Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 240

Mary Smith

Tue, 21 Apr 2026

CISA—Certified Information Systems Auditor - Part 240

1. When performing an audit of a client relationship management (CRM) system migration project, which of the following should be of GREATEST concern to an IS auditor?

A) The technical migration is planned for a Friday preceding a long weekend, and the time window is too short for completing all tasks.
B) Employees pilot-testing the system are concerned that the data representation in the new system is completely different from the old system.
C) A single implementation is planned, immediately decommissioning the legacy system.
D) Five weeks prior to the target date, there are still numerous defects in the printing functionality of the new system's software.



2. Which of the following reports should an IS auditor use to check compliance with a service level agreements (SLA) requirement for uptime?

A) Utilization reports
B) Hardware error reports
C) System logs
D) Availability reports



3. A benefit of quality of service (QoS) is that the:

A) entire network's availability and performance will be significantly improved.
B) telecom carrier will provide the company with accurate service-level compliance reports.
C) participating applications will have guaranteed service levels.
D) communications link will be supported by security controls to perform secure online transactions.



4. An organization has outsourced its help desk. Which of the following indicators would be the best to include in the SLA?

A) Overall number of users supported
B) Percentage of incidents solved in the first call
C) Number of incidents reported to the help desk
D) Number of agents answering the phones



5. The PRIMARY objective of service-level management (SLM) is to:

A) define, agree, record and manage the required levels of service.
B) ensure that services are managed to deliver the highest achievable level of availability.
C) keep the costs associated with any service at a minimum.
D) monitor and report any legal noncompliance to business management.



1. Right Answer: C
Explanation: Major system migrations should include a phase of parallel operation or a phased cut-over to reduce implementation risks. Decommissioning or disposing of the old hardware would complicate any fallback strategy, should the new system not operate correctly. A weekend can be used as a time buffer so that the new system will have a better chance of being up and running after the weekend. A different data representation does not mean different data presentation at the front end. Even when this is the case, this issue can be solved by adequate training and user support. The printing functionality is commonly one of the last functions to be tested in a new system because it is usually the last step performed in any business event. Thus, meaningful testing and the respective error fixing are only possible after all other parts of the software have been successfully tested.

2. Right Answer: D
Explanation: IS inactivity, such as downtime, is addressed by availability reports. These reports provide the time periods during which the computer was available for utilization by users or other processes. Utilization reports document the use of computer equipment, and can be used by management to predict how/where/when resources are required. Hardware error reports provide information to aid in detecting hardware failures and initiating corrective action. System logs are a recording of the system's activities.

3. Right Answer: C
Explanation: The main function of QoS is to optimize network performance by assigning priority to business applications and end users, through the allocation of dedicated parts of the bandwidth to specific traffic. Choice A is not true because the communication itself will not be improved. While the speed of data exchange for specific applications could be faster, availability will not be improved. The QoS tools that many carriers are using do not provide reports of service levels; however, there are other tools that will generate service-level reports. Even when QoS is integrated with firewalls, VPNs, encryption tools and others, the tool itself is not intended to provide security controls.

4. Right Answer: B
Explanation: Since it is about service level (performance) indicators, the percentage of incidents solved on the first call is the only option that is relevant. Choices A, C and D are not quality measures of the help desk service.

5. Right Answer: A
Explanation: The objective of service-level management (SLM) is to negotiate, document and manage (i.e., provide and monitor) the services in the manner in which the customer requires those services. This does not necessarily ensure that services are delivered at the highest achievable level of availability (e.g., redundancy and clustering). Although maximizing availability might be necessary for some critical services, it cannot be applied as a general rule of thumb. SLM cannot ensure that costs for all services will be kept at a low or minimum level, since costs associated with a service will directly reflect the customer's requirements. Monitoring and reporting legal noncompliance is not a part of SLM.

0 Comments

Leave a comment