CISA Trivia 4 — Questions and Answers
Question 1: What is the purpose of a business impact analysis (BIA) in the context of IT auditing?
- Identify critical systems and the financial impact of their disruption (Correct answer)
- Assess the technical architecture of data centers
- Review vendor contracts for compliance
- Evaluate employee performance in IT departments
Correct answer: Identify critical systems and the financial impact of their disruption
A BIA identifies critical business functions and quantifies the financial and operational impact of disruptions to guide recovery planning.
Question 2: Which recovery metric defines the maximum tolerable period of data loss after a disruption?
- Recovery Point Objective (RPO) (Correct answer)
- Recovery Time Objective (RTO)
- Mean Time to Recover (MTTR)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Point Objective (RPO)
RPO defines the maximum age of data that must be recovered from backup for normal operations to resume.
Question 3: In a hot site disaster recovery arrangement, the alternate facility is characterized by:
- Fully operational hardware, software, and data ready for immediate failover (Correct answer)
- Empty space that must be equipped before use
- Basic infrastructure but no data replication
- A shared facility used by multiple organizations
Correct answer: Fully operational hardware, software, and data ready for immediate failover
A hot site is a fully equipped, mirror facility that can take over operations immediately after a disaster.
Question 4: What does 'chain of custody' refer to in IS auditing and digital forensics?
- The documented trail showing who handled evidence and when (Correct answer)
- The hierarchy of IT management approvals
- A sequence of data backup procedures
- The escalation path for audit findings
Correct answer: The documented trail showing who handled evidence and when
Chain of custody documents the chronological handling of evidence to ensure its integrity and admissibility.
Question 5: Which type of access control model assigns permissions based on a user's role within an organization?
- Role-Based Access Control (RBAC) (Correct answer)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC grants access based on predefined roles, simplifying administration and supporting least privilege.
Question 6: What is the primary objective of penetration testing in an IS audit context?
- Identify exploitable vulnerabilities before malicious actors do (Correct answer)
- Confirm all patches are applied
- Validate user access rights
- Test backup restoration procedures
Correct answer: Identify exploitable vulnerabilities before malicious actors do
Penetration testing simulates real-world attacks to uncover vulnerabilities that could be exploited by adversaries.
Question 7: Which ISACA standard requires IS auditors to maintain independence from the areas they audit?
- ISACA IS Audit and Assurance Standard 1002 (Correct answer)
- ISACA IS Audit Standard 1401
- COBIT 5 APO12
- ISO/IEC 27001 Clause 9
Correct answer: ISACA IS Audit and Assurance Standard 1002
ISACA Standard 1002 (Organisational Independence) requires auditors to be independent from the functions and activities they audit.
What is the purpose of a business impact analysis (BIA) in the context of IT auditing?