Certified Information Systems Auditor MCQ Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Information Systems Auditor MCQ flashcards as text
During an IS audit, an auditor discovers that change management procedures are not being followed for emergency fixes. What is the MOST significant risk?
Answer: Unauthorized or erroneous changes introduced to production
Bypassing change management for emergency fixes creates the highest risk of introducing unauthorized or erroneous changes that can compromise system integrity.
An IS auditor is reviewing access controls and finds that terminated employees still have active accounts 30 days after separation. The PRIMARY concern is:
Answer: Potential unauthorized access to sensitive systems
Active accounts for terminated employees represent a direct threat of unauthorized access, which is the primary security risk to address.
Which control type BEST describes a system that automatically locks a user account after five failed login attempts?
Answer: Preventive control
Account lockout after failed attempts is a preventive control because it stops further unauthorized access attempts before a breach occurs.
An IS auditor is evaluating a company's disaster recovery plan. Which metric defines the maximum acceptable period of data loss following a disruption?
Answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum age of data that must be recovered after a disaster to resume normal operations.
When auditing an ERP system, an IS auditor should be MOST concerned with which of the following segregation of duties conflicts?
Answer: An accounts payable clerk who can also approve payments
An accounts payable clerk who can also approve payments creates a direct conflict that enables fraud without detection.
During a penetration test scoping meeting, the client insists the auditor must not test the payroll system. The IS auditor should:
Answer: Proceed without testing payroll and note the scope limitation in the report
Auditors must respect client-defined scope limitations and document them clearly so report readers understand coverage constraints.
Which sampling technique is MOST appropriate when an IS auditor wants to give every transaction an equal chance of being selected for testing?
Answer: Random sampling
Random sampling ensures every item in the population has an equal probability of selection, eliminating auditor bias.