CISA Certified Information Systems Auditor MCQ 2 — Questions and Answers
Question 1: During an IS audit, an auditor discovers that change management procedures are not being followed for emergency fixes. What is the MOST significant risk?
- Increased project costs
- Unauthorized or erroneous changes introduced to production (Correct answer)
- Slower deployment of fixes
- Lack of developer accountability
Correct answer: Unauthorized or erroneous changes introduced to production
Bypassing change management for emergency fixes creates the highest risk of introducing unauthorized or erroneous changes that can compromise system integrity.
Question 2: An IS auditor is reviewing access controls and finds that terminated employees still have active accounts 30 days after separation. The PRIMARY concern is:
- Wasted software licenses
- Potential unauthorized access to sensitive systems (Correct answer)
- Non-compliance with HR procedures
- Increased IT support workload
Correct answer: Potential unauthorized access to sensitive systems
Active accounts for terminated employees represent a direct threat of unauthorized access, which is the primary security risk to address.
Question 3: Which control type BEST describes a system that automatically locks a user account after five failed login attempts?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Account lockout after failed attempts is a preventive control because it stops further unauthorized access attempts before a breach occurs.
Question 4: An IS auditor is evaluating a company's disaster recovery plan. Which metric defines the maximum acceptable period of data loss following a disruption?
- Recovery Time Objective (RTO)
- Mean Time to Repair (MTTR)
- Recovery Point Objective (RPO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum age of data that must be recovered after a disaster to resume normal operations.
Question 5: When auditing an ERP system, an IS auditor should be MOST concerned with which of the following segregation of duties conflicts?
- A developer who also writes system documentation
- An accounts payable clerk who can also approve payments (Correct answer)
- A DBA who can also read application logs
- A security officer who also reviews audit logs
Correct answer: An accounts payable clerk who can also approve payments
An accounts payable clerk who can also approve payments creates a direct conflict that enables fraud without detection.
Question 6: During a penetration test scoping meeting, the client insists the auditor must not test the payroll system. The IS auditor should:
- Proceed without testing payroll and note the scope limitation in the report (Correct answer)
- Refuse to conduct the engagement without full access
- Test payroll anyway because it is the highest-risk system
- Escalate to regulators about the client's non-cooperation
Correct answer: Proceed without testing payroll and note the scope limitation in the report
Auditors must respect client-defined scope limitations and document them clearly so report readers understand coverage constraints.
Question 7: Which sampling technique is MOST appropriate when an IS auditor wants to give every transaction an equal chance of being selected for testing?
- Judgmental sampling
- Stratified sampling
- Random sampling (Correct answer)
- Cluster sampling
Correct answer: Random sampling
Random sampling ensures every item in the population has an equal probability of selection, eliminating auditor bias.
During an IS audit, an auditor discovers that change management procedures are not being followed for emergency fixes.
What is the MOST significant risk?