CISA Certified Information Systems Auditor 3 — Questions and Answers
Question 1: An IS auditor is reviewing a disaster recovery plan (DRP). Which metric defines the maximum acceptable time to restore a system after a disruption?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Time Objective (RTO)
RTO is the target time within which a business process must be restored after a disaster to avoid unacceptable consequences.
Question 2: Which type of access control enforces permissions based on the sensitivity label of the resource and the clearance level of the user?
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC)
- Mandatory Access Control (MAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Mandatory Access Control (MAC)
MAC uses sensitivity labels and clearance levels set by a central authority, not the data owner, to control access.
Question 3: An auditor is assessing the change management process. Which control is MOST critical to verify?
- Changes are documented after implementation
- All changes are tested in production
- Changes are approved before implementation (Correct answer)
- Developers have access to production systems
Correct answer: Changes are approved before implementation
Pre-implementation approval ensures that only authorized, tested, and justified changes are made to production systems.
Question 4: In the context of IS auditing, 'audit universe' refers to:
- The total number of auditors in an organization
- All auditable entities within the scope of the audit function (Correct answer)
- External regulatory requirements
- The organization's IT asset inventory
Correct answer: All auditable entities within the scope of the audit function
The audit universe encompasses all potential audit subjects from which the audit plan is derived.
Question 5: Which of the following BEST describes a compensating control?
- A control that prevents a risk from occurring
- A detective control that identifies errors after they occur
- A control that mitigates risk when the primary control cannot be implemented (Correct answer)
- A control mandated by regulation
Correct answer: A control that mitigates risk when the primary control cannot be implemented
A compensating control is an alternative measure used to satisfy a requirement when the standard control is not feasible.
Question 6: An IS auditor reviewing network security finds that firewall rules have not been reviewed in three years. What is the MOST significant risk?
- Increased hardware maintenance costs
- Outdated rules may allow unauthorized access or block legitimate traffic (Correct answer)
- Network performance degradation
- Difficulty generating compliance reports
Correct answer: Outdated rules may allow unauthorized access or block legitimate traffic
Stale firewall rules can contain obsolete permissions that expose the network to threats or create operational issues.
Question 7: When reviewing application controls, which control type BEST prevents data entry errors at the source?
- Edit checks and validation rules (Correct answer)
- Batch totals reconciliation
- Exception reporting
- Audit logs
Correct answer: Edit checks and validation rules
Input validation and edit checks prevent invalid data from entering the system at the point of entry.
An IS auditor is reviewing a disaster recovery plan (DRP).
Which metric defines the maximum acceptable time to restore a system after a disruption?