โ† All CISA Flashcard Decks

Trivia Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Trivia flashcards as text
  1. In IS auditing, what is 'sampling risk'?

    Answer: The risk that the auditor's conclusion based on a sample differs from the conclusion if the entire population were examined

    Sampling risk is the possibility that the auditor's sample-based conclusion does not reflect the actual state of the entire population.

  2. Which of the following best describes 'data integrity' in information systems?

    Answer: Assurance that data is accurate, complete, and has not been altered without authorization

    Data integrity means data is accurate, complete, consistent, and protected from unauthorized modification.

  3. What is the term for the IS audit technique where the auditor processes simulated transactions through a live system to test controls?

    Answer: Integrated test facility (ITF)

    An ITF introduces fictitious test entities and transactions into a production system to verify that controls operate correctly.

  4. Which phase of the SDLC presents the greatest opportunity for IS auditors to influence security and control design?

    Answer: Requirements and design

    Auditor involvement during requirements and design is most effective because changes are least costly at this early stage.

  5. What is 'patch management' and why is it relevant to IS auditors?

    Answer: The process of applying software updates to fix vulnerabilities, which auditors review for timeliness and completeness

    Patch management involves deploying vendor-issued fixes; auditors assess whether patches are applied promptly to reduce exposure.

  6. In the context of CISA, what is the primary purpose of an IS audit charter?

    Answer: Define the authority, scope, and responsibilities of the IS audit function

    An IS audit charter formally establishes the mandate, independence, authority, and scope of the internal IS audit function.

  7. Which of the following best describes a 'compensating control'?

    Answer: A control that mitigates risk when the primary control is absent or ineffective

    A compensating control reduces risk to an acceptable level when the ideal primary control cannot be implemented.