Certified Information Systems Auditor Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Information Systems Auditor flashcards as text
An IS auditor discovers that a system administrator has both the ability to create user accounts and approve access requests. This BEST represents a violation of:
Answer: Separation of duties
Separation of duties requires that no single individual control all aspects of a critical transaction or process to reduce fraud risk.
During a business continuity audit, which of the following is the MOST important indicator that a BCP is effective?
Answer: The plan has been successfully tested and updated
A BCP that has been tested and kept current demonstrates actual operational effectiveness, not just paper compliance.
Which IS audit approach BEST supports continuous auditing of high-volume transaction systems?
Answer: Embedded audit modules that monitor transactions in real time
Embedded audit modules allow auditors to continuously monitor transactions as they occur, enabling timely detection of anomalies.
An auditor is evaluating a software development lifecycle (SDLC). Which phase is MOST critical for ensuring security requirements are addressed early?
Answer: Requirements and design
Incorporating security requirements during requirements and design (shift-left) is far less costly than retrofitting security after development.
In IT risk management, a threat is BEST described as:
Answer: A potential cause of an unwanted incident
A threat is any potential event or action that could exploit a vulnerability and cause harm to an asset.
Which of the following is the PRIMARY objective of an IT general control (ITGC) review?
Answer: To evaluate controls over the IT environment that support application controls
ITGCs provide the foundation for reliable application controls by ensuring the integrity of the overall IT environment.
An organization's data classification policy assigns 'confidential' to customer PII. An auditor finds this data stored unencrypted on a shared network drive. The FIRST recommended action is to:
Answer: Report the finding and recommend encrypting or relocating the data
Auditors should report findings and make recommendations; immediate remediation decisions belong to management.