Information System Auditing Process Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information System Auditing Process flashcards as text
During an IT general controls audit, which area would an IS auditor focus on to assess whether program changes are authorized and tested before moving to production?
Answer: Change management controls
Change management controls govern the authorization, testing, and migration of program changes from development to production environments.
What does 'audit universe' refer to in internal audit planning?
Answer: All auditable entities or activities within an organization
The audit universe comprises all auditable entities—processes, systems, departments—from which the audit plan is derived based on risk assessment.
An IS auditor uses Computer-Assisted Audit Techniques (CAATs) to analyze an entire population of transactions. This approach is PRIMARILY beneficial because it:
Answer: Allows 100% coverage of transactions, reducing sampling risk
CAATs enable auditors to analyze complete data populations rather than samples, eliminating sampling risk and increasing audit coverage.
Which of the following BEST describes 'inherent risk' in the context of IS auditing?
Answer: The susceptibility of an area to a material misstatement assuming no controls
Inherent risk is the level of risk present in the absence of any mitigating controls—the raw, uncontrolled risk of an area.
When reviewing Business Continuity Planning (BCP), an IS auditor should PRIMARILY assess whether:
Answer: Recovery procedures have been tested and meet recovery time objectives
The most critical BCP control is that recovery procedures are regularly tested and validated against documented Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
An IS auditor reviews system logs and identifies repeated failed login attempts on a privileged account followed by a successful login. This MOST likely indicates:
Answer: A potential brute-force attack resulting in unauthorized access
Repeated failed logins followed by success on a privileged account is a classic indicator of a brute-force or credential-stuffing attack.
Which phase of the IS audit process involves comparing actual results against expected criteria to identify exceptions?
Answer: Fieldwork and evidence gathering
During fieldwork, auditors execute audit procedures—testing, observing, and comparing evidence against defined audit criteria to identify deviations.