Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 305 discussion

Actual exam question from Isaca's CISA
Question #: 305
Topic #: 1
[All CISA Questions]

An organization implemented a cybersecurity policy last year. Which of the following is the GREATEST indicator that the policy may need to be revised?

  • A. A significant increase in authorized connections to third parties
  • B. A significant increase in cybersecurity audit findings
  • C. A significant increase in external attack attempts
  • D. A significant increase in approved exceptions
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
PurpleParrot
3 months ago
Selected Answer: B
Direct Indicator of Policy Gaps: A significant increase in audit findings directly indicates that there are weaknesses or deficiencies in the current cybersecurity controls, which are often tied to the policy itself. It suggests that the policy may not be adequately addressing security requirements or is not being implemented effectively. Focus on Effectiveness: Audit findings assess the effectiveness of controls and policies, making this the most direct indicator that the policy may need revision to address identified issues and improve overall security posture.
upvoted 1 times
...
Sibsankar
8 months, 3 weeks ago
D is right
upvoted 1 times
...
AB1237
1 year, 2 months ago
Selected Answer: C
A significant increase in external attack attempts is typically a more direct and urgent signal that the policy may no longer adequately address the evolving security challenges posed by external threats. It highlights the need for proactive policy revisions to strengthen the organization's cybersecurity defenses.
upvoted 1 times
...
3008
1 year, 6 months ago
Selected Answer: D
When exceptions become more frequent, it suggests that the policy is not meeting the needs of the organization, and employees are finding ways to work around it. This may indicate that the policy is too strict, difficult to follow, or not aligned with business needs. As a result, the policy needs to be revised to better align with the needs of the organization while still providing adequate protection against cyber threats.
upvoted 4 times
...
MichaelHoang
1 year, 10 months ago
Selected Answer: D
i think the answer is D. In the option B, the audit finding does not always mean the policy is not sufficient and need to udpate. However, the increasing of exception approval means that the policy is not cover all aspect hence exception approval is required.
upvoted 2 times
...
Staanlee
1 year, 11 months ago
Selected Answer: B
B seems to be the right answer. A significant increase in cybersecurity audit findings
upvoted 2 times
MohamedAbdelaal
1 year, 7 months ago
The audit finding is not necessary to be related to the policy design, the problem could be in the implementation
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...