โ† All ISACA Flashcard Decks

Information System Auditing Process Flashcards

7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information System Auditing Process flashcards as text
  1. An IS auditor is assessing the adequacy of password policies. Which finding represents the HIGHEST risk?

    Answer: Passwords do not expire for service accounts

    Non-expiring passwords on service accounts pose significant risk because a compromised credential may go undetected indefinitely with no forced rotation.

  2. The ISACA IS Audit and Assurance Standard requires that IS audit conclusions be based on:

    Answer: Sufficient and appropriate audit evidence

    IS audit standards require that conclusions and opinions be supported by sufficient (enough) and appropriate (relevant and reliable) audit evidence.

  3. When assessing data integrity controls in a financial application, an IS auditor would MOST likely use which technique?

    Answer: Test data containing valid and invalid records to verify system edits

    Submitting test data with known valid and invalid values verifies that the application correctly accepts, rejects, and processes records per its edit and validation rules.

  4. Which of the following BEST describes 'audit risk'?

    Answer: The risk that the auditor expresses an incorrect opinion due to undetected material errors

    Audit risk is the risk that the auditor reaches an incorrect conclusion (e.g., issues a clean opinion when material errors exist) due to failures in detection.

  5. An IS auditor finds that developers have access to the production environment. This PRIMARILY violates the principle of:

    Answer: Segregation of duties

    Allowing developers access to production violates segregation of duties because the same person who creates code should not be able to deploy or modify it in production.

  6. During an audit, the MOST reliable type of evidence an IS auditor can obtain is:

    Answer: Documentary evidence obtained directly from independent third parties

    Evidence obtained directly from independent third parties (external confirmations, externally generated documents) is the most reliable because it is not subject to manipulation by the auditee.

  7. An IS auditor reviewing patch management would consider controls MOST effective if:

    Answer: Critical patches are applied within a defined SLA following testing in a non-production environment

    Effective patch management requires a defined SLA for critical patches, with testing in a non-production environment prior to production deployment to balance security and stability.