CISA Certified Information Systems Auditor MCQ 3 — Questions and Answers
Question 1: An IS auditor reviews a company's IT governance framework and finds no formal IT steering committee. The GREATEST risk of this gap is:
- IT projects may not align with business objectives (Correct answer)
- Developers lack technical guidance
- Security patches may be delayed
- Audit findings go unreported
Correct answer: IT projects may not align with business objectives
Without an IT steering committee, there is no formal mechanism to align IT investments and projects with overall business strategy.
Question 2: A CAATs tool is BEST used by an IS auditor to:
- Interview control owners about their processes
- Analyze large volumes of transaction data for anomalies (Correct answer)
- Document audit findings in a structured format
- Observe IT operations in real time
Correct answer: Analyze large volumes of transaction data for anomalies
Computer-Assisted Audit Techniques (CAATs) are specifically designed to process large transaction datasets to identify exceptions, trends, and anomalies.
Question 3: During a review of a third-party vendor contract, an IS auditor notices the contract lacks a right-to-audit clause. This PRIMARILY means:
- The vendor can charge higher service fees
- The organization cannot independently verify the vendor's control effectiveness (Correct answer)
- The vendor is not required to deliver SLA reports
- The contract is legally unenforceable
Correct answer: The organization cannot independently verify the vendor's control effectiveness
Without a right-to-audit clause, the organization has no contractual basis to independently assess whether the vendor's controls are operating effectively.
Question 4: Which of the following BEST describes the purpose of a control self-assessment (CSA)?
- To replace the external audit process entirely
- To allow management and staff to assess the effectiveness of internal controls (Correct answer)
- To document all IT assets for insurance purposes
- To validate financial statements before year-end reporting
Correct answer: To allow management and staff to assess the effectiveness of internal controls
CSA is a process in which operational management and staff directly evaluate the effectiveness and efficiency of controls in their own areas.
Question 5: An IS auditor finds that application logs are stored on the same server as the application itself. The MAIN risk is:
- Logs consume too much disk space
- An attacker who compromises the server could also alter or delete logs (Correct answer)
- Log review becomes too slow for analysts
- Developers might accidentally view sensitive log data
Correct answer: An attacker who compromises the server could also alter or delete logs
Co-locating logs with the application means a successful attacker can cover their tracks by modifying or deleting the very logs that would record the attack.
Question 6: Under the COBIT framework, which of the five governance objectives specifically addresses the transparent reporting of IT performance to stakeholders?
- Realize Benefits
- Optimize Risk
- Resource Optimization
- Ensure Transparency to Stakeholders (Correct answer)
Correct answer: Ensure Transparency to Stakeholders
COBIT's 'Ensure Transparency to Stakeholders' governance objective focuses on providing accurate and timely information to all relevant parties about IT performance.
Question 7: When assessing the risk associated with outsourcing IT operations, an IS auditor should FIRST:
- Review the vendor's SOC 2 Type II report
- Terminate the outsourcing agreement if controls are weak
- Identify which critical business processes depend on the outsourced service (Correct answer)
- Hire an independent third party to audit the vendor
Correct answer: Identify which critical business processes depend on the outsourced service
Understanding which critical processes rely on the outsourced service establishes the risk context necessary for all subsequent audit steps.
An IS auditor reviews a company's IT governance framework and finds no formal IT steering committee.
The GREATEST risk of this gap is: