Information System Auditing Process Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information System Auditing Process flashcards as text
An IS auditor is assessing the adequacy of password policies. Which finding represents the HIGHEST risk?
Answer: Passwords do not expire for service accounts
Non-expiring passwords on service accounts pose significant risk because a compromised credential may go undetected indefinitely with no forced rotation.
The ISACA IS Audit and Assurance Standard requires that IS audit conclusions be based on:
Answer: Sufficient and appropriate audit evidence
IS audit standards require that conclusions and opinions be supported by sufficient (enough) and appropriate (relevant and reliable) audit evidence.
When assessing data integrity controls in a financial application, an IS auditor would MOST likely use which technique?
Answer: Test data containing valid and invalid records to verify system edits
Submitting test data with known valid and invalid values verifies that the application correctly accepts, rejects, and processes records per its edit and validation rules.
Which of the following BEST describes 'audit risk'?
Answer: The risk that the auditor expresses an incorrect opinion due to undetected material errors
Audit risk is the risk that the auditor reaches an incorrect conclusion (e.g., issues a clean opinion when material errors exist) due to failures in detection.
An IS auditor finds that developers have access to the production environment. This PRIMARILY violates the principle of:
Answer: Segregation of duties
Allowing developers access to production violates segregation of duties because the same person who creates code should not be able to deploy or modify it in production.
During an audit, the MOST reliable type of evidence an IS auditor can obtain is:
Answer: Documentary evidence obtained directly from independent third parties
Evidence obtained directly from independent third parties (external confirmations, externally generated documents) is the most reliable because it is not subject to manipulation by the auditee.
An IS auditor reviewing patch management would consider controls MOST effective if:
Answer: Critical patches are applied within a defined SLA following testing in a non-production environment
Effective patch management requires a defined SLA for critical patches, with testing in a non-production environment prior to production deployment to balance security and stability.