation:
A firewall is a set of related programs, located at a network gateway server, that protects the resources of
a private network from users of other networks. An enterprise with an intranet that allows its workers
access to the wider Internet installs a firewall to prevent outsiders from accessing its own private data
resources and for controlling the outside resources to which its own users have access. Basically, a
firewall, working closely with a router program, filters all network packets to determine whether or not to
forward them toward their destination. A firewall includes or works with a proxy server that makes network
requests on behalf of workstation users. A firewall is often installed in a specially designated computer
separate from the rest of the network so no incoming request can get directed to private network
resources.

NO.3 The MOST significant level of effort for business continuity planning (BCP) generally is required during
the:
A. testing stage.
B. evaluation stage.
C. maintenance stage.
D. early stages of planning.
Answer: D

ISACA demo   CISA   CISA certification   CISA
Explanation:
Company.com in the early stages of a BCP will incur the most significant level of program development
effort, which will level out as the BCP moves into maintenance, testing and evaluation stages. It is during
the planning stage that an IS auditor will play an important role in obtaining senior management's
commitment to resources and assignment of BCP responsibilities.

NO.4 A data administrator is responsible for: A. maintaining database system software.
B. defining data elements, data names and their relationship.
C. developing physical database structures.
D. developing data dictionary system software.
Answer: B

ISACA dumps   CISA   CISA   CISA certification   CISA
Explanation:
A data administrator is responsible for defining data elements, data names and their relationship. Choices
A, C and D are functions of a database administrator (DBA)

NO.5 Structured programming is BEST described as a technique that:
A. provides knowledge of program functions to other programmers via peer reviews.
B. reduces the maintenance time of programs by the use of small-scale program modules.
C. makes the readable coding reflect as closely as possible the dynamic execution of the program.
D. controls the coding and testing of the high-level functions of the program in the development process.
Answer: B

ISACA   CISA exam simulations   CISA study guide
Explanation:
A characteristic of structured programming is smaller, workable units. Structured programming has
evolved because smaller, workable units are easier to maintain. Structured programming is a style of
programming which restricts the kinds of control structures. This limitation is not crippling. Any program
can be written with allowed control structures. Structured programming is sometimes referred to as
go-to-less programming, since a go-to statement is not allowed. This is perhaps the most well known
restriction of the style, since go-to statements were common at the time structured programming was
becoming more popular. Statement labels also become unnecessary, except in languages where
subroutines are identified by labels.

NO.6 IS management has decided to rewrite a legacy customer relations system using fourth generation
languages (4GLs). Which of the following risks is MOST often associated with system development using
4GLs?
A. Inadequate screen/report design facilities
B. Complex programming language subsets
C. Lack of portability across operating systems
D. Inability to perform data intensive operations
Answer: D

ISACA   CISA answers real questions   CISA
Explanation:
4.Ls are usually not suitable for data intensive operations. Instead, they are used mainly for graphic user
interface (GUI) design or as simple query/report generators.
Incorrect answers:
A, B. Screen/report design facilities are one of the main advantages of 4GLs, and 4GLs have simple
programming language subsets.
C. Portability is also one of the main advantages of 4GLs.

NO.7 Which of the following types of data validation editing checks is used to determine if a field contains
data, and not zeros or blanks?
A. Check digit
B. Existence check
C. Completeness check
D. Reasonableness check
Answer: C

ISACA   CISA   CISA   CISA exam simulations
Explanation:
A completeness check is used to determine if a field contains data and not zeros or blanks. Incorrect
answers:
A. A check digit is a digit calculated mathematically to ensure original data was not altered.
B. An existence check also checks entered data for agreement to predetermined criteria.
D. A reasonableness check matches input to predetermined reasonable limits or occurrence rates.

NO.8 To affix a digital signature to a message, the sender must first create a message digest by applying a
cryptographic hashing algorithm against:
A. the entire message and thereafter enciphering the message digest using the sender's private key.
B. any arbitrary part of the message and thereafter enciphering the message digest using the sender's
private key.
C. the entire message and thereafter enciphering the message using the sender's private key.
D. the entire message and thereafter enciphering the message along with the message digest using the
sender's private key.
Answer: A

ISACA   CISA   CISA   CISA practice test
Explanation:
A digital signature is a cryptographic method that ensures data integrity, authentication of the message,
and non-repudiation. To ensure these, the sender first creates a message digest by applying a
cryptographic hashing algorithm against the entire message and thereafter enciphers the message digest
using the sender's private key. A message digest is created by applying a cryptographic hashing algorithm
against the entire message not on any arbitrary part of the message. After creating the message digest,
only the message digest is enciphered using the sender's private key, not the message.

NO.9 Which of the following is a dynamic analysis tool for the purpose of testing software modules?
A. Blackbox test
B. Desk checking
C. Structured walk-through
D. Design and code
Answer: A

ISACA certification   CISA   CISA   CISA questions
Explanation:
A blackbox test is a dynamic analysis tool for testing software modules. During the testing of software
modules a blackbox test works first in a cohesive manner as one single unit/entity, consisting of numerous
modules and second, with the user data that flows across software modules. In some cases, this even
drives the software behavior.
Incorrect answers:
In choices B, C and D, the software (design or code) remains static and somebody simply closely
examines it by applying his/her mind, without actually activating the software. Hence, these cannot be
referred to as dynamic analysis tools.

NO.10 Which of the following hardware devices relieves the central computer from performing network
control, format conversion and message handling tasks?
A. Spool
B. Cluster controller
C. Protocol converter
D. Front end processor
Answer: D

ISACA   CISA   CISA   CISA   CISA
Explanation:
A front-end processor is a hardware device that connects all communication lines to a central computer to
relieve the central computer.

NO.11 A LAN administrator normally would be restricted from:
A. having end-user responsibilities.
B. reporting to the end-user manager.
C. having programming responsibilities.
D. being responsible for LAN security administration.
Answer: C

ISACA   CISA test questions   CISA certification training   CISA certification
Explanation:
A LAN administrator should not have programming responsibilities but may have end- user
responsibilities. The LAN administrator may report to the director of the IPF or, in a decentralized
operation, to the end-user manager. In small organizations, the LAN administrator also may be
responsible for security administration over the LAN.

NO.12 An offsite information processing facility having electrical wiring, air conditioning and flooring, but no
computer or communications equipment is a:
A. cold site.
B. warm site.
C. dial-up site.
D. duplicate processing facility.
Answer: A

ISACA   CISA   CISA
Explanation:
A cold site is ready to receive equipment but does not offer any components at the site in advance of the
need.
Incorrect answers:
B. A warm site is an offsite backup facility that is configured partially with network connections and
selected peripheral equipment, such as disk and tape units, controllers and CPUs, to operate an
information processing facility.
D. A duplicate information processing facility is a dedicated, self-developed recovery site that can back up
critical applications.

NO.13 Which of the following systems-based approaches would a financial processing company employ to
monitor spending patterns to identify abnormal patterns and report them?
A. A neural network
B. Database management software
C. Management information systems
D. Computer assisted audit techniques
Answer: A Explanation:
A neural network will monitor and learn patterns, reporting exceptions for investigation. Incorrect answers:
B. Database management software is a method of storing and retrieving data.
C. Management information systems provide management statistics but do not normally have a
monitoring and detection function.
D. Computer-assisted audit techniques detect specific situations, but are not intended to learn patterns
and detect abnormalities.

NO.14 A hub is a device that connects:
A. two LANs using different protocols.
B. a LAN with a WAN.
C. a LAN with a metropolitan area network (MAN).
D. two segments of a single LAN.
Answer: D

ISACA demo   CISA   CISA dumps   CISA   CISA answers real questions
Explanation:
A hub is a device that connects two segments of a single LAN. A hub is a repeater. It provides transparent
connectivity to users on all segments of the same LAN. It is a level 1 device. Incorrect answers:
A. A bridge operates at level 2 of the OSI layer and is used to connect two LANs using different protocols
(e.g., joining an ethernet and token network) to form a logical network.
B. A gateway, which is a level 7 device, is used to connect a LAN to a WAN.
C. A LAN is connected with a MAN using a router, which operates in the network layer.

NO.15 A sequence of bits appended to a digital document that is used to secure an e-mail sent through the
Internet is called a:
A. digest signature.
B. electronic signature.
C. digital signature.
D. hash signature.
Answer: C

ISACA practice test   CISA   CISA dumps   CISA dumps   CISA
Explanation:
A digital signature through the private cryptographic key authenticates a transmission from a sender
through the private cryptographic key. It is a string of bits that uniquely represent another string of bits, a
digital document. An electronic signature refers to the string of bits that digitally represents a handwritten
signature captured by a computer system when a human applies it on an electronic pen pad, connected
to the system.

NO.16 A call-back system requires that a user with an id and password call a remote server through a dial-up
line, then the server disconnects and: A. dials back to the user machine based on the user id and
password using a telephone number from its database.
B. dials back to the user machine based on the user id and password using a telephone number provided
by the user during this connection.
C. waits for a redial back from the user machine for reconfirmation and then verifies the user id and
password using its database.
D. waits for a redial back from the user machine for reconfirmation and then verifies the user id and
password using the sender's database.
Answer: A

ISACA   CISA braindump   CISA   CISA   CISA exam prep
Explanation:
A call-back system in a net centric environment would mean that a user with an id and password calls a
remote server through a dial-up line first, and then the server disconnects and dials back to the user
machine based on the user id and password using a telephone number from its database. Although the
server can depend upon its own database, it cannot know the authenticity of the dialer when the user dials
again. The server cannot depend upon the sender's database to dial back as the same could be
manipulated.

NO.17 Which of the following is a benefit of using callback devices?
A. Provide an audit trail
B. Can be used in a switchboard environment
C. Permit unlimited user mobility
D. Allow call forwarding
Answer: A

ISACA exam dumps   CISA   CISA   CISA   CISA exam simulations   CISA
Explanation:
A callback feature hooks into the access control software and logs all authorized and unauthorized access
attempts, permitting the follow-up and further review of potential breaches. Call forwarding (choice D) is a
means of potentially bypassing callback control. By dialing through an authorized phone number from an
unauthorized phone number, a perpetrator can gain computer access. This vulnerability can be controlled
through callback systems that are available.

NO.18 Which of the following would be the BEST method for ensuring that critical fields in a master record
have been updated properly?
A. Field checks
B. Control totals
C. Reasonableness checks
D. A before-and-after maintenance report
Answer: D

ISACA braindump   CISA answers real questions   CISA   CISA practice test   CISA test   CISA questions
Explanation:
A before-and-after maintenance report is the best answer because a visual review would provide the most
positive verification that updating was proper.

NO.19 Which of the following BEST describes the necessary documentation for an enterprise product
reengineering (EPR) software installation?
A. Specific developments only
B. Business requirements only
C. All phases of the installation must be documented
D. No need to develop a customer specific documentation
Answer: C

ISACA braindump   CISA questions   CISA test questions
Explanation:
A global enterprise product reengineering (EPR) software package can be applied to a business to
replace, simplify and improve the quality of IS processing. Documentation is intended to help understand
how, why and which solutions that have been selected and implemented, and therefore must be specific
to the project. Documentation is also intended to support quality assurance and must be comprehensive.

NO.20 Which of the following network configuration options contains a direct link between any two host
machines?
A. Bus
B. Ring
C. Star
D. Completely connected (mesh)
Answer: D

ISACA   CISA   CISA study guide   CISA braindump
Explanation:
A completely connected mesh configuration creates a direct link between any two host machines.
Incorrect answers:
A. A bus configuration links all stations along one transmission line.
B. A ring configuration forms a circle, and all stations are attached to a point on the transmission circle.
D. In a star configuration each station is linked directly to a main hub.

NO.21 Which of the following is MOST likely to result from a business process reengineering (BPR) project?
A. An increased number of people using technology
B. Significant cost savings, through a reduction in the complexity of information technology
C. A weaker organizational structures and less accountability
D. Increased information protection (IP) risk will increase
Answer: A

ISACA   CISA test questions   CISA demo   CISA
Explanation:
A BPR project more often leads to an increased number of people using technology, and this would be a
cause for concern. Incorrect answers:
B. As BPR is often technology oriented, and this technology is usually more complex and volatile than in
the past, cost savings do not often materialize in this area.
D. There is no reason for IP to conflict with a BPR project, unless the project is not run properly.

NO.22 A database administrator is responsible for:
A. defining data ownership.
B. establishing operational standards for the data dictionary.
C. creating the logical and physical database.
D. establishing ground rules for ensuring data integrity and security.
Answer: C

ISACA   CISA study guide   CISA exam prep   CISA
Explanation:
A database administrator is responsible for creating and controlling the logical and physical database.
Defining data ownership resides with the head of the user department or top management if the data is
common to the organization. IS management and the data administrator are responsible for establishing
operational standards for the data dictionary. Establishing ground rules for ensuring data integrity and
security in line with the corporate security policy is a function of the security administrator.

NO.23 In an EDI process, the device which transmits and receives electronic documents is the:
A. communications handler.
B. EDI translator.
C. application interface.
D. EDI interface.
Answer: A

ISACA questions   CISA exam prep   CISA
Explanation:
A communications handler transmits and receives electronic documents between trading partners
and/or wide area networks (WANs).
Incorrect answers:
B. An EDI translator translates data between the standard format and a trading partner's proprietary
format.
C. An application interface moves electronic transactions to, or from, the application system and performs
data mapping.
D. An EDI interface manipulates and routes data between the application system and the communications
handler.

NO.24 Which of the following is a telecommunication device that translates data from digital form to analog
form and back to digital?
A. Multiplexer
B. Modem
C. Protocol converter
D. Concentrator
Answer: B

ISACA   CISA   CISA demo   CISA
Explanation:
A modem is a device that translates data from digital to analog and back to digital.

NO.25 Which of the following data validation edits is effective in detecting transposition and transcription
errors?
A. Range check
B. Check digit
C. Validity check
D. Duplicate check
Answer: B

ISACA   CISA test   CISA study guide   CISA
Explanation:
A check digit is a numeric value that is calculated mathematically and is appended to data to
ensure that the original data have not been altered or an incorrect, but valid, value substituted.
This control is effective in detecting transposition and transcription errors.
Incorrect answers:
A. A range check is checking data that matches a predetermined range of values.
C. A validity check is programmed checking of the data validity in accordance with predetermined criteria.
D. In a duplicate check, new or fresh transactions are matched to those previously entered to ensure that
they are not already in the system.

NO.26 A number of system failures are occurring when corrections to previously detected errors are
resubmitted for acceptance testing. This would indicate that the maintenance team is probably not
adequately performing which of the following types of testing?
A. Unit testing
B. Integration testing
C. Design walk-throughs
D. Configuration management
Answer: B

ISACA exam prep   CISA   CISA
Explanation:
A common system maintenance problem is that errors are often corrected quickly (especially when
deadlines are tight) , units are tested by the programmer, and then transferred to the acceptance test area.
This often results in system problems that should have been detected during integration or system testing.
Integration testing aims at ensuring that the major components of the system interface correctly.

NO.27 Which of the following translates e-mail formats from one network to another so that the message can
travel through all the networks?
A. Gateway
B. Protocol converter
C. Front-end communication processor
D. Concentrator/multiplexor
Answer: A

ISACA   CISA questions   CISA   CISA exam
Explanation:
A gateway performs the job of translating e-mail formats from one network to another so messages can
make their way through all the networks.
Incorrect answers:
B. A protocol converter is a hardware device that converts between two different types of transmissions,
such as asynchronous and synchronous transmissions.
C. A front-end communication processor connects all network communication lines to a central computer
to relieve the central computer from performing network control, format conversion and message handling
tasks.
D. A concentrator/multiplexor is a device used for combining several lower-speed channels into a
higher-speed channel.

NO.28 An IS auditor reviewing the key roles and responsibilities of the database administrator (DBA) is
LEAST likely to expect the job description of the DBA to include:
A. defining the conceptual schema.
B. defining security and integrity checks.
C. liaising with users in developing data model.
D. mapping data model with the internal schema.
Answer: D Explanation:
A DBA only in rare instances should be mapping data elements from the data model to the internal
schema (physical data storage definitions). To do so would eliminate data independence for application
systems. Mapping of the data model occurs with the conceptual schema since the conceptual schema
represents the enterprisewide view of data within an organization and is the basis for deriving an end-user
department data model.

NO.29 Which of the following tests is an IS auditor performing when a sample of programs is selected to
determine if the source and object versions are the same?
A. A substantive test of program library controls
B. A compliance test of program library controls
C. A compliance test of the program compiler controls
D. A substantive test of the program compiler controls
Answer: B

ISACA demo   CISA test   CISA dumps   CISA
Explanation:
A compliance test determines if controls are operating as designed and are being applied in a manner that
complies with management policies and procedures. For example, if the IS auditor is concerned whether
program library controls are working properly, the IS auditor might select a sample of programs to
determine if the source and object versions are the same. In other words, the broad objective of any
compliance test is to provide auditors with reasonable assurance that a particular control on which the
auditor plans to rely is operating as the auditor perceived it in the preliminary evaluation.

NO.30 The use of a GANTT chart can:
A. aid in scheduling project tasks.
B. determine project checkpoints.
C. ensure documentation standards.
D. direct the post-implementation review.
Answer: A

ISACA test questions   CISA pdf   CISA   CISA   CISA test   CISA original questions
Explanation:
A GANTT chart is used in project control. It may aid in the identification of needed checkpoints but its
primary use is in scheduling. It will not ensure the completion of documentation nor will it provide direction
for the post-implementation review.

ISACA CISA certification can guarantee you have good job prospects, because ISACA certification CISA exam is a difficult test of IT knowledge, passing ISACA certification CISA exam proves that your IT expertise a strong and you can be qualified for a good job.