ISACA CISA Certified Information Systems Auditor Exam — Questions and Answers
Question 1: Which of the following represents a KEY principle of IT governance according to ISO/IEC 38500?
- Evaluate, direct, and monitor (Correct answer)
- Prioritize cost savings over innovation
- Acquire only proven technology
- Delegate all IT decisions to the CIO
Correct answer: Evaluate, direct, and monitor
ISO/IEC 38500 defines IT governance through three key principles: evaluate current and future IT use, direct preparation and implementation of plans, and monitor conformance and performance.
Question 2: An IS auditor is assessing a project that used prototyping as its development approach. The PRIMARY risk of this methodology is:
- Vendor lock-in to prototyping tools
- Too much time spent on requirements gathering
- Insufficient technical documentation and scope creep (Correct answer)
- Excessive unit testing of prototype modules
Correct answer: Insufficient technical documentation and scope creep
Prototyping can lead to inadequate formal documentation and uncontrolled scope expansion as stakeholders continually request enhancements to the prototype.
Question 3: In IS audit planning, which approach helps an auditor identify control gaps by mapping risks to existing controls?
- Entity-relationship diagramming
- Data flow diagramming
- Flowcharting
- Control matrix (risk-control matrix) (Correct answer)
Correct answer: Control matrix (risk-control matrix)
A risk-control matrix maps identified risks to the controls designed to mitigate them, making it easy to spot areas where controls are absent, weak, or duplicated.
Question 4: During application testing, what is the MAIN purpose of boundary value analysis?
- Verifying system performance under peak load conditions
- Confirming user interface color schemes meet accessibility standards
- Testing input values at the edges of valid ranges where defects are most likely (Correct answer)
- Measuring database query response times
Correct answer: Testing input values at the edges of valid ranges where defects are most likely
Boundary value analysis tests values at, just below, and just above defined input limits, where programming errors are most commonly found.
Question 5: When should IS audit planning ideally begin relative to the audit fieldwork?
- Only after the prior audit's findings are remediated
- Immediately before fieldwork starts
- Well in advance to allow adequate preparation, risk assessment, and resource allocation (Correct answer)
- After preliminary interviews with management are complete
Correct answer: Well in advance to allow adequate preparation, risk assessment, and resource allocation
Planning should begin well in advance of fieldwork to allow time for risk assessment, scoping, resource scheduling, and coordination with auditees.
Question 6: An IS auditor discovers that a shared administrator account is used by several network engineers to manage critical infrastructure. Which of the following is the GREATEST risk associated with this practice?
- Complexity in managing access when an engineer changes roles.
- Increased likelihood of password compromise due to social engineering.
- Violation of the principle of 'need-to-know'.
- Inability to trace specific actions to an individual engineer. (Correct answer)
Correct answer: Inability to trace specific actions to an individual engineer.
The primary risk of using shared accounts is the loss of accountability. If a malicious or erroneous action occurs, it is impossible to determine which specific individual performed the action because the audit logs will only show the shared account name.
Question 7: In IT risk management, what does the term 'risk aggregation' refer to?
- Splitting a large risk into smaller, manageable components
- Combining multiple small risks to understand their cumulative effect on the organization (Correct answer)
- Transferring multiple risks to a single insurance policy
- Documenting all risks in a centralized risk register
Correct answer: Combining multiple small risks to understand their cumulative effect on the organization
Risk aggregation combines individual risks to reveal their combined impact, which may be greater than any single risk in isolation.
Question 8: An IS auditor is developing a risk-based audit plan. Which of the following is the FIRST step the auditor should perform?
- Develop the audit scope and objectives for specific high-risk areas.
- Review the findings and workpapers from the previous year's audit.
- Interview senior management to understand their perspective on risk.
- Identify the organization's critical assets and business processes. (Correct answer)
Correct answer: Identify the organization's critical assets and business processes.
The foundational step in a risk-based audit approach is to understand what is most important to the organization. By identifying critical assets and key business processes, the auditor can then effectively assess the threats and vulnerabilities associated with them to determine areas of highest risk.
Question 9: Which IS audit planning concept ensures that audit conclusions are supported by sufficient, reliable, relevant, and useful evidence?
- Audit risk model
- Audit evidence standards (Correct answer)
- Audit materiality
- Audit independence
Correct answer: Audit evidence standards
Audit evidence standards require that the evidence gathered be sufficient (enough), reliable (trustworthy), relevant (pertinent to the objective), and useful (supportive of conclusions).
Question 10: The COSO Internal Control — Integrated Framework is primarily designed to help organizations with which concern?
- Delivering IT services efficiently
- Network security architecture
- Agile software development practices
- Internal control and enterprise risk management (Correct answer)
Correct answer: Internal control and enterprise risk management
COSO is a widely adopted framework for designing, implementing, and evaluating internal control and enterprise risk management across an organization.
Question 11: Which risk treatment option involves transferring the financial consequences of a risk to a third party?
- Risk transfer (Correct answer)
- Risk mitigation
- Risk acceptance
- Risk avoidance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to another party, such as through insurance or outsourcing contracts.
Question 12: An IS auditor is planning a review of access controls. The PRIMARY reason for performing a preliminary survey is to:
- Document findings for the audit report
- Replace the need for detailed testing of controls
- Obtain sufficient understanding of the environment to develop audit procedures (Correct answer)
- Identify all control deficiencies before fieldwork begins
Correct answer: Obtain sufficient understanding of the environment to develop audit procedures
A preliminary survey provides the auditor with enough understanding of the systems, processes, and environment to design appropriate and targeted audit procedures.
Question 13: A company stores backup media at a facility 2 miles from the primary data center. An IS auditor's MAIN concern would be:
- The media may not be properly labeled for identification
- The backup facility may have different environmental controls
- The proximity may mean both sites are affected by the same regional disaster (Correct answer)
- The cost of transporting media to the offsite location
Correct answer: The proximity may mean both sites are affected by the same regional disaster
Offsite storage must be far enough away to avoid being impacted by the same disaster (flood, hurricane, earthquake) that affects the primary site.
Question 14: An organization uses a third-party cloud provider for critical data processing. Which audit approach is MOST appropriate to assess the provider's controls?
- Rely solely on contractual guarantees
- Review the vendor's marketing materials
- Conduct an on-site audit of every data center
- Obtain and evaluate a SOC 2 Type II report (Correct answer)
Correct answer: Obtain and evaluate a SOC 2 Type II report
A SOC 2 Type II report provides an independent assessment of a service organization's controls over a period of time.
Question 15: A company has decided to accept the risk associated with a potential data breach because the cost of the recommended countermeasure exceeds the potential loss. Which of the following risk response strategies has the company adopted?
- Risk Acceptance (Correct answer)
- Risk Transfer
- Risk Mitigation
- Risk Avoidance
Correct answer: Risk Acceptance
Risk acceptance is a strategy where an organization decides to accept a risk's potential consequences without taking further action to reduce it. This is often done when the cost of mitigation outweighs the potential loss, or the risk falls within the defined risk appetite.
Question 16: Which of the following is the PRIMARY objective of a structured walkthrough during system development?
- Assigning blame for coding errors to individual developers
- Documenting project budget expenditures
- Peer review of code or design to identify defects early (Correct answer)
- Training end users on the new system
Correct answer: Peer review of code or design to identify defects early
Structured walkthroughs are formal peer review sessions designed to detect errors in design, code, or documentation before they propagate to later phases.
Question 17: What is the MAIN purpose of a Business Impact Analysis (BIA) in the context of IT risk management?
- To assess the compliance posture of the organization
- To identify all security vulnerabilities in IT systems
- To determine the criticality of business processes and recovery priorities (Correct answer)
- To calculate the cost of implementing risk controls
Correct answer: To determine the criticality of business processes and recovery priorities
A BIA identifies which business processes are most critical, helping prioritize IT risk management and recovery efforts accordingly.
Question 18: An IS auditor is evaluating the business continuity preparedness of a large financial institution. Which of the following provides the MOST assurance that the business continuity plan (BCP) is effective and will function as intended in a real disaster?
- A full-scale interruption test conducted at the alternate processing site. (Correct answer)
- A comprehensive business impact analysis (BIA) that is updated quarterly.
- Annual review and approval of the BCP by senior management.
- A recent, successful tabletop exercise with key stakeholders.
Correct answer: A full-scale interruption test conducted at the alternate processing site.
A full-scale interruption test, where actual operations are failed over to the alternate site, provides the highest level of assurance that the BCP is effective. This type of test validates not just the documentation and the team's understanding (like a tabletop), but also the technical capabilities, procedures, and personnel readiness in a simulated real-world scenario.
Question 19: An IS auditor notices that a key IT system has not been audited in three years. According to risk-based planning, this fact PRIMARILY affects which planning element?
- Residual risk
- Detection risk
- Control risk assessment
- Audit frequency prioritization (Correct answer)
Correct answer: Audit frequency prioritization
A long gap since the last audit increases the priority of that system in audit frequency planning, as unaudited areas may have accumulated undetected risks.
Question 20: During a review of an application's authentication mechanism, an IS auditor finds session tokens that never expire. What is the PRIMARY risk?
- Password policies cannot be enforced without session expiration
- Users must re-authenticate too frequently, reducing productivity
- Captured session tokens can be reused indefinitely by attackers (Correct answer)
- System performance degrades as sessions accumulate
Correct answer: Captured session tokens can be reused indefinitely by attackers
Non-expiring session tokens allow session hijacking attacks to persist indefinitely, granting long-term unauthorized access.
Question 21: What is the PURPOSE of a change freeze period in IT change management?
- To give the CAB time to review a backlog of requests
- To prevent changes during high-risk periods such as peak business times or audits (Correct answer)
- To halt all IT operations for system maintenance
- To allow developers to catch up on documentation
Correct answer: To prevent changes during high-risk periods such as peak business times or audits
Change freeze periods minimize the risk of introducing instability during critical business periods when system reliability is paramount.
Question 22: A financial services firm determines that its trading system has an MTD of 30 minutes. Which recovery strategy is MOST appropriate?
- Warm site with 4-hour restoration time
- Weekly full backups stored offsite
- Hot site with synchronous replication and automated failover (Correct answer)
- Cold site with 24-hour equipment procurement process
Correct answer: Hot site with synchronous replication and automated failover
A 30-minute MTD requires near-instant failover capability, only achievable through a hot site with real-time synchronous replication and automated switchover.
Question 23: Which of the following is an example of an IT governance output?
- An approved IT policy defining acceptable use (Correct answer)
- A firewall rule blocking external traffic
- A database backup completed overnight
- A server patch applied to production systems
Correct answer: An approved IT policy defining acceptable use
IT governance outputs include policies, principles, frameworks, and accountability structures—not day-to-day operational activities like patching or backups.
Question 24: Which ISACA standard requires IS auditors to maintain independence from the areas they audit?
- ISO/IEC 27001 Clause 9
- COBIT 5 APO12
- ISACA IS Audit and Assurance Standard 1002 (Correct answer)
- ISACA IS Audit Standard 1401
Correct answer: ISACA IS Audit and Assurance Standard 1002
ISACA Standard 1002 (Organisational Independence) requires auditors to be independent from the functions and activities they audit.
Question 25: An organization categorizes changes as standard, normal, and emergency. What is the defining characteristic of a standard change?
- It requires full CAB approval every time
- It is initiated only by senior management
- It is pre-approved because it follows a documented, low-risk procedure (Correct answer)
- It bypasses testing due to time constraints
Correct answer: It is pre-approved because it follows a documented, low-risk procedure
Standard changes have been pre-assessed as low-risk with established procedures, allowing them to proceed without repeated full CAB review.
Question 26: A CISA auditor notes that management consistently accepts risks without documented justification. What is the PRIMARY concern?
- Risk acceptance decisions lack accountability and auditability (Correct answer)
- Management may be understating the organization's risk appetite
- IT staff will not prioritize remediation efforts
- The risk register will become too large to manage
Correct answer: Risk acceptance decisions lack accountability and auditability
Undocumented risk acceptance decisions cannot be audited or reviewed, undermining governance and accountability.
Question 27: When reviewing an organization's incident response plan, an IS auditor should verify that the plan includes which of the following as a CRITICAL element?
- Technical specifications for all security tools used in response
- A requirement to report all incidents to law enforcement
- A list of all potential threats ranked by likelihood
- Defined roles, responsibilities, and escalation procedures (Correct answer)
Correct answer: Defined roles, responsibilities, and escalation procedures
Clearly defined roles, responsibilities, and escalation procedures ensure coordinated and timely response when an incident occurs, which is the most critical operational element.
Question 28: What does a Gantt chart PRIMARILY help an IS auditor assess during a systems development review?
- Code quality and defect density
- Project schedule and milestone adherence (Correct answer)
- Budget variance and cost overruns
- Vendor contract compliance
Correct answer: Project schedule and milestone adherence
A Gantt chart visually represents task timelines and milestones, allowing auditors to assess schedule progress and delays.
Question 29: An IS auditor recommends that DR test scenarios should include which of the following to be MOST effective?
- Scenarios that guarantee a successful recovery outcome
- A variety of realistic, risk-based scenarios including partial and full failures (Correct answer)
- Only scenarios that the team has previously rehearsed
- Scenarios designed by IT staff without business input
Correct answer: A variety of realistic, risk-based scenarios including partial and full failures
Effective DR tests use diverse, realistic scenarios based on actual risk assessments, including partial outages, to surface a wider range of gaps.
Question 30: A company is concerned that its employees may be accidentally or maliciously sending sensitive customer lists via corporate email to external parties. Which of the following would be the MOST effective control to detect and prevent this specific type of data exfiltration?
- Conducting regular security awareness training on data handling.
- Deploying a host-based intrusion prevention system (HIPS) on all workstations.
- Implementing end-to-end email encryption.
- Implementing a network-based Data Loss Prevention (DLP) solution. (Correct answer)
Correct answer: Implementing a network-based Data Loss Prevention (DLP) solution.
A Data Loss Prevention (DLP) solution is specifically designed to address this risk. Network-based DLP tools can inspect outbound email traffic in real-time, identify content that matches predefined patterns or classifications for sensitive data (like customer lists), and then block, quarantine, or alert on the transmission, thereby preventing the data leak.
Question 31: An IS auditor is reviewing a healthcare organization's EHR system. Which logical access control would BEST address the HIPAA minimum necessary standard?
- Using VPN for all remote access to patient records
- Implementing context-based access that limits record visibility to treating clinicians (Correct answer)
- Enabling full audit logging of all record accesses
- Requiring strong passwords for all clinical staff
Correct answer: Implementing context-based access that limits record visibility to treating clinicians
Context-based access ensures clinicians only see records for patients under their direct care, aligning with HIPAA's minimum necessary requirement.
Question 32: An organization migrates to a new ERP system using a phased approach. The PRIMARY advantage of this strategy over a big-bang cutover is:
- Reduced disruption and ability to isolate issues by module (Correct answer)
- Elimination of data conversion requirements
- Faster overall implementation timeline
- Lower total project cost
Correct answer: Reduced disruption and ability to isolate issues by module
Phased implementation reduces risk by limiting scope at each stage, making it easier to identify and resolve problems without impacting the entire organization.
Question 33: When reviewing an Agile development project, an IS auditor should be MOST concerned if:
- Security and compliance requirements are consistently deferred to later sprints (Correct answer)
- Daily standups are held remotely via video conference
- Sprints are two weeks long instead of four weeks
- The product backlog is maintained in a digital tool rather than on paper
Correct answer: Security and compliance requirements are consistently deferred to later sprints
Continuously deferring security and compliance work creates technical debt and may result in a system that fails regulatory requirements at launch.
Question 34: In a risk-based audit approach, the IS auditor's decisions on the nature, timing, and extent of testing should be PRIMARILY based on the:
- assessment of inherent and control risks. (Correct answer)
- previous year's audit findings and recommendations.
- complexity of the organization's IT environment.
- availability of skilled audit staff and resources.
Correct answer: assessment of inherent and control risks.
A risk-based approach requires the auditor to focus resources on areas with the greatest potential for material misstatement or control failure. The assessment of inherent risk (the susceptibility of an area to error) and control risk (the risk that controls will fail to prevent or detect an error) is the key driver for determining how, when, and how much testing is needed.
Question 35: An IS auditor is evaluating controls over privileged accounts in a large enterprise. Which of the following is the MOST effective control for mitigating the risks associated with administrator access?
- Enforcing a complex password policy for all administrator accounts.
- Conducting annual background checks on all system administrators.
- Requiring all administrators to sign a nondisclosure agreement (NDA).
- Implementing a Privileged Access Management (PAM) solution with session monitoring. (Correct answer)
Correct answer: Implementing a Privileged Access Management (PAM) solution with session monitoring.
A Privileged Access Management (PAM) solution is the most effective and comprehensive control. It provides a centralized mechanism to vault credentials, enforce least privilege, implement just-in-time access, and, most importantly, monitor and record privileged sessions, which creates strong accountability and detectability.
Question 36: An IS auditor reviewing system documentation finds that no operations manual exists for a newly implemented system. The PRIMARY concern is:
- The system may not integrate with social media platforms
- Operations staff may be unable to maintain or recover the system properly (Correct answer)
- Development costs may increase in the next phase
- End users may not enjoy the interface
Correct answer: Operations staff may be unable to maintain or recover the system properly
Without an operations manual, staff lack the guidance needed for routine operations, troubleshooting, and disaster recovery, increasing operational risk.
Question 37: A third-party vendor has access to sensitive customer data. Which risk management activity is MOST critical?
- Conducting an annual penetration test on internal systems
- Implementing multi-factor authentication for employees
- Encrypting all internal databases
- Performing vendor risk assessments and due diligence reviews (Correct answer)
Correct answer: Performing vendor risk assessments and due diligence reviews
Third-party access requires formal vendor risk assessments to evaluate whether the vendor's controls adequately protect the organization's data.
Question 38: Which ISACA framework is MOST directly aligned with IT risk management practices for CISA candidates?
- ISO 9001
- ITIL 4
- COBIT 2019 (Correct answer)
- TOGAF
Correct answer: COBIT 2019
COBIT 2019 is ISACA's primary governance and management framework, which includes specific guidance on IT risk management.
Question 39: A CISA auditor is evaluating the IT risk management framework. Which characteristic is MOST indicative of a mature risk management process?
- The IT department manages all risks without executive involvement
- Risk registers are maintained exclusively by the audit team
- Risk management is embedded in all IT project and change management processes (Correct answer)
- Risk assessments are performed only when incidents occur
Correct answer: Risk management is embedded in all IT project and change management processes
A mature risk management process is embedded across IT operations and projects, making risk consideration a routine part of all decisions rather than a reactive exercise.
Question 40: A company outsources its application development to a third-party vendor. Which control is MOST important for the IS auditor to verify?
- Contractual rights to audit the vendor and review deliverables (Correct answer)
- The vendor uses the same programming language as internal staff
- The vendor's office is in the same time zone
- Development staff turnover is below industry average
Correct answer: Contractual rights to audit the vendor and review deliverables
Contractual audit rights ensure the organization retains oversight of vendor activities, code quality, and security practices throughout the engagement.
Question 41: An IS auditor is evaluating a company's disaster recovery plan. Which metric defines the maximum acceptable period of data loss following a disruption?
- Mean Time to Repair (MTTR)
- Maximum Tolerable Downtime (MTD)
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO) (Correct answer)
Correct answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum age of data that must be recovered after a disaster to resume normal operations.
Question 42: An organization uses Key Risk Indicators (KRIs). What is the PRIMARY purpose of KRIs?
- To provide early warning signals of increasing risk exposure (Correct answer)
- To replace the need for a formal risk assessment
- To document risk scenarios for audit purposes
- To measure the effectiveness of IT controls after an incident
Correct answer: To provide early warning signals of increasing risk exposure
KRIs act as leading indicators that signal when risk levels are approaching thresholds, enabling proactive management.
Question 43: In IT risk management, a threat is BEST described as:
- The impact of a security breach
- A potential cause of an unwanted incident (Correct answer)
- A weakness in a system that can be exploited
- The likelihood of an adverse event occurring
Correct answer: A potential cause of an unwanted incident
A threat is any potential event or action that could exploit a vulnerability and cause harm to an asset.
Question 44: Which of the following BEST describes the purpose of a risk appetite statement?
- To document risk mitigation strategies
- To define the level of risk the organization is willing to accept (Correct answer)
- To assign risk owners to each identified risk
- To list all identified risks in the organization
Correct answer: To define the level of risk the organization is willing to accept
A risk appetite statement articulates how much risk the board and senior management are willing to tolerate in pursuit of business objectives.
Question 45: The MOST effective control to prevent SQL injection vulnerabilities in a newly developed web application is:
- Implementing strong password policies for database administrators
- Restricting physical access to the database server
- Using parameterized queries and input validation in application code (Correct answer)
- Encrypting all data stored in the database
Correct answer: Using parameterized queries and input validation in application code
Parameterized queries separate SQL logic from user-supplied data, preventing malicious input from being interpreted as SQL commands.
Question 46: Which of the following BEST describes the relationship between audit objectives and audit procedures in IS audit planning?
- Audit objectives are set by the auditee, not the auditor
- Audit procedures and objectives are developed independently
- Audit objectives drive the design of audit procedures used to gather evidence (Correct answer)
- Audit procedures define the objectives the auditor wants to achieve
Correct answer: Audit objectives drive the design of audit procedures used to gather evidence
Audit objectives define what the auditor seeks to determine, and audit procedures are then designed specifically to gather the evidence needed to meet those objectives.
Question 47: An IS auditor is planning an audit of an organization that recently implemented an AI-based fraud detection system. Which audit area deserves the MOST attention in the initial planning phase?
- Number of fraud alerts generated daily
- Algorithm bias, model validation, and governance of AI decision-making (Correct answer)
- Vendor support contract terms
- Physical security of AI servers
Correct answer: Algorithm bias, model validation, and governance of AI decision-making
AI systems introduce risks around model accuracy, bias, and lack of explainability, making algorithm validation and governance the most critical areas for an IS auditor to plan around.
Question 48: Which SDLC phase is MOST concerned with translating business requirements into technical specifications?
- Programming and testing
- Implementation
- Systems design (Correct answer)
- Feasibility study
Correct answer: Systems design
The systems design phase converts logical business requirements into detailed technical blueprints for developers.
Question 49: What is the term for the IS audit technique where the auditor processes simulated transactions through a live system to test controls?
- Data analytics
- Integrated test facility (ITF) (Correct answer)
- Parallel simulation
- Continuous auditing
Correct answer: Integrated test facility (ITF)
An ITF introduces fictitious test entities and transactions into a production system to verify that controls operate correctly.
Question 50: Which of the following network redundancy configurations provides the HIGHEST availability for a critical link?
- Load balancing across identical links with no failover
- Hot standby with automatic failover (Correct answer)
- Periodic tape backup of router configurations
- Cold standby requiring manual activation
Correct answer: Hot standby with automatic failover
Hot standby with automatic failover switches traffic to the backup link instantly without human intervention, maximizing uptime.
Question 51: The original code was later restored when a malicious programmer changed a production software to alter data. Which of the following would be able to catch the malicious activity the BEST?
- Reviewing system log files (Correct answer)
- Comparing source code
- Comparing object code
- Reviewing executable and source code integrity
Correct answer: Reviewing system log files
System log files record user activities, system events, and changes made to configurations or data. In the event of a malicious programmer altering production software, these logs would provide an audit trail detailing who accessed the system, when the changes occurred, and potentially what modifications were made. This makes reviewing system log files the most effective method for detecting and investigating unauthorized activity and identifying the malicious actor.
Question 52: An organization wants to determine the financial impact of a specific risk scenario. Which formula is MOST relevant?
- Control Effectiveness = 1 − Residual Risk
- ALE = ARO × SLE (Correct answer)
- Risk Score = Likelihood + Impact
- Risk = Threat × Vulnerability
Correct answer: ALE = ARO × SLE
ALE (Annualized Loss Expectancy) = ARO (Annualized Rate of Occurrence) × SLE (Single Loss Expectancy) quantifies expected annual financial loss.
Question 53: When planning an IS audit, an auditor should review the organization's IT policies, standards, and procedures to:
- understand the control environment and established control objectives. (Correct answer)
- design specific substantive tests to detect fraud.
- evaluate the technical competence of the IT staff.
- determine the required sample sizes for compliance testing.
Correct answer: understand the control environment and established control objectives.
Reviewing governance documents like policies, standards, and procedures gives the auditor a clear understanding of management's intent and the established control framework. This forms the basis for evaluating the adequacy and effectiveness of internal controls.
Question 54: After completing a DR test, management decides the results do not need to be shared with the board. An IS auditor should flag this because:
- The board needs to personally restore backup systems
- The board is responsible for approving all technical configurations
- DR test results must be published publicly under US law
- Board-level oversight of DR program effectiveness is a governance best practice (Correct answer)
Correct answer: Board-level oversight of DR program effectiveness is a governance best practice
Governance frameworks such as COBIT and ISO 22301 require that DR program results be reported to senior leadership and the board to ensure appropriate oversight of organizational resilience.
Question 55: An auditor is reviewing the background check procedure while inspecting a company's hiring procedure. The auditor is primarily concerned with whether background checks are conducted on all employees and whether the results of those checks result in decisions not to hire someone. Which of the following methods for gathering evidence will support this audit goal?
- Get a copy of the background check ledger that lists the names of the applicants, the findings of the background checks, and the choices to hire or not to hire. (Correct answer)
- Examine the background check procedure and make a note of the qualities that are mentioned for each candidate.
- Request the full contents of background checks along with hire/no-hire decisions.
- Request the hire/no-hire decisions from the auditee.
Correct answer: Get a copy of the background check ledger that lists the names of the applicants, the findings of the background checks, and the choices to hire or not to hire.
The auditor's goal is to verify that background checks are conducted on all employees and that the results influence hiring decisions. A background check ledger that lists applicants, the findings of their checks, and the final hire/no-hire decisions directly provides the necessary evidence to achieve this objective. It allows the auditor to trace the process from check initiation to the final decision for a population of applicants.
Question 56: An IS auditor is planning an audit of a cloud-hosted ERP system. Which consideration is UNIQUE to cloud environments compared to on-premises systems?
- Reliance on third-party audits such as SOC 2 reports to assess provider controls (Correct answer)
- Requirement to review change management procedures
- Need to evaluate user access controls
- Importance of evaluating backup and recovery processes
Correct answer: Reliance on third-party audits such as SOC 2 reports to assess provider controls
In cloud environments, the auditor typically cannot directly test provider infrastructure controls and must rely on third-party assurance reports like SOC 2 Type II to evaluate those controls.
Question 57: Which of the following BEST represents the relationship between risk tolerance and risk appetite?
- Risk tolerance is broader than risk appetite
- Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it (Correct answer)
- Risk tolerance and risk appetite are interchangeable terms
- Risk appetite applies to individual risks; tolerance applies to overall strategy
Correct answer: Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it
Risk appetite is the overall level of risk an organization is willing to pursue, while risk tolerance is the acceptable variance around that appetite for specific risks.
Question 58: In the context of IS audit planning, 'scope creep' refers to:
- Additional testing required when control deficiencies are found
- Expanding the audit team mid-engagement
- The process of narrowing scope to focus on high-risk areas
- Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines (Correct answer)
Correct answer: Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines
Scope creep occurs when the audit scope expands incrementally beyond original boundaries without formal approval, potentially compromising audit quality and resource management.
Question 59: During a network review, an auditor finds that network administrators share a single privileged account. This PRIMARILY violates the principle of:
- Non-repudiation and individual accountability (Correct answer)
- Defense in depth
- Network segmentation
- Least privilege for end users
Correct answer: Non-repudiation and individual accountability
Shared accounts make it impossible to attribute actions to specific individuals, undermining accountability and audit trails.
Question 60: When scheduling DR tests, the MOST important factor an IS auditor should verify is that tests are:
- Approved by senior management and aligned with business risk (Correct answer)
- Limited to IT staff to avoid business disruption
- Performed at least once every five years
- Conducted only during weekends to minimize impact
Correct answer: Approved by senior management and aligned with business risk
DR tests should have management approval and be scheduled based on business risk tolerance, criticality of systems, and regulatory requirements.
Question 61: An IS auditor is planning an audit and must evaluate whether to use Computer-Assisted Audit Techniques (CAATs). The PRIMARY advantage of CAATs is:
- They reduce the need for interviewing auditees
- They eliminate the need for auditor judgment
- They enable analysis of entire data populations rather than just samples (Correct answer)
- They ensure 100% accuracy of audit findings
Correct answer: They enable analysis of entire data populations rather than just samples
CAATs allow auditors to analyze complete data populations rather than relying on samples, providing greater coverage and statistical confidence in findings.
Question 62: When auditing a DevOps environment, which control is MOST critical to verify regarding the deployment pipeline?
- That all deployments are performed manually by a senior engineer
- That deployments occur only on Fridays to maximize monitoring time
- That automated security scans and approval gates are embedded in the CI/CD pipeline (Correct answer)
- That developers attend weekly code review meetings
Correct answer: That automated security scans and approval gates are embedded in the CI/CD pipeline
Embedding automated security scans and approval gates in the CI/CD pipeline ensures every deployment is vetted for vulnerabilities and authorized before reaching production.
Question 63: The management is starting to wonder about the timeline and completion of an audit project that is going far too long. This audit might be deficient in:
- Effective project management (Correct answer)
- Clearly stated scope and objectives
- Enough skilled auditors
- Cooperation from individual auditees
Correct answer: Effective project management
When an audit project extends beyond its expected timeline and management expresses concern, it indicates a breakdown in the audit's planning, execution, or monitoring. Effective project management for an audit involves clearly defining scope, setting realistic timelines, allocating resources efficiently, and consistently tracking progress. A deficiency in these areas leads to delays and concerns about the project's completion.
Question 64: A rollback plan for a database schema change should PRIMARILY include:
- A timeline for when the change will be re-attempted
- Approval signatures from all CAB members
- Steps to restore the previous schema and validate data integrity (Correct answer)
- The contact list of all affected stakeholders
Correct answer: Steps to restore the previous schema and validate data integrity
A database rollback plan must define precise steps to revert the schema and verify that data has not been corrupted during restoration.
Question 65: During a DR test, a member of the recovery team cannot locate the call tree and is unable to notify key stakeholders. This BEST highlights a gap in:
- DR plan accessibility and communication procedures (Correct answer)
- Encryption of recovery media
- Server backup frequency
- Network redundancy
Correct answer: DR plan accessibility and communication procedures
Recovery team members must be able to access communication tools and call trees immediately; failure to do so indicates the plan is not accessible or communication procedures are inadequate.
Question 66: During a BCP audit, an IS auditor finds that the organization has not updated its BCP in three years. What is the MOST significant risk?
- Executive management may not have signed off on the plan
- The plan may be stored in an insecure location
- The plan may not reflect current business processes and systems (Correct answer)
- The BCP may not include a communication tree
Correct answer: The plan may not reflect current business processes and systems
An outdated BCP may fail to account for changes in infrastructure, personnel, and critical processes, making it ineffective during a real disaster.
Question 67: Which of the following is the BEST control for preventing DNS spoofing attacks?
- Disabling all external DNS queries
- Implementing DNSSEC to cryptographically sign DNS records (Correct answer)
- Using SNMP to monitor DNS traffic
- Configuring DNS servers on the DMZ only
Correct answer: Implementing DNSSEC to cryptographically sign DNS records
DNSSEC adds digital signatures to DNS records, allowing resolvers to verify authenticity and reject forged responses.
Question 68: An IS auditor notes that a company's disaster recovery plan has not been tested since a major cloud migration project was completed one year ago. The PRIMARY risk associated with this finding is that the:
- cost of a future test will be significantly higher.
- DRP may not be aligned with the current technology infrastructure. (Correct answer)
- employees may be unaware of their roles and responsibilities.
- organization may be out of compliance with industry regulations.
Correct answer: DRP may not be aligned with the current technology infrastructure.
Disaster recovery plans must be tested regularly, especially after significant changes to the IT environment, such as a cloud migration. The primary risk of not testing after such a change is that the documented recovery procedures are likely outdated and will not work for the new infrastructure, rendering the plan ineffective in a real disaster.
Question 69: An IS auditor is reviewing the change management process for a critical financial application. It is noted that developers are able to promote their own code changes directly into the production environment. This practice represents a failure of which fundamental control principle?
- Principle of least privilege
- Security by design
- Defense in depth
- Segregation of duties (SoD) (Correct answer)
Correct answer: Segregation of duties (SoD)
Segregation of duties (SoD) is a fundamental internal control concept that involves separating tasks and responsibilities among different people to prevent fraud and errors. Allowing a developer to write code and also promote it to production without independent oversight violates SoD, as it creates an opportunity for unauthorized or untested changes to be implemented.
Question 70: Which of the following represents a compensating control when segregation of duties cannot be fully implemented due to staffing constraints?
- Reducing the number of systems in the environment
- Implementing stronger physical access controls
- Enhanced monitoring and supervisory review of all transactions (Correct answer)
- Increasing user training on ethical behavior
Correct answer: Enhanced monitoring and supervisory review of all transactions
When full segregation of duties is infeasible, enhanced monitoring and supervisory review provides detective controls to identify misuse.
Question 71: What is the PRIMARY goal of IT risk communication within an organization?
- To ensure decision-makers have timely, accurate risk information (Correct answer)
- To document all risks in a central repository
- To transfer risk responsibility to risk owners
- To satisfy external regulatory requirements
Correct answer: To ensure decision-makers have timely, accurate risk information
Risk communication ensures that relevant stakeholders receive accurate information to make informed decisions about risk response.
Question 72: An IS auditor is assessing the maturity of an organization's IT risk management process using CMMI levels. A process that is documented, standardized, and consistently applied organization-wide BEST corresponds to which maturity level?
- Level 4 – Quantitatively Managed
- Level 2 – Managed
- Level 1 – Initial
- Level 3 – Defined (Correct answer)
Correct answer: Level 3 – Defined
CMMI Level 3 (Defined) is characterized by processes that are documented, standardized, and consistently applied across the entire organization.
Question 73: An organization is preparing to migrate data from a legacy system to a new ERP platform. Which of the following is the MOST critical control for an IS auditor to verify before the data conversion process begins?
- A complete data backup of the legacy system has been performed and validated.
- The data conversion logic has been reviewed and approved by the data owners. (Correct answer)
- End-user training on the new ERP system has been concluded.
- The new ERP system's user acceptance testing (UAT) has been successfully completed.
Correct answer: The data conversion logic has been reviewed and approved by the data owners.
The accuracy and integrity of the data in the new system depend entirely on the correctness of the conversion logic. Therefore, having the data owners—who are responsible for the data's quality—review and approve the logic is the most critical control to prevent data corruption or misinterpretation during migration. While the other options are important steps in the overall implementation, they do not directly address the integrity of the data conversion itself.
Question 74: Which of the following BEST describes the relationship between change management and patch management?
- Patch management is an entirely separate process with no overlap
- Change management controls do not apply to vendor-supplied patches
- Patches are a type of change and should follow the change management process (Correct answer)
- Patch management supersedes change management for security fixes
Correct answer: Patches are a type of change and should follow the change management process
Patches modify system behavior and therefore represent changes that should be assessed, tested, approved, and documented through the standard change management process.
Question 75: During a DR test, the team successfully restores data but discovers the restored database is missing two hours of transactions. Which control failure does this MOST directly indicate?
- Inadequate physical security at the recovery site
- Failure to encrypt backup data
- Insufficient staffing at the recovery site
- Replication or backup frequency not meeting the RPO (Correct answer)
Correct answer: Replication or backup frequency not meeting the RPO
Missing two hours of transactions means the backup or replication interval was too long, causing the RPO to be exceeded.
Question 76: A CISA auditor finds that a company's risk register has not been updated in 18 months. What is the PRIMARY concern?
- Emerging risks may not be identified or monitored (Correct answer)
- The risk register format may be outdated
- Risk owners have not been assigned
- The audit trail is incomplete
Correct answer: Emerging risks may not be identified or monitored
A stale risk register means new and evolving threats may go unrecognized, leaving the organization exposed to unmanaged risks.
Question 77: Which metric BEST measures the effectiveness of an IT risk management program over time?
- Total IT security budget spent per year
- Number of security policies reviewed annually
- Number of vulnerabilities discovered per scan
- Reduction in residual risk levels across the risk register (Correct answer)
Correct answer: Reduction in residual risk levels across the risk register
Tracking reductions in residual risk levels directly measures whether the risk management program is achieving its goal of lowering actual risk exposure.
Question 78: During a review of disaster recovery test documentation, an IS auditor's PRIMARY objective is to verify that:
- all members of the recovery team participated in the test.
- the test results were analyzed and the DRP was updated with lessons learned. (Correct answer)
- senior management was present to observe the test execution.
- the test was completed within the allocated budget.
Correct answer: the test results were analyzed and the DRP was updated with lessons learned.
Disaster recovery testing is not a one-time event but an iterative process designed for continuous improvement. The primary objective from an audit perspective is to ensure that the organization learns from the test. This involves analyzing the results, identifying any weaknesses or discrepancies, and updating the disaster recovery plan (DRP) accordingly to enhance its effectiveness for future incidents.
Question 79: Which attack does port security on a switch PRIMARILY mitigate?
- Phishing emails
- MAC flooding and unauthorized device connections (Correct answer)
- SQL injection
- Denial-of-service via ICMP floods
Correct answer: MAC flooding and unauthorized device connections
Port security limits the number of MAC addresses per port, preventing MAC flooding attacks that can overflow CAM tables.
Question 80: An IS auditor evaluating a software quality assurance program should expect to find metrics that track:
- Defect density, test coverage, and open defect aging (Correct answer)
- Number of lines of code written per sprint
- Manager approval time for change requests
- Developer coffee consumption and office hours
Correct answer: Defect density, test coverage, and open defect aging
Defect density, test coverage, and defect aging are key quality indicators that reflect the reliability and completeness of testing efforts.
Question 81: After a DR test, which document should be updated FIRST to reflect lessons learned?
- The annual audit report
- The employee handbook
- The network topology diagram
- The disaster recovery plan (Correct answer)
Correct answer: The disaster recovery plan
Lessons learned from DR tests must be incorporated directly into the DR plan to improve future recovery capability before the next incident or test.
Question 82: A 'governance gap' in IT occurs when:
- There is a difference between the intended governance design and its actual implementation (Correct answer)
- Network latency exceeds acceptable thresholds
- The IT budget exceeds approved limits
- Business users bypass IT approval for new software
Correct answer: There is a difference between the intended governance design and its actual implementation
A governance gap exists when the governance framework as designed does not match how governance is actually practiced within the organization.
Question 83: During IS audit planning, which document formally authorizes the audit and defines its scope, objectives, and resources?
- Risk register
- Engagement letter (Correct answer)
- Audit charter
- Audit program
Correct answer: Engagement letter
The engagement letter (or audit engagement letter) formally authorizes the audit and outlines scope, objectives, timing, and resource requirements agreed upon between the auditor and management.
Question 84: A small organization has limited IT staff, making strict segregation of duties within the change management process difficult. Which of the following is the BEST compensating control an IS auditor should recommend?
- Implementing a fully automated change deployment tool.
- Requiring all changes to be approved by the CEO.
- Conducting independent event log and activity monitoring. (Correct answer)
- Cross-training all IT staff on change management procedures.
Correct answer: Conducting independent event log and activity monitoring.
When segregation of duties is not feasible, a strong compensating control is independent monitoring and review of activities. Regularly reviewing detailed event logs and user activity can detect unauthorized or improper changes made by staff who may have conflicting permissions.
Question 85: Which DR test approach allows both the primary and recovery sites to process transactions simultaneously to compare output accuracy?
- Full interruption test
- Checklist review
- Simulation test
- Parallel test (Correct answer)
Correct answer: Parallel test
A parallel test runs the recovery site alongside the primary site so outputs can be compared without interrupting live operations.
Question 86: Which of the following BEST describes the purpose of a data loss prevention (DLP) solution?
- Encrypting all data stored on endpoint devices
- Detecting and blocking unauthorized transmission of sensitive data (Correct answer)
- Monitoring network bandwidth utilization
- Preventing unauthorized users from logging into systems
Correct answer: Detecting and blocking unauthorized transmission of sensitive data
DLP solutions detect, monitor, and block the unauthorized exfiltration or transmission of sensitive data across endpoints, networks, and cloud services.
Question 87: During an IT audit, a CISA finds that risk assessments are performed annually by IT staff without business unit input. What is the GREATEST weakness?
- Assessments are not frequent enough
- The assessments are not automated
- IT staff are not qualified to assess risk
- Risk assessments lack business context and may miss operational risks (Correct answer)
Correct answer: Risk assessments lack business context and may miss operational risks
Excluding business units means assessments may miss key operational risks and fail to align with business objectives.
Question 88: The Maximum Tolerable Downtime (MTD) for a critical process is 4 hours. The RTO is set at 6 hours. This situation indicates:
- The RTO exceeds MTD, meaning recovery may not happen before unacceptable damage occurs (Correct answer)
- The recovery plan is adequate since RTO is greater than MTD
- The BIA needs to be redone to align these metrics
- The MTD and RTO are properly aligned
Correct answer: The RTO exceeds MTD, meaning recovery may not happen before unacceptable damage occurs
The RTO must always be less than or equal to the MTD; an RTO greater than MTD means the system may not be restored before irreversible damage occurs.
Question 89: Which firewall rule principle states that anything not explicitly permitted should be denied?
- Default deny (implicit deny) (Correct answer)
- Least privilege
- Defense in depth
- Default permit
Correct answer: Default deny (implicit deny)
An implicit deny rule drops all traffic not explicitly allowed, minimizing exposure to unknown or unauthorized connections.
Question 90: An IS auditor finds that network infrastructure devices have not received security patches in 18 months. The BEST recommendation is to:
- Disable the devices until patches are applied
- Accept the risk since patches may disrupt network operations
- Require vendors to patch devices remotely without testing
- Implement a formal patch management process with defined SLAs for critical devices (Correct answer)
Correct answer: Implement a formal patch management process with defined SLAs for critical devices
A formal patch management process with defined timelines ensures vulnerabilities are addressed systematically without unnecessary disruption.
Question 91: During IS audit planning, which of the following is the BEST source for understanding an organization's IT risk posture?
- Industry benchmarking reports
- The organization's enterprise risk management (ERM) framework and IT risk register (Correct answer)
- Vendor documentation for installed software
- Prior year's financial statements
Correct answer: The organization's enterprise risk management (ERM) framework and IT risk register
The ERM framework and IT risk register document the organization's identified risks, their likelihood and impact, and existing mitigations — making them the primary source for risk-based audit planning.
Question 92: An organization implements a new payroll system in parallel with the legacy system for two pay cycles. The PRIMARY purpose of parallel operations is to:
- Accelerate the decommissioning of the old system
- Train payroll staff on both systems simultaneously
- Reduce hardware costs by sharing processing load
- Validate that the new system produces correct results by comparing outputs (Correct answer)
Correct answer: Validate that the new system produces correct results by comparing outputs
Parallel operations allow organizations to compare outputs from both systems, confirming the new system's accuracy before full cutover.
Question 93: An Intrusion Prevention System (IPS) differs from an IDS primarily because an IPS can:
- Log network traffic for forensic analysis
- Generate alerts for suspicious activity
- Actively block or drop malicious traffic in real time (Correct answer)
- Perform vulnerability scans on endpoints
Correct answer: Actively block or drop malicious traffic in real time
An IPS sits inline with traffic and can actively block threats, whereas an IDS only monitors and alerts.
Question 94: Which of the following BEST describes an access control matrix?
- A network diagram showing firewall rules between zones
- A risk register mapping threats to corresponding controls
- A biometric template database mapping users to physical characteristics
- A table defining what operations each subject can perform on each object (Correct answer)
Correct answer: A table defining what operations each subject can perform on each object
An access control matrix is a formal model that maps subjects (users/processes) to objects (resources) and their permitted operations.
Question 95: Which of the following BEST describes a risk-based audit approach in IS audit planning?
- Auditing every system and process equally regardless of risk level
- Following a fixed template that does not change between audit cycles
- Focusing only on financial systems because they pose the most regulatory risk
- Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently (Correct answer)
Correct answer: Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently
A risk-based approach directs audit resources toward the areas posing the greatest risk, ensuring that audit effort is proportionate to the likelihood and impact of potential issues.
Question 96: During a network audit, an IS auditor finds that SNMP v1 is still in use. The PRIMARY concern is:
- SNMP v1 uses too much bandwidth
- SNMP v1 does not support IPv6
- SNMP v1 community strings are transmitted in plaintext (Correct answer)
- SNMP v1 cannot monitor router interfaces
Correct answer: SNMP v1 community strings are transmitted in plaintext
SNMP v1 community strings (essentially passwords) are sent in cleartext, making them vulnerable to interception.
Question 97: A software development team is using an Agile methodology. To ensure risk is managed effectively, when should risk management activities be performed?
- Only at the end of the project, during the post-implementation review.
- Continuously throughout the project lifecycle, especially during sprint planning. (Correct answer)
- Only at the beginning of the project, during the initial planning phase.
- By a separate, independent risk management team after each major release.
Correct answer: Continuously throughout the project lifecycle, especially during sprint planning.
In Agile methodologies, which are iterative and incremental, risk management cannot be a one-time event. It must be an ongoing process that is integrated into the regular project rhythm. Risks should be identified, assessed, and responded to continuously, often as part of sprint planning, daily stand-ups, and retrospectives, to adapt to changing requirements and project conditions.
Question 98: In software project management, a critical path PRIMARILY helps an IS auditor assess:
- The total number of defects in the system
- Which tasks, if delayed, will directly extend the project completion date (Correct answer)
- The cost impact of scope changes
- Vendor performance against SLA metrics
Correct answer: Which tasks, if delayed, will directly extend the project completion date
The critical path identifies the sequence of dependent tasks with zero float, meaning any delay on these tasks delays the entire project.
Question 99: An IS auditor notes that DR tests are only conducted by the IT department without business unit participation. The GREATEST risk of this approach is:
- Failure to validate recovery of business processes, not just technical systems (Correct answer)
- Increased cost of testing
- Violation of change management policies
- Excessive system downtime during tests
Correct answer: Failure to validate recovery of business processes, not just technical systems
Without business unit involvement, DR tests may confirm technical recovery but miss whether business processes, workflows, and outputs are actually restored correctly.
Question 100: When auditing a data conversion during system migration, the IS auditor should PRIMARILY verify that:
- The new system uses a modern database engine
- The old system was decommissioned on schedule
- Data entry screens match legacy system layouts
- All data was accurately and completely transferred to the new system (Correct answer)
Correct answer: All data was accurately and completely transferred to the new system
Data integrity and completeness during conversion is critical; any data loss or corruption directly impacts business continuity and reliability of the new system.
Question 101: An IS auditor is planning to audit a cloud-based customer relationship management (CRM) system. Which of the following is the MOST important initial step?
- Verifying the encryption standards used for data in transit to the cloud provider.
- Requesting and reviewing the Service Organization Control (SOC) 2 report from the cloud vendor. (Correct answer)
- Conducting a vulnerability scan of the cloud provider's infrastructure.
- Interviewing the organization's sales team to understand their use of the CRM.
Correct answer: Requesting and reviewing the Service Organization Control (SOC) 2 report from the cloud vendor.
When auditing a system hosted by a third party, the most efficient and critical first step is to review the vendor's SOC 2 report. This report provides an independent assessment of the vendor's controls related to security, availability, processing integrity, confidentiality, and privacy, which is essential for scoping the audit and understanding the control environment.
Question 102: Which sampling technique is most appropriate when an IS auditor wants every item in the population to have an equal chance of selection?
- Stratified sampling
- Cluster sampling
- Judgmental sampling
- Simple random sampling (Correct answer)
Correct answer: Simple random sampling
Simple random sampling gives every item in the population an equal and independent probability of being selected, eliminating selection bias.
Question 103: Which of the following is the MOST effective control to detect unauthorized privilege escalation in an operating system?
- Annual user access reviews
- Segregation of duties for system administrators
- Periodic password resets for all users
- Real-time monitoring and alerting of privilege use (Correct answer)
Correct answer: Real-time monitoring and alerting of privilege use
Real-time monitoring detects and alerts on privilege escalation events as they occur, enabling immediate response.
Question 104: An IS auditor is reviewing a change management process. Which control BEST ensures only authorized changes reach production?
- Automated code compilation logs
- Mandatory code comments in all programs
- Weekly status meetings with the project manager
- Segregation of duties between developers and production migration staff (Correct answer)
Correct answer: Segregation of duties between developers and production migration staff
Segregation of duties prevents developers from promoting their own code, ensuring an independent review before production migration.
Question 105: During a BCP test, an organization discovers its backup tapes contain corrupted data. What control failure does this PRIMARILY represent?
- Inadequate encryption of backup data
- Failure to validate backup integrity through regular restoration testing (Correct answer)
- Lack of a documented recovery procedure
- Insufficient offsite storage of backup media
Correct answer: Failure to validate backup integrity through regular restoration testing
Backups must be regularly tested through actual restoration to verify data integrity; storing backups without testing them is a critical control gap.
Question 106: Which of the following BEST reduces the risk of unauthorized wireless network access?
- Enabling WEP encryption on all access points
- Using WPA3 with strong pre-shared keys and 802.1X authentication (Correct answer)
- Broadcasting the SSID to help users locate the network
- Placing access points near exterior walls for better signal
Correct answer: Using WPA3 with strong pre-shared keys and 802.1X authentication
WPA3 with 802.1X provides enterprise-grade authentication and strong encryption, making unauthorized access significantly harder.
Question 107: A penetration test differs from a vulnerability assessment primarily because a penetration test:
- Generates a compliance report for auditors
- Is conducted exclusively by internal staff
- Only scans for known CVEs using automated tools
- Actively attempts to exploit discovered vulnerabilities (Correct answer)
Correct answer: Actively attempts to exploit discovered vulnerabilities
Penetration testing goes beyond identifying vulnerabilities by actually attempting to exploit them to determine real-world impact.
Question 108: What is the PRIMARY purpose of conducting periodic user access reviews?
- To document all user login activity
- To measure system performance under load
- To enforce password complexity policies
- To identify and remove excessive or inappropriate access rights (Correct answer)
Correct answer: To identify and remove excessive or inappropriate access rights
Access reviews ensure access rights remain appropriate as roles change, preventing accumulation of unnecessary privileges over time.
Question 109: An IS auditor is reviewing IT risk management practices. Which finding represents the MOST significant control gap?
- Risk scenarios are not linked to specific business processes (Correct answer)
- Risk register entries lack a target remediation date
- Risk assessments are performed every 18 months instead of annually
- Risk owners have not formally acknowledged their responsibilities
Correct answer: Risk scenarios are not linked to specific business processes
Risk scenarios disconnected from business processes cannot be properly prioritized or mitigated because their business impact is unknown.
Question 110: Which change management control BEST ensures that production libraries are only updated by authorized personnel?
- Mandatory change request forms for all modifications
- Automated change scheduling tools
- Regular change advisory board meetings
- Version control system with role-based access controls (Correct answer)
Correct answer: Version control system with role-based access controls
Role-based access controls on version control systems restrict who can commit or deploy code, directly enforcing authorization requirements.
Question 111: A company implements a data classification policy with four levels: Public, Internal, Confidential, and Restricted. Which control is MOST critical for Restricted data?
- Restricting access on a need-to-know basis with strong authentication and audit logging (Correct answer)
- Storing all Restricted data on a dedicated file server
- Requiring employees to sign a non-disclosure agreement before accessing Restricted data
- Watermarking all printed copies of Restricted documents
Correct answer: Restricting access on a need-to-know basis with strong authentication and audit logging
Need-to-know access combined with strong authentication and full audit logging provides the most comprehensive protection for the highest-sensitivity data classification.
Question 112: An IS auditor reviewing network diagrams notices that production and development environments share the same network segment. The MAIN risk is:
- Higher infrastructure costs for the organization
- Difficulty in assigning IP addresses to new devices
- Slower network performance in production
- Potential for development activity to compromise production systems (Correct answer)
Correct answer: Potential for development activity to compromise production systems
Mixing production and development on the same segment can allow vulnerabilities or misconfigurations in dev to impact live systems.
Question 113: Which risk assessment approach assigns numerical values to the likelihood and impact of risks to calculate an overall risk score?
- Qualitative risk assessment
- Delphi technique
- Quantitative risk assessment (Correct answer)
- Control self-assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values and formulas (e.g., ALE = ARO × SLE) to express risk in financial or statistical terms.
Question 114: When auditing physical security controls for a data center, which finding would represent the HIGHEST risk?
- Visitor badges are a different color from employee badges
- Security camera footage is retained for only 14 days
- Terminated employees' access badges are deactivated within 24 hours (Correct answer)
- The server room door uses a PIN code without a backup biometric reader
Correct answer: Terminated employees' access badges are deactivated within 24 hours
Retaining departed employees' access for any period after termination allows them to potentially access physical areas, representing an immediate and significant risk.
Question 115: An organization implements a new cloud platform. At which stage of the IT lifecycle should risk assessment FIRST occur?
- During the planning and design phase (Correct answer)
- After the first security incident involving the platform
- After deployment and user acceptance testing
- When the first audit of the platform is scheduled
Correct answer: During the planning and design phase
Risk assessment should occur during planning and design so that controls can be built in from the start, reducing the cost and effort of remediation later.
Question 116: During testing, a developer discovers a critical defect but the project manager instructs the team to proceed to production anyway. The IS auditor's BEST response is to:
- Accept the decision since it is management's prerogative
- Document the risk and escalate to senior management (Correct answer)
- Immediately shut down the project
- Rewrite the affected module independently
Correct answer: Document the risk and escalate to senior management
The auditor's role is to document findings and escalate unresolved risks through proper governance channels, not to override management decisions unilaterally.
Question 117: In the context of IT risk management, what is 'inherent risk'?
- Risk that cannot be mitigated under any circumstances
- Risk level before any controls are applied (Correct answer)
- Risk accepted by senior management
- Risk remaining after controls are implemented
Correct answer: Risk level before any controls are applied
Inherent risk is the raw or gross risk that exists in the absence of any control measures.
Question 118: Which logical access control approach would BEST prevent an insider from exfiltrating bulk customer records from a database?
- Implementing query result row-count limits and data loss prevention controls (Correct answer)
- Requiring VPN access for all database connections
- Requiring dual approval for all database schema changes
- Enforcing complex passwords for database accounts
Correct answer: Implementing query result row-count limits and data loss prevention controls
Row-count limits on query results and DLP controls detect and restrict bulk data extraction, targeting the exfiltration method directly.
Question 119: Which protocol provides encrypted remote administration of network devices and is preferred over Telnet?
- FTP
- HTTP
- SNMP v2
- SSH (Correct answer)
Correct answer: SSH
SSH (Secure Shell) encrypts the entire session, whereas Telnet transmits credentials and data in plaintext.
Question 120: A DMZ (Demilitarized Zone) is BEST described as:
- A VLAN reserved for administrative management traffic
- A backup network used only during disaster recovery
- A segment where only internal users can access resources
- A network zone between the internet and the internal network that hosts public-facing services (Correct answer)
Correct answer: A network zone between the internet and the internal network that hosts public-facing services
A DMZ provides a buffer zone that exposes public services (e.g., web servers) while shielding the internal network.
Question 121: During a post-implementation review of a new CRM system, an IS auditor's PRIMARY objective is to determine whether:
- all identified bugs and defects from the testing phase have been resolved.
- the system has met the business objectives and delivers the expected benefits. (Correct answer)
- the project was completed within the allocated budget and timeframe.
- end-users are satisfied with the new system's user interface and performance.
Correct answer: the system has met the business objectives and delivers the expected benefits.
The primary purpose of a post-implementation review is to assess whether the system has achieved its intended business objectives and delivered the value proposed in the business case. While budget, bug resolution, and user satisfaction are important factors to review, the ultimate measure of success is the system's ability to support and improve business processes as originally intended.
Question 122: Which metric BEST measures the effectiveness of IT governance in delivering business value?
- Return on IT investments (ROI) (Correct answer)
- Number of IT projects initiated per year
- Server uptime percentage
- Number of IT staff certifications
Correct answer: Return on IT investments (ROI)
ROI on IT investments directly measures whether IT is delivering measurable business value, which is the core objective of IT governance.
Question 123: An IS auditor is assessing an organization's vulnerability management program. Which metric is MOST useful for evaluating the program's effectiveness?
- Percentage of systems covered by the vulnerability scanner
- Total number of vulnerabilities discovered per scan
- Mean time to remediate critical vulnerabilities (Correct answer)
- Number of security scans performed per quarter
Correct answer: Mean time to remediate critical vulnerabilities
Mean time to remediate critical vulnerabilities measures how quickly the organization closes its highest-risk exposures, reflecting the program's actual risk-reduction effectiveness.
Question 124: Which of the following is the MOST effective way to ensure IT risks are aligned with business strategy?
- Requiring all employees to complete annual security awareness training
- Conducting quarterly vulnerability scans
- Integrating IT risk management into enterprise risk management (ERM) (Correct answer)
- Deploying a Security Information and Event Management (SIEM) system
Correct answer: Integrating IT risk management into enterprise risk management (ERM)
Integrating IT risk management into ERM ensures that technology risks are evaluated in the context of overall business objectives and risk appetite.
Question 125: An organization uses tokenization to protect customer payment data. What is the PRIMARY advantage of tokenization over encryption for this use case?
- Tokens are meaningless outside the tokenization system, reducing the value of a data breach (Correct answer)
- Tokenization is mandated by PCI DSS for all payment data
- Tokenization does not require any key management
- Tokenized data can be decrypted faster than encrypted data
Correct answer: Tokens are meaningless outside the tokenization system, reducing the value of a data breach
Tokens are random substitutes with no mathematical relationship to the original data, so stolen tokens have no value to an attacker without access to the token vault.
Question 126: An IS auditor is assessing a federated identity management system. Which of the following represents the GREATEST advantage from a logical access control perspective?
- Removal of the need for access recertification processes
- Centralized identity governance across multiple organizations without sharing credentials (Correct answer)
- Elimination of the need for any authentication mechanisms
- Automatic granting of administrative rights across federated systems
Correct answer: Centralized identity governance across multiple organizations without sharing credentials
Federated identity allows users to authenticate once with a trusted provider while accessing resources across organizations without transmitting actual credentials.
Question 127: An IS auditor reviewing software procurement should FIRST verify that the vendor's product:
- Has the lowest licensing cost available
- Is widely used by competitors in the same industry
- Meets the organization's defined functional and security requirements (Correct answer)
- Supports the latest programming language standards
Correct answer: Meets the organization's defined functional and security requirements
Alignment with documented requirements is the foundational criterion before evaluating cost, market share, or technology features.
Question 128: During an audit, it is discovered that the organization has not defined its risk appetite. What is the PRIMARY concern for the IS auditor?
- Compliance with industry regulations cannot be achieved.
- Risk mitigation efforts may not be aligned with business objectives. (Correct answer)
- The frequency of risk assessments is likely insufficient.
- The organization may be overspending on security controls.
Correct answer: Risk mitigation efforts may not be aligned with business objectives.
Risk appetite is the amount and type of risk that an organization is willing to pursue or retain. Without a clearly defined risk appetite, there is no strategic guidance for making risk-based decisions. This can lead to a misalignment between risk management activities and the organization's strategic goals and objectives, resulting in either excessive risk-taking or overly cautious behavior that stifles innovation.
Question 129: When auditing a VPN implementation, an IS auditor should FIRST verify that:
- Strong encryption algorithms and multi-factor authentication are enforced (Correct answer)
- VPN software licenses are current
- All employees are required to use VPN regardless of location
- VPN connection logs are deleted after 30 days
Correct answer: Strong encryption algorithms and multi-factor authentication are enforced
Strong encryption and MFA are the foundational controls that protect VPN tunnels from interception and unauthorized access.
Question 130: A data center's physical security controls are being examined by an IS auditor, who finds various cause for concern. Which one of the following is the MOST crucial?
- Scheduled maintenance of the fire suppression system was not performed.
- The emergency exit door is blocked. (Correct answer)
- There are no security cameras inside the data center.
- The emergency power off button cover is missing.
Correct answer: The emergency exit door is blocked.
The obstruction of the emergency escape is the most significant issue because life safety is always the top priority.
Question 131: An IS auditor plans to rely on the work of an internal audit team. Which condition MUST be assessed before placing reliance on their work?
- The competence and objectivity of the internal audit function (Correct answer)
- Whether internal auditors use the same tools as external auditors
- The number of years the internal audit team has been in place
- Whether the internal audit team reports to the CFO
Correct answer: The competence and objectivity of the internal audit function
Before relying on internal audit work, an IS auditor must evaluate the internal audit team's technical competence and organizational objectivity to ensure their work meets adequate standards.
Question 132: Under the US Health Insurance Portability and Accountability Act (HIPAA), covered entities must implement which type of controls to protect electronic Protected Health Information (ePHI) stored in databases?
- Contractual agreements with patients only
- Only physical security controls
- Technical controls only
- Administrative, physical, and technical safeguards (Correct answer)
Correct answer: Administrative, physical, and technical safeguards
HIPAA's Security Rule requires covered entities to implement a combination of administrative safeguards (policies), physical safeguards (facility controls), and technical safeguards (encryption, access controls) to protect ePHI.
Question 133: In IS audit planning, materiality is BEST defined as:
- The risk level assigned to a specific audit area
- The minimum number of control failures that trigger a finding
- The dollar threshold above which errors must be reported
- The significance of a matter in the context of the audit objectives and stakeholder decision-making (Correct answer)
Correct answer: The significance of a matter in the context of the audit objectives and stakeholder decision-making
Materiality refers to the significance or importance of information, errors, or omissions in the context of the financial statements or audit objectives that could influence stakeholder decisions.
Question 134: Which role is PRIMARILY responsible for accepting residual risk within an organization?
- IT security manager
- Risk owner or senior management (Correct answer)
- Chief Information Officer (CIO)
- External auditor
Correct answer: Risk owner or senior management
Risk acceptance is a management decision and must be made by the appropriate risk owner or senior management with the authority to do so.
Question 135: Which of the following is the CORRECT sequence for developing a Business Continuity Plan?
- Risk Assessment → BIA → Plan Development → Test (Correct answer)
- Test → BIA → Risk Assessment → Plan Development
- Plan Development → Risk Assessment → BIA → Test
- BIA → Plan Development → Risk Assessment → Test
Correct answer: Risk Assessment → BIA → Plan Development → Test
Risk assessment identifies threats, BIA quantifies their impact, plan development addresses the findings, and testing validates the plan.
Question 136: Which of the following BEST describes the role of configuration management in system development?
- Approving capital expenditure for IT infrastructure
- Managing employee workstation hardware inventories
- Controlling and tracking changes to software components and their versions (Correct answer)
- Scheduling project team meetings and sprint reviews
Correct answer: Controlling and tracking changes to software components and their versions
Configuration management ensures that software components are versioned, tracked, and controlled so that any version can be reproduced and changes are auditable.
Question 137: A CISA auditor reviewing network segmentation should PRIMARILY verify that:
- All systems reside on a single flat network
- Wireless and wired networks share the same subnet
- Firewalls are only deployed at the network perimeter
- Critical systems are isolated in separate network zones (Correct answer)
Correct answer: Critical systems are isolated in separate network zones
Proper network segmentation places critical systems in isolated zones to limit the blast radius of a breach.
Question 138: When assessing inherent risk during IS audit planning, the auditor should consider:
- Management's response to prior audit findings
- The cost of implementing additional controls
- The risk that exists independent of any controls (Correct answer)
- The effectiveness of existing controls
Correct answer: The risk that exists independent of any controls
Inherent risk is the susceptibility of an assertion or area to a material misstatement or error assuming no related controls exist.
Question 139: Which of the following scenarios BEST illustrates an inappropriate restriction on audit scope that an IS auditor should escalate?
- Management requests the auditor avoid reviewing a specific high-risk system due to 'sensitivity' (Correct answer)
- Management asks for a preliminary briefing before the audit report is finalized
- The audit committee requests a focus on cybersecurity controls
- Management provides a list of recommended contacts for interviews
Correct answer: Management requests the auditor avoid reviewing a specific high-risk system due to 'sensitivity'
When management restricts access to a high-risk area without valid justification, it represents a scope limitation that must be escalated to the audit committee as it impairs audit independence.
Question 140: An IS auditor is reviewing an organization's IT strategic planning process. Which of the following is the MOST crucial for ensuring the alignment of the IT strategy with the business strategy?
- The IT strategic plan is primarily driven by the latest technological innovations.
- The IT strategic plan is reviewed and approved by the IT department's senior management.
- The IT steering committee is composed of representatives from key business functions and IT. (Correct answer)
- The IT budget is allocated based on the previous year's expenditures.
Correct answer: The IT steering committee is composed of representatives from key business functions and IT.
The primary role of an IT steering committee is to ensure that IT activities are aligned with business objectives. By having representation from key business functions, the committee can ensure that IT plans, projects, and investments support the overall goals of the enterprise. [2, 3]
Question 141: When assessing the risk associated with outsourcing IT operations, an IS auditor should FIRST:
- Terminate the outsourcing agreement if controls are weak
- Hire an independent third party to audit the vendor
- Identify which critical business processes depend on the outsourced service (Correct answer)
- Review the vendor's SOC 2 Type II report
Correct answer: Identify which critical business processes depend on the outsourced service
Understanding which critical processes rely on the outsourced service establishes the risk context necessary for all subsequent audit steps.
Question 142: A financial institution is designing the logical access controls for its new online banking platform. To provide strong assurance of user identity, which of the following should be the MINIMUM requirement for customer authentication?
- A complex password that changes every 90 days.
- Biometric authentication, such as a fingerprint scan.
- Multi-factor authentication (MFA). (Correct answer)
- A user ID combined with a security question.
Correct answer: Multi-factor authentication (MFA).
Multi-factor authentication (MFA) is the industry standard and best practice for providing strong authentication. It requires users to present two or more different types of credentials (e.g., something they know, something they have, something they are), making it significantly harder for unauthorized users to gain access even if one factor is compromised.
Question 143: Which of the following is the PRIMARY purpose of an IS audit charter?
- To list the specific systems and applications to be audited during the fiscal year.
- To document the detailed audit procedures and testing methodologies.
- To outline the annual budget and resource allocation for the IS audit function.
- To establish the authority, scope, and responsibilities of the IS audit function. (Correct answer)
Correct answer: To establish the authority, scope, and responsibilities of the IS audit function.
The audit charter is a high-level document that establishes the authority, independence, scope, and overall responsibility of the audit function. It is approved by the highest level of management and the audit committee and provides the foundation for all audit activities.
Question 144: A CISA auditor is reviewing router access control lists (ACLs). The MOST important audit step is to verify that ACLs:
- Reflect the organization's network security policy and follow least privilege (Correct answer)
- Are only applied on external-facing interfaces
- Are as permissive as possible to avoid blocking legitimate traffic
- Have not been changed in the past 12 months
Correct answer: Reflect the organization's network security policy and follow least privilege
ACLs should be derived from and aligned with the security policy, permitting only necessary traffic on each interface.
Question 145: Which of the following BEST describes the purpose of an audit program in IS audit planning?
- A set of detailed instructions guiding the auditor through specific procedures to achieve audit objectives (Correct answer)
- A schedule of all audits planned for the year
- A high-level document authorizing the audit function
- A summary of findings presented to management
Correct answer: A set of detailed instructions guiding the auditor through specific procedures to achieve audit objectives
An audit program is a detailed set of procedures and instructions that guide the auditor in gathering sufficient evidence to meet the specific objectives of the audit.
Question 146: In IS auditing, 'audit risk' is composed of which three components?
- Inherent risk, control risk, and detection risk (Correct answer)
- Residual risk, inherent risk, and risk appetite
- Operational risk, financial risk, and strategic risk
- Detection risk, compliance risk, and fraud risk
Correct answer: Inherent risk, control risk, and detection risk
Audit risk is the product of inherent risk (risk without controls), control risk (risk that controls fail), and detection risk (risk auditors miss a material issue).
Question 147: Which of the following is the PRIMARY purpose of network traffic analysis in an IS audit?
- To replace firewall rules with more efficient configurations
- To configure QoS policies for business-critical applications
- To detect anomalous traffic patterns that may indicate a security incident (Correct answer)
- To measure the bandwidth consumed by individual users
Correct answer: To detect anomalous traffic patterns that may indicate a security incident
Traffic analysis helps auditors identify deviations from baseline behavior that could signal unauthorized access, data exfiltration, or malware.
Question 148: What is the purpose of the ISACA organizational independence audit standard?
- To ensure that the auditor has the appearance of independence.
- The auditor's placement in the organization should ensure the auditor can act independently. (Correct answer)
- To ensure that the auditor has a separate operating budget.
- The auditor should not work in the same organization as the auditee.
Correct answer: The auditor's placement in the organization should ensure the auditor can act independently.
The ISACA organizational independence audit standard aims to ensure that the IS audit function is positioned within the organization in a way that allows auditors to perform their duties objectively and without undue influence. This typically means the audit function reports to a high level, such as the audit committee or board, to maintain both the appearance and the reality of independence. It's about the structural arrangement that enables unbiased audit work.
Question 149: During IS audit planning, the auditor reviews prior audit workpapers. The PRIMARY benefit of this review is to:
- Avoid duplication by skipping areas already tested
- Understand previously identified risks, findings, and remediation status to inform current planning (Correct answer)
- Copy prior procedures to save planning time
- Confirm that prior auditors used appropriate methodologies
Correct answer: Understand previously identified risks, findings, and remediation status to inform current planning
Reviewing prior workpapers helps identify historical risk areas, outstanding findings, and whether remediation was completed, all of which inform current audit risk assessment and focus.
Question 150: Which of the following provides the GREATEST assurance that a disaster recovery plan (DRP) will function as intended when required?
- The use of a hot site with mirrored data.
- A comprehensive tabletop exercise with all key personnel.
- A full interruption test conducted at the alternate site. (Correct answer)
- A recent review and sign-off by senior management.
Correct answer: A full interruption test conducted at the alternate site.
A full interruption test, also known as a full-scale test, is the most rigorous and realistic testing method. It involves shutting down the primary production environment and failing over completely to the recovery site. This type of test provides the highest level of assurance because it is the most accurate simulation of an actual disaster, validating that all components of the plan work together effectively in a real-world scenario.
Question 151: An IS auditor reviewing system retirement (decommissioning) should PRIMARILY confirm that:
- Data retention requirements are met and data is migrated or archived per policy (Correct answer)
- The retired system's source code is deleted from all media
- The project manager has signed the project closure document
- New system licenses have been purchased to replace the old ones
Correct answer: Data retention requirements are met and data is migrated or archived per policy
Compliance with data retention policies and proper archiving or migration of historical data is the primary risk when retiring a system.
Question 152: An IS auditor planning an audit of the software development lifecycle (SDLC) should PRIMARILY focus on which phase for the highest control risk?
- Testing phase
- Requirements gathering phase
- Production deployment phase (Correct answer)
- Maintenance phase
Correct answer: Production deployment phase
Production deployment is the highest-risk SDLC phase because unauthorized or untested code moving to production can directly impact business operations and data integrity.
ISACA CISA Certified Information Systems Auditor Exam
The ISACA Certified Information Systems Auditor (CISA) Exam covers IS audit planning, IT governance, risk management, system development, change management controls, business continuity, disaster recovery, logical access controls, network security, and data management across five domains.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds