โ† All CISA Flashcard Decks

Certified Information Systems Auditor MCQ Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Information Systems Auditor MCQ flashcards as text
  1. An IS auditor reviews a company's IT governance framework and finds no formal IT steering committee. The GREATEST risk of this gap is:

    Answer: IT projects may not align with business objectives

    Without an IT steering committee, there is no formal mechanism to align IT investments and projects with overall business strategy.

  2. A CAATs tool is BEST used by an IS auditor to:

    Answer: Analyze large volumes of transaction data for anomalies

    Computer-Assisted Audit Techniques (CAATs) are specifically designed to process large transaction datasets to identify exceptions, trends, and anomalies.

  3. During a review of a third-party vendor contract, an IS auditor notices the contract lacks a right-to-audit clause. This PRIMARILY means:

    Answer: The organization cannot independently verify the vendor's control effectiveness

    Without a right-to-audit clause, the organization has no contractual basis to independently assess whether the vendor's controls are operating effectively.

  4. Which of the following BEST describes the purpose of a control self-assessment (CSA)?

    Answer: To allow management and staff to assess the effectiveness of internal controls

    CSA is a process in which operational management and staff directly evaluate the effectiveness and efficiency of controls in their own areas.

  5. An IS auditor finds that application logs are stored on the same server as the application itself. The MAIN risk is:

    Answer: An attacker who compromises the server could also alter or delete logs

    Co-locating logs with the application means a successful attacker can cover their tracks by modifying or deleting the very logs that would record the attack.

  6. Under the COBIT framework, which of the five governance objectives specifically addresses the transparent reporting of IT performance to stakeholders?

    Answer: Ensure Transparency to Stakeholders

    COBIT's 'Ensure Transparency to Stakeholders' governance objective focuses on providing accurate and timely information to all relevant parties about IT performance.

  7. When assessing the risk associated with outsourcing IT operations, an IS auditor should FIRST:

    Answer: Identify which critical business processes depend on the outsourced service

    Understanding which critical processes rely on the outsourced service establishes the risk context necessary for all subsequent audit steps.