CISA Certified Information Systems Auditor MCQ 4 — Questions and Answers
Question 1: An IS auditor is reviewing an organization's patch management process and finds that critical patches take an average of 45 days to deploy. The BEST recommendation is:
- Accept the risk because vendors often release flawed patches
- Implement a risk-based patching policy with shorter windows for critical vulnerabilities (Correct answer)
- Require all patches to be tested for 60 days before deployment
- Outsource patch management to a managed service provider
Correct answer: Implement a risk-based patching policy with shorter windows for critical vulnerabilities
A risk-based patching policy prioritizes critical patches for faster deployment while allowing more time for lower-risk patches.
Question 2: Which type of audit evidence is considered the MOST reliable?
- Verbal confirmation from management
- Photocopied documents provided by the auditee
- Original source documents examined directly by the auditor (Correct answer)
- Summary reports generated by the auditee's ERP system
Correct answer: Original source documents examined directly by the auditor
Original source documents that the auditor personally examines are the most reliable because they are unfiltered and not subject to manipulation by the auditee.
Question 3: During a database audit, an IS auditor discovers that a DBA has unrestricted access to production data including personal health information. The IMMEDIATE recommended action is:
- Revoke all DBA access until a full review is complete
- Implement compensating controls such as enhanced logging and periodic access reviews (Correct answer)
- Report the DBA to law enforcement
- Require the DBA to sign a data handling agreement
Correct answer: Implement compensating controls such as enhanced logging and periodic access reviews
Compensating controls like audit logging and access reviews address the risk without disrupting operations while a longer-term least-privilege solution is designed.
Question 4: An IS auditor evaluating business continuity planning should PRIMARILY ensure that:
- The BCP is stored offsite in a fireproof safe
- Recovery procedures have been tested and results documented (Correct answer)
- The BCP was approved by the board of directors
- All employees have memorized their emergency roles
Correct answer: Recovery procedures have been tested and results documented
An untested BCP cannot be relied upon; testing with documented results is the only way to verify recovery procedures will actually work.
Question 5: Which of the following is a key characteristic that distinguishes an IS audit from a general financial audit?
- IS audits require board approval; financial audits do not
- IS audits focus on IT-related controls supporting information integrity and availability (Correct answer)
- IS audits are only conducted by external parties
- IS audits do not produce formal reports
Correct answer: IS audits focus on IT-related controls supporting information integrity and availability
IS audits specifically assess IT controls around data integrity, confidentiality, and availability, whereas financial audits focus on the accuracy of financial statements.
Question 6: When reviewing a software development lifecycle (SDLC), an IS auditor should verify that security requirements are addressed:
- Only during the testing phase before production release
- During the requirements and design phases as early as possible (Correct answer)
- After deployment when vulnerabilities are identified in production
- Exclusively by the security team, not developers
Correct answer: During the requirements and design phases as early as possible
Addressing security in the requirements and design phases is far less costly and more effective than finding vulnerabilities after deployment.
Question 7: An IS auditor is assessing the maturity of an organization's IT risk management process using CMMI levels. A process that is documented, standardized, and consistently applied organization-wide BEST corresponds to which maturity level?
- Level 1 – Initial
- Level 2 – Managed
- Level 3 – Defined (Correct answer)
- Level 4 – Quantitatively Managed
Correct answer: Level 3 – Defined
CMMI Level 3 (Defined) is characterized by processes that are documented, standardized, and consistently applied across the entire organization.
An IS auditor is reviewing an organization's patch management process and finds that critical patches take an average of 45 days to deploy.
The BEST recommendation is: