The PRIMARY benefit of automating application testing is to:
Correct Answer: A
Explanation The primary benefit of automating application testing is to provide test consistency. Automated testing can ensure that the same test cases are executed in the same manner and order every time, which can improve the reliability and accuracy of the test results. Providing more flexibility, replacing all manual test processes, and reducing the time to review code are possible benefits of automating application testing, but they are not the primary benefit. References: ISACA, CISA Review Manual, 27th Edition, 2020, p. 3091 ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
Question 617
While reviewing the IT infrastructure, an IS auditor notices that storage resources are continuously being added. The IS auditor should:
Correct Answer: C
Explanation/Reference: Explanation: Capacity management is the planning and monitoring of computer resources to ensure that available IT resources are used efficiently and effectively. Business criticality must be considered before recommending a disk mirroring solution and offsite storage is unrelated to the problem. Though data compression may save disk space, it could affect system performance.
Question 618
The business case for an information system investment should be available for review until the:
Correct Answer: D
The business case for an information system investment is a document that provides the rationale and justification for the investment, based on the expected costs, benefits, risks, and impacts of the project12. The business case should be available for review until the benefits have been fully realized, because it serves as a baseline for measuring the actual performance and outcomes of the project against the planned ones34. This helps to evaluate the success and value of the investment, and to identify any gaps or issues that need to be addressed5. References 1: The Business Case for Security - CISA 2: Beyond the Business Case: New Approaches to IT Investment 3: #HowTo: Build a Business Case for Cybersecurity Investment 4: ISACA CISA Certified Information Systems Auditor Exam ... - PUPUWEB 5: The Business Case for Security | CISA
Question 619
The BEST way to evaluate the effectiveness of a newly developed application is to:
Correct Answer: D
The best way to evaluate the effectiveness of a newly developed application is to review acceptance testing results. Acceptance testing is a process of verifying that the application meets the specified requirements and expectations of the users and stakeholders. Acceptance testing results can provide evidence of the functionality, usability, reliability, performance, security and quality of the application. Performing a post- implementation review, analyzing load testing results, and performing a secure code review are also important activities for evaluating an application, but they are not as comprehensive or conclusive as acceptance testing results. References: Info Technology and Systems Resources | COBIT, Risk, Governance ... - ISACA, IT Governance and Process Maturity
Question 620
A characteristic of a digital signature is that it
Correct Answer: B
Explanation A digital signature is a specific type of e-signature that is backed by a digital certificate. A digital certificate is a document that contains the public key of a signer and is issued by a trusted third party called a certificate authority (CA). A digital signature provides proof of the identity of the signer and the integrity of the signed document. A characteristic of a digital signature is that it is unique to the message. This means that a digital signature cannot be copied from one document to another without being detected as invalid. A digital signature is created by applying a mathematical function called a hashing algorithm to the document. A hashing algorithm produces a fixed-length output called a hash or digest from any input data. The hash is unique to the input data; any change in the input data will result in a different hash. The signer then encrypts the hash with their private key (a secret key that only they know) to create the digital signature. The encrypted hash is attached to the document as the digital signature. The recipient of the document can verify the digital signature by decrypting it with the signer's public key (a key that is publicly available and matches the private key) to obtain the hash. The recipient then applies the same hashing algorithm to the document to generate another hash. The recipient then compares the two hashes; if they match, it means that the document has not been altered and that the signer is authentic. Therefore, a digital signature is unique to the message because it is derived from the hash of the message, which is unique to the message. References: 7: Free Online Signature Generator (Type or Draw) | Signaturely 8: What are digital signatures and certificates? | Acrobat Sign - Adobe 9: eSign PDF with Electronic Signature Free Online - Smallpdf