Free Certified Information Systems Auditor Trivia Questions and Answers — Questions and Answers
Question 1: An auditor is reviewing the background check procedure while inspecting a company's hiring procedure. The auditor is primarily concerned with whether background checks are conducted on all employees and whether the results of those checks result in decisions not to hire someone. Which of the following methods for gathering evidence will support this audit goal?
- Get a copy of the background check ledger that lists the names of the applicants, the findings of the background checks, and the choices to hire or not to hire. (Correct answer)
- Request the full contents of background checks along with hire/no-hire decisions.
- Examine the background check procedure and make a note of the qualities that are mentioned for each candidate.
- Request the hire/no-hire decisions from the auditee.
Correct answer: Get a copy of the background check ledger that lists the names of the applicants, the findings of the background checks, and the choices to hire or not to hire.
The auditor's goal is to verify that background checks are conducted on all employees and that the results influence hiring decisions. A background check ledger that lists applicants, the findings of their checks, and the final hire/no-hire decisions directly provides the necessary evidence to achieve this objective. It allows the auditor to trace the process from check initiation to the final decision for a population of applicants.
Question 2: Which risk categories should be taken into account when planning an audit, as per ISACA Audit Standard 1202?
- Cybersecurity risk
- Fraud risk
- Financial risk
- Business risk (Correct answer)
Correct answer: Business risk
ISACA Audit Standard 1202, 'Risk Assessment in Planning,' mandates that the IS auditor identify and assess risks relevant to the audit objectives. This primarily refers to business risks, which encompass various threats that could impact an organization's ability to achieve its strategic and operational objectives. By understanding business risks, the auditor can focus their efforts on areas with the highest potential impact.
Question 3: Which of the following best exemplifies a user account provisioning process control self-assessment?
- Verifies that user account updates were only made by authorized persons
- Active Directory should be checked to make sure that only domain administrators can modify user account permissions.
- Reconciliation of all user account changes with ticketing system requests that have been granted (Correct answer)
- Verification that the right people approved all changes to user accounts
Correct answer: Reconciliation of all user account changes with ticketing system requests that have been granted
Control Self-Assessment (CSA) involves management and staff directly assessing the effectiveness of controls within their own processes. Reconciling user account changes with approved ticketing system requests is a practical, ongoing check that the process owner can perform to verify that user account provisioning controls are operating as intended. This direct verification by the team responsible for the process is a prime example of CSA.
Question 4: What could happen if an IS auditor breaks the ISACA Code of Professional Ethics when they are members of ISACA and CISA certified?
- Imprisonment
- Termination of employment
- Loss of ISACA certifications (Correct answer)
- Fines
Correct answer: Loss of ISACA certifications
The ISACA Code of Professional Ethics outlines the mandatory standards of professional conduct for all ISACA members and certification holders. A violation of this code can lead to disciplinary actions, with the most severe consequence for certified individuals being the suspension or revocation of their ISACA certifications, such as CISA. This ensures the integrity and credibility of the ISACA professional community.
Question 5: The audit client argues with the conclusions after receiving a Sarbanes-Oxley audit report from an auditor that lists 12 exceptions. The unhappy audit customer demands a $25,000 fee in exchange for the removal of any six conclusions from the report. The validity of each of the 12 findings was confirmed after a review of the audit findings. How ought the auditor to move forward?
- The auditor should reject the payment and remove six of the findings.
- The auditor should report the matter to his or her manager. (Correct answer)
- The auditor should report the incident to the audit client's audit committee.
- The auditor should reject the payment and meet the auditee halfway by removing three of the findings.
Correct answer: The auditor should report the matter to his or her manager.
The auditor is facing an ethical dilemma involving a potential bribe and pressure to compromise audit findings, which is a serious breach of professional ethics and independence. Since the auditor has already confirmed the validity of the findings, the appropriate course of action is to immediately report the incident to their manager. The manager can then provide guidance, escalate the issue, and ensure proper handling in accordance with firm policies and ethical standards.
Question 6: An audit of a change control procedure is being conducted. The control owner provided the following description of the procedure during a walkthrough: "Before Wednesday at 5 o'clock, engineers organize their changes and email the IT manager to inform them. The engineers then carry out their modifications on Friday night during the change window." What conclusions, if any, should the auditor mention?
- The change control process lacks review and approval steps. (Correct answer)
- The change control process is fine as is, but could be improved by creating a ledger of changes.
- The change control process is fine as is.
- The change control process lacks a review step.
Correct answer: The change control process lacks review and approval steps.
A robust change control process requires formal review and approval steps *before* any changes are implemented. The description states engineers 'inform' the IT manager, which is not equivalent to a formal review and approval process. Without explicit review and approval, there's a significant risk of unauthorized, untested, or conflicting changes being introduced, which can lead to system instability or security vulnerabilities.
Question 7: The audit charter ought to:
- document the audit procedures designed to achieve the planned audit objectives.
- be dynamic and change to coincide with the changing nature of technology and the audit profession.
- outline the overall authority, scope and responsibilities of the audit function. (Correct answer)
- clearly state audit objectives for, and the delegation of, authority to the maintenance and review of internal controls
Correct answer: outline the overall authority, scope and responsibilities of the audit function.
The audit charter is a formal document that establishes the purpose, authority, and responsibility of the internal audit function within an organization. It defines the audit's overall scope, its organizational reporting lines, and the types of activities it is authorized to undertake. This document provides the foundational framework and mandate for all audit work, ensuring clarity and independence.
An auditor is reviewing the background check procedure while inspecting a company's hiring procedure.
The auditor is primarily concerned with whether background checks are conducted on all employees and whether the results of those checks result in decisions not to hire someone.
Which of the following methods for gathering evidence will support this audit goal?