CISA Certified Information Systems Auditor 5 β Questions and Answers
Question 1: Which of the following frameworks is MOST commonly used to assess IT governance and management practices in a CISA audit?
- ITIL v4
- COBIT 2019 (Correct answer)
- ISO/IEC 27001
- NIST CSF
Correct answer: COBIT 2019
COBIT 2019 is ISACA's primary framework for IT governance and management, directly aligned with CISA's domain focus.
Question 2: An auditor reviewing patch management finds that critical patches are applied within 30 days but the vendor recommends 7 days. What is the auditor's BEST conclusion?
- The process is acceptable since patches are eventually applied
- The organization is exposed to elevated risk during the gap period (Correct answer)
- The vendor recommendation is too aggressive and can be ignored
- The process should be halted until patches are applied in real time
Correct answer: The organization is exposed to elevated risk during the gap period
Delaying critical patches beyond vendor recommendations leaves known vulnerabilities unaddressed, increasing exposure to exploitation.
Question 3: When conducting an audit of logical access controls, an auditor should PRIMARILY verify that:
- All users have administrator privileges for efficiency
- Access rights are based on business need and reviewed periodically (Correct answer)
- Passwords are stored in plaintext for easy reset
- Remote access is disabled for all employees
Correct answer: Access rights are based on business need and reviewed periodically
Logical access controls should enforce least privilege and be subject to periodic recertification to ensure ongoing appropriateness.
Question 4: An IS auditor is assessing an organization's incident response capability. Which element is MOST critical for a mature program?
- A large dedicated security team
- Documented procedures that have been tested and rehearsed (Correct answer)
- Purchase of the latest security tools
- Annual mandatory security awareness training
Correct answer: Documented procedures that have been tested and rehearsed
Documented, tested incident response procedures ensure the organization can respond effectively and consistently when an incident occurs.
Question 5: Which of the following BEST demonstrates due diligence by IT management regarding information security?
- Purchasing cybersecurity insurance
- Conducting regular risk assessments and acting on findings (Correct answer)
- Outsourcing all security functions to a MSSP
- Publishing an acceptable use policy
Correct answer: Conducting regular risk assessments and acting on findings
Due diligence requires actively identifying risks and taking informed action, not just transferring or delegating responsibility.
Question 6: During an audit of database controls, an auditor finds that database administrators (DBAs) have unrestricted access to production data without any monitoring. The MOST significant risk is:
- Database performance degradation
- Unauthorized modification or exfiltration of sensitive data without detection (Correct answer)
- Increased licensing costs
- Difficulty performing database upgrades
Correct answer: Unauthorized modification or exfiltration of sensitive data without detection
Unmonitored privileged access to production data creates high risk of insider threat and data integrity compromise.
Question 7: An IS auditor reviewing a data backup process should FIRST verify that:
- Backups are stored in the same building as production systems
- Backup restoration has been successfully tested (Correct answer)
- Daily backups are performed for all data
- Backup media is labeled correctly
Correct answer: Backup restoration has been successfully tested
Untested backups cannot be relied upon for recovery; successful restoration tests are the only proof that backups are valid.
Which of the following frameworks is MOST commonly used to assess IT governance and management practices in a CISA audit?