CISA Trivia 5 β Questions and Answers
Question 1: In IS auditing, what is 'sampling risk'?
- The risk that the auditor's conclusion based on a sample differs from the conclusion if the entire population were examined (Correct answer)
- The risk of selecting an unrepresentative audit team
- The probability that a system is sampled too frequently
- The chance that sampling tools malfunction during testing
Correct answer: The risk that the auditor's conclusion based on a sample differs from the conclusion if the entire population were examined
Sampling risk is the possibility that the auditor's sample-based conclusion does not reflect the actual state of the entire population.
Question 2: Which of the following best describes 'data integrity' in information systems?
- Assurance that data is accurate, complete, and has not been altered without authorization (Correct answer)
- Ensuring data is always available when needed
- Restricting data access to authorized users only
- Encrypting data during transmission
Correct answer: Assurance that data is accurate, complete, and has not been altered without authorization
Data integrity means data is accurate, complete, consistent, and protected from unauthorized modification.
Question 3: What is the term for the IS audit technique where the auditor processes simulated transactions through a live system to test controls?
- Integrated test facility (ITF) (Correct answer)
- Parallel simulation
- Continuous auditing
- Data analytics
Correct answer: Integrated test facility (ITF)
An ITF introduces fictitious test entities and transactions into a production system to verify that controls operate correctly.
Question 4: Which phase of the SDLC presents the greatest opportunity for IS auditors to influence security and control design?
- Requirements and design (Correct answer)
- Testing
- Implementation
- Maintenance
Correct answer: Requirements and design
Auditor involvement during requirements and design is most effective because changes are least costly at this early stage.
Question 5: What is 'patch management' and why is it relevant to IS auditors?
- The process of applying software updates to fix vulnerabilities, which auditors review for timeliness and completeness (Correct answer)
- Installing new software versions to add features
- Managing user access patches after role changes
- Updating audit report templates
Correct answer: The process of applying software updates to fix vulnerabilities, which auditors review for timeliness and completeness
Patch management involves deploying vendor-issued fixes; auditors assess whether patches are applied promptly to reduce exposure.
Question 6: In the context of CISA, what is the primary purpose of an IS audit charter?
- Define the authority, scope, and responsibilities of the IS audit function (Correct answer)
- List the credentials required for audit staff
- Document audit findings from previous engagements
- Establish the budget for the audit department
Correct answer: Define the authority, scope, and responsibilities of the IS audit function
An IS audit charter formally establishes the mandate, independence, authority, and scope of the internal IS audit function.
Question 7: Which of the following best describes a 'compensating control'?
- A control that mitigates risk when the primary control is absent or ineffective (Correct answer)
- An automated duplicate of a manual control
- A control applied retroactively after an incident
- A financial offset for audit findings
Correct answer: A control that mitigates risk when the primary control is absent or ineffective
A compensating control reduces risk to an acceptable level when the ideal primary control cannot be implemented.
In IS auditing, what is 'sampling risk'?