ISACA Certification Exams (e.g., CISA, CISM, CRISC, CGEIT) — Questions and Answers
Question 1: Which control BEST ensures the completeness of batch processing runs?
- Reconciling record counts and control totals before and after processing (Correct answer)
- Using a dedicated batch processing server
- Scheduling batch jobs during maintenance windows
- Encrypting batch input files at rest
Correct answer: Reconciling record counts and control totals before and after processing
Control totals and record counts provide a mathematical verification that all input records were processed and no records were added, dropped, or duplicated.
Question 2: Which statement BEST describes the relationship between Information Systems Audit and Control Association Certification certification and industry evolution?
- Requirements become less stringent over time
- Certification requirements never change
- Changes only occur when government mandates them
- Requirements evolve periodically to reflect advances in knowledge and practice (Correct answer)
Correct answer: Requirements evolve periodically to reflect advances in knowledge and practice
Certification requirements evolve to keep pace with professional and technological advances.
Question 3: Why is regular testing important for business continuity plans?
- Delay recovery
- Ignore plan flaws
- Reduce preparedness
- Verify plan effectiveness (Correct answer)
Correct answer: Verify plan effectiveness
Regular testing of business continuity plans (BCPs) is crucial to ensure that they are effective, up-to-date, and that personnel are familiar with their roles. Testing helps identify weaknesses, gaps, or outdated information within the plan before a real incident occurs. This verification process allows for necessary revisions, significantly increasing the likelihood of a successful recovery when a disruption happens.
Question 4: A change advisory board (CAB) is PRIMARILY responsible for which activity?
- Testing all system changes after they have been implemented
- Writing and coding the changes requested by the business
- Training users on new system features and updates
- Reviewing and authorizing change requests prior to implementation (Correct answer)
Correct answer: Reviewing and authorizing change requests prior to implementation
The CAB reviews change requests and authorizes implementation, ensuring each change is evaluated for risk, business impact, and necessity before proceeding.
Question 5: Formal change management for infrastructure changes exists PRIMARILY to achieve which outcome?
- Prevent unauthorized changes and minimize the risk of unplanned outages (Correct answer)
- Reduce the total number of people authorized to make changes
- Ensure infrastructure changes are implemented as rapidly as possible
- Eliminate the requirement for pre-deployment testing
Correct answer: Prevent unauthorized changes and minimize the risk of unplanned outages
Formal change management requires authorization and testing before deployment, preventing unauthorized modifications and reducing the likelihood of outages caused by failed changes.
Question 6: An organization uses a Responsibility Assignment Matrix (RACI) for IT governance decisions. The 'A' in RACI stands for:
- Acknowledged
- Accountable (Correct answer)
- Authorized
- Advised
Correct answer: Accountable
In a RACI matrix, 'A' stands for Accountable — the one person ultimately answerable for the correct completion of a task.
Question 7: What does 'audit universe' refer to in internal audit planning?
- The complete set of audit standards applicable to an organization
- All external regulations an organization must comply with
- The total number of auditors available in the department
- All auditable entities or activities within an organization (Correct answer)
Correct answer: All auditable entities or activities within an organization
The audit universe comprises all auditable entities—processes, systems, departments—from which the audit plan is derived based on risk assessment.
Question 8: What is a physical control in information security?
- Encryption
- Password policy
- Firewall
- Locks and guards (Correct answer)
Correct answer: Locks and guards
Physical controls in information security are tangible measures designed to protect physical assets, including hardware, facilities, and the data stored within them, from unauthorized access, damage, or theft. Locks on doors, security guards, surveillance cameras, and alarm systems are examples of physical controls. They create a secure environment, complementing logical and administrative controls.
Question 9: What is the PRIMARY purpose of obtaining ISACA certification in Information Systems Audit and Control Association Certification?
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To satisfy a personal achievement goal
- To bypass educational requirements
- To guarantee employment
Correct answer: To demonstrate verified competency and adherence to professional standards
Certification demonstrates verified competency and adherence to professional standards.
Question 10: Which of the following BEST describes a man-in-the-middle (MITM) attack?
- An attacker floods a target system with traffic to deny service
- An attacker injects malicious code into a web application database
- An attacker secretly intercepts and potentially alters communications between two parties (Correct answer)
- An attacker exploits a buffer overflow to gain elevated privileges
Correct answer: An attacker secretly intercepts and potentially alters communications between two parties
In a MITM attack, the attacker secretly positions themselves between two communicating parties to intercept, read, or modify data.
Question 11: What is the primary goal of IT governance?
- Align IT with organizational goals (Correct answer)
- Ignore business needs
- Increase IT spending
- Delay IT projects
Correct answer: Align IT with organizational goals
The primary goal of IT governance is to ensure that an organization's IT strategy and operations are aligned with its overall business objectives. This alignment helps maximize the value derived from IT investments, optimize resource utilization, and manage IT-related risks effectively to support strategic goals.
Question 12: When a ISACA professional encounters an unexpected result during a procedure, the FIRST action should be to:
- Repeat the procedure immediately
- Continue and address it later
- Report without preliminary assessment
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess unexpected results is critical for safety and quality.
Question 13: When implementing COBIT, an organization starts by defining stakeholder needs and translating them into enterprise goals. This step is part of the:
- Process capability assessment
- Governance and management objectives cascade (Correct answer)
- IT balanced scorecard
- Risk and compliance evaluation
Correct answer: Governance and management objectives cascade
COBIT's goals cascade translates stakeholder needs into enterprise goals, then IT-related goals, then governance and management objectives.
Question 14: Which metric BEST measures the effectiveness of IT governance in delivering business value?
- Number of IT governance meetings held per year
- Percentage of IT investments achieving expected business outcomes (Correct answer)
- Total IT spending as a percentage of revenue
- Number of IT projects completed on budget
Correct answer: Percentage of IT investments achieving expected business outcomes
Governance effectiveness is best measured by whether IT investments actually realize the business outcomes they were intended to deliver.
Question 15: When auditing an organization's network operations center (NOC), an IS auditor should FIRST determine whether:
- All alerts are logged to email
- Network diagrams are printed and posted on the wall
- Monitoring tools provide real-time alerts for threshold breaches (Correct answer)
- The NOC is staffed 24/7
Correct answer: Monitoring tools provide real-time alerts for threshold breaches
Real-time alerting on threshold breaches is the foundational control that enables the NOC to detect and respond to incidents promptly.
Question 16: Which COBIT 2019 design factor relates to the organization's current level of capability in its IT processes?
- Risk profile
- Enterprise strategy
- Current IT capability level (Correct answer)
- IT implementation methods
Correct answer: Current IT capability level
Current IT capability level is one of COBIT 2019's design factors that shapes how governance and management objectives are prioritized.
Question 17: Which of the following BEST describes the purpose of a follow-up audit?
- To identify new risks that emerged since the original audit
- To verify that management has implemented agreed-upon corrective actions (Correct answer)
- To expand the original audit scope to cover additional areas
- To issue a revised audit report with updated findings
Correct answer: To verify that management has implemented agreed-upon corrective actions
A follow-up audit determines whether management has taken timely and effective corrective action to address findings from the original audit.
Question 18: When a ISACA professional identifies a potential regulatory violation, the CORRECT first step is to:
- Wait to see if it resolves on its own
- Discuss it casually with coworkers
- Address it only if directly affected
- Document the violation and report through proper channels (Correct answer)
Correct answer: Document the violation and report through proper channels
Proper documentation and reporting through established channels ensures accountability.
Question 19: What is the purpose of fieldwork in IS audit?
- Gather and analyze evidence (Correct answer)
- Define audit scope
- Conduct training
- Prepare audit report
Correct answer: Gather and analyze evidence
Fieldwork is the phase where auditors execute the planned audit procedures to collect and analyze evidence. This involves examining documentation, interviewing personnel, and testing controls to determine their effectiveness and identify any control deficiencies or non-compliance within the information systems.
Question 20: An organization is evaluating its change management process. Which finding indicates an ineffective process?
- Change advisory board meetings are held weekly
- Emergency changes are frequently implemented without post-implementation review (Correct answer)
- Standard changes follow a pre-approved template
- All changes require impact assessments
Correct answer: Emergency changes are frequently implemented without post-implementation review
Emergency changes that consistently bypass post-implementation review create unreviewed risk and suggest the emergency process is being misused to avoid normal controls.
Question 21: An organization has a high IT risk appetite but weak internal controls. An IS auditor should PRIMARILY recommend:
- Increasing IT spending to match the risk appetite
- Transferring all residual risk to a third party
- Reducing the risk appetite to match existing controls
- Aligning the control environment with the documented risk appetite (Correct answer)
Correct answer: Aligning the control environment with the documented risk appetite
Risk appetite must be supported by a matching control environment; the audit finding is the misalignment between stated appetite and actual controls.
Question 22: What is the PRIMARY reason for regulatory compliance in the Information Systems Audit and Control Association Certification profession?
- To protect public safety, ensure quality, and maintain professional integrity (Correct answer)
- To avoid penalties and fines only
- To justify higher service fees
- To create additional paperwork
Correct answer: To protect public safety, ensure quality, and maintain professional integrity
Regulatory compliance protects public safety, ensures quality, and maintains professional integrity.
Question 23: Which documentation practice BEST demonstrates regulatory compliance for ISACA certified professionals?
- Relying on memory for routine procedures
- Maintaining organized, dated, and signed records of all activities (Correct answer)
- Filing documents only when audited
- Keeping informal handwritten notes
Correct answer: Maintaining organized, dated, and signed records of all activities
Organized, dated, and signed records demonstrate systematic regulatory compliance.
Question 24: What is redundancy in information systems?
- Reducing backups
- Duplicate components for availability (Correct answer)
- Single point of failure
- Ignoring failures
Correct answer: Duplicate components for availability
Redundancy in information systems refers to the practice of duplicating critical components, such as hardware, software, or network paths, to ensure continuous operation even if one component fails. By having multiple instances, the system can automatically switch to a backup, preventing a single point of failure from causing downtime. This significantly enhances system availability and reliability.
Question 25: Which risk management approach is MOST effective for ISACA professionals when evaluating potential workplace hazards?
- Reactive analysis after incidents occur
- Proactive hazard identification and assessment (Correct answer)
- Delegating all safety decisions to management
- Relying solely on historical accident data
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur.
Question 26: Which framework is commonly used for IT governance?
- NIST
- ITIL
- COBIT (Correct answer)
- ISO 27001
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is a widely recognized framework for IT governance and management. It provides a comprehensive set of principles, processes, and practices that help organizations align IT with business goals, manage risks, and optimize resources to deliver value.
Question 27: Which phase of the IS audit process involves comparing actual results against expected criteria to identify exceptions?
- Reporting
- Fieldwork and evidence gathering (Correct answer)
- Audit planning
- Follow-up
Correct answer: Fieldwork and evidence gathering
During fieldwork, auditors execute audit procedures—testing, observing, and comparing evidence against defined audit criteria to identify deviations.
Question 28: In ISACA practice, what happens when regulations are updated?
- Previous certifications are revoked
- Professionals must update knowledge and practices to meet new requirements (Correct answer)
- Existing professionals are grandfathered in
- Changes apply only to new professionals
Correct answer: Professionals must update knowledge and practices to meet new requirements
All professionals must update their knowledge and practices when regulations change.
Question 29: Which of the following BEST describes a tabletop exercise in the context of business continuity?
- A full live failover to the alternate processing site
- A discussion-based walkthrough of a disaster scenario without activating recovery systems (Correct answer)
- An annual review of the BCP document by management
- A technical test of backup media restoration
Correct answer: A discussion-based walkthrough of a disaster scenario without activating recovery systems
A tabletop exercise engages key personnel in a scenario discussion to identify gaps and clarify roles without the cost and disruption of a full operational test.
Question 30: Which regulatory requirement is UNIVERSAL across all Information Systems Audit and Control Association Certification practice settings?
- Using specific proprietary software
- Limiting services to local jurisdictions
- Working exclusively during business hours
- Maintaining current certification and continuing education (Correct answer)
Correct answer: Maintaining current certification and continuing education
Maintaining current certification and continuing education is a universal regulatory requirement.
Question 31: What is the MOST effective way for new ISACA professionals to build competency?
- Focusing solely on advanced topics
- Studying certification materials exclusively
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Learning through trial and error
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building competency requires formal education, mentored practice, and ongoing development.
Question 32: An IS auditor discovers that automated system-generated reports used for management decisions cannot be reproduced or reconciled to source data. This is BEST classified as a deficiency in:
- Physical security controls
- Report integrity and completeness controls (Correct answer)
- Identity and access management controls
- Network perimeter controls
Correct answer: Report integrity and completeness controls
The inability to reproduce or reconcile reports to source data indicates a failure in report integrity controls, undermining confidence in management's decision-making information.
Question 33: When evaluating vendor proposals during system acquisition, what should an IS auditor verify is included in the RFP (Request for Proposal)?
- The vendor's internal marketing strategy
- Security, compliance, and audit requirements (Correct answer)
- Only technical specifications and pricing
- Vendor stock prices and financial forecasts
Correct answer: Security, compliance, and audit requirements
Including security, compliance, and audit requirements in the RFP ensures vendors understand and commit to these critical obligations from the outset of the relationship.
Question 34: What is risk management in IT governance?
- Increase risk exposure
- Identify and mitigate risks (Correct answer)
- Delay decisions
- Ignore risks
Correct answer: Identify and mitigate risks
Risk management in IT governance is the systematic process of identifying, assessing, and treating potential threats to an organization's information assets and IT operations. Its purpose is to minimize the likelihood and impact of adverse events, such as data breaches or system failures. By proactively identifying and mitigating risks, organizations can protect their investments, maintain business continuity, and ensure compliance.
Question 35: In Information Systems Audit and Control Association Certification practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Wait for a supervisor to notice the issue
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
- Document it for the next safety audit
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels.
Question 36: Which of the following BEST describes 'inherent risk' in the context of IS auditing?
- The risk that the auditor's procedures will fail to detect errors
- The risk that remains after management has applied controls
- The susceptibility of an area to a material misstatement assuming no controls (Correct answer)
- The combined risk of a material error occurring and not being detected
Correct answer: The susceptibility of an area to a material misstatement assuming no controls
Inherent risk is the level of risk present in the absence of any mitigating controls—the raw, uncontrolled risk of an area.
Question 37: Which approach is MOST important for ISACA professionals when applying technical procedures?
- Adhering to established protocols while adapting to specific conditions (Correct answer)
- Applying the same technique without variation
- Following personal shortcuts
- Using the fastest method regardless of standards
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to protocols with professional judgment for adaptation.
Question 38: Which metric best measures the effectiveness of an organization's disaster recovery plan?
- Frequency of DR plan updates
- Recovery Time Objective (RTO) achieved (Correct answer)
- Number of backup tapes created
- Cost of DR infrastructure
Correct answer: Recovery Time Objective (RTO) achieved
Achieving the defined RTO demonstrates that the DR plan can restore operations within the acceptable downtime window.
Question 39: An IS auditor is assessing the adequacy of password policies. Which finding represents the HIGHEST risk?
- Password history prevents reuse of the last 10 passwords
- Passwords do not expire for service accounts (Correct answer)
- Passwords must be at least 8 characters long
- Users are required to change passwords every 90 days
Correct answer: Passwords do not expire for service accounts
Non-expiring passwords on service accounts pose significant risk because a compromised credential may go undetected indefinitely with no forced rotation.
Question 40: In Information Systems Audit and Control Association Certification practice, what is the CORRECT sequence when performing a technical procedure?
- Execute immediately and document only if issues arise
- Document, execute, then plan
- Execute, then plan and review
- Plan, prepare, execute, verify, and document (Correct answer)
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows: plan, prepare, execute, verify, and document.
Question 41: Under the CISA framework, which of the following is the MOST important indicator that an organization's IT governance is effective?
- IT goals consistently support and enable business objectives (Correct answer)
- IT governance roles are assigned to senior IT staff
- IT governance policies are documented and published
- IT governance committee meets on a quarterly schedule
Correct answer: IT goals consistently support and enable business objectives
Effective IT governance is ultimately demonstrated by IT outcomes that consistently support and advance business objectives, not just process compliance.
Question 42: During an IT general controls audit, which area would an IS auditor focus on to assess whether program changes are authorized and tested before moving to production?
- Logical access controls
- Change management controls (Correct answer)
- Backup and recovery controls
- Physical security controls
Correct answer: Change management controls
Change management controls govern the authorization, testing, and migration of program changes from development to production environments.
Question 43: What is an audit program?
- Financial statement
- Plan of audit procedures (Correct answer)
- Project management plan
- Security policy
Correct answer: Plan of audit procedures
An audit program is a detailed, step-by-step plan that outlines the specific procedures and tests to be performed during an audit engagement. It ensures a systematic and comprehensive approach to gathering evidence, helping auditors achieve their objectives efficiently and consistently while maintaining quality.
Question 44: In an Agile development methodology, what is the PRIMARY audit concern compared to a traditional waterfall approach?
- Documentation and formal change control may be less rigorous (Correct answer)
- Agile typically produces lower quality code
- Agile requires significantly more testing phases
- Agile introduces more security vulnerabilities by default
Correct answer: Documentation and formal change control may be less rigorous
Agile's iterative and flexible nature may result in less formal documentation and change control, creating audit challenges around completeness and traceability.
Question 45: An IS auditor discovers that IT governance policies were last updated five years ago. What should the auditor PRIMARILY recommend?
- Require management to sign off on existing policies as-is
- Establish a periodic policy review cycle aligned with business change (Correct answer)
- Immediately suspend all IT operations until policies are updated
- Replace all policies with industry-standard templates
Correct answer: Establish a periodic policy review cycle aligned with business change
Governance policies must be reviewed and updated periodically to remain aligned with evolving business strategy, technology, and regulatory requirements.
Question 46: A hot site differs from a warm site primarily because a hot site:
- Is less expensive to maintain on an ongoing basis
- Requires 24–72 hours to become operational
- Has fully operational systems with current data ready for immediate failover (Correct answer)
- Is owned by the organization rather than a third party
Correct answer: Has fully operational systems with current data ready for immediate failover
A hot site mirrors the production environment with up-to-date data, enabling near-immediate failover, while a warm site requires additional configuration time.
Question 47: Which phase of the audit process involves identifying key risks and controls?
- Fieldwork
- Reporting
- Follow-up
- Planning (Correct answer)
Correct answer: Planning
The planning phase is crucial in an IS audit as it involves defining the audit scope, objectives, and methodology. During this phase, auditors identify key risks and controls relevant to the systems being audited, which guides the subsequent fieldwork and ensures an efficient and focused audit approach.
Question 48: Under ISACA standards, an IS auditor who identifies a significant IT risk outside the original audit scope should:
- Immediately halt the audit and replan from scratch
- Communicate it to management and consider whether scope expansion is warranted (Correct answer)
- Ignore it since it is outside the defined scope
- Include it in current report findings without consultation
Correct answer: Communicate it to management and consider whether scope expansion is warranted
Professional standards require IS auditors to communicate significant risks discovered outside scope to management, and to evaluate whether expanding the scope is appropriate.
Question 49: An organization replicates data to a remote site every four hours. This interval represents the:
- Recovery Point Objective (RPO) (Correct answer)
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Point Objective (RPO)
The replication interval defines the maximum data loss the organization can tolerate, which is the definition of the Recovery Point Objective.
Question 50: During data conversion from a legacy to a new system, which procedure is MOST important for ensuring data integrity?
- Converting all data to a single standardized format
- Performing parallel processing and reconciling results between systems (Correct answer)
- Deleting duplicate records prior to migration
- Compressing data to reduce storage requirements
Correct answer: Performing parallel processing and reconciling results between systems
Parallel processing runs both systems simultaneously and reconciles outputs to verify the new system produces accurate results consistent with the legacy system.
Question 51: An IS auditor reviewing problem management should verify that:
- Problem management meetings occur daily
- Problem tickets are assigned to senior staff only
- All incidents are escalated to problem management
- Root cause analyses are completed and permanent fixes are tracked to closure (Correct answer)
Correct answer: Root cause analyses are completed and permanent fixes are tracked to closure
Effective problem management requires identifying root causes and ensuring permanent fixes are implemented and verified, not just documenting the occurrence.
Question 52: Which encryption mode is most appropriate for encrypting large amounts of data where parallel processing is desired?
- Cipher Block Chaining (CBC)
- Electronic Codebook (ECB)
- Output Feedback (OFB)
- Counter (CTR) (Correct answer)
Correct answer: Counter (CTR)
Counter (CTR) mode allows parallel encryption and decryption of blocks, making it ideal for large data sets.
Question 53: An IS auditor reviewing a business continuity plan (BCP) finds that the plan has not been tested in three years. The MOST significant risk is:
- Testing costs have not been budgeted
- The BCP vendor contract may have expired
- Staff may be unfamiliar with the document's formatting
- The plan may contain outdated procedures that fail during an actual disaster (Correct answer)
Correct answer: The plan may contain outdated procedures that fail during an actual disaster
Untested plans may reference decommissioned systems, departed personnel, or obsolete procedures, causing failures precisely when recovery is most critical.
Question 54: User acceptance testing (UAT) is PRIMARILY performed by which group?
- IS auditors
- Quality assurance specialists
- End users and business stakeholders (Correct answer)
- Development team members
Correct answer: End users and business stakeholders
UAT is performed by end users and business stakeholders to confirm the system meets their operational requirements before go-live approval.
Question 55: Why is user training critical in protecting information assets?
- Ignore security policies
- Prevent incidents through awareness (Correct answer)
- Increase user mistakes
- Reduce system use
Correct answer: Prevent incidents through awareness
User training is critical in protecting information assets because human error and social engineering are significant causes of security incidents. Educating users about security policies, best practices, phishing awareness, and safe data handling empowers them to recognize and avoid threats. A well-informed workforce acts as a strong first line of defense, significantly reducing the organization's overall risk exposure.
Question 56: An IS auditor finds that emergency changes are implemented without any post-implementation review. This finding represents:
- A control weakness that requires remediation (Correct answer)
- A best practice for expediting high-priority changes
- An acceptable exception given the time-critical nature of emergencies
- A standard procedure consistent with ITIL emergency change guidance
Correct answer: A control weakness that requires remediation
All changes, including emergency changes, require post-implementation review to confirm objectives were met and to assess any residual risks introduced.
Question 57: During a data center audit, an IS auditor finds that system logs are stored on the same server being monitored. The MAIN risk is:
- An attacker could alter logs to conceal unauthorized activity (Correct answer)
- Log storage consumes excessive disk space
- Compliance reports may take longer to generate
- Log retrieval performance may be degraded
Correct answer: An attacker could alter logs to conceal unauthorized activity
Storing logs on the monitored system allows an attacker who compromises that system to modify or delete audit trails, eliminating evidence of their actions.
Question 58: Which access control model assigns permissions based on the sensitivity label of information and the security clearance of users?
- Mandatory Access Control (MAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
- Role-Based Access Control (RBAC)
- Discretionary Access Control (DAC)
Correct answer: Mandatory Access Control (MAC)
Mandatory Access Control (MAC) uses security labels and clearances to govern access, and is common in government/military environments.
Question 59: What is the BEST way for a Information Systems Audit and Control Association Certification professional to stay current with regulatory changes?
- Depend on colleagues to share updates
- Monitor regulatory bodies, attend CE, and participate in professional associations (Correct answer)
- Check regulations only during renewal
- Rely solely on employer notifications
Correct answer: Monitor regulatory bodies, attend CE, and participate in professional associations
Staying current requires monitoring agencies, attending CE, and participating in professional associations.
Question 60: Why is performance measurement important in IT governance?
- Reduce accountability
- Increase costs
- Ignore performance
- Ensure objectives are met (Correct answer)
Correct answer: Ensure objectives are met
Performance measurement in IT governance is crucial because it provides a systematic way to track progress against defined IT objectives and strategies. By regularly measuring performance, organizations can identify whether IT initiatives are on track, delivering expected value, and contributing to overall business goals. This allows for timely adjustments and ensures accountability, ultimately helping to achieve desired outcomes.
Question 61: Under Val IT, the concept of 'investment portfolio management' means:
- Ensuring IT hardware is depreciated correctly
- Tracking ROI on completed IT projects only
- Managing the server and application asset inventory
- Selecting and balancing IT investments across risk and return profiles (Correct answer)
Correct answer: Selecting and balancing IT investments across risk and return profiles
Val IT's investment portfolio management ensures an organization selects, balances, and monitors IT investments to maximize business value.
Question 62: When performing a review of physical access controls to a data center, an IS auditor would MOST appropriately:
- Check whether the data center door is made of metal
- Interview only the security guard on duty
- Review the building's general floor plan
- Request the access control system logs and compare them against authorized access lists (Correct answer)
Correct answer: Request the access control system logs and compare them against authorized access lists
Reviewing access logs against authorized access lists directly tests whether only authorized individuals accessed the data center and whether any unauthorized access occurred.
Question 63: Which of the following BEST describes the role of Key Risk Indicators (KRIs) in IT governance?
- They measure the financial return on IT investments
- They provide early warning signals of increasing risk exposure (Correct answer)
- They document historical security incidents for audit purposes
- They track whether IT service level agreements are being met
Correct answer: They provide early warning signals of increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are rising, enabling proactive governance responses before risks materialize.
Question 64: When auditing an outsourced software development arrangement, an IS auditor should PRIMARILY review which documentation?
- Contract terms, SLAs, and right-to-audit clauses (Correct answer)
- Marketing materials provided by the vendor
- The vendor's office location and physical size
- The vendor's employee compensation structures
Correct answer: Contract terms, SLAs, and right-to-audit clauses
Contract terms, SLAs, and right-to-audit clauses define vendor obligations and provide the legal basis for the auditor to assess vendor performance and controls.
Question 65: What role does calibration play in maintaining technical accuracy for Information Systems Audit and Control Association Certification professionals?
- It only matters during inspections
- It is only necessary for new equipment
- It ensures instruments produce accurate, consistent results over time (Correct answer)
- It is optional for advanced professionals
Correct answer: It ensures instruments produce accurate, consistent results over time
Regular calibration ensures instruments continue producing accurate results over time.
Question 66: What role does calibration play in maintaining technical accuracy for Information Systems Audit and Control Association Certification professionals?
- It is optional for advanced professionals
- It is only necessary for new equipment
- It only matters during inspections
- It ensures instruments produce accurate, consistent results over time (Correct answer)
Correct answer: It ensures instruments produce accurate, consistent results over time
Regular calibration ensures instruments continue producing accurate results over time.
Question 67: An IS auditor reviewing an organization's key management practices should verify that cryptographic keys are:
- Changed only when a security incident is detected
- Generated using approved algorithms and protected throughout their lifecycle (Correct answer)
- Stored in plaintext within the application that uses them
- Kept exclusively by the CEO and CISO for accountability
Correct answer: Generated using approved algorithms and protected throughout their lifecycle
Effective key management requires keys to be generated with approved algorithms and protected (encrypted, access-controlled) across their entire lifecycle.
Question 68: Which practice BEST demonstrates that an organization's IT governance framework supports ethical use of technology?
- Publishing an annual IT spending report
- Establishing and enforcing an acceptable use policy with consequences (Correct answer)
- Conducting annual IT audits with external auditors
- Deploying data loss prevention tools across all endpoints
Correct answer: Establishing and enforcing an acceptable use policy with consequences
An acceptable use policy with enforced consequences establishes clear ethical boundaries and holds users accountable for technology use.
Question 69: Which testing methodology evaluates system functionality based on inputs and outputs without knowledge of internal code structure?
- Regression testing
- Black-box testing (Correct answer)
- White-box testing
- Gray-box testing
Correct answer: Black-box testing
Black-box testing evaluates system behavior from an external perspective using inputs and outputs, without any knowledge of internal logic or code.
Question 70: When a ISACA professional encounters an unexpected result during a procedure, the FIRST action should be to:
- Repeat the procedure immediately
- Report without preliminary assessment
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Continue and address it later
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess unexpected results is critical for safety and quality.
Question 71: Which control is MOST important to verify when auditing a change management process?
- Emergency changes bypass authorization controls
- Change logs are maintained only for major changes
- All changes are tested directly in production
- Changes are approved by appropriate authority before implementation (Correct answer)
Correct answer: Changes are approved by appropriate authority before implementation
Authorization by appropriate authority ensures changes are reviewed and approved before implementation, preventing unauthorized modifications.
Question 72: What is the role of the IT steering committee?
- Develop software
- Provide oversight and direction (Correct answer)
- Handle user support
- Manage daily IT tasks
Correct answer: Provide oversight and direction
The IT steering committee plays a crucial role in IT governance by providing strategic oversight and direction for an organization's IT initiatives. It ensures that IT projects and investments are aligned with business objectives, monitors performance, and makes key decisions regarding IT strategy and resource allocation.
Question 73: Which of the following is the MOST important characteristic of audit evidence?
- It must be approved by the auditee before use
- It must be obtained within the first week of fieldwork
- It must always be obtained through computer-assisted tools
- It must be sufficient and appropriate to support audit conclusions (Correct answer)
Correct answer: It must be sufficient and appropriate to support audit conclusions
Audit standards universally require evidence to be sufficient (adequate quantity) and appropriate (relevant quality and reliability) to support the auditor's conclusions.
Question 74: Which factor MOST significantly affects the quality of technical outcomes in ISACA practice?
- The brand of equipment
- The practitioner's training, preparation, and attention to detail (Correct answer)
- Speed of procedure completion
- The time of day
Correct answer: The practitioner's training, preparation, and attention to detail
Quality depends primarily on training, preparation, and attention to detail.
Question 75: Which of the following cloud deployment models gives an organization the MOST control over its security configurations?
- Public cloud
- Hybrid cloud
- Private cloud (Correct answer)
- Community cloud
Correct answer: Private cloud
A private cloud is dedicated to a single organization, giving it full control over security configurations, policies, and infrastructure.
Question 76: Which foundational principle is MOST important for success in Information Systems Audit and Control Association Certification?
- Specializing in only one narrow area
- Maintaining minimum certification requirements
- Maximizing financial returns
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 77: When reviewing Business Continuity Planning (BCP), an IS auditor should PRIMARILY assess whether:
- The BCP document has been printed and distributed to all staff
- The IT department wrote the plan without business input
- Recovery procedures have been tested and meet recovery time objectives (Correct answer)
- All servers have been replaced within the last three years
Correct answer: Recovery procedures have been tested and meet recovery time objectives
The most critical BCP control is that recovery procedures are regularly tested and validated against documented Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Question 78: What documentation is MOST critical to maintain for safety compliance in the Information Systems Audit and Control Association Certification field?
- Client marketing preferences
- Incident reports, training records, and inspection logs (Correct answer)
- Annual revenue reports
- Employee vacation schedules
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation for demonstrating compliance.
Question 79: What distinguishes a Information Systems Audit and Control Association Certification certified professional from a non-certified practitioner?
- Certified professionals only work in larger organizations
- Certified professionals always have more experience
- There is no meaningful difference
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 80: When an IS auditor identifies a control deficiency during fieldwork, what is the MOST appropriate immediate action?
- Immediately report it to external regulators
- Dismiss it if it appears minor
- Document the finding and discuss it with management before finalizing (Correct answer)
- Include it in the audit report without informing management
Correct answer: Document the finding and discuss it with management before finalizing
Auditors should document findings and discuss them with management during the exit conference to confirm facts before issuing the final report.
Question 81: Which metric is MOST useful for evaluating the effectiveness of an incident response program?
- Annual security training completion rate
- Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents (Correct answer)
- Total number of security tools deployed
- Number of security policies documented
Correct answer: Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents
MTTD and MTTR directly measure how quickly threats are identified and contained, reflecting the operational performance of the incident response process.
Question 82: When a ISACA professional identifies a potential regulatory violation, the CORRECT first step is to:
- Discuss it casually with coworkers
- Wait to see if it resolves on its own
- Document the violation and report through proper channels (Correct answer)
- Address it only if directly affected
Correct answer: Document the violation and report through proper channels
Proper documentation and reporting through established channels ensures accountability.
Question 83: What is the primary objective of an information system audit?
- Design hardware systems
- To develop software
- Evaluate effectiveness of controls (Correct answer)
- Manage IT projects
Correct answer: Evaluate effectiveness of controls
The primary objective of an information system audit is to evaluate the effectiveness of an organization's IT controls. This assessment determines whether controls are adequately protecting information assets, ensuring data integrity, confidentiality, and availability, and helping to identify weaknesses and ensure compliance.
Question 84: Which backup strategy provides the FASTEST recovery time while minimizing backup storage requirements?
- Daily full backups of all data
- Differential backups taken every hour
- Incremental-only backups stored indefinitely
- A combination of full and incremental backups with a recovery catalog (Correct answer)
Correct answer: A combination of full and incremental backups with a recovery catalog
A full backup combined with incremental backups and a recovery catalog balances storage efficiency with manageable restore complexity when guided by the catalog.
Question 85: Which environmental control is MOST critical for preventing hardware damage in a data center?
- Maintaining temperature and humidity within manufacturer-specified ranges (Correct answer)
- Installing motion-sensor lighting to reduce energy costs
- Painting server racks a light color to reflect heat
- Using anti-static mats at all workstations
Correct answer: Maintaining temperature and humidity within manufacturer-specified ranges
Excessive heat or humidity directly causes hardware failures; maintaining conditions within manufacturer specifications is the primary environmental control.
Question 86: Which of the following BEST describes the principle of least privilege?
- Users should be given only the minimum access rights necessary to perform their job functions (Correct answer)
- Users should be granted access to all systems unless explicitly denied
- Privileged accounts should be shared among administrators to ensure availability
- Access rights should never be reviewed once initially granted
Correct answer: Users should be given only the minimum access rights necessary to perform their job functions
The principle of least privilege limits user access rights to only what is necessary to perform authorized tasks, reducing the attack surface.
Question 87: When conducting a risk assessment for ISACA operations, which factor should receive the HIGHEST priority?
- Time required for safety training
- Convenience for daily operations
- Probability and severity of potential harm (Correct answer)
- Cost of implementing safety measures
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment.
Question 88: ISO/IEC 38500 defines IT governance principles for corporate governance of IT. Which of the following is NOT one of its six principles?
- Acquisition
- Responsibility
- Optimization (Correct answer)
- Strategy
Correct answer: Optimization
ISO/IEC 38500's six principles are Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour — Optimization is not among them.
Question 89: A security information and event management (SIEM) system is PRIMARILY used to:
- Scan networks for open vulnerabilities
- Prevent malware from executing on endpoints
- Aggregate and correlate security events for real-time analysis (Correct answer)
- Encrypt data stored in databases
Correct answer: Aggregate and correlate security events for real-time analysis
SIEM systems collect, aggregate, and correlate log and event data from multiple sources to detect and alert on security incidents.
Question 90: An organization wants to ensure that sensitive data cannot be recovered after hard drive disposal. Which method provides the STRONGEST assurance?
- Physical destruction of the drive (Correct answer)
- Logical formatting of the drive
- Overwriting with a single pass of zeros
- Degaussing the magnetic media
Correct answer: Physical destruction of the drive
Physical destruction (shredding, crushing) provides the strongest assurance that data cannot be recovered from disposed media.
Question 91: What is the PRIMARY purpose of a business impact analysis (BIA)?
- Calculate the total cost of a disaster
- Select appropriate backup technology
- Train staff on emergency procedures
- Identify critical business functions and their recovery priorities (Correct answer)
Correct answer: Identify critical business functions and their recovery priorities
A BIA identifies critical business processes, their dependencies, and the impact of disruption to establish recovery priorities and objectives.
Question 92: What should an audit report include?
- Employee evaluations
- Only positive feedback
- Financial statements
- Findings, conclusions, recommendations (Correct answer)
Correct answer: Findings, conclusions, recommendations
A comprehensive audit report should clearly present the audit findings, which are factual observations of control weaknesses or strengths. It must also include conclusions drawn from these findings and actionable recommendations for improvement, enabling management to address identified issues effectively and enhance the control environment.
Question 93: What is the PRIMARY reason for regulatory compliance in the Information Systems Audit and Control Association Certification profession?
- To justify higher service fees
- To avoid penalties and fines only
- To create additional paperwork
- To protect public safety, ensure quality, and maintain professional integrity (Correct answer)
Correct answer: To protect public safety, ensure quality, and maintain professional integrity
Regulatory compliance protects public safety, ensures quality, and maintains professional integrity.
Question 94: In the context of IT governance, 'benefit realization' refers to:
- Measuring IT uptime and system availability
- Calculating the total cost of ownership of IT assets
- Ensuring IT investments deliver their intended business value (Correct answer)
- Documenting the technical capabilities of IT systems
Correct answer: Ensuring IT investments deliver their intended business value
Benefit realization is the governance practice of ensuring that promised business benefits from IT investments are actually achieved post-implementation.
Question 95: An IS auditor finds that IT management reports to the CFO rather than directly to the CEO or board. What governance concern should be raised?
- IT strategy may be overly focused on financial efficiency over innovation (Correct answer)
- IT security may be under-resourced
- IT budget oversight may be duplicated across departments
- IT projects may bypass procurement controls
Correct answer: IT strategy may be overly focused on financial efficiency over innovation
Reporting to the CFO can bias IT decisions toward cost reduction rather than strategic business enablement.
Question 96: Which rollback procedure consideration is MOST critical before executing a production system upgrade?
- Whether the rollback procedure has been tested and a documented fallback plan exists (Correct answer)
- Whether the rollback process takes more than one hour
- Whether all end users have been notified about the potential rollback
- Whether the rollback preserves developer configuration preferences
Correct answer: Whether the rollback procedure has been tested and a documented fallback plan exists
Testing the rollback procedure before go-live ensures the organization can reliably revert to the prior stable state if the upgrade fails.
Question 97: When assessing third-party vendor security, which document MOST comprehensively defines required security obligations?
- Non-Disclosure Agreement (NDA)
- Master Service Agreement (MSA)
- Service Level Agreement (SLA)
- Data Processing Agreement (DPA) with security annexes (Correct answer)
Correct answer: Data Processing Agreement (DPA) with security annexes
A Data Processing Agreement with security annexes specifies technical and organizational security requirements for vendors handling personal or sensitive data.
Question 98: Which of the following network segmentation techniques BEST isolates a web-facing server from internal corporate resources?
- Deploying an intrusion prevention system on the server
- Using a host-based firewall on the server
- VPN tunneling between segments
- Placing the server in a DMZ (demilitarized zone) (Correct answer)
Correct answer: Placing the server in a DMZ (demilitarized zone)
A DMZ isolates public-facing servers from internal networks using firewalls, limiting the blast radius of a compromise.
Question 99: Which factor MOST significantly affects the quality of technical outcomes in ISACA practice?
- The brand of equipment
- The time of day
- The practitioner's training, preparation, and attention to detail (Correct answer)
- Speed of procedure completion
Correct answer: The practitioner's training, preparation, and attention to detail
Quality depends primarily on training, preparation, and attention to detail.
Question 100: Which of the following is the PRIMARY objective of a security operations center (SOC)?
- To manage user identity provisioning and access requests
- To perform annual penetration tests on critical infrastructure
- To develop and enforce security policies across the organization
- To continuously monitor, detect, and respond to cybersecurity incidents (Correct answer)
Correct answer: To continuously monitor, detect, and respond to cybersecurity incidents
A SOC provides 24/7 monitoring and response capabilities to detect, analyze, and contain security incidents in real time.
Question 101: When conducting a risk assessment for ISACA operations, which factor should receive the HIGHEST priority?
- Cost of implementing safety measures
- Probability and severity of potential harm (Correct answer)
- Time required for safety training
- Convenience for daily operations
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment.
Question 102: Which type of malware disguises itself as legitimate software to trick users into installing it?
- Worm
- Logic bomb
- Rootkit
- Trojan horse (Correct answer)
Correct answer: Trojan horse
A Trojan horse masquerades as benign or useful software while carrying a malicious payload, tricking users into executing it.
Question 103: During a system development project, which SDLC phase is primarily concerned with identifying and documenting business requirements?
- Implementation
- System testing
- Requirements analysis (Correct answer)
- System design
Correct answer: Requirements analysis
Requirements analysis is the phase where business and functional requirements are gathered and documented to ensure the system meets user needs.
Question 104: Which foundational principle is MOST important for success in Information Systems Audit and Control Association Certification?
- Specializing in only one narrow area
- Maintaining minimum certification requirements
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maximizing financial returns
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 105: What is the role of encryption in protecting information?
- Delete data
- Store data openly
- Secure data via conversion (Correct answer)
- Ignore data
Correct answer: Secure data via conversion
Encryption is a cryptographic technique that transforms data into an unreadable format, known as ciphertext, using an algorithm and a key. Its role in protecting information is to secure data both in transit and at rest, making it unintelligible to unauthorized individuals. Only those with the correct decryption key can convert the data back into its original, readable form, thereby safeguarding its confidentiality.
Question 106: A data owner is PRIMARILY responsible for which of the following?
- Patching vulnerabilities in systems storing the data
- Classifying data and defining access rules (Correct answer)
- Monitoring network traffic for anomalies
- Implementing technical security controls
Correct answer: Classifying data and defining access rules
The data owner is accountable for classifying information and establishing appropriate access control policies.
Question 107: What is the main goal of business resilience?
- Ensure operations continuity (Correct answer)
- Reduce security
- Increase downtime
- Ignore risks
Correct answer: Ensure operations continuity
The main goal of business resilience is to ensure that an organization can withstand and recover from disruptions, maintaining its critical operations and services. It encompasses the ability to adapt to changes, absorb shocks, and rapidly restore functionality after an incident. This focus on continuity minimizes downtime and protects the organization's reputation and financial stability.
Question 108: Which of the following is the BEST indicator that patch management processes are effective?
- All servers are running the same OS version
- Vendor patch notifications are archived
- Mean time to patch critical vulnerabilities meets defined SLAs (Correct answer)
- Patches are applied manually by administrators
Correct answer: Mean time to patch critical vulnerabilities meets defined SLAs
Measuring mean time to patch against defined SLAs provides a quantifiable indication of whether vulnerabilities are being remediated in a timely manner.
Question 109: In Information Systems Audit and Control Association Certification, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To reduce daily workload
- To satisfy insurance requirements only
- To evaluate employee performance reviews
- To ensure personnel can respond effectively in emergencies (Correct answer)
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies.
Question 110: When evaluating an organization's IT operations, an IS auditor should verify that operator procedures are:
- Documented, approved, and reviewed periodically (Correct answer)
- Memorized by all operations staff
- Created by individual operators based on experience
- Stored exclusively on the operators' workstations
Correct answer: Documented, approved, and reviewed periodically
Documented, approved, and periodically reviewed procedures ensure consistency, accountability, and alignment with current operational and security requirements.
Question 111: An IS auditor beginning a review of a system acquisition should FIRST examine which document?
- Post-implementation review reports
- The business case and requirements specification (Correct answer)
- User acceptance test results
- System training documentation
Correct answer: The business case and requirements specification
The business case and requirements specification establish the baseline against which all subsequent activities and outcomes are measured.
Question 112: A large enterprise uses a federated IT governance model. This means IT governance decisions are:
- Made solely by the board of directors
- Outsourced to a third-party governance provider
- Made exclusively by the corporate IT department
- Distributed across business units with some central coordination (Correct answer)
Correct answer: Distributed across business units with some central coordination
A federated model distributes IT governance authority to business units while maintaining central coordination for enterprise-wide standards.
Question 113: Which configuration management practice BEST supports an audit trail for system changes?
- Limiting configuration access to only senior IT staff
- Requiring weekly backups of all configurations
- Encrypting all configuration files at rest
- Maintaining a configuration management database (CMDB) (Correct answer)
Correct answer: Maintaining a configuration management database (CMDB)
A CMDB tracks configuration items, their attributes, and their change history, providing a comprehensive record that supports audit trails and impact analysis.
Question 114: How does the ISACA body of knowledge relate to daily professional practice?
- It provides the foundational framework guiding decision-making and standard practices (Correct answer)
- It is only for academic research
- It is theoretical with limited application
- It only applies during exams
Correct answer: It provides the foundational framework guiding decision-making and standard practices
The body of knowledge provides the framework guiding daily decision-making and practices.
Question 115: An IS auditor finds that developers have access to the production environment. This PRIMARILY violates the principle of:
- Segregation of duties (Correct answer)
- Defense in depth
- Least privilege only
- Non-repudiation
Correct answer: Segregation of duties
Allowing developers access to production violates segregation of duties because the same person who creates code should not be able to deploy or modify it in production.
Question 116: What is the PRIMARY purpose of obtaining ISACA certification in Information Systems Audit and Control Association Certification?
- To satisfy a personal achievement goal
- To bypass educational requirements
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To guarantee employment
Correct answer: To demonstrate verified competency and adherence to professional standards
Certification demonstrates verified competency and adherence to professional standards.
Question 117: When auditing an outsourced data center, an IS auditor should rely PRIMARILY on:
- Annual financial statements of the vendor
- Verbal assurances from the vendor's account manager
- SSAE 18 SOC 2 Type II reports and contractual audit rights clauses (Correct answer)
- The vendor's marketing materials and certifications list
Correct answer: SSAE 18 SOC 2 Type II reports and contractual audit rights clauses
SOC 2 Type II reports provide an independent, structured assessment of controls over a period of time, and audit rights clauses allow the organization to verify controls directly.
Question 118: Which sampling method gives every item in a population an equal chance of selection, making it the most statistically representative?
- Cluster sampling
- Random sampling (Correct answer)
- Judgmental sampling
- Stratified sampling
Correct answer: Random sampling
Random (statistical) sampling ensures each item has an equal probability of selection, supporting statistically valid conclusions.
Question 119: Which ISO standard provides the code of practice for information security controls and is frequently referenced alongside ISO/IEC 27001?
- ISO/IEC 20000
- ISO/IEC 38500
- ISO/IEC 31000
- ISO/IEC 27002 (Correct answer)
Correct answer: ISO/IEC 27002
ISO/IEC 27002 is the code of practice providing guidance on implementing information security controls referenced in ISO/IEC 27001.
Question 120: What is the PRIMARY purpose of a post-implementation review (PIR)?
- To train end users on the new system
- To document the technical system architecture
- To identify and remediate security vulnerabilities
- To evaluate whether the system meets its original objectives (Correct answer)
Correct answer: To evaluate whether the system meets its original objectives
A post-implementation review assesses whether the implemented system meets the defined business objectives and performance criteria established before development.
Question 121: Which of the following BEST describes the role of a reciprocal agreement in business continuity?
- An organization maintains a cold site at a secondary location
- Two organizations share a common disaster recovery budget
- Two organizations agree to provide each other computing resources in the event of a disaster (Correct answer)
- An organization contracts with a third-party hot site provider
Correct answer: Two organizations agree to provide each other computing resources in the event of a disaster
A reciprocal agreement is a mutual arrangement between two organizations to host each other's operations during a disaster, though resource conflicts are a known risk.
Question 122: During a review of IS operations, an IS auditor should verify that service level agreements (SLAs) with IT vendors:
- Focus solely on cost benchmarks
- Include measurable performance targets, reporting requirements, and remedies for non-compliance (Correct answer)
- Are reviewed only when a performance issue occurs
- Are negotiated exclusively by the IT department without legal review
Correct answer: Include measurable performance targets, reporting requirements, and remedies for non-compliance
Effective SLAs must define measurable targets and consequences for non-compliance to be enforceable and to provide a basis for vendor performance evaluation.
Question 123: An organization's IT steering committee approves a major ERP implementation but the business case shows negative NPV. An IS auditor should FIRST:
- Require the project to be cancelled immediately
- Recommend the organization reduce the project scope
- Report the decision to external regulators
- Verify whether non-financial strategic benefits justify the investment (Correct answer)
Correct answer: Verify whether non-financial strategic benefits justify the investment
A negative NPV does not automatically make an investment wrong; strategic, compliance, or competitive benefits may justify it if properly documented.
Question 124: A port scan reveals that TCP port 23 is open on a server. What risk does this MOST likely indicate?
- A misconfigured FTP service is exposing files
- Unencrypted web traffic is being transmitted
- Telnet is running, transmitting credentials in plaintext (Correct answer)
- Remote desktop access is enabled without authentication
Correct answer: Telnet is running, transmitting credentials in plaintext
TCP port 23 is the default port for Telnet, which transmits all data including passwords in cleartext, posing a significant confidentiality risk.
Question 125: An IS auditor reviewing patch management would consider controls MOST effective if:
- Patches are applied manually by individual system administrators without documentation
- Critical patches are applied within a defined SLA following testing in a non-production environment (Correct answer)
- The organization waits 12 months before applying patches to ensure stability
- Patches are applied only after end users report problems
Correct answer: Critical patches are applied within a defined SLA following testing in a non-production environment
Effective patch management requires a defined SLA for critical patches, with testing in a non-production environment prior to production deployment to balance security and stability.
Question 126: The ISACA IS Audit and Assurance Standard requires that IS audit conclusions be based on:
- Management representations alone
- Prior year audit findings
- Sufficient and appropriate audit evidence (Correct answer)
- Industry benchmarking data
Correct answer: Sufficient and appropriate audit evidence
IS audit standards require that conclusions and opinions be supported by sufficient (enough) and appropriate (relevant and reliable) audit evidence.
Question 127: Why is documentation critical in business resilience?
- Provide response and recovery guidelines (Correct answer)
- Increase confusion
- Delay actions
- Reduce planning
Correct answer: Provide response and recovery guidelines
Documentation is critical in business resilience because it provides clear, detailed instructions and guidelines for responding to and recovering from disruptive events. Well-documented plans ensure that all personnel understand their roles, procedures, and necessary actions during a crisis. This clarity reduces confusion, speeds up decision-making, and facilitates a more organized and effective recovery process.
Question 128: Why are audit logs important?
- Ignore security events
- Track access and detect breaches (Correct answer)
- Reduce data integrity
- Slow system performance
Correct answer: Track access and detect breaches
Audit logs are chronological records of system activities, including user logins, file access, system changes, and security events. They are crucial for tracking who accessed what, when, and from where, providing an invaluable forensic trail. By reviewing audit logs, organizations can detect unauthorized access, identify security breaches, investigate incidents, and ensure accountability.
Question 129: How should Information Systems Audit and Control Association Certification professionals handle procedures that have been updated or revised?
- Wait for mandatory enforcement
- Continue using the original method
- Only apply updates to new cases
- Review updates, complete required training, and implement revised procedures (Correct answer)
Correct answer: Review updates, complete required training, and implement revised procedures
Professionals must review changes, complete training, and implement revised procedures.
Question 130: In IT governance and change management, the RACI model is used to define which of the following?
- Responsible, Accountable, Consulted, and Informed roles (Correct answer)
- Request, Approval, Change, and Incident tracking
- Risk, Accountability, Control, and Integration responsibilities
- Review, Authorize, Check, and Implement steps
Correct answer: Responsible, Accountable, Consulted, and Informed roles
RACI stands for Responsible, Accountable, Consulted, and Informed — a framework that clearly defines roles and responsibilities for each activity in a process.
Question 131: A vulnerability assessment differs from a penetration test in that a vulnerability assessment:
- Requires explicit written authorization from system owners
- Is performed only by external third-party security firms
- Simulates a full attack chain to achieve a specific objective
- Identifies and reports weaknesses without actively exploiting them (Correct answer)
Correct answer: Identifies and reports weaknesses without actively exploiting them
A vulnerability assessment identifies and classifies security weaknesses, while a penetration test actively exploits them to demonstrate real-world impact.
Question 132: What is the primary purpose of information asset protection?
- Ignore risks
- Increase data sharing
- Safeguard confidentiality, integrity, availability (Correct answer)
- Reduce security
Correct answer: Safeguard confidentiality, integrity, availability
The primary purpose of information asset protection is to safeguard the Confidentiality, Integrity, and Availability (CIA) triad of information. Confidentiality ensures data is accessible only to authorized users, integrity ensures data is accurate and unaltered, and availability ensures data and systems are accessible when needed. Protecting these three aspects is fundamental to maintaining trust, compliance, and business operations.
Question 133: What is the purpose of a data classification scheme?
- Ignore data privacy
- Increase data exposure
- Categorize data by sensitivity (Correct answer)
- Delete unnecessary data
Correct answer: Categorize data by sensitivity
A data classification scheme is a framework used to categorize an organization's data based on its sensitivity, value, and regulatory requirements. By classifying data (e.g., public, internal, confidential, restricted), organizations can apply appropriate security controls, access restrictions, and retention policies. This ensures that sensitive information receives the highest level of protection, aligning security efforts with data importance.
Question 134: An IS auditor reviewing IT governance notes that IT investments are approved project-by-project with no portfolio view. The PRIMARY risk is:
- IT vendors may not be evaluated consistently
- Projects may not follow the system development life cycle
- Individual projects may exceed their budgets
- IT investments may be duplicated or conflict with each other (Correct answer)
Correct answer: IT investments may be duplicated or conflict with each other
Without a portfolio view, investments can overlap, conflict, or miss opportunities for synergy, resulting in suboptimal resource use.
Question 135: Data loss prevention (DLP) tools are PRIMARILY designed to:
- Back up critical data to an off-site location automatically
- Block ransomware from encrypting corporate files
- Monitor user behavior for insider threat indicators
- Detect and prevent unauthorized transmission of sensitive data (Correct answer)
Correct answer: Detect and prevent unauthorized transmission of sensitive data
DLP tools inspect data in motion, at rest, and in use to prevent sensitive information from leaving the organization without authorization.
Question 136: In Information Systems Audit and Control Association Certification practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Wait for a supervisor to notice the issue
- Continue working and report at end of shift
- Document it for the next safety audit
- Immediately secure the area and report the hazard (Correct answer)
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels.
Question 137: What distinguishes a Information Systems Audit and Control Association Certification certified professional from a non-certified practitioner?
- Certified professionals only work in larger organizations
- There is no meaningful difference
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
- Certified professionals always have more experience
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 138: When auditing application controls, which control type BEST ensures that all data entered into a system has been processed completely?
- Batch totals (Correct answer)
- Hash totals
- Sequence checks
- Edit checks
Correct answer: Batch totals
Batch totals compare the sum of input records to a predetermined control total, ensuring all records in the batch were fully processed.
Question 139: An IS auditor is reviewing a Software Development Life Cycle (SDLC). At which phase should security requirements FIRST be formally incorporated?
- Testing phase
- Requirements/design phase (Correct answer)
- Post-implementation review
- Implementation phase
Correct answer: Requirements/design phase
Security requirements should be identified and documented during the requirements and design phase—'security by design'—to avoid costly remediation later.
Question 140: What is the purpose of a business impact analysis (BIA)?
- Identify critical functions and impact (Correct answer)
- Manage employees
- Monitor network traffic
- Develop software
Correct answer: Identify critical functions and impact
A Business Impact Analysis (BIA) is a systematic process used to identify and evaluate the potential effects of an interruption to critical business operations. It helps determine the most vital functions, their interdependencies, and the financial and operational consequences of their unavailability. The BIA provides essential data for developing effective business continuity and disaster recovery strategies.
Question 141: Which plan focuses on recovering IT systems after a disaster?
- Incident response plan
- Business continuity plan
- Disaster recovery plan (Correct answer)
- Security policy
Correct answer: Disaster recovery plan
A disaster recovery plan (DRP) specifically outlines the procedures and resources required to restore an organization's IT systems, applications, and data after a catastrophic event or disaster. While a business continuity plan (BCP) focuses on maintaining critical business functions, the DRP is a subset that details the technical steps for IT infrastructure recovery. Its primary aim is to minimize IT-related downtime and data loss.
Question 142: An IS auditor uses Computer-Assisted Audit Techniques (CAATs) to analyze an entire population of transactions. This approach is PRIMARILY beneficial because it:
- Eliminates the need for audit documentation
- Reduces the time spent on audit planning
- Replaces the need for auditor judgment
- Allows 100% coverage of transactions, reducing sampling risk (Correct answer)
Correct answer: Allows 100% coverage of transactions, reducing sampling risk
CAATs enable auditors to analyze complete data populations rather than samples, eliminating sampling risk and increasing audit coverage.
Question 143: Which process ensures IT investments deliver expected benefits?
- Change management
- Incident management
- Value management (Correct answer)
- Risk assessment
Correct answer: Value management
Value management is the process within IT governance that focuses on ensuring that IT investments and services deliver the expected benefits and return on investment to the organization. It involves defining, monitoring, and optimizing the value derived from IT initiatives throughout their lifecycle. This process helps organizations justify IT spending and demonstrate its contribution to business objectives.
Question 144: An effective patch management process should ENSURE which of the following practices?
- Patches are applied without management approval to minimize delay
- Patches are tested in a non-production environment before deployment (Correct answer)
- Only security patches are required; performance patches are optional
- All patches are applied immediately upon vendor release
Correct answer: Patches are tested in a non-production environment before deployment
Testing patches in a non-production environment before deployment ensures that untested updates do not disrupt or destabilize production systems.
Question 145: Which standard guides IS audit practices?
- HIPAA
- SOX
- ISO 9001
- ISACA GAAS (Correct answer)
Correct answer: ISACA GAAS
ISACA's Generally Accepted Auditing Standards (GAAS) provide a framework of principles and practices that guide information systems auditors in conducting their work. Adhering to these standards ensures consistency, quality, and credibility in IS audit engagements, promoting professional excellence.
Question 146: An IS auditor finds that system administrators have the ability to modify audit logs. This PRIMARILY represents a failure of:
- Physical access controls to the data center
- Segregation of duties and audit trail integrity controls (Correct answer)
- Network segmentation policies
- Password complexity requirements
Correct answer: Segregation of duties and audit trail integrity controls
Allowing those being monitored to modify the records of their activity undermines the integrity of the audit trail and violates segregation of duties.
Question 147: Which of the following BEST describes 'audit risk'?
- The risk that a control will fail to prevent an error
- The risk that the auditor expresses an incorrect opinion due to undetected material errors (Correct answer)
- The risk that audit costs will exceed the approved budget
- The risk that management will override audit findings
Correct answer: The risk that the auditor expresses an incorrect opinion due to undetected material errors
Audit risk is the risk that the auditor reaches an incorrect conclusion (e.g., issues a clean opinion when material errors exist) due to failures in detection.
Question 148: What is the role of an incident response team?
- Audit financials
- Ignore incidents
- Develop software
- Manage and mitigate incidents (Correct answer)
Correct answer: Manage and mitigate incidents
An incident response team (IRT) is responsible for detecting, analyzing, containing, eradicating, and recovering from security incidents or other disruptive events. Their primary role is to minimize the impact of incidents, restore normal operations quickly, and prevent recurrence. By having a dedicated team, organizations can respond systematically and effectively to protect their assets and maintain business continuity.
Question 149: In software development, what is the MAIN objective of unit testing?
- Confirming user acceptance of the overall system
- Validating individual code modules or functions in isolation (Correct answer)
- Testing complete end-to-end business workflows
- Verifying integration between system components
Correct answer: Validating individual code modules or functions in isolation
Unit testing validates that individual code modules or functions work correctly in isolation before being integrated with other components.
Question 150: An IS auditor is reviewing access controls and finds that 15% of sampled user accounts belong to terminated employees. This finding BEST represents a weakness in:
- User access provisioning controls
- Change management controls
- Segregation of duties controls
- User access termination controls (Correct answer)
Correct answer: User access termination controls
Active accounts for terminated employees indicate a failure in the offboarding/access revocation process, which is a user access termination control.
Question 151: An IS auditor discovers evidence of fraud during a routine audit. What should the auditor do FIRST?
- Destroy the evidence to protect the organization
- Complete the original audit scope before addressing the fraud
- Confront the suspected employee directly
- Immediately expand audit scope and notify appropriate management or legal counsel (Correct answer)
Correct answer: Immediately expand audit scope and notify appropriate management or legal counsel
Upon discovering potential fraud, the auditor should expand scope as needed and notify appropriate levels of management or legal counsel per established protocols.
Question 152: During a penetration test, the tester has full knowledge of the system architecture and source code. This approach is called:
- Gray-box testing
- White-box testing (Correct answer)
- Black-box testing
- Red team testing
Correct answer: White-box testing
White-box (or crystal-box) testing gives the tester complete knowledge of the internal system, enabling thorough coverage of the codebase.
ISACA Certification Exams (e.g., CISA, CISM, CRISC, CGEIT)
ISACA offers several certifications (CISA, CISM, CRISC, CGEIT) that validate expertise in information systems audit, security, risk, and governance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds