Free Certified Information Systems Auditor MCQ Questions and Answers — Questions and Answers
Question 1: The management is starting to wonder about the timeline and completion of an audit project that is going far too long. This audit might be deficient in:
- Cooperation from individual auditees
- Enough skilled auditors
- Clearly stated scope and objectives
- Effective project management (Correct answer)
Correct answer: Effective project management
When an audit project extends beyond its expected timeline and management expresses concern, it indicates a breakdown in the audit's planning, execution, or monitoring. Effective project management for an audit involves clearly defining scope, setting realistic timelines, allocating resources efficiently, and consistently tracking progress. A deficiency in these areas leads to delays and concerns about the project's completion.
Question 2: Which statement regarding the ISACA Audit Standards and Audit Guidelines is accurate?
- ISACA Audit Guidelines are mandatory
- ISACA Audit Standards are mandatory (Correct answer)
- ISACA Audit Standards are only mandatory for SOX audits
- ISACA Audit Standards are optional
Correct answer: ISACA Audit Standards are mandatory
ISACA's IT Audit and Assurance Standards are mandatory requirements for all ISACA members and certification holders, including CISA-certified professionals. These standards provide the foundational principles and requirements for conducting professional IS audits. While ISACA Audit Guidelines offer helpful advice and best practices, they are not mandatory.
Question 3: Can an auditor depend on the audit client's risk estimate for audit planning?
- No. The auditor must perform a risk assessment himself or herself
- No. The auditor does not require a risk assessment to develop an audit plan
- Yes, in all cases
- Yes, if the risk assessment was performed by a qualified external entity (Correct answer)
Correct answer: Yes, if the risk assessment was performed by a qualified external entity
An auditor can rely on a client's risk assessment for audit planning, but only under specific conditions. The assessment must have been performed by a qualified external entity, ensuring objectivity and adherence to professional standards. However, the auditor must still exercise professional skepticism and evaluate the adequacy and appropriateness of the client's assessment before incorporating it into their own audit plan.
Question 4: The user account request and fulfillment process is being audited by an auditor. The auditor cannot inspect every transaction in the event population because there are hundreds of them. A random sample of transactions and some of the transactions for privileged access requests are wanted by the auditor. This kind of sampling is referred to as:
- Random sampling
- Statistical sampling
- Judgmental sampling (Correct answer)
- Stratified sampling
Correct answer: Judgmental sampling
Judgmental sampling involves the auditor using their professional expertise and knowledge to select specific items for examination. In this scenario, the auditor is not only taking a random sample but also specifically choosing transactions related to privileged access requests due to their higher risk. This deliberate selection based on auditor judgment, rather than purely statistical methods or stratification, characterizes judgmental sampling.
Question 5: A plan for an audit is being created by an auditor for the accounts payment function. The auditor wishes to choose transactions from low, medium, and big payment amounts rather than randomly choosing transactions to investigate. Which example methodology fits this approach the best?
- Non-random sampling
- Judgmental sampling
- Statistical sampling
- Stratified sampling (Correct answer)
Correct answer: Stratified sampling
Stratified sampling involves dividing the entire population into distinct, homogeneous subgroups (strata) based on specific characteristics, and then drawing samples from each stratum. By choosing transactions from low, medium, and big payment amounts, the auditor is creating strata based on transaction value. This method ensures that all relevant categories are represented in the sample, providing a more comprehensive and targeted review.
Question 6: What is the purpose of the ISACA organizational independence audit standard?
- To ensure that the auditor has the appearance of independence.
- The auditor's placement in the organization should ensure the auditor can act independently. (Correct answer)
- To ensure that the auditor has a separate operating budget.
- The auditor should not work in the same organization as the auditee.
Correct answer: The auditor's placement in the organization should ensure the auditor can act independently.
The ISACA organizational independence audit standard aims to ensure that the IS audit function is positioned within the organization in a way that allows auditors to perform their duties objectively and without undue influence. This typically means the audit function reports to a high level, such as the audit committee or board, to maintain both the appearance and the reality of independence. It's about the structural arrangement that enables unbiased audit work.
Question 7: Which of the following audit types would be suitable for a provider of financial services, like a payroll service?
- AUP
- Sarbanes-Oxley
- SSAE18 (Correct answer)
- SAS70
Correct answer: SSAE18
SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the current professional standard for reporting on controls at service organizations. A payroll service provider is a service organization, and its clients would typically request a SOC 1 (Service Organization Control 1) report, which falls under SSAE 18, to understand the effectiveness of controls relevant to financial reporting. SAS 70 was the predecessor standard.
The management is starting to wonder about the timeline and completion of an audit project that is going far too long.
This audit might be deficient in: