CISA Certified Information Systems Auditor 4 — Questions and Answers
Question 1: An IS auditor discovers that a system administrator has both the ability to create user accounts and approve access requests. This BEST represents a violation of:
- Least privilege principle
- Separation of duties (Correct answer)
- Need-to-know principle
- Due diligence
Correct answer: Separation of duties
Separation of duties requires that no single individual control all aspects of a critical transaction or process to reduce fraud risk.
Question 2: During a business continuity audit, which of the following is the MOST important indicator that a BCP is effective?
- The plan is formally documented and approved
- The plan has been successfully tested and updated (Correct answer)
- All employees have read the plan
- The plan was created by an external consultant
Correct answer: The plan has been successfully tested and updated
A BCP that has been tested and kept current demonstrates actual operational effectiveness, not just paper compliance.
Question 3: Which IS audit approach BEST supports continuous auditing of high-volume transaction systems?
- Annual comprehensive audits
- Embedded audit modules that monitor transactions in real time (Correct answer)
- Quarterly sampling of transactions
- Interviewing process owners annually
Correct answer: Embedded audit modules that monitor transactions in real time
Embedded audit modules allow auditors to continuously monitor transactions as they occur, enabling timely detection of anomalies.
Question 4: An auditor is evaluating a software development lifecycle (SDLC). Which phase is MOST critical for ensuring security requirements are addressed early?
- Testing
- Deployment
- Requirements and design (Correct answer)
- Maintenance
Correct answer: Requirements and design
Incorporating security requirements during requirements and design (shift-left) is far less costly than retrofitting security after development.
Question 5: In IT risk management, a threat is BEST described as:
- A weakness in a system that can be exploited
- A potential cause of an unwanted incident (Correct answer)
- The likelihood of an adverse event occurring
- The impact of a security breach
Correct answer: A potential cause of an unwanted incident
A threat is any potential event or action that could exploit a vulnerability and cause harm to an asset.
Question 6: Which of the following is the PRIMARY objective of an IT general control (ITGC) review?
- To assess the accuracy of financial statements
- To evaluate controls over the IT environment that support application controls (Correct answer)
- To review individual application functionality
- To assess physical security of data centers only
Correct answer: To evaluate controls over the IT environment that support application controls
ITGCs provide the foundation for reliable application controls by ensuring the integrity of the overall IT environment.
Question 7: An organization's data classification policy assigns 'confidential' to customer PII. An auditor finds this data stored unencrypted on a shared network drive. The FIRST recommended action is to:
- Immediately delete the data
- Report the finding and recommend encrypting or relocating the data (Correct answer)
- Notify all employees about proper data handling
- Assess whether anyone has accessed the data
Correct answer: Report the finding and recommend encrypting or relocating the data
Auditors should report findings and make recommendations; immediate remediation decisions belong to management.
An IS auditor discovers that a system administrator has both the ability to create user accounts and approve access requests.
This BEST represents a violation of: