ISACA CISA Certified Information Systems Auditor Exam — Questions and Answers
Question 1: During a network review, an auditor finds that network administrators share a single privileged account. This PRIMARILY violates the principle of:
- Network segmentation
- Least privilege for end users
- Defense in depth
- Non-repudiation and individual accountability (Correct answer)
Correct answer: Non-repudiation and individual accountability
Shared accounts make it impossible to attribute actions to specific individuals, undermining accountability and audit trails.
Question 2: Which metric BEST measures the effectiveness of an IT risk management program over time?
- Reduction in residual risk levels across the risk register (Correct answer)
- Number of security policies reviewed annually
- Total IT security budget spent per year
- Number of vulnerabilities discovered per scan
Correct answer: Reduction in residual risk levels across the risk register
Tracking reductions in residual risk levels directly measures whether the risk management program is achieving its goal of lowering actual risk exposure.
Question 3: During a BCP test, an organization discovers its backup tapes contain corrupted data. What control failure does this PRIMARILY represent?
- Lack of a documented recovery procedure
- Inadequate encryption of backup data
- Insufficient offsite storage of backup media
- Failure to validate backup integrity through regular restoration testing (Correct answer)
Correct answer: Failure to validate backup integrity through regular restoration testing
Backups must be regularly tested through actual restoration to verify data integrity; storing backups without testing them is a critical control gap.
Question 4: An IS auditor finds that a legacy system cannot enforce password complexity requirements. What is the MOST appropriate recommendation?
- Implement compensating controls such as additional authentication factors (Correct answer)
- Accept the risk as unavoidable for legacy systems
- Immediately decommission the legacy system
- Manually enforce password policies through HR policies only
Correct answer: Implement compensating controls such as additional authentication factors
When a system cannot enforce a technical control, compensating controls such as MFA or enhanced monitoring should be implemented to offset the risk.
Question 5: A cold site differs from a warm or hot site in that it:
- Provides only physical space and basic utilities, requiring equipment to be installed before use (Correct answer)
- Is used exclusively for tabletop exercises
- Has fully mirrored live data at all times
- Automatically fails over without human intervention
Correct answer: Provides only physical space and basic utilities, requiring equipment to be installed before use
A cold site provides the physical facility but no pre-installed hardware or software, requiring the organization to procure and configure equipment after declaring a disaster.
Question 6: During the audit planning phase for a financial institution, an IS auditor discovers that a new online banking platform was implemented without a formal risk assessment. Which of the following is the MOST appropriate action for the auditor to take?
- Expand the audit scope to include a thorough risk assessment of the new platform. (Correct answer)
- Immediately report a significant finding of non-compliance to the audit committee.
- Proceed with the original audit plan but note the lack of a risk assessment in the final report.
- Recommend that management commission an independent risk assessment post-implementation.
Correct answer: Expand the audit scope to include a thorough risk assessment of the new platform.
The discovery of a significant change to the IT environment, especially one implemented without a risk assessment, requires the auditor to adjust the audit plan. Expanding the scope to assess the risks associated with the new platform is the most proactive and responsible action to ensure potential vulnerabilities are identified and evaluated.
Question 7: Which of the following is the PRIMARY objective of implementing the principle of least privilege within an identity and access management program?
- To ensure users can perform all tasks associated with their job role without interruption.
- To limit the potential damage from a compromised account or insider threat. (Correct answer)
- To simplify the access control list (ACL) for network administrators.
- To streamline the user access review and certification process.
Correct answer: To limit the potential damage from a compromised account or insider threat.
The principle of least privilege dictates that a user should only be granted the minimum permissions necessary to perform their job functions. Its primary security goal is to reduce the 'attack surface' and limit the 'blast radius' of a security breach. If an account is compromised, the attacker's capabilities are restricted to only that account's minimal permissions, thus containing the potential damage.
Question 8: Which of the following BEST describes the purpose of a risk appetite statement?
- To assign risk owners to each identified risk
- To document risk mitigation strategies
- To define the level of risk the organization is willing to accept (Correct answer)
- To list all identified risks in the organization
Correct answer: To define the level of risk the organization is willing to accept
A risk appetite statement articulates how much risk the board and senior management are willing to tolerate in pursuit of business objectives.
Question 9: Which of the following BEST describes the role of configuration management in system development?
- Managing employee workstation hardware inventories
- Approving capital expenditure for IT infrastructure
- Controlling and tracking changes to software components and their versions (Correct answer)
- Scheduling project team meetings and sprint reviews
Correct answer: Controlling and tracking changes to software components and their versions
Configuration management ensures that software components are versioned, tracked, and controlled so that any version can be reproduced and changes are auditable.
Question 10: Which of the following is the CORRECT sequence for developing a Business Continuity Plan?
- Risk Assessment → BIA → Plan Development → Test (Correct answer)
- Test → BIA → Risk Assessment → Plan Development
- Plan Development → Risk Assessment → BIA → Test
- BIA → Plan Development → Risk Assessment → Test
Correct answer: Risk Assessment → BIA → Plan Development → Test
Risk assessment identifies threats, BIA quantifies their impact, plan development addresses the findings, and testing validates the plan.
Question 11: An IS auditor is evaluating DR test documentation. Which finding would be MOST concerning?
- The test took slightly longer than the RTO
- One minor system was not included in the scope
- Test results are undated and lack signatures from responsible parties (Correct answer)
- Test results include minor deviations from the plan
Correct answer: Test results are undated and lack signatures from responsible parties
Undated and unsigned test records lack the basic governance controls needed to demonstrate accountability and cannot serve as reliable audit evidence.
Question 12: Which of the following BEST explains why a business continuity plan must be treated as a living document?
- Business processes, systems, personnel, and risks change over time, making static plans obsolete (Correct answer)
- External auditors require new versions before each engagement
- The plan must be rewritten whenever a new CIO is appointed
- Regulatory requirements mandate annual document versioning
Correct answer: Business processes, systems, personnel, and risks change over time, making static plans obsolete
Organizations constantly change, so BCPs must be updated to reflect new systems, staff, processes, and threat landscapes to remain effective.
Question 13: In IS audit planning, which approach helps an auditor identify control gaps by mapping risks to existing controls?
- Data flow diagramming
- Control matrix (risk-control matrix) (Correct answer)
- Entity-relationship diagramming
- Flowcharting
Correct answer: Control matrix (risk-control matrix)
A risk-control matrix maps identified risks to the controls designed to mitigate them, making it easy to spot areas where controls are absent, weak, or duplicated.
Question 14: During IS audit planning, which of the following is the BEST source for understanding an organization's IT risk posture?
- Prior year's financial statements
- The organization's enterprise risk management (ERM) framework and IT risk register (Correct answer)
- Vendor documentation for installed software
- Industry benchmarking reports
Correct answer: The organization's enterprise risk management (ERM) framework and IT risk register
The ERM framework and IT risk register document the organization's identified risks, their likelihood and impact, and existing mitigations — making them the primary source for risk-based audit planning.
Question 15: When assessing inherent risk during IS audit planning, the auditor should consider:
- The cost of implementing additional controls
- The risk that exists independent of any controls (Correct answer)
- The effectiveness of existing controls
- Management's response to prior audit findings
Correct answer: The risk that exists independent of any controls
Inherent risk is the susceptibility of an assertion or area to a material misstatement or error assuming no related controls exist.
Question 16: A software development team uses an iterative methodology where working software is delivered in short cycles. This BEST describes:
- Rapid application development (RAD)
- Waterfall development
- Agile/Scrum development (Correct answer)
- Spiral model development
Correct answer: Agile/Scrum development
Agile/Scrum delivers working software in short, time-boxed sprints with frequent stakeholder feedback and iterative refinement.
Question 17: During a post-implementation review, an IS auditor finds that user acceptance testing (UAT) was bypassed due to project deadline pressure. What is the PRIMARY risk?
- Development team morale decreases
- Project documentation becomes incomplete
- Budget overruns in future phases
- Undiscovered defects may reach production (Correct answer)
Correct answer: Undiscovered defects may reach production
Skipping UAT means business requirements may not be met and defects unknown to users can propagate into the live environment.
Question 18: An organization is implementing a new cloud storage solution for sensitive data. Which of the following should the IS auditor verify FIRST?
- Whether the cloud provider uses the same antivirus solution as the organization
- Whether the cloud provider is publicly traded and financially stable
- Whether the cloud provider offers 99.99% uptime SLA
- Whether the organization retains control of encryption keys used to protect the data (Correct answer)
Correct answer: Whether the organization retains control of encryption keys used to protect the data
Retaining control of encryption keys ensures that the organization can protect its data even if the cloud provider is compromised, subpoenaed, or goes out of business.
Question 19: An IS auditor is reviewing IT risk management practices. Which finding represents the MOST significant control gap?
- Risk register entries lack a target remediation date
- Risk owners have not formally acknowledged their responsibilities
- Risk assessments are performed every 18 months instead of annually
- Risk scenarios are not linked to specific business processes (Correct answer)
Correct answer: Risk scenarios are not linked to specific business processes
Risk scenarios disconnected from business processes cannot be properly prioritized or mitigated because their business impact is unknown.
Question 20: An IS auditor reviewing system documentation finds that no operations manual exists for a newly implemented system. The PRIMARY concern is:
- Development costs may increase in the next phase
- Operations staff may be unable to maintain or recover the system properly (Correct answer)
- The system may not integrate with social media platforms
- End users may not enjoy the interface
Correct answer: Operations staff may be unable to maintain or recover the system properly
Without an operations manual, staff lack the guidance needed for routine operations, troubleshooting, and disaster recovery, increasing operational risk.
Question 21: Which party should APPROVE the final DR test plan before testing begins?
- The recovery site vendor
- The external auditor
- Senior management or the steering committee (Correct answer)
- The IT operations manager only
Correct answer: Senior management or the steering committee
Senior management or the steering committee must approve DR test plans to ensure organizational alignment, resource commitment, and accountability.
Question 22: Which of the following is the PRIMARY responsibility of executive management regarding business continuity planning?
- Performing risk assessments and BIA studies
- Writing and maintaining detailed recovery procedures
- Conducting annual BCP tests and drills
- Sponsoring and approving the BCP program and providing adequate resources (Correct answer)
Correct answer: Sponsoring and approving the BCP program and providing adequate resources
Executive management's primary BCP role is governance: providing leadership commitment, funding, and policy approval for the overall program.
Question 23: During a post-implementation review of a new CRM system, an IS auditor's PRIMARY objective is to determine whether:
- all identified bugs and defects from the testing phase have been resolved.
- the system has met the business objectives and delivers the expected benefits. (Correct answer)
- the project was completed within the allocated budget and timeframe.
- end-users are satisfied with the new system's user interface and performance.
Correct answer: the system has met the business objectives and delivers the expected benefits.
The primary purpose of a post-implementation review is to assess whether the system has achieved its intended business objectives and delivered the value proposed in the business case. While budget, bug resolution, and user satisfaction are important factors to review, the ultimate measure of success is the system's ability to support and improve business processes as originally intended.
Question 24: An IS auditor finds that network infrastructure devices have not received security patches in 18 months. The BEST recommendation is to:
- Implement a formal patch management process with defined SLAs for critical devices (Correct answer)
- Accept the risk since patches may disrupt network operations
- Require vendors to patch devices remotely without testing
- Disable the devices until patches are applied
Correct answer: Implement a formal patch management process with defined SLAs for critical devices
A formal patch management process with defined timelines ensures vulnerabilities are addressed systematically without unnecessary disruption.
Question 25: An IS auditor is evaluating the adequacy of an organization's BCP. Which of the following would provide the MOST assurance that the plan is effective?
- Certification that the plan was reviewed by a consulting firm
- A signed attestation from management that the plan is complete
- Documented results from a recent successful full-scale test (Correct answer)
- Evidence that all employees have read and acknowledged the plan
Correct answer: Documented results from a recent successful full-scale test
Actual test results demonstrating that recovery objectives were met provide the strongest evidence of BCP effectiveness.
Question 26: During IS audit planning, the concept of 'audit universe' refers to:
- The total number of staff available for audit work
- The complete inventory of auditable entities from which the audit plan is derived (Correct answer)
- All potential risks identified across the organization
- The set of regulatory requirements applicable to the organization
Correct answer: The complete inventory of auditable entities from which the audit plan is derived
The audit universe is the comprehensive inventory of all auditable entities — systems, processes, departments — that forms the basis for developing a risk-based audit plan.
Question 27: An IS auditor evaluates an organization's identity governance program and finds that user access reviews are performed annually. What is the PRIMARY weakness of this approach?
- Excessive or unauthorized access can persist for up to 12 months before detection (Correct answer)
- Users may forget their access rights have been reviewed
- Annual reviews are not required by most regulatory frameworks
- Annual reviews generate too much administrative overhead
Correct answer: Excessive or unauthorized access can persist for up to 12 months before detection
Annual access reviews allow inappropriate access to go undetected for up to a year, significantly increasing the risk window for insider threats and privilege abuse.
Question 28: During an IT audit, a CISA finds that risk assessments are performed annually by IT staff without business unit input. What is the GREATEST weakness?
- Assessments are not frequent enough
- Risk assessments lack business context and may miss operational risks (Correct answer)
- IT staff are not qualified to assess risk
- The assessments are not automated
Correct answer: Risk assessments lack business context and may miss operational risks
Excluding business units means assessments may miss key operational risks and fail to align with business objectives.
Question 29: Which of the following BEST describes the purpose of a Key Risk Indicator (KRI) in IT risk management?
- To measure the performance of the IT department after a risk has materialized.
- To calculate the precise financial impact of a specific risk event.
- To provide a historical record of all IT security incidents.
- To serve as an early warning signal that a risk is emerging or exceeding its threshold. (Correct answer)
Correct answer: To serve as an early warning signal that a risk is emerging or exceeding its threshold.
Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposures in various areas of the enterprise. They are forward-looking and designed to alert management before a risk materializes into a loss event, allowing for proactive risk mitigation.
Question 30: An IS auditor is reviewing a change management process. Which control BEST ensures only authorized changes reach production?
- Automated code compilation logs
- Mandatory code comments in all programs
- Segregation of duties between developers and production migration staff (Correct answer)
- Weekly status meetings with the project manager
Correct answer: Segregation of duties between developers and production migration staff
Segregation of duties prevents developers from promoting their own code, ensuring an independent review before production migration.
Question 31: When performing an IT risk assessment, what does 'threat likelihood' measure?
- The potential damage a threat could cause if it occurs
- The number of assets exposed to the threat
- The cost of implementing a control to prevent the threat
- The probability that a threat will exploit a vulnerability (Correct answer)
Correct answer: The probability that a threat will exploit a vulnerability
Threat likelihood estimates how probable it is that a given threat will actually materialize and exploit an existing vulnerability.
Question 32: Which of the following BEST describes the purpose of an audit program in IS audit planning?
- A high-level document authorizing the audit function
- A schedule of all audits planned for the year
- A summary of findings presented to management
- A set of detailed instructions guiding the auditor through specific procedures to achieve audit objectives (Correct answer)
Correct answer: A set of detailed instructions guiding the auditor through specific procedures to achieve audit objectives
An audit program is a detailed set of procedures and instructions that guide the auditor in gathering sufficient evidence to meet the specific objectives of the audit.
Question 33: In software project management, a critical path PRIMARILY helps an IS auditor assess:
- Vendor performance against SLA metrics
- The total number of defects in the system
- The cost impact of scope changes
- Which tasks, if delayed, will directly extend the project completion date (Correct answer)
Correct answer: Which tasks, if delayed, will directly extend the project completion date
The critical path identifies the sequence of dependent tasks with zero float, meaning any delay on these tasks delays the entire project.
Question 34: Which of the following activities BEST demonstrates that an organization's security controls are operating effectively, rather than merely existing?
- Maintaining a current inventory of all security policies and procedures
- Conducting regular control testing and reviewing exception reports (Correct answer)
- Documenting all security controls in the risk register
- Having all security policies approved by senior management
Correct answer: Conducting regular control testing and reviewing exception reports
Regular testing validates that controls function as intended in practice, while exception reports reveal gaps between expected and actual control performance.
Question 35: During a follow-up audit, an IS auditor finds that management agreed to a corrective action but implemented a different, untested solution instead. The auditor should:
- Assess whether the alternative solution adequately addresses the original risk (Correct answer)
- Close the finding since management took some action
- Escalate immediately to regulators
- Accept the new solution if management believes it is effective
Correct answer: Assess whether the alternative solution adequately addresses the original risk
The auditor's responsibility is to verify that the original risk is addressed, regardless of whether the solution matches what was originally agreed upon.
Question 36: During a network audit, an IS auditor finds that SNMP v1 is still in use. The PRIMARY concern is:
- SNMP v1 community strings are transmitted in plaintext (Correct answer)
- SNMP v1 cannot monitor router interfaces
- SNMP v1 does not support IPv6
- SNMP v1 uses too much bandwidth
Correct answer: SNMP v1 community strings are transmitted in plaintext
SNMP v1 community strings (essentially passwords) are sent in cleartext, making them vulnerable to interception.
Question 37: What does a Gantt chart PRIMARILY help an IS auditor assess during a systems development review?
- Code quality and defect density
- Project schedule and milestone adherence (Correct answer)
- Vendor contract compliance
- Budget variance and cost overruns
Correct answer: Project schedule and milestone adherence
A Gantt chart visually represents task timelines and milestones, allowing auditors to assess schedule progress and delays.
Question 38: In IT risk management, what does 'residual risk' refer to?
- Risk transferred to a third party
- Risk remaining after controls are applied (Correct answer)
- Risk identified but not yet assessed
- Risk that has been fully eliminated
Correct answer: Risk remaining after controls are applied
Residual risk is the level of risk that remains after control measures have been implemented.
Question 39: The Maximum Tolerable Downtime (MTD) for a critical process is 4 hours. The RTO is set at 6 hours. This situation indicates:
- The recovery plan is adequate since RTO is greater than MTD
- The BIA needs to be redone to align these metrics
- The MTD and RTO are properly aligned
- The RTO exceeds MTD, meaning recovery may not happen before unacceptable damage occurs (Correct answer)
Correct answer: The RTO exceeds MTD, meaning recovery may not happen before unacceptable damage occurs
The RTO must always be less than or equal to the MTD; an RTO greater than MTD means the system may not be restored before irreversible damage occurs.
Question 40: Which of the following scenarios would MOST likely require an immediate, unplanned update to the DR plan?
- Annual review cycle is due next month
- A major application is migrated to a new cloud platform (Correct answer)
- A junior employee joins the IT team
- The company leases additional office space
Correct answer: A major application is migrated to a new cloud platform
Migrating a critical application to a new platform fundamentally changes recovery dependencies, procedures, and RTO/RPO assumptions, requiring immediate DR plan updates.
Question 41: An IS auditor is evaluating single sign-on (SSO) implementation. What is the PRIMARY risk associated with SSO?
- Reduced user productivity due to multiple logins
- Higher administrative overhead for access management
- Single point of failure for authentication (Correct answer)
- Increased password complexity requirements
Correct answer: Single point of failure for authentication
If SSO credentials are compromised, an attacker gains access to all integrated systems simultaneously.
Question 42: An IS auditor is evaluating the IT risk assessment process for a financial services company. The auditor finds that the company uses a qualitative approach, categorizing risks as 'High,' 'Medium,' and 'Low.' The PRIMARY disadvantage of this approach is that it:
- is too complex and time-consuming for most organizations.
- makes it difficult to perform a cost-benefit analysis for countermeasures. (Correct answer)
- is not compliant with international standards like ISO 27005.
- requires specialized software tools to implement effectively.
Correct answer: makes it difficult to perform a cost-benefit analysis for countermeasures.
A qualitative risk assessment uses subjective judgment to assess the likelihood and impact of risk, often using descriptive categories (e.g., High, Medium, Low). While useful for prioritizing risks, its primary weakness is the lack of quantitative data (e.g., monetary values). This subjectivity makes it difficult to conduct a rigorous cost-benefit analysis when evaluating the financial viability of implementing specific controls.
Question 43: An IS auditor finds that developers have direct access to the production environment. The MOST significant risk is:
- Slower deployment cycles due to access conflicts
- Unauthorized or untested changes could be made directly to production (Correct answer)
- Increased help desk ticket volume
- Developer productivity may decrease
Correct answer: Unauthorized or untested changes could be made directly to production
Direct developer access to production breaks segregation of duties and enables unauthorized modifications that bypass change control processes.
Question 44: During a review of identity and access management, an IS auditor notes that the organization has not performed a user access review for over a year, despite significant employee turnover and role changes. The PRIMARY risk this creates is:
- noncompliance with software licensing agreements.
- increased help desk costs for password resets.
- the accumulation of excessive access rights, known as privilege creep. (Correct answer)
- inefficient onboarding of new employees.
Correct answer: the accumulation of excessive access rights, known as privilege creep.
Failure to conduct regular user access reviews leads to 'privilege creep,' where users accumulate access rights beyond what is required for their current job function. This increases the risk of unauthorized access and data breaches, as former employees may retain access or current employees may have excessive privileges.
Question 45: A company outsources its application development to a third-party vendor. Which control is MOST important for the IS auditor to verify?
- The vendor uses the same programming language as internal staff
- Development staff turnover is below industry average
- Contractual rights to audit the vendor and review deliverables (Correct answer)
- The vendor's office is in the same time zone
Correct answer: Contractual rights to audit the vendor and review deliverables
Contractual audit rights ensure the organization retains oversight of vendor activities, code quality, and security practices throughout the engagement.
Question 46: Which protocol provides encrypted remote administration of network devices and is preferred over Telnet?
- SNMP v2
- SSH (Correct answer)
- HTTP
- FTP
Correct answer: SSH
SSH (Secure Shell) encrypts the entire session, whereas Telnet transmits credentials and data in plaintext.
Question 47: What does the acronym COBIT stand for?
- Control Objectives for Business and Related Technology (Correct answer)
- Controls and Objectives for Business and Information Technology
- Control Outcomes for Business and IT
- Certified Objectives for Business and Information Technology
Correct answer: Control Objectives for Business and Related Technology
COBIT stands for Control Objectives for Business and Related Technology, the IT governance and management framework developed by ISACA.
Question 48: The COBIT 2019 management domain APO primarily deals with which activities?
- Delivering IT services and managing operations
- Monitoring IT performance against business objectives
- Aligning IT strategy with business goals, planning IT resources, and organizing IT functions (Correct answer)
- Building and acquiring new IT systems
Correct answer: Aligning IT strategy with business goals, planning IT resources, and organizing IT functions
APO (Align, Plan and Organize) covers strategic alignment, IT resource planning, portfolio management, risk management, and organizational structures.
Question 49: During IS audit planning, an auditor reviews organizational charts and job descriptions. The PRIMARY purpose is to:
- Understand segregation of duties and the assignment of IT responsibilities (Correct answer)
- Identify potential fraud perpetrators
- Determine headcount for staffing risk assessment
- Evaluate employee performance
Correct answer: Understand segregation of duties and the assignment of IT responsibilities
Reviewing organizational charts and job descriptions helps the auditor understand how IT responsibilities are assigned and whether proper segregation of duties exists.
Question 50: When planning an IS audit for a regulated financial institution, which external requirement should MOST influence the audit plan?
- The organization's internal IT strategy document
- The IT vendor's recommended audit procedures
- Competitor audit practices
- Applicable regulatory requirements and compliance mandates (e.g., FFIEC, SOX) (Correct answer)
Correct answer: Applicable regulatory requirements and compliance mandates (e.g., FFIEC, SOX)
Regulatory requirements define mandatory compliance areas that must be covered in the audit plan, taking precedence over internal preferences or vendor guidance.
Question 51: A software development team is using an Agile methodology. To ensure risk is managed effectively, when should risk management activities be performed?
- Only at the end of the project, during the post-implementation review.
- Only at the beginning of the project, during the initial planning phase.
- By a separate, independent risk management team after each major release.
- Continuously throughout the project lifecycle, especially during sprint planning. (Correct answer)
Correct answer: Continuously throughout the project lifecycle, especially during sprint planning.
In Agile methodologies, which are iterative and incremental, risk management cannot be a one-time event. It must be an ongoing process that is integrated into the regular project rhythm. Risks should be identified, assessed, and responded to continuously, often as part of sprint planning, daily stand-ups, and retrospectives, to adapt to changing requirements and project conditions.
Question 52: An IS auditor reviewing software procurement should FIRST verify that the vendor's product:
- Has the lowest licensing cost available
- Supports the latest programming language standards
- Meets the organization's defined functional and security requirements (Correct answer)
- Is widely used by competitors in the same industry
Correct answer: Meets the organization's defined functional and security requirements
Alignment with documented requirements is the foundational criterion before evaluating cost, market share, or technology features.
Question 53: When auditing access control logs, an IS auditor should prioritize reviewing which of the following?
- Failed login attempts and after-hours access by privileged users (Correct answer)
- Successful logins during business hours
- Password change frequency across all users
- Total number of user accounts in the system
Correct answer: Failed login attempts and after-hours access by privileged users
Failed logins may indicate intrusion attempts, and after-hours privileged access is a key indicator of potential misuse or compromise.
Question 54: During a security audit, an IS auditor finds that developers have direct write access to the production database. What is the PRIMARY concern?
- The database may not be adequately backed up
- Developers may slow down production performance with poorly optimized queries
- Direct production access bypasses change management controls and increases insider threat risk (Correct answer)
- Developers lack the expertise to manage production data safely
Correct answer: Direct production access bypasses change management controls and increases insider threat risk
Direct developer access to production bypasses change management and audit trails, enabling unauthorized data modification and violating separation of duties.
Question 55: Which of the following BEST describes the purpose of a data loss prevention (DLP) solution?
- To detect and prevent unauthorized transmission of sensitive data outside the organization (Correct answer)
- To encrypt data at rest in all storage systems
- To back up sensitive data to an offsite location automatically
- To monitor network bandwidth consumed by data transfers
Correct answer: To detect and prevent unauthorized transmission of sensitive data outside the organization
DLP tools inspect content in motion, at rest, and in use to identify and block unauthorized exfiltration of sensitive information.
Question 56: Which firewall rule principle states that anything not explicitly permitted should be denied?
- Least privilege
- Default permit
- Default deny (implicit deny) (Correct answer)
- Defense in depth
Correct answer: Default deny (implicit deny)
An implicit deny rule drops all traffic not explicitly allowed, minimizing exposure to unknown or unauthorized connections.
Question 57: A DMZ (Demilitarized Zone) is BEST described as:
- A network zone between the internet and the internal network that hosts public-facing services (Correct answer)
- A VLAN reserved for administrative management traffic
- A backup network used only during disaster recovery
- A segment where only internal users can access resources
Correct answer: A network zone between the internet and the internal network that hosts public-facing services
A DMZ provides a buffer zone that exposes public services (e.g., web servers) while shielding the internal network.
Question 58: An organization wants to determine the financial impact of a specific risk scenario. Which formula is MOST relevant?
- ALE = ARO × SLE (Correct answer)
- Control Effectiveness = 1 − Residual Risk
- Risk Score = Likelihood + Impact
- Risk = Threat × Vulnerability
Correct answer: ALE = ARO × SLE
ALE (Annualized Loss Expectancy) = ARO (Annualized Rate of Occurrence) × SLE (Single Loss Expectancy) quantifies expected annual financial loss.
Question 59: An IS auditor reviewing network diagrams notices that production and development environments share the same network segment. The MAIN risk is:
- Difficulty in assigning IP addresses to new devices
- Slower network performance in production
- Potential for development activity to compromise production systems (Correct answer)
- Higher infrastructure costs for the organization
Correct answer: Potential for development activity to compromise production systems
Mixing production and development on the same segment can allow vulnerabilities or misconfigurations in dev to impact live systems.
Question 60: An IS auditor reviewing a company's encryption practices finds that sensitive data at rest is encrypted using a symmetric key stored in the same database as the data. What is the PRIMARY concern?
- Symmetric encryption is insufficient for data at rest
- The encryption key and ciphertext are co-located, negating protection (Correct answer)
- The database lacks proper indexing for encrypted fields
- The encryption algorithm may be outdated
Correct answer: The encryption key and ciphertext are co-located, negating protection
Storing the encryption key alongside the encrypted data defeats the purpose of encryption, since an attacker who gains access to the database obtains both.
Question 61: Which of the following BEST describes a risk-based audit approach in IS audit planning?
- Following a fixed template that does not change between audit cycles
- Auditing every system and process equally regardless of risk level
- Focusing only on financial systems because they pose the most regulatory risk
- Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently (Correct answer)
Correct answer: Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently
A risk-based approach directs audit resources toward the areas posing the greatest risk, ensuring that audit effort is proportionate to the likelihood and impact of potential issues.
Question 62: In IT risk management, what does the term 'risk aggregation' refer to?
- Splitting a large risk into smaller, manageable components
- Documenting all risks in a centralized risk register
- Combining multiple small risks to understand their cumulative effect on the organization (Correct answer)
- Transferring multiple risks to a single insurance policy
Correct answer: Combining multiple small risks to understand their cumulative effect on the organization
Risk aggregation combines individual risks to reveal their combined impact, which may be greater than any single risk in isolation.
Question 63: A parallel test of the business continuity plan is conducted. Which statement BEST describes this type of test?
- Primary operations are shut down and all processing moves to the recovery site
- Recovery systems are activated at the alternate site while primary operations continue normally (Correct answer)
- Recovery procedures are reviewed and discussed without any actual system activation
- Only the communication and notification procedures are tested
Correct answer: Recovery systems are activated at the alternate site while primary operations continue normally
In a parallel test, the backup site is activated and processes data while the primary site continues to operate, validating recovery capability without operational risk.
Question 64: In IS audit planning, materiality is BEST defined as:
- The minimum number of control failures that trigger a finding
- The significance of a matter in the context of the audit objectives and stakeholder decision-making (Correct answer)
- The risk level assigned to a specific audit area
- The dollar threshold above which errors must be reported
Correct answer: The significance of a matter in the context of the audit objectives and stakeholder decision-making
Materiality refers to the significance or importance of information, errors, or omissions in the context of the financial statements or audit objectives that could influence stakeholder decisions.
Question 65: During an audit of database controls, an auditor finds that database administrators (DBAs) have unrestricted access to production data without any monitoring. The MOST significant risk is:
- Difficulty performing database upgrades
- Increased licensing costs
- Unauthorized modification or exfiltration of sensitive data without detection (Correct answer)
- Database performance degradation
Correct answer: Unauthorized modification or exfiltration of sensitive data without detection
Unmonitored privileged access to production data creates high risk of insider threat and data integrity compromise.
Question 66: A company has decided to accept the risk associated with a potential data breach because the cost of the recommended countermeasure exceeds the potential loss. Which of the following risk response strategies has the company adopted?
- Risk Transfer
- Risk Mitigation
- Risk Acceptance (Correct answer)
- Risk Avoidance
Correct answer: Risk Acceptance
Risk acceptance is a strategy where an organization decides to accept a risk's potential consequences without taking further action to reduce it. This is often done when the cost of mitigation outweighs the potential loss, or the risk falls within the defined risk appetite.
Question 67: A penetration test differs from a vulnerability assessment primarily because a penetration test:
- Generates a compliance report for auditors
- Only scans for known CVEs using automated tools
- Is conducted exclusively by internal staff
- Actively attempts to exploit discovered vulnerabilities (Correct answer)
Correct answer: Actively attempts to exploit discovered vulnerabilities
Penetration testing goes beyond identifying vulnerabilities by actually attempting to exploit them to determine real-world impact.
Question 68: During a SDLC audit, an IS auditor notices that requirements sign-off was obtained from IT management only, excluding business users. This represents a weakness in:
- Technical architecture review
- Requirements validation and stakeholder engagement (Correct answer)
- Project budgeting controls
- Testing environment setup
Correct answer: Requirements validation and stakeholder engagement
Requirements must be approved by business stakeholders who will use the system, not just IT, to ensure the solution meets actual business needs.
Question 69: A company stores customer credit card data. According to the Payment Card Industry Data Security Standard (PCI DSS), what is the MINIMUM requirement for protecting stored cardholder data?
- All cardholder data must be deleted within 30 days of a transaction
- Primary account numbers (PAN) must be rendered unreadable wherever stored (Correct answer)
- All cardholder data must be encrypted using AES-256
- Cardholder data must be stored only on isolated air-gapped systems
Correct answer: Primary account numbers (PAN) must be rendered unreadable wherever stored
PCI DSS requires that PANs be rendered unreadable in storage through methods such as truncation, hashing, tokenization, or strong cryptography.
Question 70: What is the MAIN advantage of using a risk scenario approach in IT risk management?
- It satisfies regulatory requirements without further analysis
- It replaces the need for a risk register
- It provides concrete, realistic examples that link threats to business impact (Correct answer)
- It eliminates the need for quantitative risk calculations
Correct answer: It provides concrete, realistic examples that link threats to business impact
Risk scenarios describe specific threat events and their potential business consequences, making abstract risks tangible and easier to assess.
Question 71: What is the primary purpose of IT governance frameworks such as COBIT for an organization?
- To automate IT operations and eliminate manual processes
- To enforce specific regulatory compliance mandates
- To replace internal audit and compliance functions entirely
- To provide a common language and framework for aligning IT with business objectives (Correct answer)
Correct answer: To provide a common language and framework for aligning IT with business objectives
IT governance frameworks like COBIT provide a structured approach and common language to ensure IT activities align with and deliver value to business objectives.
Question 72: An IS auditor is reviewing change management controls at a financial institution. The HIGHEST risk finding would be:
- Developers can deploy to production without operations team involvement (Correct answer)
- Change windows occasionally extend past scheduled times
- CAB meetings occur weekly instead of bi-weekly
- Some minor changes are processed without full CAB sign-off
Correct answer: Developers can deploy to production without operations team involvement
Developer access to production deployment eliminates the separation of duties between development and operations, a critical control in regulated environments.
Question 73: When reviewing a software development lifecycle (SDLC), an IS auditor should verify that security requirements are addressed:
- During the requirements and design phases as early as possible (Correct answer)
- Exclusively by the security team, not developers
- After deployment when vulnerabilities are identified in production
- Only during the testing phase before production release
Correct answer: During the requirements and design phases as early as possible
Addressing security in the requirements and design phases is far less costly and more effective than finding vulnerabilities after deployment.
Question 74: An IS auditor recommends that DR test scenarios should include which of the following to be MOST effective?
- A variety of realistic, risk-based scenarios including partial and full failures (Correct answer)
- Scenarios that guarantee a successful recovery outcome
- Scenarios designed by IT staff without business input
- Only scenarios that the team has previously rehearsed
Correct answer: A variety of realistic, risk-based scenarios including partial and full failures
Effective DR tests use diverse, realistic scenarios based on actual risk assessments, including partial outages, to surface a wider range of gaps.
Question 75: Which of the following is the PRIMARY purpose of network traffic analysis in an IS audit?
- To measure the bandwidth consumed by individual users
- To configure QoS policies for business-critical applications
- To replace firewall rules with more efficient configurations
- To detect anomalous traffic patterns that may indicate a security incident (Correct answer)
Correct answer: To detect anomalous traffic patterns that may indicate a security incident
Traffic analysis helps auditors identify deviations from baseline behavior that could signal unauthorized access, data exfiltration, or malware.
Question 76: The concept of 'due professional care' in IS auditing requires that an auditor:
- Guarantee the accuracy of all findings and conclusions
- Always issue a qualified audit opinion
- Complete the audit within a budget-specified timeframe
- Apply the care and skill expected of a reasonably prudent IS auditor (Correct answer)
Correct answer: Apply the care and skill expected of a reasonably prudent IS auditor
Due professional care requires IS auditors to exercise the skill and diligence expected of a reasonably prudent professional, not perfection or guaranteed outcomes.
Question 77: Which of the following is the PRIMARY purpose of an IS audit charter?
- To list the specific systems and applications to be audited during the fiscal year.
- To outline the annual budget and resource allocation for the IS audit function.
- To establish the authority, scope, and responsibilities of the IS audit function. (Correct answer)
- To document the detailed audit procedures and testing methodologies.
Correct answer: To establish the authority, scope, and responsibilities of the IS audit function.
The audit charter is a high-level document that establishes the authority, independence, scope, and overall responsibility of the audit function. It is approved by the highest level of management and the audit committee and provides the foundation for all audit activities.
Question 78: During an audit, an IS auditor finds that privileged accounts are used for routine daily tasks by IT staff. What is the PRIMARY recommendation?
- Implement separate standard accounts for routine tasks (Correct answer)
- Enable additional logging for privileged accounts only
- Increase the complexity of privileged account passwords
- Require manager approval for each privileged account use
Correct answer: Implement separate standard accounts for routine tasks
Privileged accounts should be used only when elevated rights are needed; daily tasks should use standard accounts to reduce exposure risk.
Question 79: Which risk assessment approach assigns numerical values to the likelihood and impact of risks to calculate an overall risk score?
- Qualitative risk assessment
- Delphi technique
- Control self-assessment
- Quantitative risk assessment (Correct answer)
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values and formulas (e.g., ALE = ARO × SLE) to express risk in financial or statistical terms.
Question 80: An IS auditor is planning an audit of a cloud-hosted ERP system. Which consideration is UNIQUE to cloud environments compared to on-premises systems?
- Reliance on third-party audits such as SOC 2 reports to assess provider controls (Correct answer)
- Need to evaluate user access controls
- Requirement to review change management procedures
- Importance of evaluating backup and recovery processes
Correct answer: Reliance on third-party audits such as SOC 2 reports to assess provider controls
In cloud environments, the auditor typically cannot directly test provider infrastructure controls and must rely on third-party assurance reports like SOC 2 Type II to evaluate those controls.
Question 81: Which role is PRIMARILY responsible for accepting residual risk within an organization?
- Chief Information Officer (CIO)
- Risk owner or senior management (Correct answer)
- External auditor
- IT security manager
Correct answer: Risk owner or senior management
Risk acceptance is a management decision and must be made by the appropriate risk owner or senior management with the authority to do so.
Question 82: In BCP terminology, which term refers to the minimum level of services that must be maintained for the organization to survive a disaster?
- Maximum Tolerable Downtime
- Service Level Agreement
- Minimum Business Continuity Objective (MBCO) (Correct answer)
- Recovery Point Objective
Correct answer: Minimum Business Continuity Objective (MBCO)
MBCO defines the minimum level of services and/or products acceptable to achieve the business objectives during a disruption.
Question 83: An organization needs to encrypt a large database for data-at-rest protection. Performance is a key requirement, and the system processing the data is in a secure, controlled environment. Which of the following encryption methods is MOST appropriate for this scenario?
- Hashing
- Symmetric encryption (Correct answer)
- Digital signature
- Asymmetric encryption
Correct answer: Symmetric encryption
Symmetric encryption uses a single key for both encryption and decryption, which is significantly faster and more computationally efficient than asymmetric encryption. This makes it the ideal choice for encrypting large volumes of data, such as entire databases or files at rest.
Question 84: During a review of an application's authentication mechanism, an IS auditor finds session tokens that never expire. What is the PRIMARY risk?
- System performance degrades as sessions accumulate
- Captured session tokens can be reused indefinitely by attackers (Correct answer)
- Users must re-authenticate too frequently, reducing productivity
- Password policies cannot be enforced without session expiration
Correct answer: Captured session tokens can be reused indefinitely by attackers
Non-expiring session tokens allow session hijacking attacks to persist indefinitely, granting long-term unauthorized access.
Question 85: A software development project is using a traditional Waterfall methodology. An IS auditor would be MOST concerned about the risk of:
- a lack of detailed documentation for each phase.
- requirements not being fully defined and understood until late in the lifecycle. (Correct answer)
- the project scope expanding without formal control.
- insufficient stakeholder involvement throughout the project.
Correct answer: requirements not being fully defined and understood until late in the lifecycle.
A key characteristic and major risk of the Waterfall model is its linear and sequential nature, where each phase must be completed before the next begins. This means that requirements must be fully defined and frozen upfront. Any misunderstandings or changes discovered during the testing or implementation phase are very difficult and costly to address, making this the biggest inherent risk of the methodology.
Question 86: Which of the following is the PRIMARY objective of a structured walkthrough during system development?
- Assigning blame for coding errors to individual developers
- Documenting project budget expenditures
- Training end users on the new system
- Peer review of code or design to identify defects early (Correct answer)
Correct answer: Peer review of code or design to identify defects early
Structured walkthroughs are formal peer review sessions designed to detect errors in design, code, or documentation before they propagate to later phases.
Question 87: An IS auditor is planning an audit in an environment where management has implemented continuous monitoring tools. The auditor should PRIMARILY:
- Assume controls are effective since continuous monitoring is in place
- Rely entirely on continuous monitoring results and skip independent testing
- Replace audit sampling with management's monitoring reports
- Evaluate the design and effectiveness of the continuous monitoring tools as part of the audit plan (Correct answer)
Correct answer: Evaluate the design and effectiveness of the continuous monitoring tools as part of the audit plan
The auditor must assess whether the continuous monitoring tools themselves are properly designed and operating effectively before placing any reliance on their output.
Question 88: An IS auditor is assessing a project that used prototyping as its development approach. The PRIMARY risk of this methodology is:
- Excessive unit testing of prototype modules
- Vendor lock-in to prototyping tools
- Too much time spent on requirements gathering
- Insufficient technical documentation and scope creep (Correct answer)
Correct answer: Insufficient technical documentation and scope creep
Prototyping can lead to inadequate formal documentation and uncontrolled scope expansion as stakeholders continually request enhancements to the prototype.
Question 89: An IS auditor is planning to audit a cloud-based customer relationship management (CRM) system. Which of the following is the MOST important initial step?
- Conducting a vulnerability scan of the cloud provider's infrastructure.
- Verifying the encryption standards used for data in transit to the cloud provider.
- Interviewing the organization's sales team to understand their use of the CRM.
- Requesting and reviewing the Service Organization Control (SOC) 2 report from the cloud vendor. (Correct answer)
Correct answer: Requesting and reviewing the Service Organization Control (SOC) 2 report from the cloud vendor.
When auditing a system hosted by a third party, the most efficient and critical first step is to review the vendor's SOC 2 report. This report provides an independent assessment of the vendor's controls related to security, availability, processing integrity, confidentiality, and privacy, which is essential for scoping the audit and understanding the control environment.
Question 90: Which domain covers the largest percentage of the CISA exam according to ISACA's content outline?
- Protection of Information Assets
- Governance and Management of IT
- Information Systems Auditing Process (Correct answer)
- Information Systems Acquisition, Development and Implementation
Correct answer: Information Systems Auditing Process
The Information Systems Auditing Process domain carries the highest weight at 21% of the CISA exam.
Question 91: Which element is MOST critical to include in a business continuity plan for an organization that relies heavily on third-party vendors?
- Vendor financial ratings
- A list of alternative vendors with no contract in place
- Third-party vendor continuity and resilience requirements (Correct answer)
- Vendor contact lists only
Correct answer: Third-party vendor continuity and resilience requirements
Organizations must ensure third-party vendors have adequate continuity plans and contractual obligations to support recovery objectives.
Question 92: During a CISA audit of the testing phase, an auditor discovers that developers performed their own integration testing with no independent review. This violates the principle of:
- Segregation of duties (Correct answer)
- Defense in depth
- Need to know
- Least privilege access
Correct answer: Segregation of duties
Segregation of duties requires that testing be performed or reviewed independently from development to ensure objectivity and catch biases.
Question 93: An IS auditor is planning a review of access controls. The PRIMARY reason for performing a preliminary survey is to:
- Replace the need for detailed testing of controls
- Document findings for the audit report
- Obtain sufficient understanding of the environment to develop audit procedures (Correct answer)
- Identify all control deficiencies before fieldwork begins
Correct answer: Obtain sufficient understanding of the environment to develop audit procedures
A preliminary survey provides the auditor with enough understanding of the systems, processes, and environment to design appropriate and targeted audit procedures.
Question 94: Which of the following BEST describes a risk scenario used in IT risk management frameworks like COBIT?
- A description of a past security incident
- A financial model that calculates potential losses
- A narrative that connects a threat actor, event, and business impact (Correct answer)
- A list of controls that prevent a specific risk
Correct answer: A narrative that connects a threat actor, event, and business impact
A risk scenario in COBIT combines a threat source, vulnerability, and resulting business impact into a coherent narrative for assessment purposes.
Question 95: Which of the following is the BEST control for preventing DNS spoofing attacks?
- Configuring DNS servers on the DMZ only
- Using SNMP to monitor DNS traffic
- Implementing DNSSEC to cryptographically sign DNS records (Correct answer)
- Disabling all external DNS queries
Correct answer: Implementing DNSSEC to cryptographically sign DNS records
DNSSEC adds digital signatures to DNS records, allowing resolvers to verify authenticity and reject forged responses.
Question 96: A CISA auditor finds that a company's risk register has not been updated in 18 months. What is the PRIMARY concern?
- Emerging risks may not be identified or monitored (Correct answer)
- The audit trail is incomplete
- Risk owners have not been assigned
- The risk register format may be outdated
Correct answer: Emerging risks may not be identified or monitored
A stale risk register means new and evolving threats may go unrecognized, leaving the organization exposed to unmanaged risks.
Question 97: During a risk assessment, a CISA auditor discovers that a critical system has no documented risk treatment plan. What should the auditor recommend FIRST?
- Accept the risk and document it in the audit report
- Transfer the risk to a third-party provider immediately
- Immediately shut down the system until a plan is in place
- Assign a risk owner and develop a formal risk treatment plan (Correct answer)
Correct answer: Assign a risk owner and develop a formal risk treatment plan
The immediate priority is assigning accountability and creating a formal treatment plan to address the gap in governance.
Question 98: An organization wants to reduce its RTO from 8 hours to 1 hour. Which action would MOST directly achieve this goal?
- Upgrading from a cold site to a hot site with pre-configured systems (Correct answer)
- Purchasing cyber insurance with a rapid-response clause
- Increasing the frequency of full system backups
- Hiring additional IT staff dedicated to disaster recovery
Correct answer: Upgrading from a cold site to a hot site with pre-configured systems
Upgrading to a hot site with pre-configured, ready-to-use systems eliminates the time needed to procure, install, and configure equipment, directly reducing RTO.
Question 99: When reviewing an Agile development project, an IS auditor should be MOST concerned if:
- The product backlog is maintained in a digital tool rather than on paper
- Security and compliance requirements are consistently deferred to later sprints (Correct answer)
- Daily standups are held remotely via video conference
- Sprints are two weeks long instead of four weeks
Correct answer: Security and compliance requirements are consistently deferred to later sprints
Continuously deferring security and compliance work creates technical debt and may result in a system that fails regulatory requirements at launch.
Question 100: An IS auditor is reviewing an organization's IT risk management process. Which of the following is the MOST critical first step in this process?
- Conducting a business impact analysis (BIA).
- Implementing security controls.
- Developing risk response plans.
- Identifying and classifying information assets. (Correct answer)
Correct answer: Identifying and classifying information assets.
The foundational step in any IT risk management process is to understand what needs to be protected. This involves identifying all information assets and classifying them based on their value and sensitivity to the organization. Without this, it is impossible to effectively assess threats, vulnerabilities, and potential impacts, or to select appropriate risk responses.
Question 101: A CISA auditor is evaluating the IT risk management framework. Which characteristic is MOST indicative of a mature risk management process?
- Risk assessments are performed only when incidents occur
- Risk registers are maintained exclusively by the audit team
- Risk management is embedded in all IT project and change management processes (Correct answer)
- The IT department manages all risks without executive involvement
Correct answer: Risk management is embedded in all IT project and change management processes
A mature risk management process is embedded across IT operations and projects, making risk consideration a routine part of all decisions rather than a reactive exercise.
Question 102: The audit charter ought to:
- outline the overall authority, scope and responsibilities of the audit function. (Correct answer)
- clearly state audit objectives for, and the delegation of, authority to the maintenance and review of internal controls
- document the audit procedures designed to achieve the planned audit objectives.
- be dynamic and change to coincide with the changing nature of technology and the audit profession.
Correct answer: outline the overall authority, scope and responsibilities of the audit function.
The audit charter is a formal document that establishes the purpose, authority, and responsibility of the internal audit function within an organization. It defines the audit's overall scope, its organizational reporting lines, and the types of activities it is authorized to undertake. This document provides the foundational framework and mandate for all audit work, ensuring clarity and independence.
Question 103: An IS auditor is reviewing the change management process for a critical financial application. It is noted that developers are able to promote their own code changes directly into the production environment. This practice represents a failure of which fundamental control principle?
- Security by design
- Segregation of duties (SoD) (Correct answer)
- Defense in depth
- Principle of least privilege
Correct answer: Segregation of duties (SoD)
Segregation of duties (SoD) is a fundamental internal control concept that involves separating tasks and responsibilities among different people to prevent fraud and errors. Allowing a developer to write code and also promote it to production without independent oversight violates SoD, as it creates an opportunity for unauthorized or untested changes to be implemented.
Question 104: During application testing, what is the MAIN purpose of boundary value analysis?
- Testing input values at the edges of valid ranges where defects are most likely (Correct answer)
- Measuring database query response times
- Verifying system performance under peak load conditions
- Confirming user interface color schemes meet accessibility standards
Correct answer: Testing input values at the edges of valid ranges where defects are most likely
Boundary value analysis tests values at, just below, and just above defined input limits, where programming errors are most commonly found.
Question 105: When auditing a VPN implementation, an IS auditor should FIRST verify that:
- VPN software licenses are current
- All employees are required to use VPN regardless of location
- VPN connection logs are deleted after 30 days
- Strong encryption algorithms and multi-factor authentication are enforced (Correct answer)
Correct answer: Strong encryption algorithms and multi-factor authentication are enforced
Strong encryption and MFA are the foundational controls that protect VPN tunnels from interception and unauthorized access.
Question 106: Which of the following is an example of a QUALITATIVE risk analysis technique?
- Using a 5x5 risk heat map with High/Medium/Low ratings (Correct answer)
- Computing the Return on Security Investment (ROSI)
- Estimating Single Loss Expectancy (SLE) in dollars
- Calculating Annualized Loss Expectancy (ALE)
Correct answer: Using a 5x5 risk heat map with High/Medium/Low ratings
A risk heat map using descriptive categories like High, Medium, and Low is a qualitative technique that does not rely on precise numerical values.
Question 107: An IS auditor concludes that the planned audit cannot be completed within budget due to expanded scope. The auditor should FIRST:
- Inform management and obtain approval for additional resources or a revised scope (Correct answer)
- Carry over remaining work to the next audit cycle without disclosure
- Reduce testing in low-risk areas to compensate
- Issue a qualified audit opinion due to resource constraints
Correct answer: Inform management and obtain approval for additional resources or a revised scope
When audit constraints arise, the auditor must communicate transparently with management to either secure additional resources or formally revise the scope through proper approval.
Question 108: During an audit, it is discovered that the organization has not defined its risk appetite. What is the PRIMARY concern for the IS auditor?
- The organization may be overspending on security controls.
- Risk mitigation efforts may not be aligned with business objectives. (Correct answer)
- Compliance with industry regulations cannot be achieved.
- The frequency of risk assessments is likely insufficient.
Correct answer: Risk mitigation efforts may not be aligned with business objectives.
Risk appetite is the amount and type of risk that an organization is willing to pursue or retain. Without a clearly defined risk appetite, there is no strategic guidance for making risk-based decisions. This can lead to a misalignment between risk management activities and the organization's strategic goals and objectives, resulting in either excessive risk-taking or overly cautious behavior that stifles innovation.
Question 109: Can an auditor depend on the audit client's risk estimate for audit planning?
- No. The auditor does not require a risk assessment to develop an audit plan
- Yes, if the risk assessment was performed by a qualified external entity (Correct answer)
- Yes, in all cases
- No. The auditor must perform a risk assessment himself or herself
Correct answer: Yes, if the risk assessment was performed by a qualified external entity
An auditor can rely on a client's risk assessment for audit planning, but only under specific conditions. The assessment must have been performed by a qualified external entity, ensuring objectivity and adherence to professional standards. However, the auditor must still exercise professional skepticism and evaluate the adequacy and appropriateness of the client's assessment before incorporating it into their own audit plan.
Question 110: An IS auditor is planning an audit of an organization that recently implemented an AI-based fraud detection system. Which audit area deserves the MOST attention in the initial planning phase?
- Physical security of AI servers
- Algorithm bias, model validation, and governance of AI decision-making (Correct answer)
- Vendor support contract terms
- Number of fraud alerts generated daily
Correct answer: Algorithm bias, model validation, and governance of AI decision-making
AI systems introduce risks around model accuracy, bias, and lack of explainability, making algorithm validation and governance the most critical areas for an IS auditor to plan around.
Question 111: Which type of access control model assigns permissions based on a user's role within an organization?
- Attribute-Based Access Control (ABAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC grants access based on predefined roles, simplifying administration and supporting least privilege.
Question 112: Which risk categories should be taken into account when planning an audit, as per ISACA Audit Standard 1202?
- Financial risk
- Cybersecurity risk
- Business risk (Correct answer)
- Fraud risk
Correct answer: Business risk
ISACA Audit Standard 1202, 'Risk Assessment in Planning,' mandates that the IS auditor identify and assess risks relevant to the audit objectives. This primarily refers to business risks, which encompass various threats that could impact an organization's ability to achieve its strategic and operational objectives. By understanding business risks, the auditor can focus their efforts on areas with the highest potential impact.
Question 113: During IS audit planning, the auditor reviews prior audit workpapers. The PRIMARY benefit of this review is to:
- Copy prior procedures to save planning time
- Confirm that prior auditors used appropriate methodologies
- Understand previously identified risks, findings, and remediation status to inform current planning (Correct answer)
- Avoid duplication by skipping areas already tested
Correct answer: Understand previously identified risks, findings, and remediation status to inform current planning
Reviewing prior workpapers helps identify historical risk areas, outstanding findings, and whether remediation was completed, all of which inform current audit risk assessment and focus.
Question 114: A rollback plan for a database schema change should PRIMARILY include:
- Approval signatures from all CAB members
- A timeline for when the change will be re-attempted
- Steps to restore the previous schema and validate data integrity (Correct answer)
- The contact list of all affected stakeholders
Correct answer: Steps to restore the previous schema and validate data integrity
A database rollback plan must define precise steps to revert the schema and verify that data has not been corrupted during restoration.
Question 115: Which testing type validates that a new system does not adversely affect existing integrated systems?
- Stress testing
- Regression testing (Correct answer)
- Unit testing
- Parallel testing
Correct answer: Regression testing
Regression testing re-runs prior test cases to confirm that new changes have not broken existing functionality in interconnected systems.
Question 116: An IS auditor is planning an audit and must evaluate whether to use Computer-Assisted Audit Techniques (CAATs). The PRIMARY advantage of CAATs is:
- They ensure 100% accuracy of audit findings
- They reduce the need for interviewing auditees
- They eliminate the need for auditor judgment
- They enable analysis of entire data populations rather than just samples (Correct answer)
Correct answer: They enable analysis of entire data populations rather than just samples
CAATs allow auditors to analyze complete data populations rather than relying on samples, providing greater coverage and statistical confidence in findings.
Question 117: Which recovery metric defines the maximum tolerable period of data loss after a disruption?
- Recovery Point Objective (RPO) (Correct answer)
- Mean Time to Recover (MTTR)
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Point Objective (RPO)
RPO defines the maximum age of data that must be recovered from backup for normal operations to resume.
Question 118: During testing, a developer discovers a critical defect but the project manager instructs the team to proceed to production anyway. The IS auditor's BEST response is to:
- Document the risk and escalate to senior management (Correct answer)
- Immediately shut down the project
- Rewrite the affected module independently
- Accept the decision since it is management's prerogative
Correct answer: Document the risk and escalate to senior management
The auditor's role is to document findings and escalate unresolved risks through proper governance channels, not to override management decisions unilaterally.
Question 119: Which security concept is BEST demonstrated when a financial system requires both a manager and an accountant to approve wire transfers above a threshold?
- Least privilege
- Defense in depth
- Need to know
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Requiring two individuals from different roles to authorize a transaction enforces separation of duties, preventing any single person from completing a sensitive transaction alone.
Question 120: Which network security device inspects packet headers and filters traffic based on predefined rules without examining packet content?
- Packet-filtering firewall (Correct answer)
- Stateful firewall
- Intrusion Detection System
- Web application firewall
Correct answer: Packet-filtering firewall
A packet-filtering firewall examines IP headers, ports, and protocols but does not inspect the actual content of packets.
Question 121: When auditing a data conversion during system migration, the IS auditor should PRIMARILY verify that:
- The new system uses a modern database engine
- All data was accurately and completely transferred to the new system (Correct answer)
- The old system was decommissioned on schedule
- Data entry screens match legacy system layouts
Correct answer: All data was accurately and completely transferred to the new system
Data integrity and completeness during conversion is critical; any data loss or corruption directly impacts business continuity and reliability of the new system.
Question 122: A company is concerned that its employees may be accidentally or maliciously sending sensitive customer lists via corporate email to external parties. Which of the following would be the MOST effective control to detect and prevent this specific type of data exfiltration?
- Deploying a host-based intrusion prevention system (HIPS) on all workstations.
- Conducting regular security awareness training on data handling.
- Implementing a network-based Data Loss Prevention (DLP) solution. (Correct answer)
- Implementing end-to-end email encryption.
Correct answer: Implementing a network-based Data Loss Prevention (DLP) solution.
A Data Loss Prevention (DLP) solution is specifically designed to address this risk. Network-based DLP tools can inspect outbound email traffic in real-time, identify content that matches predefined patterns or classifications for sensitive data (like customer lists), and then block, quarantine, or alert on the transmission, thereby preventing the data leak.
Question 123: Within ISACA's framework, which component provides IS auditors with specific step-by-step procedures for conducting an audit?
- Tools and Techniques (Correct answer)
- Standards
- Audit charters
- Guidelines
Correct answer: Tools and Techniques
Tools and Techniques are practical resources that provide IS auditors with specific procedures, checklists, and methods to apply the Standards and Guidelines.
Question 124: Which of the following BEST reduces the risk of unauthorized wireless network access?
- Enabling WEP encryption on all access points
- Broadcasting the SSID to help users locate the network
- Placing access points near exterior walls for better signal
- Using WPA3 with strong pre-shared keys and 802.1X authentication (Correct answer)
Correct answer: Using WPA3 with strong pre-shared keys and 802.1X authentication
WPA3 with 802.1X provides enterprise-grade authentication and strong encryption, making unauthorized access significantly harder.
Question 125: An IS auditor planning an audit of the software development lifecycle (SDLC) should PRIMARILY focus on which phase for the highest control risk?
- Testing phase
- Production deployment phase (Correct answer)
- Requirements gathering phase
- Maintenance phase
Correct answer: Production deployment phase
Production deployment is the highest-risk SDLC phase because unauthorized or untested code moving to production can directly impact business operations and data integrity.
Question 126: During a DR tabletop exercise, the team discovers the backup media restoration procedure references a tool no longer installed on recovery servers. This finding BEST illustrates the importance of:
- Testing during off-peak hours
- Offsite media rotation schedules
- Encrypting backup media
- Keeping DR documentation current with production changes (Correct answer)
Correct answer: Keeping DR documentation current with production changes
The gap between documented procedures and the actual recovery environment shows that DR documentation must be updated whenever production systems change.
Question 127: Which of the following scenarios BEST illustrates an inappropriate restriction on audit scope that an IS auditor should escalate?
- Management provides a list of recommended contacts for interviews
- Management requests the auditor avoid reviewing a specific high-risk system due to 'sensitivity' (Correct answer)
- The audit committee requests a focus on cybersecurity controls
- Management asks for a preliminary briefing before the audit report is finalized
Correct answer: Management requests the auditor avoid reviewing a specific high-risk system due to 'sensitivity'
When management restricts access to a high-risk area without valid justification, it represents a scope limitation that must be escalated to the audit committee as it impairs audit independence.
Question 128: An Intrusion Prevention System (IPS) differs from an IDS primarily because an IPS can:
- Generate alerts for suspicious activity
- Actively block or drop malicious traffic in real time (Correct answer)
- Log network traffic for forensic analysis
- Perform vulnerability scans on endpoints
Correct answer: Actively block or drop malicious traffic in real time
An IPS sits inline with traffic and can actively block threats, whereas an IDS only monitors and alerts.
Question 129: Which of the following network redundancy configurations provides the HIGHEST availability for a critical link?
- Periodic tape backup of router configurations
- Load balancing across identical links with no failover
- Hot standby with automatic failover (Correct answer)
- Cold standby requiring manual activation
Correct answer: Hot standby with automatic failover
Hot standby with automatic failover switches traffic to the backup link instantly without human intervention, maximizing uptime.
Question 130: An organization conducts a business continuity test where key team members gather in a conference room to discuss their roles and responsibilities in response to a simulated disaster scenario presented by a facilitator. Which type of test does this scenario describe?
- Tabletop exercise (Correct answer)
- Parallel test
- Walk-through test
- Full interruption test
Correct answer: Tabletop exercise
This scenario describes a tabletop exercise. A tabletop exercise is a discussion-based session where team members review and discuss their roles and responses to a particular emergency situation, without any actual activation of recovery systems. It's used to validate plans and confirm team members' understanding of their roles.
Question 131: During a DR test, the team successfully restores data but discovers the restored database is missing two hours of transactions. Which control failure does this MOST directly indicate?
- Replication or backup frequency not meeting the RPO (Correct answer)
- Insufficient staffing at the recovery site
- Inadequate physical security at the recovery site
- Failure to encrypt backup data
Correct answer: Replication or backup frequency not meeting the RPO
Missing two hours of transactions means the backup or replication interval was too long, causing the RPO to be exceeded.
Question 132: Which sampling technique is most appropriate when an IS auditor wants every item in the population to have an equal chance of selection?
- Judgmental sampling
- Simple random sampling (Correct answer)
- Cluster sampling
- Stratified sampling
Correct answer: Simple random sampling
Simple random sampling gives every item in the population an equal and independent probability of being selected, eliminating selection bias.
Question 133: A company has strong IT controls but no formal IT governance structure. The MOST likely consequence is:
- IT controls may not address the right risks or business priorities (Correct answer)
- The company will face immediate regulatory penalties
- IT staff turnover will increase significantly
- Controls will fail more frequently
Correct answer: IT controls may not address the right risks or business priorities
Without governance directing which risks matter most, even strong controls may protect against the wrong threats while leaving strategic risks unaddressed.
Question 134: Which of the following is the PRIMARY security benefit of implementing a Single Sign-On (SSO) solution across an organization?
- It improves the user experience by eliminating the need for multiple logins.
- It transfers the risk of authentication to a third-party vendor.
- It centralizes the administration of user accounts.
- It reduces the attack surface by decreasing the number of stored credentials. (Correct answer)
Correct answer: It reduces the attack surface by decreasing the number of stored credentials.
The primary security benefit of SSO is that it reduces the attack surface. By centralizing authentication, it minimizes the number of places where passwords are stored and entered, which in turn reduces the risk of password theft, reuse, and leakage.
Question 135: Which phase of the SDLC presents the greatest opportunity for IS auditors to influence security and control design?
- Testing
- Maintenance
- Implementation
- Requirements and design (Correct answer)
Correct answer: Requirements and design
Auditor involvement during requirements and design is most effective because changes are least costly at this early stage.
Question 136: What does the acronym 'COBIT' stand for?
- Control Objectives for Information and Related Technologies (Correct answer)
- Certified Objectives for Business IT
- Control Operations for Integrated Business Technology
- Core Objectives for Information Technology
Correct answer: Control Objectives for Information and Related Technologies
COBIT stands for Control Objectives for Information and Related Technologies, a framework by ISACA.
Question 137: When should IS audit planning ideally begin relative to the audit fieldwork?
- Immediately before fieldwork starts
- After preliminary interviews with management are complete
- Only after the prior audit's findings are remediated
- Well in advance to allow adequate preparation, risk assessment, and resource allocation (Correct answer)
Correct answer: Well in advance to allow adequate preparation, risk assessment, and resource allocation
Planning should begin well in advance of fieldwork to allow time for risk assessment, scoping, resource scheduling, and coordination with auditees.
Question 138: What is the MAIN purpose of a Business Impact Analysis (BIA) in the context of IT risk management?
- To determine the criticality of business processes and recovery priorities (Correct answer)
- To calculate the cost of implementing risk controls
- To identify all security vulnerabilities in IT systems
- To assess the compliance posture of the organization
Correct answer: To determine the criticality of business processes and recovery priorities
A BIA identifies which business processes are most critical, helping prioritize IT risk management and recovery efforts accordingly.
Question 139: A CISA auditor is reviewing router access control lists (ACLs). The MOST important audit step is to verify that ACLs:
- Reflect the organization's network security policy and follow least privilege (Correct answer)
- Are as permissive as possible to avoid blocking legitimate traffic
- Have not been changed in the past 12 months
- Are only applied on external-facing interfaces
Correct answer: Reflect the organization's network security policy and follow least privilege
ACLs should be derived from and aligned with the security policy, permitting only necessary traffic on each interface.
Question 140: Which of the following BEST describes the purpose of a program change log?
- To record user access requests to the system
- To track software licensing compliance
- To provide an audit trail of all modifications made to production programs (Correct answer)
- To document developer time spent on each task
Correct answer: To provide an audit trail of all modifications made to production programs
A program change log maintains a chronological record of who changed what and when, forming the audit trail for production program modifications.
Question 141: When planning an IS audit, an auditor discovers that the organization recently experienced a major system migration. How should this affect the audit plan?
- Increase audit scope to cover migration risks and residual vulnerabilities (Correct answer)
- Postpone the audit until the system stabilizes
- Reduce scope since new systems have fewer legacy issues
- Focus only on pre-migration controls
Correct answer: Increase audit scope to cover migration risks and residual vulnerabilities
A recent system migration increases inherent risk and should prompt the auditor to expand scope to cover migration-related risks, data integrity issues, and control gaps.
Question 142: An auditor is assessing whether IT investments are governed effectively. The BEST evidence would be:
- IT staff performance reviews
- Vendor invoices for technology purchases
- A list of completed IT projects
- Board-approved IT investment portfolio with documented business cases and post-implementation reviews (Correct answer)
Correct answer: Board-approved IT investment portfolio with documented business cases and post-implementation reviews
A board-approved investment portfolio with business cases and post-implementation reviews demonstrates that IT investments are selected, authorized, and evaluated against expected benefits.
Question 143: A company's IT risk management process identifies a vulnerability but determines no credible threat exploits it. What is the MOST appropriate action?
- Escalate to senior management for immediate action
- Immediately remediate the vulnerability
- Monitor it in case a credible threat emerges (Correct answer)
- Document it and accept the risk without controls
Correct answer: Monitor it in case a credible threat emerges
Without a credible threat, the immediate risk is low, but the vulnerability should be monitored in case the threat landscape changes.
Question 144: During a review of IT governance, an IS auditor finds that there is no formal IT risk management program. Which of the following represents the GREATEST risk to the organization?
- The organization's risk appetite may be exceeded without senior management's awareness. (Correct answer)
- The IT department may not be able to attract skilled personnel.
- Increased cost of technology procurement.
- IT projects may not be completed on time.
Correct answer: The organization's risk appetite may be exceeded without senior management's awareness.
A formal IT risk management program is essential for identifying, assessing, and mitigating risks. Without it, the organization may unknowingly accept a level of risk that is higher than what senior management has deemed acceptable (the risk appetite), potentially leading to significant business impact. [30, 34]
Question 145: Which of the following represents a KEY principle of IT governance according to ISO/IEC 38500?
- Evaluate, direct, and monitor (Correct answer)
- Prioritize cost savings over innovation
- Delegate all IT decisions to the CIO
- Acquire only proven technology
Correct answer: Evaluate, direct, and monitor
ISO/IEC 38500 defines IT governance through three key principles: evaluate current and future IT use, direct preparation and implementation of plans, and monitor conformance and performance.
Question 146: A CISA auditor reviewing network segmentation should PRIMARILY verify that:
- Firewalls are only deployed at the network perimeter
- Critical systems are isolated in separate network zones (Correct answer)
- All systems reside on a single flat network
- Wireless and wired networks share the same subnet
Correct answer: Critical systems are isolated in separate network zones
Proper network segmentation places critical systems in isolated zones to limit the blast radius of a breach.
Question 147: A data center's physical security controls are being examined by an IS auditor, who finds various cause for concern. Which one of the following is the MOST crucial?
- Scheduled maintenance of the fire suppression system was not performed.
- The emergency power off button cover is missing.
- There are no security cameras inside the data center.
- The emergency exit door is blocked. (Correct answer)
Correct answer: The emergency exit door is blocked.
The obstruction of the emergency escape is the most significant issue because life safety is always the top priority.
Question 148: In the context of IS audit planning, 'scope creep' refers to:
- Expanding the audit team mid-engagement
- The process of narrowing scope to focus on high-risk areas
- Additional testing required when control deficiencies are found
- Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines (Correct answer)
Correct answer: Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines
Scope creep occurs when the audit scope expands incrementally beyond original boundaries without formal approval, potentially compromising audit quality and resource management.
Question 149: Which of the following BEST supports the audit trail requirements for logical access controls?
- Storing logs on the same server as the monitored application
- Centralizing logs to a write-once, tamper-evident repository (Correct answer)
- Retaining logs for a minimum of 30 days only
- Allowing system administrators to manage their own activity logs
Correct answer: Centralizing logs to a write-once, tamper-evident repository
Centralized, tamper-evident log storage ensures log integrity and prevents administrators from covering their tracks.
Question 150: Which of the following BEST describes the relationship between audit objectives and audit procedures in IS audit planning?
- Audit procedures and objectives are developed independently
- Audit objectives drive the design of audit procedures used to gather evidence (Correct answer)
- Audit objectives are set by the auditee, not the auditor
- Audit procedures define the objectives the auditor wants to achieve
Correct answer: Audit objectives drive the design of audit procedures used to gather evidence
Audit objectives define what the auditor seeks to determine, and audit procedures are then designed specifically to gather the evidence needed to meet those objectives.
Question 151: An auditor reviewing patch management finds that critical patches are applied within 30 days but the vendor recommends 7 days. What is the auditor's BEST conclusion?
- The vendor recommendation is too aggressive and can be ignored
- The organization is exposed to elevated risk during the gap period (Correct answer)
- The process is acceptable since patches are eventually applied
- The process should be halted until patches are applied in real time
Correct answer: The organization is exposed to elevated risk during the gap period
Delaying critical patches beyond vendor recommendations leaves known vulnerabilities unaddressed, increasing exposure to exploitation.
Question 152: An IS auditor notices that a corporation has contracted out software development to a startup company as a third party. Which of the following should the IS auditor advise the firm to implement in order to protect the investment they have made in software?
- A quarterly audit of the vendor facilities should be performed.
- Due diligence should be performed on the software vendor.
- There should be a source code escrow agreement in place. (Correct answer)
- A high penalty clause should be included in the contract.
Correct answer: There should be a source code escrow agreement in place.
A source code escrow agreement is primarily advised to assist safeguard the enterprise's investment in software because the source code will be accessible through a reliable third party and can be retrieved in the event that the start-up vendor goes out of business.
ISACA CISA Certified Information Systems Auditor Exam
The ISACA Certified Information Systems Auditor (CISA) Exam covers IS audit planning, IT governance, risk management, system development, change management controls, business continuity, disaster recovery, logical access controls, network security, and data management across five domains.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds