ISACA Information System Auditing Process 5 — Questions and Answers
Question 1: An IS auditor is reviewing a Software Development Life Cycle (SDLC). At which phase should security requirements FIRST be formally incorporated?
- Testing phase
- Implementation phase
- Requirements/design phase (Correct answer)
- Post-implementation review
Correct answer: Requirements/design phase
Security requirements should be identified and documented during the requirements and design phase—'security by design'—to avoid costly remediation later.
Question 2: Which of the following BEST describes the purpose of a follow-up audit?
- To identify new risks that emerged since the original audit
- To verify that management has implemented agreed-upon corrective actions (Correct answer)
- To expand the original audit scope to cover additional areas
- To issue a revised audit report with updated findings
Correct answer: To verify that management has implemented agreed-upon corrective actions
A follow-up audit determines whether management has taken timely and effective corrective action to address findings from the original audit.
Question 3: An IS auditor is evaluating an organization's IT risk management framework. Which outcome BEST demonstrates effective risk management?
- All risks have been eliminated through compensating controls
- Residual risks are documented and formally accepted by risk owners (Correct answer)
- Risk assessments are performed only when a new system is deployed
- The IT department independently manages all risks without business input
Correct answer: Residual risks are documented and formally accepted by risk owners
Effective risk management acknowledges that not all risk can be eliminated; residual risks should be documented and formally accepted by appropriate risk owners.
Question 4: When performing a review of physical access controls to a data center, an IS auditor would MOST appropriately:
- Request the access control system logs and compare them against authorized access lists (Correct answer)
- Interview only the security guard on duty
- Review the building's general floor plan
- Check whether the data center door is made of metal
Correct answer: Request the access control system logs and compare them against authorized access lists
Reviewing access logs against authorized access lists directly tests whether only authorized individuals accessed the data center and whether any unauthorized access occurred.
Question 5: Which of the following is the MOST important characteristic of audit evidence?
- It must always be obtained through computer-assisted tools
- It must be sufficient and appropriate to support audit conclusions (Correct answer)
- It must be obtained within the first week of fieldwork
- It must be approved by the auditee before use
Correct answer: It must be sufficient and appropriate to support audit conclusions
Audit standards universally require evidence to be sufficient (adequate quantity) and appropriate (relevant quality and reliability) to support the auditor's conclusions.
Question 6: An IS auditor discovers that automated system-generated reports used for management decisions cannot be reproduced or reconciled to source data. This is BEST classified as a deficiency in:
- Physical security controls
- Report integrity and completeness controls (Correct answer)
- Network perimeter controls
- Identity and access management controls
Correct answer: Report integrity and completeness controls
The inability to reproduce or reconcile reports to source data indicates a failure in report integrity controls, undermining confidence in management's decision-making information.
Question 7: Under ISACA standards, an IS auditor who identifies a significant IT risk outside the original audit scope should:
- Ignore it since it is outside the defined scope
- Include it in current report findings without consultation
- Communicate it to management and consider whether scope expansion is warranted (Correct answer)
- Immediately halt the audit and replan from scratch
Correct answer: Communicate it to management and consider whether scope expansion is warranted
Professional standards require IS auditors to communicate significant risks discovered outside scope to management, and to evaluate whether expanding the scope is appropriate.
An IS auditor is reviewing a Software Development Life Cycle (SDLC).
At which phase should security requirements FIRST be formally incorporated?