Audit Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Audit Management flashcards as text
A CISO is preparing an audit report for the board. Which characteristic is most important for the executive summary?
Answer: Concise risk-ranked findings with business impact and remediation priorities
Executive summaries should present risk-ranked findings with clear business impact and prioritized recommendations to support board-level decision-making.
Which control testing approach is most appropriate when an auditor wants to verify that preventive controls operated effectively throughout the entire audit period?
Answer: Testing a sample of transactions across the full period
Testing a sample spread across the entire period provides evidence that controls operated consistently throughout, not just at a single point in time.
Under COBIT 2019, which governance objective directly supports the audit management function by ensuring IT-related risks are identified and managed?
Answer: APO12 — Managed Risk
APO12 (Managed Risk) in COBIT 2019 governs the identification, assessment, and response to IT-related risks, directly supporting audit management activities.
What is the primary distinction between a Type I and Type II SOC 2 report?
Answer: Type I assesses control design at a point in time; Type II assesses design and operating effectiveness over a period
A SOC 2 Type I report evaluates control design at a specific date, while Type II also tests operating effectiveness over a defined review period (typically 6–12 months).
A CISO wants to reduce audit fatigue caused by multiple simultaneous audits from different regulators. Which strategy is most effective?
Answer: Implement a coordinated audit management program that consolidates evidence collection and aligns audit schedules
A coordinated audit management program consolidates evidence artifacts and aligns scheduling to reduce redundant requests and minimize disruption to operations.
Which metric best measures the effectiveness of an organization's audit follow-up process?
Answer: Percentage of findings remediated by the agreed-upon due date
Remediation rate by due date directly measures whether the organization is acting on audit findings in a timely and accountable manner.
During an audit, the team discovers evidence of potential fraud. What is the CISO's immediate priority?
Answer: Immediately notify appropriate parties (legal, board, audit committee) and preserve evidence
Suspected fraud must be immediately escalated to legal counsel, the audit committee, and appropriate management while preserving evidence for investigation.