CISA Certified Information Systems Auditor MCQ 5 — Questions and Answers
Question 1: An IS auditor reviewing a cloud environment finds that the organization has not classified its data before migrating to the cloud. The PRIMARY risk is:
- Higher cloud storage costs
- Sensitive data may be stored without appropriate security controls (Correct answer)
- Cloud performance may be degraded
- Employees may lose access to data during migration
Correct answer: Sensitive data may be stored without appropriate security controls
Without data classification, the organization cannot apply appropriate security controls, potentially exposing sensitive or regulated data in the cloud.
Question 2: During a follow-up audit, an IS auditor finds that management agreed to a corrective action but implemented a different, untested solution instead. The auditor should:
- Accept the new solution if management believes it is effective
- Close the finding since management took some action
- Assess whether the alternative solution adequately addresses the original risk (Correct answer)
- Escalate immediately to regulators
Correct answer: Assess whether the alternative solution adequately addresses the original risk
The auditor's responsibility is to verify that the original risk is addressed, regardless of whether the solution matches what was originally agreed upon.
Question 3: Which of the following BEST describes the role of an IS auditor when management asks for advice on selecting a new security tool?
- The auditor should select the tool that offers the best value
- The auditor may provide general criteria but should avoid selecting specific products to preserve independence (Correct answer)
- The auditor must refuse all advisory requests to maintain objectivity
- The auditor should implement the tool once selected to ensure it meets audit requirements
Correct answer: The auditor may provide general criteria but should avoid selecting specific products to preserve independence
IS auditors can advise on criteria and frameworks without selecting specific products, preserving independence while still adding value.
Question 4: An IS auditor finds that a company uses a single sign-on (SSO) solution for all enterprise applications. The GREATEST risk associated with SSO is:
- Users must remember too many passwords
- A compromised SSO credential grants access to all connected applications (Correct answer)
- SSO solutions are more expensive than individual passwords
- Multi-factor authentication cannot be used with SSO
Correct answer: A compromised SSO credential grants access to all connected applications
SSO creates a single point of failure — if the credential is compromised, the attacker gains access to every application connected to the SSO system.
Question 5: When assessing IT general controls (ITGCs), an IS auditor is PRIMARILY concerned with controls over:
- Individual application business rules
- Infrastructure, access management, change management, and operations (Correct answer)
- Customer-facing website functionality
- Employee productivity and output metrics
Correct answer: Infrastructure, access management, change management, and operations
ITGCs are entity-level controls covering the IT environment — including infrastructure security, logical access, change management, and IT operations — that support all applications.
Question 6: An IS auditor is reviewing a company's encryption practices and finds that encryption keys are stored in the same database as the encrypted data. This represents:
- An acceptable industry practice for performance reasons
- A significant control weakness that negates the protection of encryption (Correct answer)
- A minor finding that does not need to be reported
- Best practice because it simplifies key management
Correct answer: A significant control weakness that negates the protection of encryption
Storing encryption keys with encrypted data means anyone who gains access to the database has both the ciphertext and the key to decrypt it, rendering encryption ineffective.
Question 7: An organization conducts an annual IT risk assessment but does not update it when significant system changes occur. The MOST likely consequence is:
- The risk assessment will be too expensive to maintain
- New risks introduced by system changes will remain unidentified and unmitigated (Correct answer)
- Annual assessments will take longer to complete
- Auditors will not accept the risk assessment as valid evidence
Correct answer: New risks introduced by system changes will remain unidentified and unmitigated
Risk assessments that are not updated after major changes fail to capture new threats, leaving the organization unaware of and unprepared for emerging risks.
An IS auditor reviewing a cloud environment finds that the organization has not classified its data before migrating to the cloud.
The PRIMARY risk is: