Certified Information Systems Auditor Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Information Systems Auditor flashcards as text
Which of the following frameworks is MOST commonly used to assess IT governance and management practices in a CISA audit?
Answer: COBIT 2019
COBIT 2019 is ISACA's primary framework for IT governance and management, directly aligned with CISA's domain focus.
An auditor reviewing patch management finds that critical patches are applied within 30 days but the vendor recommends 7 days. What is the auditor's BEST conclusion?
Answer: The organization is exposed to elevated risk during the gap period
Delaying critical patches beyond vendor recommendations leaves known vulnerabilities unaddressed, increasing exposure to exploitation.
When conducting an audit of logical access controls, an auditor should PRIMARILY verify that:
Answer: Access rights are based on business need and reviewed periodically
Logical access controls should enforce least privilege and be subject to periodic recertification to ensure ongoing appropriateness.
An IS auditor is assessing an organization's incident response capability. Which element is MOST critical for a mature program?
Answer: Documented procedures that have been tested and rehearsed
Documented, tested incident response procedures ensure the organization can respond effectively and consistently when an incident occurs.
Which of the following BEST demonstrates due diligence by IT management regarding information security?
Answer: Conducting regular risk assessments and acting on findings
Due diligence requires actively identifying risks and taking informed action, not just transferring or delegating responsibility.
During an audit of database controls, an auditor finds that database administrators (DBAs) have unrestricted access to production data without any monitoring. The MOST significant risk is:
Answer: Unauthorized modification or exfiltration of sensitive data without detection
Unmonitored privileged access to production data creates high risk of insider threat and data integrity compromise.
An IS auditor reviewing a data backup process should FIRST verify that:
Answer: Backup restoration has been successfully tested
Untested backups cannot be relied upon for recovery; successful restoration tests are the only proof that backups are valid.