CISA IT Audit Standards and Frameworks 2 — Questions and Answers
Question 1: In COBIT 2019, which governance domain is responsible for evaluating stakeholder needs and setting strategic direction for IT?
- APO — Align, Plan and Organize
- EDM — Evaluate, Direct and Monitor (Correct answer)
- DSS — Deliver, Service and Support
- MEA — Monitor, Evaluate and Assess
Correct answer: EDM — Evaluate, Direct and Monitor
The EDM (Evaluate, Direct and Monitor) domain is the sole governance domain in COBIT 2019 and is responsible for evaluating options, directing management, and monitoring performance.
Question 2: ISO 27002 serves which purpose in relation to ISO 27001?
- It specifies mandatory ISMS requirements
- It provides a code of practice with guidance on information security controls (Correct answer)
- It defines IT governance principles for executives
- It establishes risk management requirements
Correct answer: It provides a code of practice with guidance on information security controls
ISO 27002 is a companion standard to ISO 27001 that provides guidance and best practices for selecting and implementing information security controls.
Question 3: Under ISACA's IS audit standards, an IS auditor's independence is described in which two forms?
- Technical independence and managerial independence
- Organizational independence and professional independence (Correct answer)
- Operational independence and strategic independence
- Internal independence and external independence
Correct answer: Organizational independence and professional independence
ISACA standards require IS auditors to maintain both organizational independence (reporting structure free from conflicts) and professional independence (objective mindset).
Question 4: The NIST Cybersecurity Framework (CSF) is built around which five core functions?
- Identify, Protect, Detect, Respond, Recover (Correct answer)
- Plan, Do, Check, Act, Improve
- Assess, Design, Implement, Monitor, Review
- Govern, Manage, Operate, Secure, Report
Correct answer: Identify, Protect, Detect, Respond, Recover
The NIST CSF organizes cybersecurity activities into five concurrent and continuous functions: Identify, Protect, Detect, Respond, and Recover.
Question 5: In COBIT 2019, capability levels range from 0 to 5. What does a capability level of 0 indicate?
- The process is fully optimized
- The process is managed and measurable
- The process does not exist or fails to achieve its purpose (Correct answer)
- The process is defined but not yet implemented
Correct answer: The process does not exist or fails to achieve its purpose
A capability level of 0 (Incomplete) indicates the process is either not implemented or fails to achieve its intended purpose.
Question 6: The concept of 'due professional care' in IS auditing requires that an auditor:
- Guarantee the accuracy of all findings and conclusions
- Apply the care and skill expected of a reasonably prudent IS auditor (Correct answer)
- Always issue a qualified audit opinion
- Complete the audit within a budget-specified timeframe
Correct answer: Apply the care and skill expected of a reasonably prudent IS auditor
Due professional care requires IS auditors to exercise the skill and diligence expected of a reasonably prudent professional, not perfection or guaranteed outcomes.
Question 7: ISO 20000 is the international standard for which domain?
- Information security management
- IT service management (Correct answer)
- Risk management processes
- Business continuity management
Correct answer: IT service management
ISO 20000 is the international standard specifying requirements for an IT service management system (SMS), aligning closely with ITIL practices.
In COBIT 2019, which governance domain is responsible for evaluating stakeholder needs and setting strategic direction for IT?