ISACA Information System Auditing Process 4 — Questions and Answers
Question 1: An IS auditor is assessing the adequacy of password policies. Which finding represents the HIGHEST risk?
- Passwords must be at least 8 characters long
- Passwords do not expire for service accounts (Correct answer)
- Users are required to change passwords every 90 days
- Password history prevents reuse of the last 10 passwords
Correct answer: Passwords do not expire for service accounts
Non-expiring passwords on service accounts pose significant risk because a compromised credential may go undetected indefinitely with no forced rotation.
Question 2: The ISACA IS Audit and Assurance Standard requires that IS audit conclusions be based on:
- Management representations alone
- Sufficient and appropriate audit evidence (Correct answer)
- Prior year audit findings
- Industry benchmarking data
Correct answer: Sufficient and appropriate audit evidence
IS audit standards require that conclusions and opinions be supported by sufficient (enough) and appropriate (relevant and reliable) audit evidence.
Question 3: When assessing data integrity controls in a financial application, an IS auditor would MOST likely use which technique?
- Physical observation of the server room
- Test data containing valid and invalid records to verify system edits (Correct answer)
- Interviews with the CFO about financial reporting
- Review of the organization chart
Correct answer: Test data containing valid and invalid records to verify system edits
Submitting test data with known valid and invalid values verifies that the application correctly accepts, rejects, and processes records per its edit and validation rules.
Question 4: Which of the following BEST describes 'audit risk'?
- The risk that a control will fail to prevent an error
- The risk that the auditor expresses an incorrect opinion due to undetected material errors (Correct answer)
- The risk that management will override audit findings
- The risk that audit costs will exceed the approved budget
Correct answer: The risk that the auditor expresses an incorrect opinion due to undetected material errors
Audit risk is the risk that the auditor reaches an incorrect conclusion (e.g., issues a clean opinion when material errors exist) due to failures in detection.
Question 5: An IS auditor finds that developers have access to the production environment. This PRIMARILY violates the principle of:
- Least privilege only
- Segregation of duties (Correct answer)
- Defense in depth
- Non-repudiation
Correct answer: Segregation of duties
Allowing developers access to production violates segregation of duties because the same person who creates code should not be able to deploy or modify it in production.
Question 6: During an audit, the MOST reliable type of evidence an IS auditor can obtain is:
- Oral representations from management
- Documentary evidence obtained directly from independent third parties (Correct answer)
- Internally generated management reports
- Photocopies of original documents provided by the auditee
Correct answer: Documentary evidence obtained directly from independent third parties
Evidence obtained directly from independent third parties (external confirmations, externally generated documents) is the most reliable because it is not subject to manipulation by the auditee.
Question 7: An IS auditor reviewing patch management would consider controls MOST effective if:
- Patches are applied manually by individual system administrators without documentation
- Critical patches are applied within a defined SLA following testing in a non-production environment (Correct answer)
- Patches are applied only after end users report problems
- The organization waits 12 months before applying patches to ensure stability
Correct answer: Critical patches are applied within a defined SLA following testing in a non-production environment
Effective patch management requires a defined SLA for critical patches, with testing in a non-production environment prior to production deployment to balance security and stability.
An IS auditor is assessing the adequacy of password policies.
Which finding represents the HIGHEST risk?