Options

CISA Review Manual - Pre-Chapter Questions Vs. Case Study Questions

naclh2onaznaclh2onaz Member Posts: 69 ■■□□□□□□□□
Im currently studying for the CISA exam and will be attending the September exam in Los Angeles. I am studying the official review manual and creating flashcards on Quizlet so I can commit the material to memory. At the end of the chapters, I am going over the Case Study questions and the Pre-Chapter questions as well. I am doing well with the pre-chapter ones but not so well on the case study ones.
An example from Chapter 2 Case Study:
Which of the following should be of MOST concern to the IS auditor?
A. User account changes are processed within three business days
B. Twenty-four hour notice is required prior to an onsite visit
C. The outsourcer does not have an IS audit function
D. Software escrow is not included in the contract

Based on the choices, I thought D was the correct answer. The book says the correct answer is A, and the reasoning is "Three business days to remove the acount of a terminated employee would create an unacceptable risk to the organization"
Account removal being an account change did not cross my mind. Had it stated "User account revocations are not processed within three business days", I would have chosen that answer.

My question is - Are the questions on the actual exam more like the pre-chapter questions or are they worded vaguely like the case study ones seem to be?
2017 Goals:
CISSP [X]
2018 Goals:
CRISC [ ]

Comments

Sign In or Register to comment.