ISACA IT Audit Fundamentals Certification Sample Questions

IT Audit Fundamentals Dumps, IT Audit Fundamentals PDF, IT Audit Fundamentals VCE, ISACA IT Audit Fundamentals VCE, ISACA IT Audit Fundamentals PDFThe purpose of this Sample Question Set is to provide you with information about the ISACA IT Audit Fundamentals exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the IT Audit Fundamentals certification test. To get familiar with real exam environment, we suggest you try our Sample ISACA IT Audit Fundamentals Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISACA IT Audit Fundamentals certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISACA IT Audit Fundamentals exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium ISACA IT Audit Fundamentals Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISACA IT Audit Fundamentals Sample Questions:

01. Employees browse external websites from workstations inside the corporate network. Which of the following BEST describes what a forward proxy server does for that outbound traffic?
a) Blocks traffic arriving from the internet and drops unknown connections
b) Assigns each workstation an internal address when it joins the network
c) Scans files for malicious code as they are written to the user's disk
d) Relays requests on the user's behalf and records them
 
02. Which of the following BEST describes how asymmetric encryption differs from symmetric encryption?
a) It replaces sensitive values with surrogate tokens held in a vault
b) It compresses the data before it is sent
c) It uses a key pair rather than a shared secret
d) It converts data to a fixed-length value rather than a readable one
 
03. An auditor reviewing operations finds that a business application slows noticeably during period end processing, and that nobody tracks how its use of processor, memory and storage changes over time. Which risk is MOST directly increased by the absence of capacity monitoring?
a) Recovery after a disruption could take longer than the plan allows
b) Demand could outgrow the resources before anyone notices
c) Errors could post to the wrong customer account without notice
d) Changes could reach production without approval
 
04. Several business units load raw extracts into a central analytics repository, and no common definition exists for what the fields in those extracts mean. Which consequence should the IT auditor report as the MOST significant?
a) Figures reported by different units cannot be compared with one another
b) Analysts cannot experiment without working against the data other people rely on
c) Capacity planning cannot take account of which units query the repository most heavily
d) Users cannot find a particular unit's extracts without asking whoever loaded them
 
05. Clerks key supplier account codes into an invoicing application, and the auditor learns that codes are sometimes entered with the characters transposed. Which edit check would BEST detect this error at the point of entry?
a) A reasonableness check comparing the invoice total with the order value
b) A completeness check confirming the code field is not blank
c) A check digit calculated from the code itself
d) A range check on the invoice amount
 
06. Staff connect to internal systems from home and from public networks. Which of the following BEST describes how a virtual private network protects those remote sessions?
a) By filtering the connection at the network perimeter
b) By encrypting the traffic in a tunnel across the untrusted network
c) By storing the session records in an encrypted database on the application host
d) By requiring an additional authentication factor each time the session is opened
 
07. An audit function reports functionally to the audit committee and carries no operational duties. One of its auditors is reviewing a business unit that rejected a platform the same auditor had recommended. Which statement BEST describes the auditor's position?
a) Independence is intact but the auditor's objectivity is threatened
b) Objectivity is intact and independence is impaired
c) The function's organizational independence has been impaired by the recommendation
d) Neither organizational independence nor the auditor's objectivity is affected here
 
08. While testing data transfers, an IT auditor finds that personal data has been sent to a location the enterprise's own agreements do not permit, and the transfer may breach applicable law. Which of the following is the MOST appropriate action for the auditor?
a) Withhold the matter until the enterprise's lawyers have reviewed and advised
b) Ask the process owner to halt the transfers
c) Report the facts and refer the legal question to counsel
d) State in the report that the enterprise has broken the applicable law
 
09. A system-enforced credit limit check and a supervisor's manual review of the same transactions both operated throughout the period under review. Which statement BEST explains why the auditor needs to examine far fewer instances of the system-enforced check?
a) The manual review applies a supervisor's professional judgment to each item
b) The automated check operates identically on every transaction
c) The automated check needs no further testing once it is implemented
d) The manual review leaves no auditable evidence
 
10. Staff have begun pasting extracts from customer contracts into a public generative artificial intelligence service so that it can summarize them. Which of the following is the auditor's PRIMARY concern?
a) The service does not appear in the enterprise's approved software inventory
b) License terms may restrict commercial use
c) The service may return a summary that misstates a negotiated contract obligation
d) Confidential contract information has left the enterprise's control

Answers:

Question: 01
Answer: d
Question: 02
Answer: c
Question: 03
Answer: b
Question: 04
Answer: a
Question: 05
Answer: c
Question: 06
Answer: b
Question: 07
Answer: a
Question: 08
Answer: c
Question: 09
Answer: b
Question: 10
Answer: d

Note: For any error in ISACA IT Audit Fundamentals certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.9 / 5 (87 votes)