โ† All CISA Flashcard Decks

Certified Information Systems Auditor Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Information Systems Auditor flashcards as text
  1. An IS auditor is reviewing a disaster recovery plan (DRP). Which metric defines the maximum acceptable time to restore a system after a disruption?

    Answer: Recovery Time Objective (RTO)

    RTO is the target time within which a business process must be restored after a disaster to avoid unacceptable consequences.

  2. Which type of access control enforces permissions based on the sensitivity label of the resource and the clearance level of the user?

    Answer: Mandatory Access Control (MAC)

    MAC uses sensitivity labels and clearance levels set by a central authority, not the data owner, to control access.

  3. An auditor is assessing the change management process. Which control is MOST critical to verify?

    Answer: Changes are approved before implementation

    Pre-implementation approval ensures that only authorized, tested, and justified changes are made to production systems.

  4. In the context of IS auditing, 'audit universe' refers to:

    Answer: All auditable entities within the scope of the audit function

    The audit universe encompasses all potential audit subjects from which the audit plan is derived.

  5. Which of the following BEST describes a compensating control?

    Answer: A control that mitigates risk when the primary control cannot be implemented

    A compensating control is an alternative measure used to satisfy a requirement when the standard control is not feasible.

  6. An IS auditor reviewing network security finds that firewall rules have not been reviewed in three years. What is the MOST significant risk?

    Answer: Outdated rules may allow unauthorized access or block legitimate traffic

    Stale firewall rules can contain obsolete permissions that expose the network to threats or create operational issues.

  7. When reviewing application controls, which control type BEST prevents data entry errors at the source?

    Answer: Edit checks and validation rules

    Input validation and edit checks prevent invalid data from entering the system at the point of entry.