CCISO Audit Management 5 — Questions and Answers
Question 1: A CISO is preparing an audit report for the board. Which characteristic is most important for the executive summary?
- Inclusion of all technical details and raw data
- Concise risk-ranked findings with business impact and remediation priorities (Correct answer)
- A comprehensive list of all audit procedures performed
- Detailed statistical analysis of sample populations
Correct answer: Concise risk-ranked findings with business impact and remediation priorities
Executive summaries should present risk-ranked findings with clear business impact and prioritized recommendations to support board-level decision-making.
Question 2: Which control testing approach is most appropriate when an auditor wants to verify that preventive controls operated effectively throughout the entire audit period?
- Inquiry of management
- Walkthrough of a single transaction
- Testing a sample of transactions across the full period (Correct answer)
- Inspection of policy documents
Correct answer: Testing a sample of transactions across the full period
Testing a sample spread across the entire period provides evidence that controls operated consistently throughout, not just at a single point in time.
Question 3: Under COBIT 2019, which governance objective directly supports the audit management function by ensuring IT-related risks are identified and managed?
- APO12 — Managed Risk (Correct answer)
- DSS05 — Managed Security Services
- BAI09 — Managed Assets
- MEA01 — Managed Performance and Conformance Monitoring
Correct answer: APO12 — Managed Risk
APO12 (Managed Risk) in COBIT 2019 governs the identification, assessment, and response to IT-related risks, directly supporting audit management activities.
Question 4: What is the primary distinction between a Type I and Type II SOC 2 report?
- Type I covers security only; Type II covers all five trust service criteria
- Type I assesses control design at a point in time; Type II assesses design and operating effectiveness over a period (Correct answer)
- Type I is performed by internal auditors; Type II requires external auditors
- Type I is public; Type II is confidential
Correct answer: Type I assesses control design at a point in time; Type II assesses design and operating effectiveness over a period
A SOC 2 Type I report evaluates control design at a specific date, while Type II also tests operating effectiveness over a defined review period (typically 6–12 months).
Question 5: A CISO wants to reduce audit fatigue caused by multiple simultaneous audits from different regulators. Which strategy is most effective?
- Refuse redundant audits citing resource constraints
- Implement a coordinated audit management program that consolidates evidence collection and aligns audit schedules (Correct answer)
- Delegate all regulatory responses to legal counsel
- Automate all control tests to eliminate manual evidence gathering
Correct answer: Implement a coordinated audit management program that consolidates evidence collection and aligns audit schedules
A coordinated audit management program consolidates evidence artifacts and aligns scheduling to reduce redundant requests and minimize disruption to operations.
Question 6: Which metric best measures the effectiveness of an organization's audit follow-up process?
- Number of audit engagements completed per year
- Percentage of findings remediated by the agreed-upon due date (Correct answer)
- Total hours spent on audit fieldwork
- Number of external auditors engaged annually
Correct answer: Percentage of findings remediated by the agreed-upon due date
Remediation rate by due date directly measures whether the organization is acting on audit findings in a timely and accountable manner.
Question 7: During an audit, the team discovers evidence of potential fraud. What is the CISO's immediate priority?
- Complete the scheduled audit before reporting the potential fraud
- Immediately notify appropriate parties (legal, board, audit committee) and preserve evidence (Correct answer)
- Confront the suspected employee to obtain a confession
- Delete audit logs to prevent premature disclosure
Correct answer: Immediately notify appropriate parties (legal, board, audit committee) and preserve evidence
Suspected fraud must be immediately escalated to legal counsel, the audit committee, and appropriate management while preserving evidence for investigation.
A CISO is preparing an audit report for the board.
Which characteristic is most important for the executive summary?