exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 631 discussion

Actual exam question from Isaca's CISA
Question #: 631
Topic #: 1
[All CISA Questions]

An IS auditor observes that exceptions have been approved for an organization's information security policy. Which of the following is MOST important for the auditor to confirm?

  • A. Exceptions do not change residual risk.
  • B. Exceptions are approved for predefined periods.
  • C. Exceptions require changes to the policy.
  • D. Exceptions are approved by the board of directors.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
1Naa
1 week, 6 days ago
Selected Answer: B
When exceptions to an information security policy are approved, it is critical that they are temporary and reviewed periodically to ensure they do not become permanent gaps in security controls. Approving exceptions for predefined periods allows the organization to re-evaluate and address the underlying causes of the exception, ensuring that risk is managed effectively over time.
upvoted 1 times
...
Swallows
1 month, 2 weeks ago
Selected Answer: A
Confirming that exceptions to the information security policy do not change the residual risk is crucial. Residual risk refers to the level of risk that remains after controls have been implemented or exceptions have been granted.
upvoted 1 times
...
3008
7 months, 1 week ago
Selected Answer: A
A is correct.
upvoted 1 times
...
meelaan
9 months, 2 weeks ago
Selected Answer: D
It has to be approved by Higher top managment
upvoted 1 times
...
Joloms
1 year ago
Exceptions are breaches in the internal controls , and residual risks are not mitigated by the internal controls as they still remain after the controls so exceptions will not wok for them A is the answer
upvoted 4 times
...
saado9
1 year, 2 months ago
B. Exceptions are approved for predefined periods.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago