ISACA Certification Exams (e.g., CISA, CISM, CRISC, CGEIT) — Questions and Answers
Question 1: In ISACA practice, what happens when regulations are updated?
- Existing professionals are grandfathered in
- Changes apply only to new professionals
- Previous certifications are revoked
- Professionals must update knowledge and practices to meet new requirements (Correct answer)
Correct answer: Professionals must update knowledge and practices to meet new requirements
All professionals must update their knowledge and practices when regulations change.
Question 2: What is the purpose of fieldwork in IS audit?
- Conduct training
- Define audit scope
- Prepare audit report
- Gather and analyze evidence (Correct answer)
Correct answer: Gather and analyze evidence
Fieldwork is the phase where auditors execute the planned audit procedures to collect and analyze evidence. This involves examining documentation, interviewing personnel, and testing controls to determine their effectiveness and identify any control deficiencies or non-compliance within the information systems.
Question 3: An IS auditor reviewing problem management should verify that:
- Problem tickets are assigned to senior staff only
- Root cause analyses are completed and permanent fixes are tracked to closure (Correct answer)
- All incidents are escalated to problem management
- Problem management meetings occur daily
Correct answer: Root cause analyses are completed and permanent fixes are tracked to closure
Effective problem management requires identifying root causes and ensuring permanent fixes are implemented and verified, not just documenting the occurrence.
Question 4: User acceptance testing (UAT) is PRIMARILY performed by which group?
- End users and business stakeholders (Correct answer)
- Quality assurance specialists
- IS auditors
- Development team members
Correct answer: End users and business stakeholders
UAT is performed by end users and business stakeholders to confirm the system meets their operational requirements before go-live approval.
Question 5: What documentation is MOST critical to maintain for safety compliance in the Information Systems Audit and Control Association Certification field?
- Annual revenue reports
- Incident reports, training records, and inspection logs (Correct answer)
- Client marketing preferences
- Employee vacation schedules
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation for demonstrating compliance.
Question 6: When conducting a risk assessment for ISACA operations, which factor should receive the HIGHEST priority?
- Convenience for daily operations
- Cost of implementing safety measures
- Time required for safety training
- Probability and severity of potential harm (Correct answer)
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment.
Question 7: What distinguishes a Information Systems Audit and Control Association Certification certified professional from a non-certified practitioner?
- Certified professionals always have more experience
- There is no meaningful difference
- Certified professionals only work in larger organizations
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 8: When a ISACA professional encounters an unexpected result during a procedure, the FIRST action should be to:
- Report without preliminary assessment
- Continue and address it later
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Repeat the procedure immediately
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess unexpected results is critical for safety and quality.
Question 9: Which statement BEST describes the relationship between Information Systems Audit and Control Association Certification certification and industry evolution?
- Changes only occur when government mandates them
- Requirements become less stringent over time
- Requirements evolve periodically to reflect advances in knowledge and practice (Correct answer)
- Certification requirements never change
Correct answer: Requirements evolve periodically to reflect advances in knowledge and practice
Certification requirements evolve to keep pace with professional and technological advances.
Question 10: Which of the following BEST illustrates the separation between governance and management of IT as defined in COBIT 2019?
- The IT steering committee selects vendors; finance approves payments
- The CIO sets IT policy; the board monitors IT performance metrics
- The board approves IT strategy; the CIO allocates IT resources to execute it (Correct answer)
- IT auditors assess controls; IT managers report results to regulators
Correct answer: The board approves IT strategy; the CIO allocates IT resources to execute it
COBIT 2019 defines governance as setting direction (board approves strategy) and management as executing within that direction (CIO allocates resources).
Question 11: During a system development project, which SDLC phase is primarily concerned with identifying and documenting business requirements?
- System design
- Requirements analysis (Correct answer)
- Implementation
- System testing
Correct answer: Requirements analysis
Requirements analysis is the phase where business and functional requirements are gathered and documented to ensure the system meets user needs.
Question 12: Which practice BEST demonstrates that an organization's IT governance framework supports ethical use of technology?
- Establishing and enforcing an acceptable use policy with consequences (Correct answer)
- Conducting annual IT audits with external auditors
- Publishing an annual IT spending report
- Deploying data loss prevention tools across all endpoints
Correct answer: Establishing and enforcing an acceptable use policy with consequences
An acceptable use policy with enforced consequences establishes clear ethical boundaries and holds users accountable for technology use.
Question 13: A port scan reveals that TCP port 23 is open on a server. What risk does this MOST likely indicate?
- Telnet is running, transmitting credentials in plaintext (Correct answer)
- Remote desktop access is enabled without authentication
- A misconfigured FTP service is exposing files
- Unencrypted web traffic is being transmitted
Correct answer: Telnet is running, transmitting credentials in plaintext
TCP port 23 is the default port for Telnet, which transmits all data including passwords in cleartext, posing a significant confidentiality risk.
Question 14: A company's board has delegated IT governance oversight to a subcommittee. An IS auditor should verify PRIMARILY that the subcommittee:
- Reports its findings and decisions to the full board (Correct answer)
- Approves all IT project budgets individually
- Has technical IT expertise among its members
- Meets at least monthly to review IT performance
Correct answer: Reports its findings and decisions to the full board
Delegating oversight does not transfer accountability; the subcommittee must report to the full board so ultimate accountability remains intact.
Question 15: In Information Systems Audit and Control Association Certification practice, what is the CORRECT sequence when performing a technical procedure?
- Execute immediately and document only if issues arise
- Execute, then plan and review
- Document, execute, then plan
- Plan, prepare, execute, verify, and document (Correct answer)
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows: plan, prepare, execute, verify, and document.
Question 16: What is a key component of IT management?
- Manage resources to deliver value (Correct answer)
- Delay projects
- Ignoring risks
- Reduce communication
Correct answer: Manage resources to deliver value
A key component of IT management is effectively managing IT resources—including people, technology, and budget—to deliver tangible value to the organization. This involves optimizing operations, ensuring reliable service delivery, and supporting business processes to achieve strategic objectives efficiently and effectively.
Question 17: A security information and event management (SIEM) system is PRIMARILY used to:
- Scan networks for open vulnerabilities
- Encrypt data stored in databases
- Prevent malware from executing on endpoints
- Aggregate and correlate security events for real-time analysis (Correct answer)
Correct answer: Aggregate and correlate security events for real-time analysis
SIEM systems collect, aggregate, and correlate log and event data from multiple sources to detect and alert on security incidents.
Question 18: Which of the following is a key metric in business resilience?
- Server brand
- Recovery Time Objective (Correct answer)
- Disk storage size
- Number of employees
Correct answer: Recovery Time Objective
Recovery Time Objective (RTO) is a key metric in business resilience that defines the maximum acceptable duration of time that a business process or system can be down after a disaster or disruption. It specifies the target time within which a business function must be restored to avoid unacceptable consequences. RTO is critical for planning and prioritizing recovery efforts.
Question 19: An IS auditor discovers that IT governance policies were last updated five years ago. What should the auditor PRIMARILY recommend?
- Require management to sign off on existing policies as-is
- Replace all policies with industry-standard templates
- Establish a periodic policy review cycle aligned with business change (Correct answer)
- Immediately suspend all IT operations until policies are updated
Correct answer: Establish a periodic policy review cycle aligned with business change
Governance policies must be reviewed and updated periodically to remain aligned with evolving business strategy, technology, and regulatory requirements.
Question 20: What is the PRIMARY purpose of an audit charter?
- To authorize the internal audit function and establish its responsibilities (Correct answer)
- To communicate audit findings to senior management
- To assign specific tasks to individual auditors
- To define the detailed audit procedures for each engagement
Correct answer: To authorize the internal audit function and establish its responsibilities
The audit charter formally establishes the internal audit function's purpose, authority, and responsibility within the organization.
Question 21: Which control is MOST important to verify when auditing a change management process?
- All changes are tested directly in production
- Change logs are maintained only for major changes
- Emergency changes bypass authorization controls
- Changes are approved by appropriate authority before implementation (Correct answer)
Correct answer: Changes are approved by appropriate authority before implementation
Authorization by appropriate authority ensures changes are reviewed and approved before implementation, preventing unauthorized modifications.
Question 22: An IS auditor uses Computer-Assisted Audit Techniques (CAATs) to analyze an entire population of transactions. This approach is PRIMARILY beneficial because it:
- Reduces the time spent on audit planning
- Eliminates the need for audit documentation
- Replaces the need for auditor judgment
- Allows 100% coverage of transactions, reducing sampling risk (Correct answer)
Correct answer: Allows 100% coverage of transactions, reducing sampling risk
CAATs enable auditors to analyze complete data populations rather than samples, eliminating sampling risk and increasing audit coverage.
Question 23: Which process identifies vulnerabilities in information assets?
- Risk assessment (Correct answer)
- User training
- Incident response
- Backup process
Correct answer: Risk assessment
A risk assessment is a systematic process that identifies potential threats and vulnerabilities to an organization's information assets. It involves analyzing the likelihood of these threats exploiting vulnerabilities and the potential impact of such events. This process helps organizations understand their risk posture and prioritize security controls to mitigate the most significant risks.
Question 24: A multinational company wants to adopt a single IT governance framework across all subsidiaries with different regulatory requirements. The BEST approach is to:
- Mandate one framework globally and ignore local variations
- Adopt whichever framework the largest subsidiary already uses
- Allow each subsidiary to choose its own framework independently
- Select a flexible framework and tailor it to local regulatory contexts (Correct answer)
Correct answer: Select a flexible framework and tailor it to local regulatory contexts
A flexible framework like COBIT can be tailored to accommodate local regulatory and operational differences while maintaining global consistency.
Question 25: In Information Systems Audit and Control Association Certification practice, what is the CORRECT sequence when performing a technical procedure?
- Execute, then plan and review
- Execute immediately and document only if issues arise
- Plan, prepare, execute, verify, and document (Correct answer)
- Document, execute, then plan
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows: plan, prepare, execute, verify, and document.
Question 26: What is the primary goal of IT governance?
- Ignore business needs
- Delay IT projects
- Increase IT spending
- Align IT with organizational goals (Correct answer)
Correct answer: Align IT with organizational goals
The primary goal of IT governance is to ensure that an organization's IT strategy and operations are aligned with its overall business objectives. This alignment helps maximize the value derived from IT investments, optimize resource utilization, and manage IT-related risks effectively to support strategic goals.
Question 27: What is the purpose of a data classification scheme?
- Categorize data by sensitivity (Correct answer)
- Ignore data privacy
- Increase data exposure
- Delete unnecessary data
Correct answer: Categorize data by sensitivity
A data classification scheme is a framework used to categorize an organization's data based on its sensitivity, value, and regulatory requirements. By classifying data (e.g., public, internal, confidential, restricted), organizations can apply appropriate security controls, access restrictions, and retention policies. This ensures that sensitive information receives the highest level of protection, aligning security efforts with data importance.
Question 28: When assessing IT governance maturity using COBIT's capability model, a score of Level 2 indicates:
- The process is established and conforms to standards
- The process is performed and managed with planned objectives (Correct answer)
- The process is undefined and undocumented
- The process is optimized and continuously improved
Correct answer: The process is performed and managed with planned objectives
COBIT's Level 2 (Managed Process) means the process is performed and managed — planned, monitored, and adjusted — with defined outcomes.
Question 29: What is the main goal of business resilience?
- Ensure operations continuity (Correct answer)
- Reduce security
- Increase downtime
- Ignore risks
Correct answer: Ensure operations continuity
The main goal of business resilience is to ensure that an organization can withstand and recover from disruptions, maintaining its critical operations and services. It encompasses the ability to adapt to changes, absorb shocks, and rapidly restore functionality after an incident. This focus on continuity minimizes downtime and protects the organization's reputation and financial stability.
Question 30: Which standard guides IS audit practices?
- HIPAA
- ISO 9001
- SOX
- ISACA GAAS (Correct answer)
Correct answer: ISACA GAAS
ISACA's Generally Accepted Auditing Standards (GAAS) provide a framework of principles and practices that guide information systems auditors in conducting their work. Adhering to these standards ensures consistency, quality, and credibility in IS audit engagements, promoting professional excellence.
Question 31: Which of the following network segmentation techniques BEST isolates a web-facing server from internal corporate resources?
- Placing the server in a DMZ (demilitarized zone) (Correct answer)
- Using a host-based firewall on the server
- Deploying an intrusion prevention system on the server
- VPN tunneling between segments
Correct answer: Placing the server in a DMZ (demilitarized zone)
A DMZ isolates public-facing servers from internal networks using firewalls, limiting the blast radius of a compromise.
Question 32: Which regulatory requirement is UNIVERSAL across all Information Systems Audit and Control Association Certification practice settings?
- Maintaining current certification and continuing education (Correct answer)
- Using specific proprietary software
- Working exclusively during business hours
- Limiting services to local jurisdictions
Correct answer: Maintaining current certification and continuing education
Maintaining current certification and continuing education is a universal regulatory requirement.
Question 33: An IS auditor finds that developers have access to the production environment. This PRIMARILY violates the principle of:
- Least privilege only
- Non-repudiation
- Defense in depth
- Segregation of duties (Correct answer)
Correct answer: Segregation of duties
Allowing developers access to production violates segregation of duties because the same person who creates code should not be able to deploy or modify it in production.
Question 34: Which encryption mode is most appropriate for encrypting large amounts of data where parallel processing is desired?
- Electronic Codebook (ECB)
- Cipher Block Chaining (CBC)
- Output Feedback (OFB)
- Counter (CTR) (Correct answer)
Correct answer: Counter (CTR)
Counter (CTR) mode allows parallel encryption and decryption of blocks, making it ideal for large data sets.
Question 35: An organization is evaluating its change management process. Which finding indicates an ineffective process?
- All changes require impact assessments
- Emergency changes are frequently implemented without post-implementation review (Correct answer)
- Change advisory board meetings are held weekly
- Standard changes follow a pre-approved template
Correct answer: Emergency changes are frequently implemented without post-implementation review
Emergency changes that consistently bypass post-implementation review create unreviewed risk and suggest the emergency process is being misused to avoid normal controls.
Question 36: An IS auditor beginning a review of a system acquisition should FIRST examine which document?
- Post-implementation review reports
- User acceptance test results
- The business case and requirements specification (Correct answer)
- System training documentation
Correct answer: The business case and requirements specification
The business case and requirements specification establish the baseline against which all subsequent activities and outcomes are measured.
Question 37: Which of the following is the MOST important characteristic of audit evidence?
- It must always be obtained through computer-assisted tools
- It must be sufficient and appropriate to support audit conclusions (Correct answer)
- It must be approved by the auditee before use
- It must be obtained within the first week of fieldwork
Correct answer: It must be sufficient and appropriate to support audit conclusions
Audit standards universally require evidence to be sufficient (adequate quantity) and appropriate (relevant quality and reliability) to support the auditor's conclusions.
Question 38: How should Information Systems Audit and Control Association Certification professionals handle procedures that have been updated or revised?
- Continue using the original method
- Wait for mandatory enforcement
- Review updates, complete required training, and implement revised procedures (Correct answer)
- Only apply updates to new cases
Correct answer: Review updates, complete required training, and implement revised procedures
Professionals must review changes, complete training, and implement revised procedures.
Question 39: Which phase of the audit process involves identifying key risks and controls?
- Follow-up
- Fieldwork
- Planning (Correct answer)
- Reporting
Correct answer: Planning
The planning phase is crucial in an IS audit as it involves defining the audit scope, objectives, and methodology. During this phase, auditors identify key risks and controls relevant to the systems being audited, which guides the subsequent fieldwork and ensures an efficient and focused audit approach.
Question 40: Which documentation practice BEST demonstrates regulatory compliance for ISACA certified professionals?
- Relying on memory for routine procedures
- Filing documents only when audited
- Keeping informal handwritten notes
- Maintaining organized, dated, and signed records of all activities (Correct answer)
Correct answer: Maintaining organized, dated, and signed records of all activities
Organized, dated, and signed records demonstrate systematic regulatory compliance.
Question 41: Which framework is commonly used for IT governance?
- ITIL
- ISO 27001
- COBIT (Correct answer)
- NIST
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is a widely recognized framework for IT governance and management. It provides a comprehensive set of principles, processes, and practices that help organizations align IT with business goals, manage risks, and optimize resources to deliver value.
Question 42: An organization implements multifactor authentication (MFA). Which combination represents true multifactor authentication?
- A password and a security question
- A username and a password
- A PIN and a smart card (Correct answer)
- A passphrase and a secondary passphrase
Correct answer: A PIN and a smart card
A PIN (something you know) combined with a smart card (something you have) satisfies two distinct authentication factors.
Question 43: During a data center audit, an IS auditor finds that system logs are stored on the same server being monitored. The MAIN risk is:
- An attacker could alter logs to conceal unauthorized activity (Correct answer)
- Log retrieval performance may be degraded
- Compliance reports may take longer to generate
- Log storage consumes excessive disk space
Correct answer: An attacker could alter logs to conceal unauthorized activity
Storing logs on the monitored system allows an attacker who compromises that system to modify or delete audit trails, eliminating evidence of their actions.
Question 44: What role does calibration play in maintaining technical accuracy for Information Systems Audit and Control Association Certification professionals?
- It only matters during inspections
- It ensures instruments produce accurate, consistent results over time (Correct answer)
- It is only necessary for new equipment
- It is optional for advanced professionals
Correct answer: It ensures instruments produce accurate, consistent results over time
Regular calibration ensures instruments continue producing accurate results over time.
Question 45: Which element of IT governance directly addresses the question: 'Who is entitled to make which IT decisions?'
- IT resource management
- IT performance management
- IT governance decision rights (Correct answer)
- IT risk management
Correct answer: IT governance decision rights
Decision rights define who has authority to make specific IT decisions, which is a foundational element of IT governance structure.
Question 46: Which metric is MOST useful for evaluating the effectiveness of an incident response program?
- Number of security policies documented
- Annual security training completion rate
- Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents (Correct answer)
- Total number of security tools deployed
Correct answer: Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents
MTTD and MTTR directly measure how quickly threats are identified and contained, reflecting the operational performance of the incident response process.
Question 47: Which of the following BEST describes a man-in-the-middle (MITM) attack?
- An attacker injects malicious code into a web application database
- An attacker secretly intercepts and potentially alters communications between two parties (Correct answer)
- An attacker floods a target system with traffic to deny service
- An attacker exploits a buffer overflow to gain elevated privileges
Correct answer: An attacker secretly intercepts and potentially alters communications between two parties
In a MITM attack, the attacker secretly positions themselves between two communicating parties to intercept, read, or modify data.
Question 48: How do backups protect information assets?
- Ignore recovery plans
- Delete original data
- Restore data after loss (Correct answer)
- Reduce storage space
Correct answer: Restore data after loss
Backups are copies of data that are stored separately from the original data. Their primary purpose in protecting information assets is to enable the restoration of data in the event of loss, corruption, or destruction due to hardware failure, cyberattacks, human error, or natural disasters. Regular and verified backups are fundamental to data recovery and business continuity.
Question 49: An IS auditor is reviewing IT governance at a company where the IT strategy committee meets quarterly but business unit heads rarely attend. What is the PRIMARY risk?
- IT costs may increase without oversight
- IT projects may be delivered late
- Security incidents may go unreported
- IT decisions may not align with business objectives (Correct answer)
Correct answer: IT decisions may not align with business objectives
Without business unit participation, IT decisions risk misalignment with actual business needs and strategy.
Question 50: What is a physical control in information security?
- Encryption
- Locks and guards (Correct answer)
- Firewall
- Password policy
Correct answer: Locks and guards
Physical controls in information security are tangible measures designed to protect physical assets, including hardware, facilities, and the data stored within them, from unauthorized access, damage, or theft. Locks on doors, security guards, surveillance cameras, and alarm systems are examples of physical controls. They create a secure environment, complementing logical and administrative controls.
Question 51: During a review of IS operations, an IS auditor should verify that service level agreements (SLAs) with IT vendors:
- Focus solely on cost benchmarks
- Are negotiated exclusively by the IT department without legal review
- Include measurable performance targets, reporting requirements, and remedies for non-compliance (Correct answer)
- Are reviewed only when a performance issue occurs
Correct answer: Include measurable performance targets, reporting requirements, and remedies for non-compliance
Effective SLAs must define measurable targets and consequences for non-compliance to be enforceable and to provide a basis for vendor performance evaluation.
Question 52: Which process ensures IT investments deliver expected benefits?
- Incident management
- Change management
- Risk assessment
- Value management (Correct answer)
Correct answer: Value management
Value management is the process within IT governance that focuses on ensuring that IT investments and services deliver the expected benefits and return on investment to the organization. It involves defining, monitoring, and optimizing the value derived from IT initiatives throughout their lifecycle. This process helps organizations justify IT spending and demonstrate its contribution to business objectives.
Question 53: An organization uses a Responsibility Assignment Matrix (RACI) for IT governance decisions. The 'A' in RACI stands for:
- Acknowledged
- Authorized
- Accountable (Correct answer)
- Advised
Correct answer: Accountable
In a RACI matrix, 'A' stands for Accountable — the one person ultimately answerable for the correct completion of a task.
Question 54: The concept of 'materiality' in IS auditing PRIMARILY helps auditors to:
- Calculate the total cost of identified control failures
- Establish the timeline for audit fieldwork
- Select the appropriate auditing software tool
- Determine which findings are significant enough to report (Correct answer)
Correct answer: Determine which findings are significant enough to report
Materiality guides auditors in assessing whether a finding is significant enough to warrant reporting and affect the overall audit opinion.
Question 55: An IS auditor discovers that developers have direct access to the production environment. What is the PRIMARY risk?
- Increased software licensing costs
- Unauthorized or untested changes may be introduced into production (Correct answer)
- Application performance may degrade due to developer testing
- Developers may be exposed to sensitive business data
Correct answer: Unauthorized or untested changes may be introduced into production
Developer access to production violates segregation of duties and could allow unauthorized, untested changes that impact integrity and availability.
Question 56: Which documentation practice BEST demonstrates regulatory compliance for ISACA certified professionals?
- Filing documents only when audited
- Maintaining organized, dated, and signed records of all activities (Correct answer)
- Relying on memory for routine procedures
- Keeping informal handwritten notes
Correct answer: Maintaining organized, dated, and signed records of all activities
Organized, dated, and signed records demonstrate systematic regulatory compliance.
Question 57: In Information Systems Audit and Control Association Certification practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Wait for a supervisor to notice the issue
- Document it for the next safety audit
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels.
Question 58: Which environmental control is MOST critical for preventing hardware damage in a data center?
- Using anti-static mats at all workstations
- Maintaining temperature and humidity within manufacturer-specified ranges (Correct answer)
- Painting server racks a light color to reflect heat
- Installing motion-sensor lighting to reduce energy costs
Correct answer: Maintaining temperature and humidity within manufacturer-specified ranges
Excessive heat or humidity directly causes hardware failures; maintaining conditions within manufacturer specifications is the primary environmental control.
Question 59: Which foundational principle is MOST important for success in Information Systems Audit and Control Association Certification?
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining minimum certification requirements
- Specializing in only one narrow area
- Maximizing financial returns
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 60: Data loss prevention (DLP) tools are PRIMARILY designed to:
- Monitor user behavior for insider threat indicators
- Back up critical data to an off-site location automatically
- Detect and prevent unauthorized transmission of sensitive data (Correct answer)
- Block ransomware from encrypting corporate files
Correct answer: Detect and prevent unauthorized transmission of sensitive data
DLP tools inspect data in motion, at rest, and in use to prevent sensitive information from leaving the organization without authorization.
Question 61: A change advisory board (CAB) is PRIMARILY responsible for which activity?
- Reviewing and authorizing change requests prior to implementation (Correct answer)
- Testing all system changes after they have been implemented
- Training users on new system features and updates
- Writing and coding the changes requested by the business
Correct answer: Reviewing and authorizing change requests prior to implementation
The CAB reviews change requests and authorizes implementation, ensuring each change is evaluated for risk, business impact, and necessity before proceeding.
Question 62: In software development, what is the MAIN objective of unit testing?
- Validating individual code modules or functions in isolation (Correct answer)
- Confirming user acceptance of the overall system
- Testing complete end-to-end business workflows
- Verifying integration between system components
Correct answer: Validating individual code modules or functions in isolation
Unit testing validates that individual code modules or functions work correctly in isolation before being integrated with other components.
Question 63: Which sampling method gives every item in a population an equal chance of selection, making it the most statistically representative?
- Cluster sampling
- Judgmental sampling
- Stratified sampling
- Random sampling (Correct answer)
Correct answer: Random sampling
Random (statistical) sampling ensures each item has an equal probability of selection, supporting statistically valid conclusions.
Question 64: An IS auditor discovers evidence of fraud during a routine audit. What should the auditor do FIRST?
- Immediately expand audit scope and notify appropriate management or legal counsel (Correct answer)
- Destroy the evidence to protect the organization
- Confront the suspected employee directly
- Complete the original audit scope before addressing the fraud
Correct answer: Immediately expand audit scope and notify appropriate management or legal counsel
Upon discovering potential fraud, the auditor should expand scope as needed and notify appropriate levels of management or legal counsel per established protocols.
Question 65: What is the role of the IT steering committee?
- Provide oversight and direction (Correct answer)
- Manage daily IT tasks
- Develop software
- Handle user support
Correct answer: Provide oversight and direction
The IT steering committee plays a crucial role in IT governance by providing strategic oversight and direction for an organization's IT initiatives. It ensures that IT projects and investments are aligned with business objectives, monitors performance, and makes key decisions regarding IT strategy and resource allocation.
Question 66: What is the MOST effective way for new ISACA professionals to build competency?
- Learning through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Focusing solely on advanced topics
- Studying certification materials exclusively
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building competency requires formal education, mentored practice, and ongoing development.
Question 67: What is the relationship between IT governance and enterprise governance?
- Enterprise governance controls IT only
- IT governance supports enterprise governance (Correct answer)
- They are unrelated
- They compete for resources
Correct answer: IT governance supports enterprise governance
IT governance is an integral component of enterprise governance, focusing specifically on the effective and ethical management of an organization's IT resources and capabilities. Its role is to ensure that IT investments deliver value, manage IT-related risks, and align IT strategy with overall business strategy. Therefore, IT governance acts as a framework that enables and supports the broader objectives of enterprise governance.
Question 68: Which of the following BEST describes the purpose of a follow-up audit?
- To verify that management has implemented agreed-upon corrective actions (Correct answer)
- To issue a revised audit report with updated findings
- To identify new risks that emerged since the original audit
- To expand the original audit scope to cover additional areas
Correct answer: To verify that management has implemented agreed-upon corrective actions
A follow-up audit determines whether management has taken timely and effective corrective action to address findings from the original audit.
Question 69: Which personal protective equipment (PPE) principle applies to ALL ISACA certified professionals regardless of their specific role?
- PPE is only necessary during formal inspections
- PPE must be properly fitted, maintained, and replaced as needed (Correct answer)
- PPE is optional if experienced in the field
- Any PPE will provide adequate protection
Correct answer: PPE must be properly fitted, maintained, and replaced as needed
Regardless of experience level, PPE must be properly fitted, regularly maintained, and replaced when worn or damaged.
Question 70: Which approach is MOST important for ISACA professionals when applying technical procedures?
- Following personal shortcuts
- Adhering to established protocols while adapting to specific conditions (Correct answer)
- Applying the same technique without variation
- Using the fastest method regardless of standards
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to protocols with professional judgment for adaptation.
Question 71: In an Agile development methodology, what is the PRIMARY audit concern compared to a traditional waterfall approach?
- Documentation and formal change control may be less rigorous (Correct answer)
- Agile introduces more security vulnerabilities by default
- Agile typically produces lower quality code
- Agile requires significantly more testing phases
Correct answer: Documentation and formal change control may be less rigorous
Agile's iterative and flexible nature may result in less formal documentation and change control, creating audit challenges around completeness and traceability.
Question 72: An IS auditor reviewing a business continuity plan (BCP) finds that the plan has not been tested in three years. The MOST significant risk is:
- The plan may contain outdated procedures that fail during an actual disaster (Correct answer)
- Testing costs have not been budgeted
- Staff may be unfamiliar with the document's formatting
- The BCP vendor contract may have expired
Correct answer: The plan may contain outdated procedures that fail during an actual disaster
Untested plans may reference decommissioned systems, departed personnel, or obsolete procedures, causing failures precisely when recovery is most critical.
Question 73: An IS auditor reviewing an organization's key management practices should verify that cryptographic keys are:
- Generated using approved algorithms and protected throughout their lifecycle (Correct answer)
- Stored in plaintext within the application that uses them
- Kept exclusively by the CEO and CISO for accountability
- Changed only when a security incident is detected
Correct answer: Generated using approved algorithms and protected throughout their lifecycle
Effective key management requires keys to be generated with approved algorithms and protected (encrypted, access-controlled) across their entire lifecycle.
Question 74: Which approach is MOST important for ISACA professionals when applying technical procedures?
- Adhering to established protocols while adapting to specific conditions (Correct answer)
- Applying the same technique without variation
- Following personal shortcuts
- Using the fastest method regardless of standards
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to protocols with professional judgment for adaptation.
Question 75: An organization's IT operations team performs all system administration, change management, and security monitoring. The GREATEST risk from this arrangement is:
- Training costs increase when staff perform multiple roles
- Lack of segregation of duties allows unauthorized changes to go undetected (Correct answer)
- Security monitoring may not be performed during change windows
- Operations staff may become overwhelmed with multiple responsibilities
Correct answer: Lack of segregation of duties allows unauthorized changes to go undetected
When the same team administers systems, approves changes, and monitors security, there is no independent check on their activities, enabling concealment of unauthorized actions.
Question 76: Why are audit logs important?
- Slow system performance
- Ignore security events
- Track access and detect breaches (Correct answer)
- Reduce data integrity
Correct answer: Track access and detect breaches
Audit logs are chronological records of system activities, including user logins, file access, system changes, and security events. They are crucial for tracking who accessed what, when, and from where, providing an invaluable forensic trail. By reviewing audit logs, organizations can detect unauthorized access, identify security breaches, investigate incidents, and ensure accountability.
Question 77: When reviewing Business Continuity Planning (BCP), an IS auditor should PRIMARILY assess whether:
- The IT department wrote the plan without business input
- The BCP document has been printed and distributed to all staff
- All servers have been replaced within the last three years
- Recovery procedures have been tested and meet recovery time objectives (Correct answer)
Correct answer: Recovery procedures have been tested and meet recovery time objectives
The most critical BCP control is that recovery procedures are regularly tested and validated against documented Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Question 78: Which of the following is an example of a compensating control when segregation of duties cannot be fully implemented?
- Outsourcing the conflicting functions to a third party
- Requiring dual signatures on all system configurations
- Disabling all user access until the conflict is resolved
- Implementing enhanced logging and supervisory review of transactions (Correct answer)
Correct answer: Implementing enhanced logging and supervisory review of transactions
Enhanced logging and supervisory review acts as a compensating control by increasing the likelihood that unauthorized activity will be detected.
Question 79: In Information Systems Audit and Control Association Certification, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To evaluate employee performance reviews
- To satisfy insurance requirements only
- To reduce daily workload
- To ensure personnel can respond effectively in emergencies (Correct answer)
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies.
Question 80: Which of the following BEST describes the purpose of security awareness training?
- To certify employees in information security standards
- To reduce human error and improve recognition of social engineering attacks (Correct answer)
- To document employee compliance with security policies
- To replace technical controls with human-based controls
Correct answer: To reduce human error and improve recognition of social engineering attacks
Security awareness training aims to reduce risk by educating users to recognize threats like phishing and practice safe security behaviors.
Question 81: What is the follow-up phase in the audit process?
- Gathering evidence
- Initial planning
- Checking implementation of actions (Correct answer)
- Drafting reports
Correct answer: Checking implementation of actions
The follow-up phase is critical to ensure that management has effectively implemented the corrective actions recommended in the audit report. This phase verifies that identified control weaknesses have been addressed, thereby improving the organization's control environment and reducing risks to information systems.
Question 82: What distinguishes a Information Systems Audit and Control Association Certification certified professional from a non-certified practitioner?
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
- Certified professionals only work in larger organizations
- Certified professionals always have more experience
- There is no meaningful difference
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 83: When assessing third-party vendor security, which document MOST comprehensively defines required security obligations?
- Service Level Agreement (SLA)
- Master Service Agreement (MSA)
- Data Processing Agreement (DPA) with security annexes (Correct answer)
- Non-Disclosure Agreement (NDA)
Correct answer: Data Processing Agreement (DPA) with security annexes
A Data Processing Agreement with security annexes specifies technical and organizational security requirements for vendors handling personal or sensitive data.
Question 84: Which concept in IT governance ensures that the board of directors remains informed about significant IT risks and opportunities?
- IT service continuity management
- Escalation procedures (Correct answer)
- Service level agreements
- IT demand management
Correct answer: Escalation procedures
Escalation procedures ensure significant IT risks, incidents, and opportunities are reported up to senior management and the board.
Question 85: During an audit, what is the importance of sampling?
- Ignore data
- Test all transactions
- Test a representative subset (Correct answer)
- Make assumptions
Correct answer: Test a representative subset
Sampling is important in an IS audit because it allows auditors to draw conclusions about an entire population of data or transactions by examining only a representative subset. This approach is efficient and cost-effective, especially when dealing with large volumes of data, while still providing sufficient assurance about control effectiveness.
Question 86: When conducting a risk assessment for ISACA operations, which factor should receive the HIGHEST priority?
- Cost of implementing safety measures
- Convenience for daily operations
- Probability and severity of potential harm (Correct answer)
- Time required for safety training
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment.
Question 87: Which foundational principle is MOST important for success in Information Systems Audit and Control Association Certification?
- Maximizing financial returns
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining minimum certification requirements
- Specializing in only one narrow area
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 88: During data conversion from a legacy to a new system, which procedure is MOST important for ensuring data integrity?
- Performing parallel processing and reconciling results between systems (Correct answer)
- Converting all data to a single standardized format
- Compressing data to reduce storage requirements
- Deleting duplicate records prior to migration
Correct answer: Performing parallel processing and reconciling results between systems
Parallel processing runs both systems simultaneously and reconciles outputs to verify the new system produces accurate results consistent with the legacy system.
Question 89: ISO/IEC 38500 defines IT governance principles for corporate governance of IT. Which of the following is NOT one of its six principles?
- Strategy
- Optimization (Correct answer)
- Responsibility
- Acquisition
Correct answer: Optimization
ISO/IEC 38500's six principles are Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour — Optimization is not among them.
Question 90: When auditing an outsourced data center, an IS auditor should rely PRIMARILY on:
- Annual financial statements of the vendor
- SSAE 18 SOC 2 Type II reports and contractual audit rights clauses (Correct answer)
- The vendor's marketing materials and certifications list
- Verbal assurances from the vendor's account manager
Correct answer: SSAE 18 SOC 2 Type II reports and contractual audit rights clauses
SOC 2 Type II reports provide an independent, structured assessment of controls over a period of time, and audit rights clauses allow the organization to verify controls directly.
Question 91: Which plan focuses on recovering IT systems after a disaster?
- Security policy
- Disaster recovery plan (Correct answer)
- Incident response plan
- Business continuity plan
Correct answer: Disaster recovery plan
A disaster recovery plan (DRP) specifically outlines the procedures and resources required to restore an organization's IT systems, applications, and data after a catastrophic event or disaster. While a business continuity plan (BCP) focuses on maintaining critical business functions, the DRP is a subset that details the technical steps for IT infrastructure recovery. Its primary aim is to minimize IT-related downtime and data loss.
Question 92: What documentation is MOST critical to maintain for safety compliance in the Information Systems Audit and Control Association Certification field?
- Employee vacation schedules
- Annual revenue reports
- Incident reports, training records, and inspection logs (Correct answer)
- Client marketing preferences
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation for demonstrating compliance.
Question 93: Formal change management for infrastructure changes exists PRIMARILY to achieve which outcome?
- Eliminate the requirement for pre-deployment testing
- Prevent unauthorized changes and minimize the risk of unplanned outages (Correct answer)
- Reduce the total number of people authorized to make changes
- Ensure infrastructure changes are implemented as rapidly as possible
Correct answer: Prevent unauthorized changes and minimize the risk of unplanned outages
Formal change management requires authorization and testing before deployment, preventing unauthorized modifications and reducing the likelihood of outages caused by failed changes.
Question 94: When auditing an organization's network operations center (NOC), an IS auditor should FIRST determine whether:
- All alerts are logged to email
- Monitoring tools provide real-time alerts for threshold breaches (Correct answer)
- The NOC is staffed 24/7
- Network diagrams are printed and posted on the wall
Correct answer: Monitoring tools provide real-time alerts for threshold breaches
Real-time alerting on threshold breaches is the foundational control that enables the NOC to detect and respond to incidents promptly.
Question 95: When a ISACA professional identifies a potential regulatory violation, the CORRECT first step is to:
- Discuss it casually with coworkers
- Document the violation and report through proper channels (Correct answer)
- Address it only if directly affected
- Wait to see if it resolves on its own
Correct answer: Document the violation and report through proper channels
Proper documentation and reporting through established channels ensures accountability.
Question 96: Which factor MOST significantly affects the quality of technical outcomes in ISACA practice?
- The brand of equipment
- The practitioner's training, preparation, and attention to detail (Correct answer)
- The time of day
- Speed of procedure completion
Correct answer: The practitioner's training, preparation, and attention to detail
Quality depends primarily on training, preparation, and attention to detail.
Question 97: Which of the following BEST describes the role of a reciprocal agreement in business continuity?
- Two organizations share a common disaster recovery budget
- An organization contracts with a third-party hot site provider
- Two organizations agree to provide each other computing resources in the event of a disaster (Correct answer)
- An organization maintains a cold site at a secondary location
Correct answer: Two organizations agree to provide each other computing resources in the event of a disaster
A reciprocal agreement is a mutual arrangement between two organizations to host each other's operations during a disaster, though resource conflicts are a known risk.
Question 98: Under ISACA standards, an IS auditor who identifies a significant IT risk outside the original audit scope should:
- Include it in current report findings without consultation
- Communicate it to management and consider whether scope expansion is warranted (Correct answer)
- Ignore it since it is outside the defined scope
- Immediately halt the audit and replan from scratch
Correct answer: Communicate it to management and consider whether scope expansion is warranted
Professional standards require IS auditors to communicate significant risks discovered outside scope to management, and to evaluate whether expanding the scope is appropriate.
Question 99: What is the PRIMARY reason for regulatory compliance in the Information Systems Audit and Control Association Certification profession?
- To justify higher service fees
- To create additional paperwork
- To avoid penalties and fines only
- To protect public safety, ensure quality, and maintain professional integrity (Correct answer)
Correct answer: To protect public safety, ensure quality, and maintain professional integrity
Regulatory compliance protects public safety, ensures quality, and maintains professional integrity.
Question 100: What is the purpose of a business impact analysis (BIA)?
- Monitor network traffic
- Identify critical functions and impact (Correct answer)
- Manage employees
- Develop software
Correct answer: Identify critical functions and impact
A Business Impact Analysis (BIA) is a systematic process used to identify and evaluate the potential effects of an interruption to critical business operations. It helps determine the most vital functions, their interdependencies, and the financial and operational consequences of their unavailability. The BIA provides essential data for developing effective business continuity and disaster recovery strategies.
Question 101: An IS auditor finds that emergency changes are implemented without any post-implementation review. This finding represents:
- A standard procedure consistent with ITIL emergency change guidance
- A best practice for expediting high-priority changes
- A control weakness that requires remediation (Correct answer)
- An acceptable exception given the time-critical nature of emergencies
Correct answer: A control weakness that requires remediation
All changes, including emergency changes, require post-implementation review to confirm objectives were met and to assess any residual risks introduced.
Question 102: What does 'audit universe' refer to in internal audit planning?
- The complete set of audit standards applicable to an organization
- All external regulations an organization must comply with
- All auditable entities or activities within an organization (Correct answer)
- The total number of auditors available in the department
Correct answer: All auditable entities or activities within an organization
The audit universe comprises all auditable entities—processes, systems, departments—from which the audit plan is derived based on risk assessment.
Question 103: What is the role of an incident response team?
- Audit financials
- Develop software
- Manage and mitigate incidents (Correct answer)
- Ignore incidents
Correct answer: Manage and mitigate incidents
An incident response team (IRT) is responsible for detecting, analyzing, containing, eradicating, and recovering from security incidents or other disruptive events. Their primary role is to minimize the impact of incidents, restore normal operations quickly, and prevent recurrence. By having a dedicated team, organizations can respond systematically and effectively to protect their assets and maintain business continuity.
Question 104: An IS auditor reviewing patch management would consider controls MOST effective if:
- The organization waits 12 months before applying patches to ensure stability
- Critical patches are applied within a defined SLA following testing in a non-production environment (Correct answer)
- Patches are applied manually by individual system administrators without documentation
- Patches are applied only after end users report problems
Correct answer: Critical patches are applied within a defined SLA following testing in a non-production environment
Effective patch management requires a defined SLA for critical patches, with testing in a non-production environment prior to production deployment to balance security and stability.
Question 105: When auditing application controls, which control type BEST ensures that all data entered into a system has been processed completely?
- Batch totals (Correct answer)
- Edit checks
- Hash totals
- Sequence checks
Correct answer: Batch totals
Batch totals compare the sum of input records to a predetermined control total, ensuring all records in the batch were fully processed.
Question 106: Which technique involves IS auditors processing test transactions through a live system to verify controls without alerting operations staff?
- Parallel simulation
- Continuous auditing
- Base case system evaluation
- Integrated Test Facility (ITF) (Correct answer)
Correct answer: Integrated Test Facility (ITF)
An Integrated Test Facility (ITF) embeds fictitious test entities within the production environment so auditors can test controls unobtrusively during normal operations.
Question 107: Which rollback procedure consideration is MOST critical before executing a production system upgrade?
- Whether the rollback procedure has been tested and a documented fallback plan exists (Correct answer)
- Whether the rollback process takes more than one hour
- Whether all end users have been notified about the potential rollback
- Whether the rollback preserves developer configuration preferences
Correct answer: Whether the rollback procedure has been tested and a documented fallback plan exists
Testing the rollback procedure before go-live ensures the organization can reliably revert to the prior stable state if the upgrade fails.
Question 108: During an IT general controls audit, which area would an IS auditor focus on to assess whether program changes are authorized and tested before moving to production?
- Logical access controls
- Backup and recovery controls
- Change management controls (Correct answer)
- Physical security controls
Correct answer: Change management controls
Change management controls govern the authorization, testing, and migration of program changes from development to production environments.
Question 109: Which metric best measures the effectiveness of an organization's disaster recovery plan?
- Recovery Time Objective (RTO) achieved (Correct answer)
- Cost of DR infrastructure
- Number of backup tapes created
- Frequency of DR plan updates
Correct answer: Recovery Time Objective (RTO) achieved
Achieving the defined RTO demonstrates that the DR plan can restore operations within the acceptable downtime window.
Question 110: Which phase of the IS audit process involves comparing actual results against expected criteria to identify exceptions?
- Reporting
- Audit planning
- Fieldwork and evidence gathering (Correct answer)
- Follow-up
Correct answer: Fieldwork and evidence gathering
During fieldwork, auditors execute audit procedures—testing, observing, and comparing evidence against defined audit criteria to identify deviations.
Question 111: Which of the following BEST describes 'inherent risk' in the context of IS auditing?
- The susceptibility of an area to a material misstatement assuming no controls (Correct answer)
- The combined risk of a material error occurring and not being detected
- The risk that the auditor's procedures will fail to detect errors
- The risk that remains after management has applied controls
Correct answer: The susceptibility of an area to a material misstatement assuming no controls
Inherent risk is the level of risk present in the absence of any mitigating controls—the raw, uncontrolled risk of an area.
Question 112: Under ITIL 4, the concept that all IT services should be co-created with customers and stakeholders is called:
- Continual improvement
- Demand management
- Service integration
- Value co-creation (Correct answer)
Correct answer: Value co-creation
ITIL 4's service value system is built on the principle of value co-creation between the service provider and its stakeholders.
Question 113: Which of the following BEST describes a rainbow table attack?
- Intercepting credentials during network transmission
- Brute-force guessing every possible password
- Exploiting weak random number generators in hash algorithms
- Using precomputed hash values to reverse password hashes (Correct answer)
Correct answer: Using precomputed hash values to reverse password hashes
A rainbow table attack uses precomputed tables of hash values to quickly reverse hashed passwords.
Question 114: An organization wants to ensure that sensitive data cannot be recovered after hard drive disposal. Which method provides the STRONGEST assurance?
- Physical destruction of the drive (Correct answer)
- Degaussing the magnetic media
- Overwriting with a single pass of zeros
- Logical formatting of the drive
Correct answer: Physical destruction of the drive
Physical destruction (shredding, crushing) provides the strongest assurance that data cannot be recovered from disposed media.
Question 115: Which factor MOST significantly affects the quality of technical outcomes in ISACA practice?
- The time of day
- The brand of equipment
- The practitioner's training, preparation, and attention to detail (Correct answer)
- Speed of procedure completion
Correct answer: The practitioner's training, preparation, and attention to detail
Quality depends primarily on training, preparation, and attention to detail.
Question 116: An IS auditor is reviewing a Software Development Life Cycle (SDLC). At which phase should security requirements FIRST be formally incorporated?
- Requirements/design phase (Correct answer)
- Testing phase
- Post-implementation review
- Implementation phase
Correct answer: Requirements/design phase
Security requirements should be identified and documented during the requirements and design phase—'security by design'—to avoid costly remediation later.
Question 117: What should an audit report include?
- Findings, conclusions, recommendations (Correct answer)
- Only positive feedback
- Financial statements
- Employee evaluations
Correct answer: Findings, conclusions, recommendations
A comprehensive audit report should clearly present the audit findings, which are factual observations of control weaknesses or strengths. It must also include conclusions drawn from these findings and actionable recommendations for improvement, enabling management to address identified issues effectively and enhance the control environment.
Question 118: Which of the following is the BEST indicator that patch management processes are effective?
- Vendor patch notifications are archived
- Patches are applied manually by administrators
- Mean time to patch critical vulnerabilities meets defined SLAs (Correct answer)
- All servers are running the same OS version
Correct answer: Mean time to patch critical vulnerabilities meets defined SLAs
Measuring mean time to patch against defined SLAs provides a quantifiable indication of whether vulnerabilities are being remediated in a timely manner.
Question 119: In Information Systems Audit and Control Association Certification, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To reduce daily workload
- To evaluate employee performance reviews
- To satisfy insurance requirements only
- To ensure personnel can respond effectively in emergencies (Correct answer)
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies.
Question 120: Which of the following BEST describes the role of Key Risk Indicators (KRIs) in IT governance?
- They track whether IT service level agreements are being met
- They measure the financial return on IT investments
- They provide early warning signals of increasing risk exposure (Correct answer)
- They document historical security incidents for audit purposes
Correct answer: They provide early warning signals of increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are rising, enabling proactive governance responses before risks materialize.
Question 121: A crisis communication plan should PRIMARILY ensure that:
- Only senior executives communicate with the media
- Marketing materials are updated after a disaster
- All communications are encrypted
- Accurate and timely information reaches stakeholders during an incident (Correct answer)
Correct answer: Accurate and timely information reaches stakeholders during an incident
The primary goal of crisis communication is to provide stakeholders—including employees, customers, and regulators—with accurate and timely information to manage the situation effectively.
Question 122: Under the CISA framework, which of the following is the MOST important indicator that an organization's IT governance is effective?
- IT governance roles are assigned to senior IT staff
- IT governance committee meets on a quarterly schedule
- IT governance policies are documented and published
- IT goals consistently support and enable business objectives (Correct answer)
Correct answer: IT goals consistently support and enable business objectives
Effective IT governance is ultimately demonstrated by IT outcomes that consistently support and advance business objectives, not just process compliance.
Question 123: What is risk management in IT governance?
- Delay decisions
- Identify and mitigate risks (Correct answer)
- Increase risk exposure
- Ignore risks
Correct answer: Identify and mitigate risks
Risk management in IT governance is the systematic process of identifying, assessing, and treating potential threats to an organization's information assets and IT operations. Its purpose is to minimize the likelihood and impact of adverse events, such as data breaches or system failures. By proactively identifying and mitigating risks, organizations can protect their investments, maintain business continuity, and ensure compliance.
Question 124: When an IS auditor identifies a control deficiency during fieldwork, what is the MOST appropriate immediate action?
- Include it in the audit report without informing management
- Document the finding and discuss it with management before finalizing (Correct answer)
- Immediately report it to external regulators
- Dismiss it if it appears minor
Correct answer: Document the finding and discuss it with management before finalizing
Auditors should document findings and discuss them with management during the exit conference to confirm facts before issuing the final report.
Question 125: During an audit, the MOST reliable type of evidence an IS auditor can obtain is:
- Photocopies of original documents provided by the auditee
- Oral representations from management
- Internally generated management reports
- Documentary evidence obtained directly from independent third parties (Correct answer)
Correct answer: Documentary evidence obtained directly from independent third parties
Evidence obtained directly from independent third parties (external confirmations, externally generated documents) is the most reliable because it is not subject to manipulation by the auditee.
Question 126: An organization replicates data to a remote site every four hours. This interval represents the:
- Recovery Point Objective (RPO) (Correct answer)
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Point Objective (RPO)
The replication interval defines the maximum data loss the organization can tolerate, which is the definition of the Recovery Point Objective.
Question 127: What is the PRIMARY reason for regulatory compliance in the Information Systems Audit and Control Association Certification profession?
- To create additional paperwork
- To avoid penalties and fines only
- To justify higher service fees
- To protect public safety, ensure quality, and maintain professional integrity (Correct answer)
Correct answer: To protect public safety, ensure quality, and maintain professional integrity
Regulatory compliance protects public safety, ensures quality, and maintains professional integrity.
Question 128: Which of the following is the PRIMARY objective of a security operations center (SOC)?
- To continuously monitor, detect, and respond to cybersecurity incidents (Correct answer)
- To manage user identity provisioning and access requests
- To develop and enforce security policies across the organization
- To perform annual penetration tests on critical infrastructure
Correct answer: To continuously monitor, detect, and respond to cybersecurity incidents
A SOC provides 24/7 monitoring and response capabilities to detect, analyze, and contain security incidents in real time.
Question 129: In ISACA practice, what happens when regulations are updated?
- Changes apply only to new professionals
- Professionals must update knowledge and practices to meet new requirements (Correct answer)
- Existing professionals are grandfathered in
- Previous certifications are revoked
Correct answer: Professionals must update knowledge and practices to meet new requirements
All professionals must update their knowledge and practices when regulations change.
Question 130: What is the BEST way for a Information Systems Audit and Control Association Certification professional to stay current with regulatory changes?
- Depend on colleagues to share updates
- Rely solely on employer notifications
- Monitor regulatory bodies, attend CE, and participate in professional associations (Correct answer)
- Check regulations only during renewal
Correct answer: Monitor regulatory bodies, attend CE, and participate in professional associations
Staying current requires monitoring agencies, attending CE, and participating in professional associations.
Question 131: Which testing methodology evaluates system functionality based on inputs and outputs without knowledge of internal code structure?
- Regression testing
- Gray-box testing
- White-box testing
- Black-box testing (Correct answer)
Correct answer: Black-box testing
Black-box testing evaluates system behavior from an external perspective using inputs and outputs, without any knowledge of internal logic or code.
Question 132: An organization's IT steering committee approves a major ERP implementation but the business case shows negative NPV. An IS auditor should FIRST:
- Verify whether non-financial strategic benefits justify the investment (Correct answer)
- Recommend the organization reduce the project scope
- Require the project to be cancelled immediately
- Report the decision to external regulators
Correct answer: Verify whether non-financial strategic benefits justify the investment
A negative NPV does not automatically make an investment wrong; strategic, compliance, or competitive benefits may justify it if properly documented.
Question 133: Which configuration management practice BEST supports an audit trail for system changes?
- Encrypting all configuration files at rest
- Limiting configuration access to only senior IT staff
- Maintaining a configuration management database (CMDB) (Correct answer)
- Requiring weekly backups of all configurations
Correct answer: Maintaining a configuration management database (CMDB)
A CMDB tracks configuration items, their attributes, and their change history, providing a comprehensive record that supports audit trails and impact analysis.
Question 134: Which backup strategy provides the FASTEST recovery time while minimizing backup storage requirements?
- A combination of full and incremental backups with a recovery catalog (Correct answer)
- Daily full backups of all data
- Incremental-only backups stored indefinitely
- Differential backups taken every hour
Correct answer: A combination of full and incremental backups with a recovery catalog
A full backup combined with incremental backups and a recovery catalog balances storage efficiency with manageable restore complexity when guided by the catalog.
Question 135: Which of the following BEST describes the concept of defense-in-depth?
- Concentrating all security resources on the most critical assets
- Encrypting all data both in transit and at rest
- Using the most advanced firewall available as the sole security control
- Applying multiple overlapping security controls so that the failure of one does not expose the system (Correct answer)
Correct answer: Applying multiple overlapping security controls so that the failure of one does not expose the system
Defense-in-depth uses multiple layers of security controls so that if one layer fails, others still provide protection.
Question 136: What is the PRIMARY purpose of a post-implementation review (PIR)?
- To document the technical system architecture
- To train end users on the new system
- To evaluate whether the system meets its original objectives (Correct answer)
- To identify and remediate security vulnerabilities
Correct answer: To evaluate whether the system meets its original objectives
A post-implementation review assesses whether the implemented system meets the defined business objectives and performance criteria established before development.
Question 137: During a feasibility study for a new IT system, which factor relates specifically to TECHNICAL feasibility?
- Whether staff have adequate training to use the system
- Whether the required technology exists to support the requirements (Correct answer)
- Whether the system will comply with applicable regulations
- Whether the project can be completed within budget
Correct answer: Whether the required technology exists to support the requirements
Technical feasibility examines whether the required technology exists or can be developed to meet the stated system requirements.
Question 138: In IT governance and change management, the RACI model is used to define which of the following?
- Request, Approval, Change, and Incident tracking
- Responsible, Accountable, Consulted, and Informed roles (Correct answer)
- Review, Authorize, Check, and Implement steps
- Risk, Accountability, Control, and Integration responsibilities
Correct answer: Responsible, Accountable, Consulted, and Informed roles
RACI stands for Responsible, Accountable, Consulted, and Informed — a framework that clearly defines roles and responsibilities for each activity in a process.
Question 139: A large enterprise uses a federated IT governance model. This means IT governance decisions are:
- Distributed across business units with some central coordination (Correct answer)
- Made solely by the board of directors
- Made exclusively by the corporate IT department
- Outsourced to a third-party governance provider
Correct answer: Distributed across business units with some central coordination
A federated model distributes IT governance authority to business units while maintaining central coordination for enterprise-wide standards.
Question 140: What does 'parallel operation' mean in the context of a system cutover strategy?
- Two development teams work on the same module simultaneously
- Two separate databases are maintained permanently going forward
- Testing is performed in parallel with active development
- Both the old and new systems run concurrently for a validation period (Correct answer)
Correct answer: Both the old and new systems run concurrently for a validation period
Parallel operation runs both the legacy and new system simultaneously so organizations can verify the new system produces correct results before fully decommissioning the old one.
Question 141: When evaluating vendor proposals during system acquisition, what should an IS auditor verify is included in the RFP (Request for Proposal)?
- Vendor stock prices and financial forecasts
- Security, compliance, and audit requirements (Correct answer)
- The vendor's internal marketing strategy
- Only technical specifications and pricing
Correct answer: Security, compliance, and audit requirements
Including security, compliance, and audit requirements in the RFP ensures vendors understand and commit to these critical obligations from the outset of the relationship.
Question 142: When a ISACA professional encounters an unexpected result during a procedure, the FIRST action should be to:
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Repeat the procedure immediately
- Continue and address it later
- Report without preliminary assessment
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess unexpected results is critical for safety and quality.
Question 143: When assessing data integrity controls in a financial application, an IS auditor would MOST likely use which technique?
- Interviews with the CFO about financial reporting
- Review of the organization chart
- Physical observation of the server room
- Test data containing valid and invalid records to verify system edits (Correct answer)
Correct answer: Test data containing valid and invalid records to verify system edits
Submitting test data with known valid and invalid values verifies that the application correctly accepts, rejects, and processes records per its edit and validation rules.
Question 144: What is the MOST effective way for new ISACA professionals to build competency?
- Learning through trial and error
- Focusing solely on advanced topics
- Studying certification materials exclusively
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building competency requires formal education, mentored practice, and ongoing development.
Question 145: An IS auditor reviewing IT governance notes that IT investments are approved project-by-project with no portfolio view. The PRIMARY risk is:
- IT investments may be duplicated or conflict with each other (Correct answer)
- IT vendors may not be evaluated consistently
- Projects may not follow the system development life cycle
- Individual projects may exceed their budgets
Correct answer: IT investments may be duplicated or conflict with each other
Without a portfolio view, investments can overlap, conflict, or miss opportunities for synergy, resulting in suboptimal resource use.
Question 146: What is the BEST way for a Information Systems Audit and Control Association Certification professional to stay current with regulatory changes?
- Check regulations only during renewal
- Monitor regulatory bodies, attend CE, and participate in professional associations (Correct answer)
- Rely solely on employer notifications
- Depend on colleagues to share updates
Correct answer: Monitor regulatory bodies, attend CE, and participate in professional associations
Staying current requires monitoring agencies, attending CE, and participating in professional associations.
Question 147: When auditing an outsourced software development arrangement, an IS auditor should PRIMARILY review which documentation?
- Contract terms, SLAs, and right-to-audit clauses (Correct answer)
- The vendor's employee compensation structures
- Marketing materials provided by the vendor
- The vendor's office location and physical size
Correct answer: Contract terms, SLAs, and right-to-audit clauses
Contract terms, SLAs, and right-to-audit clauses define vendor obligations and provide the legal basis for the auditor to assess vendor performance and controls.
Question 148: An IS auditor is assessing the adequacy of password policies. Which finding represents the HIGHEST risk?
- Passwords do not expire for service accounts (Correct answer)
- Password history prevents reuse of the last 10 passwords
- Users are required to change passwords every 90 days
- Passwords must be at least 8 characters long
Correct answer: Passwords do not expire for service accounts
Non-expiring passwords on service accounts pose significant risk because a compromised credential may go undetected indefinitely with no forced rotation.
Question 149: Which of the following cloud deployment models gives an organization the MOST control over its security configurations?
- Public cloud
- Community cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud is dedicated to a single organization, giving it full control over security configurations, policies, and infrastructure.
Question 150: Which of the following BEST describes the principle of least privilege?
- Users should be given only the minimum access rights necessary to perform their job functions (Correct answer)
- Privileged accounts should be shared among administrators to ensure availability
- Access rights should never be reviewed once initially granted
- Users should be granted access to all systems unless explicitly denied
Correct answer: Users should be given only the minimum access rights necessary to perform their job functions
The principle of least privilege limits user access rights to only what is necessary to perform authorized tasks, reducing the attack surface.
Question 151: A data owner is PRIMARILY responsible for which of the following?
- Implementing technical security controls
- Classifying data and defining access rules (Correct answer)
- Monitoring network traffic for anomalies
- Patching vulnerabilities in systems storing the data
Correct answer: Classifying data and defining access rules
The data owner is accountable for classifying information and establishing appropriate access control policies.
Question 152: When evaluating an organization's IT operations, an IS auditor should verify that operator procedures are:
- Documented, approved, and reviewed periodically (Correct answer)
- Created by individual operators based on experience
- Stored exclusively on the operators' workstations
- Memorized by all operations staff
Correct answer: Documented, approved, and reviewed periodically
Documented, approved, and periodically reviewed procedures ensure consistency, accountability, and alignment with current operational and security requirements.
ISACA Certification Exams (e.g., CISA, CISM, CRISC, CGEIT)
ISACA offers several certifications (CISA, CISM, CRISC, CGEIT) that validate expertise in information systems audit, security, risk, and governance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds