CCISO Audit Management 3 — Questions and Answers
Question 1: A CISO wants to ensure audit recommendations are implemented on schedule. Which mechanism is most effective?
- Publishing audit results publicly to create accountability pressure
- Establishing a formal tracking system with defined owners, due dates, and periodic status reviews (Correct answer)
- Requiring re-audits within 30 days of each finding
- Delegating follow-up entirely to external auditors
Correct answer: Establishing a formal tracking system with defined owners, due dates, and periodic status reviews
A formal tracking system with assigned owners, deadlines, and status reviews ensures systematic, accountable remediation of audit findings.
Question 2: Under the ISACA IT Audit framework, which term describes the root cause of a control deficiency?
- Condition
- Criteria
- Cause (Correct answer)
- Effect
Correct answer: Cause
In audit finding structure, 'cause' identifies why the control deficiency exists, helping management address the underlying problem rather than just the symptom.
Question 3: Which type of audit opinion is issued when auditors cannot obtain sufficient appropriate evidence to form a conclusion?
- Adverse opinion
- Qualified opinion
- Disclaimer of opinion (Correct answer)
- Unmodified opinion
Correct answer: Disclaimer of opinion
A disclaimer of opinion is issued when the auditor is unable to obtain sufficient evidence, making it impossible to express any audit opinion.
Question 4: Which international standard provides the primary framework for internal audit activity globally?
- ISO 27001
- COSO ERM
- IIA International Standards for the Professional Practice of Internal Auditing (Correct answer)
- COBIT 2019
Correct answer: IIA International Standards for the Professional Practice of Internal Auditing
The IIA's International Standards for the Professional Practice of Internal Auditing is the globally accepted framework governing internal audit quality and independence.
Question 5: A CISO is designing an audit universe. Which factor should have the greatest influence on audit prioritization?
- The age of the last audit performed on each area
- The number of employees in each business unit
- The risk level and potential impact associated with each auditable entity (Correct answer)
- The preferences of business unit managers
Correct answer: The risk level and potential impact associated with each auditable entity
Audit prioritization should be driven by risk level and potential business impact so that limited audit resources address the most significant exposures.
Question 6: What is the primary purpose of an audit committee in corporate governance?
- To conduct day-to-day operational audits
- To provide independent oversight of financial reporting, internal controls, and the audit process (Correct answer)
- To approve the organization's information security policy
- To manage relationships with external vendors
Correct answer: To provide independent oversight of financial reporting, internal controls, and the audit process
The audit committee provides board-level, independent oversight of financial reporting integrity, internal controls, and external and internal audit activities.
Question 7: In continuous auditing, what distinguishes it from traditional periodic auditing?
- Continuous auditing uses only external auditors
- Continuous auditing employs automated tools to assess controls and data on an ongoing basis (Correct answer)
- Continuous auditing eliminates the need for audit documentation
- Continuous auditing focuses solely on financial transactions
Correct answer: Continuous auditing employs automated tools to assess controls and data on an ongoing basis
Continuous auditing uses automated monitoring tools to evaluate controls and transactions on an ongoing basis rather than waiting for periodic scheduled reviews.
A CISO wants to ensure audit recommendations are implemented on schedule.
Which mechanism is most effective?