ISACA CISA Certified Information Systems Auditor Exam — Questions and Answers
Question 1: A software development team uses an iterative methodology where working software is delivered in short cycles. This BEST describes:
- Agile/Scrum development (Correct answer)
- Rapid application development (RAD)
- Waterfall development
- Spiral model development
Correct answer: Agile/Scrum development
Agile/Scrum delivers working software in short, time-boxed sprints with frequent stakeholder feedback and iterative refinement.
Question 2: In IS audit planning, which approach helps an auditor identify control gaps by mapping risks to existing controls?
- Entity-relationship diagramming
- Data flow diagramming
- Control matrix (risk-control matrix) (Correct answer)
- Flowcharting
Correct answer: Control matrix (risk-control matrix)
A risk-control matrix maps identified risks to the controls designed to mitigate them, making it easy to spot areas where controls are absent, weak, or duplicated.
Question 3: An organization conducts a DR simulation where team members respond to a hypothetical scenario without touching live systems. This is BEST described as a:
- Full interruption test
- Parallel test
- Tabletop exercise (Correct answer)
- Technical recovery test
Correct answer: Tabletop exercise
A tabletop exercise is a discussion-based session where participants walk through a disaster scenario verbally without activating recovery systems.
Question 4: A DMZ (Demilitarized Zone) is BEST described as:
- A backup network used only during disaster recovery
- A network zone between the internet and the internal network that hosts public-facing services (Correct answer)
- A VLAN reserved for administrative management traffic
- A segment where only internal users can access resources
Correct answer: A network zone between the internet and the internal network that hosts public-facing services
A DMZ provides a buffer zone that exposes public services (e.g., web servers) while shielding the internal network.
Question 5: Which of the following is the PRIMARY purpose of network traffic analysis in an IS audit?
- To measure the bandwidth consumed by individual users
- To configure QoS policies for business-critical applications
- To detect anomalous traffic patterns that may indicate a security incident (Correct answer)
- To replace firewall rules with more efficient configurations
Correct answer: To detect anomalous traffic patterns that may indicate a security incident
Traffic analysis helps auditors identify deviations from baseline behavior that could signal unauthorized access, data exfiltration, or malware.
Question 6: Which of the following is the MOST effective way to ensure IT risks are aligned with business strategy?
- Conducting quarterly vulnerability scans
- Deploying a Security Information and Event Management (SIEM) system
- Integrating IT risk management into enterprise risk management (ERM) (Correct answer)
- Requiring all employees to complete annual security awareness training
Correct answer: Integrating IT risk management into enterprise risk management (ERM)
Integrating IT risk management into ERM ensures that technology risks are evaluated in the context of overall business objectives and risk appetite.
Question 7: Which type of database backup captures only the data that has changed since the last full backup, minimizing backup window time?
- Full backup
- Snapshot backup
- Incremental backup (Correct answer)
- Differential backup
Correct answer: Incremental backup
Incremental backups capture only data changed since the last backup of any type (full or incremental), minimizing the backup window but requiring all incrementals and the last full backup for a complete restore.
Question 8: When scheduling DR tests, the MOST important factor an IS auditor should verify is that tests are:
- Limited to IT staff to avoid business disruption
- Performed at least once every five years
- Approved by senior management and aligned with business risk (Correct answer)
- Conducted only during weekends to minimize impact
Correct answer: Approved by senior management and aligned with business risk
DR tests should have management approval and be scheduled based on business risk tolerance, criticality of systems, and regulatory requirements.
Question 9: Which element is MOST critical to include in a business continuity plan for an organization that relies heavily on third-party vendors?
- Vendor contact lists only
- Third-party vendor continuity and resilience requirements (Correct answer)
- A list of alternative vendors with no contract in place
- Vendor financial ratings
Correct answer: Third-party vendor continuity and resilience requirements
Organizations must ensure third-party vendors have adequate continuity plans and contractual obligations to support recovery objectives.
Question 10: A CISA auditor finds that a company's risk register has not been updated in 18 months. What is the PRIMARY concern?
- The audit trail is incomplete
- Risk owners have not been assigned
- The risk register format may be outdated
- Emerging risks may not be identified or monitored (Correct answer)
Correct answer: Emerging risks may not be identified or monitored
A stale risk register means new and evolving threats may go unrecognized, leaving the organization exposed to unmanaged risks.
Question 11: What year was ISACA originally founded?
- 1967 (Correct answer)
- 1972
- 1960
- 1980
Correct answer: 1967
ISACA was founded in 1967 as the EDP Auditors Association before becoming ISACA.
Question 12: When evaluating IT governance, an IS auditor should PRIMARILY focus on whether:
- IT strategy is aligned with business objectives (Correct answer)
- The IT department has sufficient headcount
- IT systems are using the latest technology
- All software licenses are current
Correct answer: IT strategy is aligned with business objectives
IT governance ensures that IT investments and strategies are aligned with and support overall business objectives.
Question 13: An IS auditor notices that a key IT system has not been audited in three years. According to risk-based planning, this fact PRIMARILY affects which planning element?
- Detection risk
- Audit frequency prioritization (Correct answer)
- Control risk assessment
- Residual risk
Correct answer: Audit frequency prioritization
A long gap since the last audit increases the priority of that system in audit frequency planning, as unaudited areas may have accumulated undetected risks.
Question 14: An organization is planning its annual disaster recovery testing strategy. Management is concerned about the high cost and potential business disruption of a full interruption test. Which type of test would be the BEST alternative to validate the technical recovery procedures with high assurance but minimal production impact?
- A checklist review
- A parallel test (Correct answer)
- A simulation test
- A walkthrough test
Correct answer: A parallel test
A parallel test provides a high degree of assurance by activating the recovery systems and processing real data or transactions, but it does so without taking the primary systems offline. This approach allows for thorough technical validation while avoiding the disruption and risk associated with a full interruption test, making it the best alternative in this scenario.
Question 15: Which data management control MOST effectively ensures that data has not been altered during storage or transmission?
- Data masking
- Data compression
- Hash-based integrity checks (Correct answer)
- Data encryption
Correct answer: Hash-based integrity checks
Hash-based integrity checks (e.g., SHA-256 checksums) generate a fixed-length fingerprint of data that changes if the data is altered, providing a reliable mechanism to detect unauthorized modification.
Question 16: What does a change management process that includes a 'back-out trigger' PRIMARILY address?
- Pre-defined conditions under which a rollback must be initiated without further approval (Correct answer)
- Escalation procedures for unresponsive vendors
- The need to approve additional budget for failed changes
- Notification timelines for executive stakeholders
Correct answer: Pre-defined conditions under which a rollback must be initiated without further approval
A back-out trigger specifies objective criteria (e.g., error rate exceeds threshold) that automatically initiate rollback, reducing decision delays during a failed deployment.
Question 17: A software development project is using a traditional Waterfall methodology. An IS auditor would be MOST concerned about the risk of:
- requirements not being fully defined and understood until late in the lifecycle. (Correct answer)
- a lack of detailed documentation for each phase.
- the project scope expanding without formal control.
- insufficient stakeholder involvement throughout the project.
Correct answer: requirements not being fully defined and understood until late in the lifecycle.
A key characteristic and major risk of the Waterfall model is its linear and sequential nature, where each phase must be completed before the next begins. This means that requirements must be fully defined and frozen upfront. Any misunderstandings or changes discovered during the testing or implementation phase are very difficult and costly to address, making this the biggest inherent risk of the methodology.
Question 18: Which IS audit planning concept ensures that audit conclusions are supported by sufficient, reliable, relevant, and useful evidence?
- Audit materiality
- Audit risk model
- Audit independence
- Audit evidence standards (Correct answer)
Correct answer: Audit evidence standards
Audit evidence standards require that the evidence gathered be sufficient (enough), reliable (trustworthy), relevant (pertinent to the objective), and useful (supportive of conclusions).
Question 19: Which of the following BEST describes the purpose of a Key Risk Indicator (KRI) in IT risk management?
- To measure the performance of the IT department after a risk has materialized.
- To provide a historical record of all IT security incidents.
- To serve as an early warning signal that a risk is emerging or exceeding its threshold. (Correct answer)
- To calculate the precise financial impact of a specific risk event.
Correct answer: To serve as an early warning signal that a risk is emerging or exceeding its threshold.
Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposures in various areas of the enterprise. They are forward-looking and designed to alert management before a risk materializes into a loss event, allowing for proactive risk mitigation.
Question 20: Which framework does CISA primarily align with for IT governance?
- NIST CSF
- COBIT (Correct answer)
- ISO 27001
- ITIL
Correct answer: COBIT
CISA aligns primarily with COBIT, which was developed by ISACA for IT governance and management.
Question 21: An IS auditor is reviewing the change management process for a critical financial application. It is noted that developers are able to promote their own code changes directly into the production environment. This practice represents a failure of which fundamental control principle?
- Defense in depth
- Security by design
- Segregation of duties (SoD) (Correct answer)
- Principle of least privilege
Correct answer: Segregation of duties (SoD)
Segregation of duties (SoD) is a fundamental internal control concept that involves separating tasks and responsibilities among different people to prevent fraud and errors. Allowing a developer to write code and also promote it to production without independent oversight violates SoD, as it creates an opportunity for unauthorized or untested changes to be implemented.
Question 22: An IS auditor recommends that DR test scenarios should include which of the following to be MOST effective?
- Scenarios that guarantee a successful recovery outcome
- Only scenarios that the team has previously rehearsed
- A variety of realistic, risk-based scenarios including partial and full failures (Correct answer)
- Scenarios designed by IT staff without business input
Correct answer: A variety of realistic, risk-based scenarios including partial and full failures
Effective DR tests use diverse, realistic scenarios based on actual risk assessments, including partial outages, to surface a wider range of gaps.
Question 23: An auditor reviewing patch management finds that critical patches are applied within 30 days but the vendor recommends 7 days. What is the auditor's BEST conclusion?
- The process should be halted until patches are applied in real time
- The process is acceptable since patches are eventually applied
- The organization is exposed to elevated risk during the gap period (Correct answer)
- The vendor recommendation is too aggressive and can be ignored
Correct answer: The organization is exposed to elevated risk during the gap period
Delaying critical patches beyond vendor recommendations leaves known vulnerabilities unaddressed, increasing exposure to exploitation.
Question 24: A company has decided to accept the risk associated with a potential data breach because the cost of the recommended countermeasure exceeds the potential loss. Which of the following risk response strategies has the company adopted?
- Risk Mitigation
- Risk Avoidance
- Risk Acceptance (Correct answer)
- Risk Transfer
Correct answer: Risk Acceptance
Risk acceptance is a strategy where an organization decides to accept a risk's potential consequences without taking further action to reduce it. This is often done when the cost of mitigation outweighs the potential loss, or the risk falls within the defined risk appetite.
Question 25: An IS auditor reviewing DR test results notes that the RTO was met but several critical transactions were lost. Which metric was NOT achieved?
- Maximum Tolerable Downtime
- Recovery Point Objective (Correct answer)
- Recovery Time Objective
- Mean Time to Repair
Correct answer: Recovery Point Objective
RPO defines the maximum acceptable data loss measured in time; lost transactions indicate the RPO was not met even though the system came back within the RTO.
Question 26: In the context of IS audit planning, 'scope creep' refers to:
- Expanding the audit team mid-engagement
- The process of narrowing scope to focus on high-risk areas
- Additional testing required when control deficiencies are found
- Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines (Correct answer)
Correct answer: Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines
Scope creep occurs when the audit scope expands incrementally beyond original boundaries without formal approval, potentially compromising audit quality and resource management.
Question 27: A company stores backup media at a facility 2 miles from the primary data center. An IS auditor's MAIN concern would be:
- The media may not be properly labeled for identification
- The proximity may mean both sites are affected by the same regional disaster (Correct answer)
- The backup facility may have different environmental controls
- The cost of transporting media to the offsite location
Correct answer: The proximity may mean both sites are affected by the same regional disaster
Offsite storage must be far enough away to avoid being impacted by the same disaster (flood, hurricane, earthquake) that affects the primary site.
Question 28: A change management policy requires that all code changes be reviewed by a developer other than the author. This control PRIMARILY addresses which risk?
- Unauthorized or fraudulent code being introduced (Correct answer)
- System downtime during deployment
- Inadequate change documentation
- Insufficient test environment resources
Correct answer: Unauthorized or fraudulent code being introduced
Peer code review provides separation of duties, reducing the risk that a single developer could introduce malicious or erroneous code undetected.
Question 29: An IS auditor plans to rely on the work of an internal audit team. Which condition MUST be assessed before placing reliance on their work?
- The number of years the internal audit team has been in place
- Whether the internal audit team reports to the CFO
- The competence and objectivity of the internal audit function (Correct answer)
- Whether internal auditors use the same tools as external auditors
Correct answer: The competence and objectivity of the internal audit function
Before relying on internal audit work, an IS auditor must evaluate the internal audit team's technical competence and organizational objectivity to ensure their work meets adequate standards.
Question 30: Which network security device inspects packet headers and filters traffic based on predefined rules without examining packet content?
- Web application firewall
- Intrusion Detection System
- Stateful firewall
- Packet-filtering firewall (Correct answer)
Correct answer: Packet-filtering firewall
A packet-filtering firewall examines IP headers, ports, and protocols but does not inspect the actual content of packets.
Question 31: An IS auditor reviews an organization's patch management policy and finds that critical security patches are applied within 72 hours on internet-facing servers but within 30 days on internal servers. What is the AUDITOR'S BEST assessment?
- The tiered approach is acceptable only if internal servers are isolated from each other
- The policy should require uniform patching timelines across all systems
- The 30-day window for internal servers may be excessive and should be risk-assessed (Correct answer)
- The policy is adequate because internal servers are not directly exposed to the internet
Correct answer: The 30-day window for internal servers may be excessive and should be risk-assessed
A blanket 30-day patch cycle for internal servers may be too long, especially for critical vulnerabilities, and the risk should be evaluated against the organization's threat profile.
Question 32: After a successful DR test, which action is MOST critical before closing out the test?
- Publishing the test results on the company intranet
- Returning all systems to the primary site and verifying normal operations (Correct answer)
- Ordering new backup hardware
- Archiving all test logs for ten years
Correct answer: Returning all systems to the primary site and verifying normal operations
Restoring systems to the primary site and confirming normal operations ensures the recovery environment is reset and production integrity is maintained after the test.
Question 33: Which of the following BEST describes the purpose of an audit program in IS audit planning?
- A schedule of all audits planned for the year
- A set of detailed instructions guiding the auditor through specific procedures to achieve audit objectives (Correct answer)
- A summary of findings presented to management
- A high-level document authorizing the audit function
Correct answer: A set of detailed instructions guiding the auditor through specific procedures to achieve audit objectives
An audit program is a detailed set of procedures and instructions that guide the auditor in gathering sufficient evidence to meet the specific objectives of the audit.
Question 34: What is the MAIN advantage of using a risk scenario approach in IT risk management?
- It eliminates the need for quantitative risk calculations
- It satisfies regulatory requirements without further analysis
- It provides concrete, realistic examples that link threats to business impact (Correct answer)
- It replaces the need for a risk register
Correct answer: It provides concrete, realistic examples that link threats to business impact
Risk scenarios describe specific threat events and their potential business consequences, making abstract risks tangible and easier to assess.
Question 35: A CISA auditor is evaluating the IT risk management framework. Which characteristic is MOST indicative of a mature risk management process?
- Risk registers are maintained exclusively by the audit team
- Risk assessments are performed only when incidents occur
- Risk management is embedded in all IT project and change management processes (Correct answer)
- The IT department manages all risks without executive involvement
Correct answer: Risk management is embedded in all IT project and change management processes
A mature risk management process is embedded across IT operations and projects, making risk consideration a routine part of all decisions rather than a reactive exercise.
Question 36: Which of the following BEST describes a risk-based audit approach in IS audit planning?
- Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently (Correct answer)
- Auditing every system and process equally regardless of risk level
- Following a fixed template that does not change between audit cycles
- Focusing only on financial systems because they pose the most regulatory risk
Correct answer: Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently
A risk-based approach directs audit resources toward the areas posing the greatest risk, ensuring that audit effort is proportionate to the likelihood and impact of potential issues.
Question 37: An IS auditor is planning an audit in an environment where management has implemented continuous monitoring tools. The auditor should PRIMARILY:
- Replace audit sampling with management's monitoring reports
- Evaluate the design and effectiveness of the continuous monitoring tools as part of the audit plan (Correct answer)
- Assume controls are effective since continuous monitoring is in place
- Rely entirely on continuous monitoring results and skip independent testing
Correct answer: Evaluate the design and effectiveness of the continuous monitoring tools as part of the audit plan
The auditor must assess whether the continuous monitoring tools themselves are properly designed and operating effectively before placing any reliance on their output.
Question 38: In the context of IS auditing, 'audit universe' refers to:
- All auditable entities within the scope of the audit function (Correct answer)
- The organization's IT asset inventory
- The total number of auditors in an organization
- External regulatory requirements
Correct answer: All auditable entities within the scope of the audit function
The audit universe encompasses all potential audit subjects from which the audit plan is derived.
Question 39: Which of the following BEST describes the role of configuration management in system development?
- Approving capital expenditure for IT infrastructure
- Managing employee workstation hardware inventories
- Scheduling project team meetings and sprint reviews
- Controlling and tracking changes to software components and their versions (Correct answer)
Correct answer: Controlling and tracking changes to software components and their versions
Configuration management ensures that software components are versioned, tracked, and controlled so that any version can be reproduced and changes are auditable.
Question 40: An IS auditor is evaluating a company's key management practices. Which of the following represents the GREATEST risk to a public key infrastructure (PKI)?
- Issuing certificates from a third-party certificate authority
- Using certificate validity periods longer than two years
- Using SHA-256 instead of SHA-512 for certificate signing
- Failure to maintain a current certificate revocation list (CRL) (Correct answer)
Correct answer: Failure to maintain a current certificate revocation list (CRL)
An outdated CRL means that compromised or revoked certificates may still be trusted, allowing attackers to impersonate legitimate entities.
Question 41: During an IT audit, a CISA finds that risk assessments are performed annually by IT staff without business unit input. What is the GREATEST weakness?
- The assessments are not automated
- Risk assessments lack business context and may miss operational risks (Correct answer)
- Assessments are not frequent enough
- IT staff are not qualified to assess risk
Correct answer: Risk assessments lack business context and may miss operational risks
Excluding business units means assessments may miss key operational risks and fail to align with business objectives.
Question 42: Which of the following BEST describes the relationship between audit objectives and audit procedures in IS audit planning?
- Audit objectives drive the design of audit procedures used to gather evidence (Correct answer)
- Audit objectives are set by the auditee, not the auditor
- Audit procedures define the objectives the auditor wants to achieve
- Audit procedures and objectives are developed independently
Correct answer: Audit objectives drive the design of audit procedures used to gather evidence
Audit objectives define what the auditor seeks to determine, and audit procedures are then designed specifically to gather the evidence needed to meet those objectives.
Question 43: Which of the following BEST describes the principle of least privilege in the context of logical access controls?
- Administrators approve all access requests before granting
- Users are granted access to all resources they may ever need
- Access rights are assigned based on user seniority
- Users receive only the minimum access rights necessary to perform their job (Correct answer)
Correct answer: Users receive only the minimum access rights necessary to perform their job
Least privilege limits user access to only what is essential for their specific job duties, reducing the attack surface.
Question 44: In IT risk management, what does the term 'risk aggregation' refer to?
- Transferring multiple risks to a single insurance policy
- Splitting a large risk into smaller, manageable components
- Combining multiple small risks to understand their cumulative effect on the organization (Correct answer)
- Documenting all risks in a centralized risk register
Correct answer: Combining multiple small risks to understand their cumulative effect on the organization
Risk aggregation combines individual risks to reveal their combined impact, which may be greater than any single risk in isolation.
Question 45: Which SDLC phase is MOST concerned with translating business requirements into technical specifications?
- Feasibility study
- Systems design (Correct answer)
- Programming and testing
- Implementation
Correct answer: Systems design
The systems design phase converts logical business requirements into detailed technical blueprints for developers.
Question 46: An IS auditor reviewing system documentation finds that no operations manual exists for a newly implemented system. The PRIMARY concern is:
- Operations staff may be unable to maintain or recover the system properly (Correct answer)
- The system may not integrate with social media platforms
- Development costs may increase in the next phase
- End users may not enjoy the interface
Correct answer: Operations staff may be unable to maintain or recover the system properly
Without an operations manual, staff lack the guidance needed for routine operations, troubleshooting, and disaster recovery, increasing operational risk.
Question 47: Which of the following is the BEST control for preventing DNS spoofing attacks?
- Implementing DNSSEC to cryptographically sign DNS records (Correct answer)
- Disabling all external DNS queries
- Configuring DNS servers on the DMZ only
- Using SNMP to monitor DNS traffic
Correct answer: Implementing DNSSEC to cryptographically sign DNS records
DNSSEC adds digital signatures to DNS records, allowing resolvers to verify authenticity and reject forged responses.
Question 48: An IS auditor is planning an audit and must evaluate whether to use Computer-Assisted Audit Techniques (CAATs). The PRIMARY advantage of CAATs is:
- They reduce the need for interviewing auditees
- They eliminate the need for auditor judgment
- They enable analysis of entire data populations rather than just samples (Correct answer)
- They ensure 100% accuracy of audit findings
Correct answer: They enable analysis of entire data populations rather than just samples
CAATs allow auditors to analyze complete data populations rather than relying on samples, providing greater coverage and statistical confidence in findings.
Question 49: What is the PURPOSE of a change freeze period in IT change management?
- To allow developers to catch up on documentation
- To halt all IT operations for system maintenance
- To give the CAB time to review a backlog of requests
- To prevent changes during high-risk periods such as peak business times or audits (Correct answer)
Correct answer: To prevent changes during high-risk periods such as peak business times or audits
Change freeze periods minimize the risk of introducing instability during critical business periods when system reliability is paramount.
Question 50: In software project management, a critical path PRIMARILY helps an IS auditor assess:
- The cost impact of scope changes
- Vendor performance against SLA metrics
- Which tasks, if delayed, will directly extend the project completion date (Correct answer)
- The total number of defects in the system
Correct answer: Which tasks, if delayed, will directly extend the project completion date
The critical path identifies the sequence of dependent tasks with zero float, meaning any delay on these tasks delays the entire project.
Question 51: During a risk assessment, a CISA auditor discovers that a critical system has no documented risk treatment plan. What should the auditor recommend FIRST?
- Immediately shut down the system until a plan is in place
- Transfer the risk to a third-party provider immediately
- Assign a risk owner and develop a formal risk treatment plan (Correct answer)
- Accept the risk and document it in the audit report
Correct answer: Assign a risk owner and develop a formal risk treatment plan
The immediate priority is assigning accountability and creating a formal treatment plan to address the gap in governance.
Question 52: Which party should APPROVE the final DR test plan before testing begins?
- Senior management or the steering committee (Correct answer)
- The external auditor
- The recovery site vendor
- The IT operations manager only
Correct answer: Senior management or the steering committee
Senior management or the steering committee must approve DR test plans to ensure organizational alignment, resource commitment, and accountability.
Question 53: Which security testing technique involves simulating an attacker's behavior to identify exploitable vulnerabilities in a live system?
- Code review
- Vulnerability scanning
- Threat modeling
- Penetration testing (Correct answer)
Correct answer: Penetration testing
Penetration testing actively exploits vulnerabilities in a controlled manner to determine what an attacker could actually achieve, going beyond automated scanning.
Question 54: When reviewing an Agile development project, an IS auditor should be MOST concerned if:
- Sprints are two weeks long instead of four weeks
- Security and compliance requirements are consistently deferred to later sprints (Correct answer)
- Daily standups are held remotely via video conference
- The product backlog is maintained in a digital tool rather than on paper
Correct answer: Security and compliance requirements are consistently deferred to later sprints
Continuously deferring security and compliance work creates technical debt and may result in a system that fails regulatory requirements at launch.
Question 55: The original code was later restored when a malicious programmer changed a production software to alter data. Which of the following would be able to catch the malicious activity the BEST?
- Comparing object code
- Comparing source code
- Reviewing executable and source code integrity
- Reviewing system log files (Correct answer)
Correct answer: Reviewing system log files
System log files record user activities, system events, and changes made to configurations or data. In the event of a malicious programmer altering production software, these logs would provide an audit trail detailing who accessed the system, when the changes occurred, and potentially what modifications were made. This makes reviewing system log files the most effective method for detecting and investigating unauthorized activity and identifying the malicious actor.
Question 56: Can an auditor depend on the audit client's risk estimate for audit planning?
- No. The auditor must perform a risk assessment himself or herself
- Yes, if the risk assessment was performed by a qualified external entity (Correct answer)
- Yes, in all cases
- No. The auditor does not require a risk assessment to develop an audit plan
Correct answer: Yes, if the risk assessment was performed by a qualified external entity
An auditor can rely on a client's risk assessment for audit planning, but only under specific conditions. The assessment must have been performed by a qualified external entity, ensuring objectivity and adherence to professional standards. However, the auditor must still exercise professional skepticism and evaluate the adequacy and appropriateness of the client's assessment before incorporating it into their own audit plan.
Question 57: An IS auditor is reviewing controls over a company's security awareness training program. Which finding would be of GREATEST concern?
- Only 60% of employees completed the annual security awareness training
- Training content has not been updated to reflect new phishing techniques in the past 18 months (Correct answer)
- Training is delivered via an online learning management system
- Training completion is tracked but not linked to HR performance reviews
Correct answer: Training content has not been updated to reflect new phishing techniques in the past 18 months
Outdated training that does not address current attack methods fails to prepare employees for actual threats, undermining the program's effectiveness regardless of completion rates.
Question 58: An IS auditor notes that a company's disaster recovery plan has not been tested since a major cloud migration project was completed one year ago. The PRIMARY risk associated with this finding is that the:
- organization may be out of compliance with industry regulations.
- employees may be unaware of their roles and responsibilities.
- DRP may not be aligned with the current technology infrastructure. (Correct answer)
- cost of a future test will be significantly higher.
Correct answer: DRP may not be aligned with the current technology infrastructure.
Disaster recovery plans must be tested regularly, especially after significant changes to the IT environment, such as a cloud migration. The primary risk of not testing after such a change is that the documented recovery procedures are likely outdated and will not work for the new infrastructure, rendering the plan ineffective in a real disaster.
Question 59: In the context of data classification, which category MOST appropriately describes Social Security Numbers and medical records?
- Public data
- Confidential/restricted data (Correct answer)
- Internal use data
- Unclassified data
Correct answer: Confidential/restricted data
Social Security Numbers and medical records are highly sensitive personally identifiable information (PII) and protected health information (PHI) that require the highest level of data classification and protection controls.
Question 60: During an audit, it is discovered that the organization has not defined its risk appetite. What is the PRIMARY concern for the IS auditor?
- The organization may be overspending on security controls.
- The frequency of risk assessments is likely insufficient.
- Risk mitigation efforts may not be aligned with business objectives. (Correct answer)
- Compliance with industry regulations cannot be achieved.
Correct answer: Risk mitigation efforts may not be aligned with business objectives.
Risk appetite is the amount and type of risk that an organization is willing to pursue or retain. Without a clearly defined risk appetite, there is no strategic guidance for making risk-based decisions. This can lead to a misalignment between risk management activities and the organization's strategic goals and objectives, resulting in either excessive risk-taking or overly cautious behavior that stifles innovation.
Question 61: When performing an IT risk assessment, what does 'threat likelihood' measure?
- The potential damage a threat could cause if it occurs
- The cost of implementing a control to prevent the threat
- The probability that a threat will exploit a vulnerability (Correct answer)
- The number of assets exposed to the threat
Correct answer: The probability that a threat will exploit a vulnerability
Threat likelihood estimates how probable it is that a given threat will actually materialize and exploit an existing vulnerability.
Question 62: During a network audit, an IS auditor finds that SNMP v1 is still in use. The PRIMARY concern is:
- SNMP v1 community strings are transmitted in plaintext (Correct answer)
- SNMP v1 does not support IPv6
- SNMP v1 cannot monitor router interfaces
- SNMP v1 uses too much bandwidth
Correct answer: SNMP v1 community strings are transmitted in plaintext
SNMP v1 community strings (essentially passwords) are sent in cleartext, making them vulnerable to interception.
Question 63: Which metric defines the maximum amount of data an organization can afford to lose in a disaster, measured in time?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
- Mean Time to Repair (MTTR)
Correct answer: Recovery Point Objective (RPO)
RPO defines the point in time to which data must be recovered, representing the maximum acceptable data loss.
Question 64: An organization wants to determine the financial impact of a specific risk scenario. Which formula is MOST relevant?
- ALE = ARO × SLE (Correct answer)
- Control Effectiveness = 1 − Residual Risk
- Risk Score = Likelihood + Impact
- Risk = Threat × Vulnerability
Correct answer: ALE = ARO × SLE
ALE (Annualized Loss Expectancy) = ARO (Annualized Rate of Occurrence) × SLE (Single Loss Expectancy) quantifies expected annual financial loss.
Question 65: During IS audit planning, which document formally authorizes the audit and defines its scope, objectives, and resources?
- Audit charter
- Audit program
- Engagement letter (Correct answer)
- Risk register
Correct answer: Engagement letter
The engagement letter (or audit engagement letter) formally authorizes the audit and outlines scope, objectives, timing, and resource requirements agreed upon between the auditor and management.
Question 66: An IS auditor evaluating a software quality assurance program should expect to find metrics that track:
- Manager approval time for change requests
- Developer coffee consumption and office hours
- Defect density, test coverage, and open defect aging (Correct answer)
- Number of lines of code written per sprint
Correct answer: Defect density, test coverage, and open defect aging
Defect density, test coverage, and defect aging are key quality indicators that reflect the reliability and completeness of testing efforts.
Question 67: A company's IT risk management process identifies a vulnerability but determines no credible threat exploits it. What is the MOST appropriate action?
- Monitor it in case a credible threat emerges (Correct answer)
- Immediately remediate the vulnerability
- Document it and accept the risk without controls
- Escalate to senior management for immediate action
Correct answer: Monitor it in case a credible threat emerges
Without a credible threat, the immediate risk is low, but the vulnerability should be monitored in case the threat landscape changes.
Question 68: During a review of a company's business continuity plan, an IS auditor notes that the plan has not been updated in over three years, despite significant changes in business processes and IT infrastructure. Which of the following is the GREATEST risk associated with this finding?
- The cost of maintaining the outdated plan is wasted.
- The plan may not comply with outdated regulatory requirements.
- The plan may be ineffective in recovering critical operations after a disruption. (Correct answer)
- New employees may not be aware of the plan's existence.
Correct answer: The plan may be ineffective in recovering critical operations after a disruption.
The greatest risk is that the plan is no longer aligned with the current business environment and will fail when executed. Business processes, technology, and personnel change over time, and a BCP must be regularly updated and tested to ensure it remains relevant and effective for recovering the organization's critical functions.
Question 69: During application testing, what is the MAIN purpose of boundary value analysis?
- Testing input values at the edges of valid ranges where defects are most likely (Correct answer)
- Verifying system performance under peak load conditions
- Confirming user interface color schemes meet accessibility standards
- Measuring database query response times
Correct answer: Testing input values at the edges of valid ranges where defects are most likely
Boundary value analysis tests values at, just below, and just above defined input limits, where programming errors are most commonly found.
Question 70: Which of the following BEST describes the purpose of a data loss prevention (DLP) solution?
- Detecting and blocking unauthorized transmission of sensitive data (Correct answer)
- Preventing unauthorized users from logging into systems
- Monitoring network bandwidth utilization
- Encrypting all data stored on endpoint devices
Correct answer: Detecting and blocking unauthorized transmission of sensitive data
DLP solutions detect, monitor, and block the unauthorized exfiltration or transmission of sensitive data across endpoints, networks, and cloud services.
Question 71: A third-party vendor has access to sensitive customer data. Which risk management activity is MOST critical?
- Performing vendor risk assessments and due diligence reviews (Correct answer)
- Conducting an annual penetration test on internal systems
- Implementing multi-factor authentication for employees
- Encrypting all internal databases
Correct answer: Performing vendor risk assessments and due diligence reviews
Third-party access requires formal vendor risk assessments to evaluate whether the vendor's controls adequately protect the organization's data.
Question 72: Within ISACA's framework, which component provides IS auditors with specific step-by-step procedures for conducting an audit?
- Standards
- Guidelines
- Tools and Techniques (Correct answer)
- Audit charters
Correct answer: Tools and Techniques
Tools and Techniques are practical resources that provide IS auditors with specific procedures, checklists, and methods to apply the Standards and Guidelines.
Question 73: During a post-implementation review of a new CRM system, an IS auditor's PRIMARY objective is to determine whether:
- the project was completed within the allocated budget and timeframe.
- all identified bugs and defects from the testing phase have been resolved.
- the system has met the business objectives and delivers the expected benefits. (Correct answer)
- end-users are satisfied with the new system's user interface and performance.
Correct answer: the system has met the business objectives and delivers the expected benefits.
The primary purpose of a post-implementation review is to assess whether the system has achieved its intended business objectives and delivered the value proposed in the business case. While budget, bug resolution, and user satisfaction are important factors to review, the ultimate measure of success is the system's ability to support and improve business processes as originally intended.
Question 74: An IS auditor finds that developers have direct access to the production environment. The MOST significant risk is:
- Developer productivity may decrease
- Slower deployment cycles due to access conflicts
- Increased help desk ticket volume
- Unauthorized or untested changes could be made directly to production (Correct answer)
Correct answer: Unauthorized or untested changes could be made directly to production
Direct developer access to production breaks segregation of duties and enables unauthorized modifications that bypass change control processes.
Question 75: When planning an IS audit for a regulated financial institution, which external requirement should MOST influence the audit plan?
- The IT vendor's recommended audit procedures
- Applicable regulatory requirements and compliance mandates (e.g., FFIEC, SOX) (Correct answer)
- Competitor audit practices
- The organization's internal IT strategy document
Correct answer: Applicable regulatory requirements and compliance mandates (e.g., FFIEC, SOX)
Regulatory requirements define mandatory compliance areas that must be covered in the audit plan, taking precedence over internal preferences or vendor guidance.
Question 76: Under the US Health Insurance Portability and Accountability Act (HIPAA), covered entities must implement which type of controls to protect electronic Protected Health Information (ePHI) stored in databases?
- Administrative, physical, and technical safeguards (Correct answer)
- Technical controls only
- Contractual agreements with patients only
- Only physical security controls
Correct answer: Administrative, physical, and technical safeguards
HIPAA's Security Rule requires covered entities to implement a combination of administrative safeguards (policies), physical safeguards (facility controls), and technical safeguards (encryption, access controls) to protect ePHI.
Question 77: Which of the following BEST represents the relationship between risk tolerance and risk appetite?
- Risk appetite applies to individual risks; tolerance applies to overall strategy
- Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it (Correct answer)
- Risk tolerance and risk appetite are interchangeable terms
- Risk tolerance is broader than risk appetite
Correct answer: Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it
Risk appetite is the overall level of risk an organization is willing to pursue, while risk tolerance is the acceptable variance around that appetite for specific risks.
Question 78: Which of the following BEST describes the purpose of a control self-assessment (CSA)?
- To replace the external audit process
- To evaluate only financial controls
- To provide an independent third-party opinion
- To allow management and staff to assess controls collaboratively (Correct answer)
Correct answer: To allow management and staff to assess controls collaboratively
CSA is a technique where management and staff work together to assess the effectiveness of controls in their own areas.
Question 79: Which phase of the SDLC presents the greatest opportunity for IS auditors to influence security and control design?
- Implementation
- Maintenance
- Requirements and design (Correct answer)
- Testing
Correct answer: Requirements and design
Auditor involvement during requirements and design is most effective because changes are least costly at this early stage.
Question 80: When auditing a VPN implementation, an IS auditor should FIRST verify that:
- Strong encryption algorithms and multi-factor authentication are enforced (Correct answer)
- VPN connection logs are deleted after 30 days
- All employees are required to use VPN regardless of location
- VPN software licenses are current
Correct answer: Strong encryption algorithms and multi-factor authentication are enforced
Strong encryption and MFA are the foundational controls that protect VPN tunnels from interception and unauthorized access.
Question 81: During IS audit planning, an auditor reviews organizational charts and job descriptions. The PRIMARY purpose is to:
- Understand segregation of duties and the assignment of IT responsibilities (Correct answer)
- Evaluate employee performance
- Identify potential fraud perpetrators
- Determine headcount for staffing risk assessment
Correct answer: Understand segregation of duties and the assignment of IT responsibilities
Reviewing organizational charts and job descriptions helps the auditor understand how IT responsibilities are assigned and whether proper segregation of duties exists.
Question 82: An organization uses Key Risk Indicators (KRIs). What is the PRIMARY purpose of KRIs?
- To provide early warning signals of increasing risk exposure (Correct answer)
- To measure the effectiveness of IT controls after an incident
- To document risk scenarios for audit purposes
- To replace the need for a formal risk assessment
Correct answer: To provide early warning signals of increasing risk exposure
KRIs act as leading indicators that signal when risk levels are approaching thresholds, enabling proactive management.
Question 83: During IS audit planning, the concept of 'audit universe' refers to:
- The total number of staff available for audit work
- The set of regulatory requirements applicable to the organization
- The complete inventory of auditable entities from which the audit plan is derived (Correct answer)
- All potential risks identified across the organization
Correct answer: The complete inventory of auditable entities from which the audit plan is derived
The audit universe is the comprehensive inventory of all auditable entities — systems, processes, departments — that forms the basis for developing a risk-based audit plan.
Question 84: Which firewall rule principle states that anything not explicitly permitted should be denied?
- Default permit
- Defense in depth
- Least privilege
- Default deny (implicit deny) (Correct answer)
Correct answer: Default deny (implicit deny)
An implicit deny rule drops all traffic not explicitly allowed, minimizing exposure to unknown or unauthorized connections.
Question 85: Which metric BEST measures the effectiveness of an IT risk management program over time?
- Total IT security budget spent per year
- Reduction in residual risk levels across the risk register (Correct answer)
- Number of security policies reviewed annually
- Number of vulnerabilities discovered per scan
Correct answer: Reduction in residual risk levels across the risk register
Tracking reductions in residual risk levels directly measures whether the risk management program is achieving its goal of lowering actual risk exposure.
Question 86: An IS auditor is evaluating controls over privileged accounts in a large enterprise. Which of the following is the MOST effective control for mitigating the risks associated with administrator access?
- Enforcing a complex password policy for all administrator accounts.
- Requiring all administrators to sign a nondisclosure agreement (NDA).
- Implementing a Privileged Access Management (PAM) solution with session monitoring. (Correct answer)
- Conducting annual background checks on all system administrators.
Correct answer: Implementing a Privileged Access Management (PAM) solution with session monitoring.
A Privileged Access Management (PAM) solution is the most effective and comprehensive control. It provides a centralized mechanism to vault credentials, enforce least privilege, implement just-in-time access, and, most importantly, monitor and record privileged sessions, which creates strong accountability and detectability.
Question 87: Which of the following is the PRIMARY objective of a structured walkthrough during system development?
- Peer review of code or design to identify defects early (Correct answer)
- Assigning blame for coding errors to individual developers
- Documenting project budget expenditures
- Training end users on the new system
Correct answer: Peer review of code or design to identify defects early
Structured walkthroughs are formal peer review sessions designed to detect errors in design, code, or documentation before they propagate to later phases.
Question 88: During a security audit, an IS auditor finds that developers have direct write access to the production database. What is the PRIMARY concern?
- The database may not be adequately backed up
- Direct production access bypasses change management controls and increases insider threat risk (Correct answer)
- Developers lack the expertise to manage production data safely
- Developers may slow down production performance with poorly optimized queries
Correct answer: Direct production access bypasses change management controls and increases insider threat risk
Direct developer access to production bypasses change management and audit trails, enabling unauthorized data modification and violating separation of duties.
Question 89: An IS auditor is reviewing a change management process. Which control BEST ensures only authorized changes reach production?
- Automated code compilation logs
- Mandatory code comments in all programs
- Weekly status meetings with the project manager
- Segregation of duties between developers and production migration staff (Correct answer)
Correct answer: Segregation of duties between developers and production migration staff
Segregation of duties prevents developers from promoting their own code, ensuring an independent review before production migration.
Question 90: An IS auditor finds that network infrastructure devices have not received security patches in 18 months. The BEST recommendation is to:
- Implement a formal patch management process with defined SLAs for critical devices (Correct answer)
- Accept the risk since patches may disrupt network operations
- Disable the devices until patches are applied
- Require vendors to patch devices remotely without testing
Correct answer: Implement a formal patch management process with defined SLAs for critical devices
A formal patch management process with defined timelines ensures vulnerabilities are addressed systematically without unnecessary disruption.
Question 91: Which of the following BEST describes the purpose of a program change log?
- To provide an audit trail of all modifications made to production programs (Correct answer)
- To record user access requests to the system
- To track software licensing compliance
- To document developer time spent on each task
Correct answer: To provide an audit trail of all modifications made to production programs
A program change log maintains a chronological record of who changed what and when, forming the audit trail for production program modifications.
Question 92: Which of the following network redundancy configurations provides the HIGHEST availability for a critical link?
- Periodic tape backup of router configurations
- Cold standby requiring manual activation
- Load balancing across identical links with no failover
- Hot standby with automatic failover (Correct answer)
Correct answer: Hot standby with automatic failover
Hot standby with automatic failover switches traffic to the backup link instantly without human intervention, maximizing uptime.
Question 93: What is the PRIMARY goal of IT risk communication within an organization?
- To transfer risk responsibility to risk owners
- To document all risks in a central repository
- To satisfy external regulatory requirements
- To ensure decision-makers have timely, accurate risk information (Correct answer)
Correct answer: To ensure decision-makers have timely, accurate risk information
Risk communication ensures that relevant stakeholders receive accurate information to make informed decisions about risk response.
Question 94: Which testing type validates that a new system does not adversely affect existing integrated systems?
- Parallel testing
- Regression testing (Correct answer)
- Unit testing
- Stress testing
Correct answer: Regression testing
Regression testing re-runs prior test cases to confirm that new changes have not broken existing functionality in interconnected systems.
Question 95: An IS auditor is developing a risk-based audit plan. Which of the following is the FIRST step the auditor should perform?
- Interview senior management to understand their perspective on risk.
- Develop the audit scope and objectives for specific high-risk areas.
- Review the findings and workpapers from the previous year's audit.
- Identify the organization's critical assets and business processes. (Correct answer)
Correct answer: Identify the organization's critical assets and business processes.
The foundational step in a risk-based audit approach is to understand what is most important to the organization. By identifying critical assets and key business processes, the auditor can then effectively assess the threats and vulnerabilities associated with them to determine areas of highest risk.
Question 96: During a post-implementation review, an IS auditor finds that user acceptance testing (UAT) was bypassed due to project deadline pressure. What is the PRIMARY risk?
- Undiscovered defects may reach production (Correct answer)
- Development team morale decreases
- Budget overruns in future phases
- Project documentation becomes incomplete
Correct answer: Undiscovered defects may reach production
Skipping UAT means business requirements may not be met and defects unknown to users can propagate into the live environment.
Question 97: Which of the following BEST describes the purpose of a risk appetite statement?
- To document risk mitigation strategies
- To define the level of risk the organization is willing to accept (Correct answer)
- To list all identified risks in the organization
- To assign risk owners to each identified risk
Correct answer: To define the level of risk the organization is willing to accept
A risk appetite statement articulates how much risk the board and senior management are willing to tolerate in pursuit of business objectives.
Question 98: Which protocol provides encrypted remote administration of network devices and is preferred over Telnet?
- HTTP
- SNMP v2
- SSH (Correct answer)
- FTP
Correct answer: SSH
SSH (Secure Shell) encrypts the entire session, whereas Telnet transmits credentials and data in plaintext.
Question 99: An IS auditor reviewing network security finds that firewall rules have not been reviewed in three years. What is the MOST significant risk?
- Increased hardware maintenance costs
- Outdated rules may allow unauthorized access or block legitimate traffic (Correct answer)
- Difficulty generating compliance reports
- Network performance degradation
Correct answer: Outdated rules may allow unauthorized access or block legitimate traffic
Stale firewall rules can contain obsolete permissions that expose the network to threats or create operational issues.
Question 100: An IS auditor reviews logs and finds that a privileged administrator account was used to access financial records outside of business hours with no change ticket. What should the auditor do FIRST?
- Report the incident to the board of directors
- Require the administrator to change their password
- Determine whether the access was authorized and investigate the business justification (Correct answer)
- Immediately disable the administrator account
Correct answer: Determine whether the access was authorized and investigate the business justification
The auditor should first gather facts by determining whether the after-hours access was authorized before drawing conclusions or escalating the finding.
Question 101: ISO 20000 is the international standard for which domain?
- Risk management processes
- IT service management (Correct answer)
- Information security management
- Business continuity management
Correct answer: IT service management
ISO 20000 is the international standard specifying requirements for an IT service management system (SMS), aligning closely with ITIL practices.
Question 102: Which of the following change management artifacts provides the BEST evidence for an IS audit of compliance with approved procedures?
- Meeting minutes from quarterly IT governance reviews
- System performance dashboards from the change window
- Developer training completion records
- Completed change tickets with approval signatures and test results (Correct answer)
Correct answer: Completed change tickets with approval signatures and test results
Complete change tickets with documented approvals and test results provide direct evidence that each change followed the required authorization and validation steps.
Question 103: During IS audit planning, which of the following is the BEST source for understanding an organization's IT risk posture?
- Industry benchmarking reports
- Vendor documentation for installed software
- Prior year's financial statements
- The organization's enterprise risk management (ERM) framework and IT risk register (Correct answer)
Correct answer: The organization's enterprise risk management (ERM) framework and IT risk register
The ERM framework and IT risk register document the organization's identified risks, their likelihood and impact, and existing mitigations — making them the primary source for risk-based audit planning.
Question 104: An IS auditor reviewing software procurement should FIRST verify that the vendor's product:
- Is widely used by competitors in the same industry
- Supports the latest programming language standards
- Has the lowest licensing cost available
- Meets the organization's defined functional and security requirements (Correct answer)
Correct answer: Meets the organization's defined functional and security requirements
Alignment with documented requirements is the foundational criterion before evaluating cost, market share, or technology features.
Question 105: An IS auditor planning an audit of the software development lifecycle (SDLC) should PRIMARILY focus on which phase for the highest control risk?
- Production deployment phase (Correct answer)
- Maintenance phase
- Requirements gathering phase
- Testing phase
Correct answer: Production deployment phase
Production deployment is the highest-risk SDLC phase because unauthorized or untested code moving to production can directly impact business operations and data integrity.
Question 106: What could happen if an IS auditor breaks the ISACA Code of Professional Ethics when they are members of ISACA and CISA certified?
- Fines
- Termination of employment
- Imprisonment
- Loss of ISACA certifications (Correct answer)
Correct answer: Loss of ISACA certifications
The ISACA Code of Professional Ethics outlines the mandatory standards of professional conduct for all ISACA members and certification holders. A violation of this code can lead to disciplinary actions, with the most severe consequence for certified individuals being the suspension or revocation of their ISACA certifications, such as CISA. This ensures the integrity and credibility of the ISACA professional community.
Question 107: Which attack does port security on a switch PRIMARILY mitigate?
- MAC flooding and unauthorized device connections (Correct answer)
- SQL injection
- Phishing emails
- Denial-of-service via ICMP floods
Correct answer: MAC flooding and unauthorized device connections
Port security limits the number of MAC addresses per port, preventing MAC flooding attacks that can overflow CAM tables.
Question 108: Which of the following BEST describes a structured walkthrough in the context of DR testing?
- A live failover to the recovery site with production traffic
- An unannounced test to evaluate team readiness
- A review where team members individually verify their portions of the DR plan for accuracy (Correct answer)
- A vendor-led audit of the recovery facility
Correct answer: A review where team members individually verify their portions of the DR plan for accuracy
A structured walkthrough has each team member review their section of the DR plan and confirm it is accurate and feasible, without activating any systems.
Question 109: When planning an IS audit, an auditor discovers that the organization recently experienced a major system migration. How should this affect the audit plan?
- Postpone the audit until the system stabilizes
- Reduce scope since new systems have fewer legacy issues
- Increase audit scope to cover migration risks and residual vulnerabilities (Correct answer)
- Focus only on pre-migration controls
Correct answer: Increase audit scope to cover migration risks and residual vulnerabilities
A recent system migration increases inherent risk and should prompt the auditor to expand scope to cover migration-related risks, data integrity issues, and control gaps.
Question 110: When auditing database access controls, a CISA auditor should confirm that the principle of least privilege is applied by verifying:
- Shared service accounts are used to simplify management
- Read access is unrestricted to improve productivity
- All users have DBA-level access for flexibility
- Users are granted only the minimum access required for their job function (Correct answer)
Correct answer: Users are granted only the minimum access required for their job function
The principle of least privilege requires granting users only the minimum database permissions necessary to perform their specific job functions, reducing the risk of unauthorized data access or modification.
Question 111: An IS auditor discovers that a shared administrator account is used by several network engineers to manage critical infrastructure. Which of the following is the GREATEST risk associated with this practice?
- Violation of the principle of 'need-to-know'.
- Inability to trace specific actions to an individual engineer. (Correct answer)
- Complexity in managing access when an engineer changes roles.
- Increased likelihood of password compromise due to social engineering.
Correct answer: Inability to trace specific actions to an individual engineer.
The primary risk of using shared accounts is the loss of accountability. If a malicious or erroneous action occurs, it is impossible to determine which specific individual performed the action because the audit logs will only show the shared account name.
Question 112: Which of the following is the PRIMARY purpose of an IS audit charter?
- To outline the annual budget and resource allocation for the IS audit function.
- To document the detailed audit procedures and testing methodologies.
- To list the specific systems and applications to be audited during the fiscal year.
- To establish the authority, scope, and responsibilities of the IS audit function. (Correct answer)
Correct answer: To establish the authority, scope, and responsibilities of the IS audit function.
The audit charter is a high-level document that establishes the authority, independence, scope, and overall responsibility of the audit function. It is approved by the highest level of management and the audit committee and provides the foundation for all audit activities.
Question 113: Which access control technique would BEST prevent a database administrator from reading sensitive payroll data while still allowing them to perform administrative functions?
- Password complexity requirements
- Data masking or column-level encryption (Correct answer)
- Account lockout policies
- Two-factor authentication
Correct answer: Data masking or column-level encryption
Data masking or column-level encryption restricts visibility of sensitive data even from privileged DBAs performing legitimate admin tasks.
Question 114: Which risk treatment option involves transferring the financial consequences of a risk to a third party?
- Risk mitigation
- Risk avoidance
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to another party, such as through insurance or outsourcing contracts.
Question 115: An IS auditor is evaluating the IT risk assessment process for a financial services company. The auditor finds that the company uses a qualitative approach, categorizing risks as 'High,' 'Medium,' and 'Low.' The PRIMARY disadvantage of this approach is that it:
- is too complex and time-consuming for most organizations.
- makes it difficult to perform a cost-benefit analysis for countermeasures. (Correct answer)
- requires specialized software tools to implement effectively.
- is not compliant with international standards like ISO 27005.
Correct answer: makes it difficult to perform a cost-benefit analysis for countermeasures.
A qualitative risk assessment uses subjective judgment to assess the likelihood and impact of risk, often using descriptive categories (e.g., High, Medium, Low). While useful for prioritizing risks, its primary weakness is the lack of quantitative data (e.g., monetary values). This subjectivity makes it difficult to conduct a rigorous cost-benefit analysis when evaluating the financial viability of implementing specific controls.
Question 116: During the audit planning phase for a financial institution, an IS auditor discovers that a new online banking platform was implemented without a formal risk assessment. Which of the following is the MOST appropriate action for the auditor to take?
- Recommend that management commission an independent risk assessment post-implementation.
- Expand the audit scope to include a thorough risk assessment of the new platform. (Correct answer)
- Immediately report a significant finding of non-compliance to the audit committee.
- Proceed with the original audit plan but note the lack of a risk assessment in the final report.
Correct answer: Expand the audit scope to include a thorough risk assessment of the new platform.
The discovery of a significant change to the IT environment, especially one implemented without a risk assessment, requires the auditor to adjust the audit plan. Expanding the scope to assess the risks associated with the new platform is the most proactive and responsible action to ensure potential vulnerabilities are identified and evaluated.
Question 117: Which of the following BEST reduces the risk of unauthorized wireless network access?
- Enabling WEP encryption on all access points
- Using WPA3 with strong pre-shared keys and 802.1X authentication (Correct answer)
- Placing access points near exterior walls for better signal
- Broadcasting the SSID to help users locate the network
Correct answer: Using WPA3 with strong pre-shared keys and 802.1X authentication
WPA3 with 802.1X provides enterprise-grade authentication and strong encryption, making unauthorized access significantly harder.
Question 118: Which of the following testing types is specifically designed to verify that different system components work together as a single, combined unit?
- Unit testing
- User Acceptance Testing (UAT)
- Integration testing (Correct answer)
- Stress testing
Correct answer: Integration testing
Integration testing is performed after unit testing and focuses on exposing faults in the interaction between integrated modules. Its primary purpose is to verify that different components, once combined, function together correctly as a group. Unit testing focuses on individual components in isolation, stress testing evaluates performance under heavy load, and UAT confirms the system meets user needs.
Question 119: An IS auditor reviewing system retirement (decommissioning) should PRIMARILY confirm that:
- Data retention requirements are met and data is migrated or archived per policy (Correct answer)
- The retired system's source code is deleted from all media
- New system licenses have been purchased to replace the old ones
- The project manager has signed the project closure document
Correct answer: Data retention requirements are met and data is migrated or archived per policy
Compliance with data retention policies and proper archiving or migration of historical data is the primary risk when retiring a system.
Question 120: During an audit, an IS auditor finds that privileged accounts are used for routine daily tasks by IT staff. What is the PRIMARY recommendation?
- Require manager approval for each privileged account use
- Increase the complexity of privileged account passwords
- Implement separate standard accounts for routine tasks (Correct answer)
- Enable additional logging for privileged accounts only
Correct answer: Implement separate standard accounts for routine tasks
Privileged accounts should be used only when elevated rights are needed; daily tasks should use standard accounts to reduce exposure risk.
Question 121: An IS auditor reviewing change management controls notes that the organization does not track the time between change approval and implementation. Why is this a concern?
- Developers may forget the technical details of an approved change over time
- The CAB cannot calculate its approval turnaround KPI
- Change scheduling conflicts cannot be identified without time tracking
- Approved changes may be implemented after their authorization has effectively expired (Correct answer)
Correct answer: Approved changes may be implemented after their authorization has effectively expired
If changes are implemented long after approval, system conditions may have changed, rendering the original risk assessment and approval invalid.
Question 122: During a network security audit, an IS auditor observes that the organization uses a screened subnet (DMZ) architecture. What is the PRIMARY security benefit of this design?
- It provides redundancy for critical network infrastructure
- It eliminates the need for host-based firewalls on internal servers
- It encrypts all traffic between the internet and internal systems
- It isolates publicly accessible services from the internal network (Correct answer)
Correct answer: It isolates publicly accessible services from the internal network
A DMZ places publicly accessible servers in an isolated zone, preventing direct access from the internet to the internal network if a DMZ host is compromised.
Question 123: After completing a DR test, management decides the results do not need to be shared with the board. An IS auditor should flag this because:
- The board needs to personally restore backup systems
- The board is responsible for approving all technical configurations
- Board-level oversight of DR program effectiveness is a governance best practice (Correct answer)
- DR test results must be published publicly under US law
Correct answer: Board-level oversight of DR program effectiveness is a governance best practice
Governance frameworks such as COBIT and ISO 22301 require that DR program results be reported to senior leadership and the board to ensure appropriate oversight of organizational resilience.
Question 124: A company outsources its application development to a third-party vendor. Which control is MOST important for the IS auditor to verify?
- The vendor's office is in the same time zone
- Development staff turnover is below industry average
- Contractual rights to audit the vendor and review deliverables (Correct answer)
- The vendor uses the same programming language as internal staff
Correct answer: Contractual rights to audit the vendor and review deliverables
Contractual audit rights ensure the organization retains oversight of vendor activities, code quality, and security practices throughout the engagement.
Question 125: An IS auditor is reviewing an organization's IT risk management process. Which of the following is the MOST critical first step in this process?
- Implementing security controls.
- Identifying and classifying information assets. (Correct answer)
- Developing risk response plans.
- Conducting a business impact analysis (BIA).
Correct answer: Identifying and classifying information assets.
The foundational step in any IT risk management process is to understand what needs to be protected. This involves identifying all information assets and classifying them based on their value and sensitivity to the organization. Without this, it is impossible to effectively assess threats, vulnerabilities, and potential impacts, or to select appropriate risk responses.
Question 126: The COSO Internal Control — Integrated Framework is primarily designed to help organizations with which concern?
- Internal control and enterprise risk management (Correct answer)
- Delivering IT services efficiently
- Network security architecture
- Agile software development practices
Correct answer: Internal control and enterprise risk management
COSO is a widely adopted framework for designing, implementing, and evaluating internal control and enterprise risk management across an organization.
Question 127: During a review of an organization's network security, an IS auditor finds that firewall rules have not been reviewed for three years and contain numerous rules allowing 'any' traffic. What is the PRIMARY risk?
- Network administrators may have difficulty managing a large rule set
- The firewall vendor may not support firmware updates for older rule configurations
- Overly permissive rules may allow unauthorized traffic that should be blocked (Correct answer)
- Firewall performance may degrade due to excessive rule sets
Correct answer: Overly permissive rules may allow unauthorized traffic that should be blocked
Overly permissive firewall rules—especially those allowing 'any' traffic—undermine network segmentation and may permit attackers or malware to move freely across the network.
Question 128: During a network review, an auditor finds that network administrators share a single privileged account. This PRIMARILY violates the principle of:
- Least privilege for end users
- Defense in depth
- Non-repudiation and individual accountability (Correct answer)
- Network segmentation
Correct answer: Non-repudiation and individual accountability
Shared accounts make it impossible to attribute actions to specific individuals, undermining accountability and audit trails.
Question 129: During a SDLC audit, an IS auditor notices that requirements sign-off was obtained from IT management only, excluding business users. This represents a weakness in:
- Testing environment setup
- Requirements validation and stakeholder engagement (Correct answer)
- Project budgeting controls
- Technical architecture review
Correct answer: Requirements validation and stakeholder engagement
Requirements must be approved by business stakeholders who will use the system, not just IT, to ensure the solution meets actual business needs.
Question 130: Which of the following BEST describes the purpose of a Business Impact Analysis (BIA)?
- To quantify the impact of disruptions and prioritize recovery of critical functions (Correct answer)
- To identify the probability of each type of disaster occurring
- To document recovery procedures for critical systems
- To test the effectiveness of existing backup procedures
Correct answer: To quantify the impact of disruptions and prioritize recovery of critical functions
A BIA quantifies financial and operational impacts of disruptions and prioritizes which functions must be restored first.
Question 131: An IS auditor reviewing network diagrams notices that production and development environments share the same network segment. The MAIN risk is:
- Higher infrastructure costs for the organization
- Potential for development activity to compromise production systems (Correct answer)
- Slower network performance in production
- Difficulty in assigning IP addresses to new devices
Correct answer: Potential for development activity to compromise production systems
Mixing production and development on the same segment can allow vulnerabilities or misconfigurations in dev to impact live systems.
Question 132: An IS auditor is planning a review of access controls. The PRIMARY reason for performing a preliminary survey is to:
- Identify all control deficiencies before fieldwork begins
- Obtain sufficient understanding of the environment to develop audit procedures (Correct answer)
- Document findings for the audit report
- Replace the need for detailed testing of controls
Correct answer: Obtain sufficient understanding of the environment to develop audit procedures
A preliminary survey provides the auditor with enough understanding of the systems, processes, and environment to design appropriate and targeted audit procedures.
Question 133: An organization is implementing Zero Trust Architecture. Which core principle does this model rely on for logical access controls?
- Grant broad access to reduce authentication friction
- Verify every access request regardless of network location (Correct answer)
- Use perimeter firewalls as the primary access control
- Trust all internal network traffic implicitly
Correct answer: Verify every access request regardless of network location
Zero Trust operates on 'never trust, always verify,' requiring authentication and authorization for every access attempt regardless of source.
Question 134: An Intrusion Prevention System (IPS) differs from an IDS primarily because an IPS can:
- Generate alerts for suspicious activity
- Log network traffic for forensic analysis
- Actively block or drop malicious traffic in real time (Correct answer)
- Perform vulnerability scans on endpoints
Correct answer: Actively block or drop malicious traffic in real time
An IPS sits inline with traffic and can actively block threats, whereas an IDS only monitors and alerts.
Question 135: An IS auditor is evaluating DR test documentation. Which finding would be MOST concerning?
- One minor system was not included in the scope
- Test results are undated and lack signatures from responsible parties (Correct answer)
- Test results include minor deviations from the plan
- The test took slightly longer than the RTO
Correct answer: Test results are undated and lack signatures from responsible parties
Undated and unsigned test records lack the basic governance controls needed to demonstrate accountability and cannot serve as reliable audit evidence.
Question 136: An IS auditor is reviewing change management controls at a financial institution. The HIGHEST risk finding would be:
- Some minor changes are processed without full CAB sign-off
- Developers can deploy to production without operations team involvement (Correct answer)
- CAB meetings occur weekly instead of bi-weekly
- Change windows occasionally extend past scheduled times
Correct answer: Developers can deploy to production without operations team involvement
Developer access to production deployment eliminates the separation of duties between development and operations, a critical control in regulated environments.
Question 137: When planning an IS audit, an auditor should review the organization's IT policies, standards, and procedures to:
- design specific substantive tests to detect fraud.
- understand the control environment and established control objectives. (Correct answer)
- evaluate the technical competence of the IT staff.
- determine the required sample sizes for compliance testing.
Correct answer: understand the control environment and established control objectives.
Reviewing governance documents like policies, standards, and procedures gives the auditor a clear understanding of management's intent and the established control framework. This forms the basis for evaluating the adequacy and effectiveness of internal controls.
Question 138: What is the PRIMARY purpose of conducting periodic user access reviews?
- To document all user login activity
- To enforce password complexity policies
- To measure system performance under load
- To identify and remove excessive or inappropriate access rights (Correct answer)
Correct answer: To identify and remove excessive or inappropriate access rights
Access reviews ensure access rights remain appropriate as roles change, preventing accumulation of unnecessary privileges over time.
Question 139: An IS auditor is reviewing IT risk management practices. Which finding represents the MOST significant control gap?
- Risk register entries lack a target remediation date
- Risk owners have not formally acknowledged their responsibilities
- Risk scenarios are not linked to specific business processes (Correct answer)
- Risk assessments are performed every 18 months instead of annually
Correct answer: Risk scenarios are not linked to specific business processes
Risk scenarios disconnected from business processes cannot be properly prioritized or mitigated because their business impact is unknown.
Question 140: A financial institution is designing the logical access controls for its new online banking platform. To provide strong assurance of user identity, which of the following should be the MINIMUM requirement for customer authentication?
- A user ID combined with a security question.
- A complex password that changes every 90 days.
- Biometric authentication, such as a fingerprint scan.
- Multi-factor authentication (MFA). (Correct answer)
Correct answer: Multi-factor authentication (MFA).
Multi-factor authentication (MFA) is the industry standard and best practice for providing strong authentication. It requires users to present two or more different types of credentials (e.g., something they know, something they have, something they are), making it significantly harder for unauthorized users to gain access even if one factor is compromised.
Question 141: A CISA auditor reviewing network segmentation should PRIMARILY verify that:
- Wireless and wired networks share the same subnet
- All systems reside on a single flat network
- Critical systems are isolated in separate network zones (Correct answer)
- Firewalls are only deployed at the network perimeter
Correct answer: Critical systems are isolated in separate network zones
Proper network segmentation places critical systems in isolated zones to limit the blast radius of a breach.
Question 142: An IS auditor is evaluating the adequacy of an organization's BCP. Which of the following would provide the MOST assurance that the plan is effective?
- A signed attestation from management that the plan is complete
- Documented results from a recent successful full-scale test (Correct answer)
- Certification that the plan was reviewed by a consulting firm
- Evidence that all employees have read and acknowledged the plan
Correct answer: Documented results from a recent successful full-scale test
Actual test results demonstrating that recovery objectives were met provide the strongest evidence of BCP effectiveness.
Question 143: In a risk-based audit approach, the IS auditor's decisions on the nature, timing, and extent of testing should be PRIMARILY based on the:
- previous year's audit findings and recommendations.
- complexity of the organization's IT environment.
- availability of skilled audit staff and resources.
- assessment of inherent and control risks. (Correct answer)
Correct answer: assessment of inherent and control risks.
A risk-based approach requires the auditor to focus resources on areas with the greatest potential for material misstatement or control failure. The assessment of inherent risk (the susceptibility of an area to error) and control risk (the risk that controls will fail to prevent or detect an error) is the key driver for determining how, when, and how much testing is needed.
Question 144: During testing, a developer discovers a critical defect but the project manager instructs the team to proceed to production anyway. The IS auditor's BEST response is to:
- Rewrite the affected module independently
- Accept the decision since it is management's prerogative
- Document the risk and escalate to senior management (Correct answer)
- Immediately shut down the project
Correct answer: Document the risk and escalate to senior management
The auditor's role is to document findings and escalate unresolved risks through proper governance channels, not to override management decisions unilaterally.
Question 145: Which of the following BEST describes a risk scenario used in IT risk management frameworks like COBIT?
- A description of a past security incident
- A financial model that calculates potential losses
- A list of controls that prevent a specific risk
- A narrative that connects a threat actor, event, and business impact (Correct answer)
Correct answer: A narrative that connects a threat actor, event, and business impact
A risk scenario in COBIT combines a threat source, vulnerability, and resulting business impact into a coherent narrative for assessment purposes.
Question 146: A penetration test differs from a vulnerability assessment primarily because a penetration test:
- Only scans for known CVEs using automated tools
- Generates a compliance report for auditors
- Is conducted exclusively by internal staff
- Actively attempts to exploit discovered vulnerabilities (Correct answer)
Correct answer: Actively attempts to exploit discovered vulnerabilities
Penetration testing goes beyond identifying vulnerabilities by actually attempting to exploit them to determine real-world impact.
Question 147: An organization wants to implement a logical access model where permissions are assigned to groups based on job functions, rather than to individual users. Which of the following access control models BEST meets this requirement?
- Attribute-Based Access Control (ABAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is specifically designed to assign permissions to roles that correspond to business functions. Users are then assigned to these roles, which simplifies access management, enforces the principle of least privilege, and improves scalability.
Question 148: During an IS audit, an auditor discovers that a control is functioning as intended but the risk it mitigates has already been accepted by management. What is the BEST course of action?
- Document the accepted risk and note the control as redundant in the report (Correct answer)
- Escalate to the board of directors
- Recommend removing the control immediately
- Report the control as effective and move on
Correct answer: Document the accepted risk and note the control as redundant in the report
Auditors should document management-accepted risks and flag controls that may be redundant relative to the risk posture.
Question 149: When should IS audit planning ideally begin relative to the audit fieldwork?
- Well in advance to allow adequate preparation, risk assessment, and resource allocation (Correct answer)
- Only after the prior audit's findings are remediated
- Immediately before fieldwork starts
- After preliminary interviews with management are complete
Correct answer: Well in advance to allow adequate preparation, risk assessment, and resource allocation
Planning should begin well in advance of fieldwork to allow time for risk assessment, scoping, resource scheduling, and coordination with auditees.
Question 150: Which factor would MOST likely cause an IS auditor to increase the sample size during audit planning?
- High control risk (Correct answer)
- Low population size
- Low inherent risk
- Strong prior audit results
Correct answer: High control risk
High control risk means existing controls may not be effective, so the auditor needs a larger sample to gain sufficient confidence in the audit conclusions.
Question 151: During a BCP test, an organization discovers its backup tapes contain corrupted data. What control failure does this PRIMARILY represent?
- Failure to validate backup integrity through regular restoration testing (Correct answer)
- Insufficient offsite storage of backup media
- Inadequate encryption of backup data
- Lack of a documented recovery procedure
Correct answer: Failure to validate backup integrity through regular restoration testing
Backups must be regularly tested through actual restoration to verify data integrity; storing backups without testing them is a critical control gap.
Question 152: In IS audit planning, materiality is BEST defined as:
- The minimum number of control failures that trigger a finding
- The dollar threshold above which errors must be reported
- The significance of a matter in the context of the audit objectives and stakeholder decision-making (Correct answer)
- The risk level assigned to a specific audit area
Correct answer: The significance of a matter in the context of the audit objectives and stakeholder decision-making
Materiality refers to the significance or importance of information, errors, or omissions in the context of the financial statements or audit objectives that could influence stakeholder decisions.
ISACA CISA Certified Information Systems Auditor Exam
The ISACA Certified Information Systems Auditor (CISA) Exam covers IS audit planning, IT governance, risk management, system development, change management controls, business continuity, disaster recovery, logical access controls, network security, and data management across five domains.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds