CISA Trivia 3 — Questions and Answers
Question 1: What does the acronym 'COBIT' stand for?
- Control Objectives for Information and Related Technologies (Correct answer)
- Certified Objectives for Business IT
- Control Operations for Integrated Business Technology
- Core Objectives for Information Technology
Correct answer: Control Objectives for Information and Related Technologies
COBIT stands for Control Objectives for Information and Related Technologies, a framework by ISACA.
Question 2: Which of the following best describes the primary role of an IS auditor?
- Provide independent assurance that IT controls are effective (Correct answer)
- Implement security controls across the organization
- Manage IT projects and timelines
- Approve software development changes
Correct answer: Provide independent assurance that IT controls are effective
An IS auditor's primary role is to provide independent, objective assurance that IT controls are adequate and effective.
Question 3: In IS auditing, what is the term for the probability that a material error exists and will not be detected by controls?
- Audit risk (Correct answer)
- Inherent risk
- Control risk
- Detection risk
Correct answer: Audit risk
Audit risk is the overall risk that the auditor may issue an incorrect opinion; it combines inherent, control, and detection risks.
Question 4: Which IS audit technique involves examining actual transactions to verify they were processed correctly?
- Transaction testing
- Compliance testing
- Substantive testing (Correct answer)
- Walkthrough testing
Correct answer: Substantive testing
Substantive testing verifies the accuracy and completeness of actual transactions and data outputs.
Question 5: What is the primary purpose of an IT general control (ITGC)?
- Provide a foundation for application controls to function effectively (Correct answer)
- Prevent all unauthorized access
- Ensure 100% uptime of systems
- Validate business transactions in real time
Correct answer: Provide a foundation for application controls to function effectively
ITGCs provide the environment in which application controls operate, ensuring their effectiveness across systems.
Question 6: Which of the following is an example of a preventive control?
- Segregation of duties (Correct answer)
- Audit log review
- Intrusion detection system
- Incident response plan
Correct answer: Segregation of duties
Segregation of duties is a preventive control that reduces the risk of errors or fraud by dividing responsibilities.
Question 7: The concept of 'due professional care' in IS auditing requires auditors to:
- Apply reasonable skill and diligence to audit work (Correct answer)
- Guarantee the discovery of all fraud
- Certify systems are fully secure
- Provide legal advice on compliance matters
Correct answer: Apply reasonable skill and diligence to audit work
Due professional care means applying the skill and diligence that a reasonably prudent auditor would use in similar circumstances.
What does the acronym 'COBIT' stand for?