← All ISACA Flashcard Decks

Mixed Deck — All ISACA Topics Flashcards

100 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All ISACA Topics flashcards as text
  1. An IS auditor reviewing IT governance notes that IT investments are approved project-by-project with no portfolio view. The PRIMARY risk is:

    Answer: IT investments may be duplicated or conflict with each other

    Without a portfolio view, investments can overlap, conflict, or miss opportunities for synergy, resulting in suboptimal resource use.

  2. What is a key component of IT management?

    Answer: Manage resources to deliver value

    A key component of IT management is effectively managing IT resources—including people, technology, and budget—to deliver tangible value to the organization. This involves optimizing operations, ensuring reliable service delivery, and supporting business processes to achieve strategic objectives efficiently and effectively.

  3. An organization is evaluating its change management process. Which finding indicates an ineffective process?

    Answer: Emergency changes are frequently implemented without post-implementation review

    Emergency changes that consistently bypass post-implementation review create unreviewed risk and suggest the emergency process is being misused to avoid normal controls.

  4. Which of the following BEST describes the purpose of security awareness training?

    Answer: To reduce human error and improve recognition of social engineering attacks

    Security awareness training aims to reduce risk by educating users to recognize threats like phishing and practice safe security behaviors.

  5. Which of the following is an example of a compensating control when segregation of duties cannot be fully implemented?

    Answer: Implementing enhanced logging and supervisory review of transactions

    Enhanced logging and supervisory review acts as a compensating control by increasing the likelihood that unauthorized activity will be detected.

  6. When evaluating an organization's IT operations, an IS auditor should verify that operator procedures are:

    Answer: Documented, approved, and reviewed periodically

    Documented, approved, and periodically reviewed procedures ensure consistency, accountability, and alignment with current operational and security requirements.

  7. Which metric BEST measures the effectiveness of IT governance in delivering business value?

    Answer: Percentage of IT investments achieving expected business outcomes

    Governance effectiveness is best measured by whether IT investments actually realize the business outcomes they were intended to deliver.

  8. Which approach is MOST important for ISACA professionals when applying technical procedures?

    Answer: Adhering to established protocols while adapting to specific conditions

    Technical procedures require adherence to protocols with professional judgment for adaptation.

  9. Which testing methodology evaluates system functionality based on inputs and outputs without knowledge of internal code structure?

    Answer: Black-box testing

    Black-box testing evaluates system behavior from an external perspective using inputs and outputs, without any knowledge of internal logic or code.

  10. How should Information Systems Audit and Control Association Certification professionals handle procedures that have been updated or revised?

    Answer: Review updates, complete required training, and implement revised procedures

    Professionals must review changes, complete training, and implement revised procedures.

  11. Which of the following BEST describes the role of a reciprocal agreement in business continuity?

    Answer: Two organizations agree to provide each other computing resources in the event of a disaster

    A reciprocal agreement is a mutual arrangement between two organizations to host each other's operations during a disaster, though resource conflicts are a known risk.

  12. What is the PRIMARY purpose of a business impact analysis (BIA)?

    Answer: Identify critical business functions and their recovery priorities

    A BIA identifies critical business processes, their dependencies, and the impact of disruption to establish recovery priorities and objectives.

  13. When assessing IT governance maturity using COBIT's capability model, a score of Level 2 indicates:

    Answer: The process is performed and managed with planned objectives

    COBIT's Level 2 (Managed Process) means the process is performed and managed — planned, monitored, and adjusted — with defined outcomes.

  14. The concept of 'materiality' in IS auditing PRIMARILY helps auditors to:

    Answer: Determine which findings are significant enough to report

    Materiality guides auditors in assessing whether a finding is significant enough to warrant reporting and affect the overall audit opinion.

  15. Which documentation practice BEST demonstrates regulatory compliance for ISACA certified professionals?

    Answer: Maintaining organized, dated, and signed records of all activities

    Organized, dated, and signed records demonstrate systematic regulatory compliance.

  16. What is the PRIMARY purpose of a post-implementation review (PIR)?

    Answer: To evaluate whether the system meets its original objectives

    A post-implementation review assesses whether the implemented system meets the defined business objectives and performance criteria established before development.

  17. A vulnerability assessment differs from a penetration test in that a vulnerability assessment:

    Answer: Identifies and reports weaknesses without actively exploiting them

    A vulnerability assessment identifies and classifies security weaknesses, while a penetration test actively exploits them to demonstrate real-world impact.

  18. An IS auditor is reviewing capacity management practices. Which finding represents the GREATEST risk?

    Answer: No formal process exists to forecast resource utilization trends

    Without trend forecasting, the organization cannot proactively address capacity constraints, increasing the risk of performance degradation or outages.

  19. A data owner is PRIMARILY responsible for which of the following?

    Answer: Classifying data and defining access rules

    The data owner is accountable for classifying information and establishing appropriate access control policies.

  20. What distinguishes a Information Systems Audit and Control Association Certification certified professional from a non-certified practitioner?

    Answer: Certification validates competency through standardized assessment against benchmarks

    Certification provides objective validation of competency through standardized assessment.