← All CISA Flashcard Decks

Certified Information Systems Auditor MCQ Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Certified Information Systems Auditor MCQ flashcards as text
  1. An IS auditor is reviewing an organization's patch management process and finds that critical patches take an average of 45 days to deploy. The BEST recommendation is:

    Answer: Implement a risk-based patching policy with shorter windows for critical vulnerabilities

    A risk-based patching policy prioritizes critical patches for faster deployment while allowing more time for lower-risk patches.

  2. Which type of audit evidence is considered the MOST reliable?

    Answer: Original source documents examined directly by the auditor

    Original source documents that the auditor personally examines are the most reliable because they are unfiltered and not subject to manipulation by the auditee.

  3. During a database audit, an IS auditor discovers that a DBA has unrestricted access to production data including personal health information. The IMMEDIATE recommended action is:

    Answer: Implement compensating controls such as enhanced logging and periodic access reviews

    Compensating controls like audit logging and access reviews address the risk without disrupting operations while a longer-term least-privilege solution is designed.

  4. An IS auditor evaluating business continuity planning should PRIMARILY ensure that:

    Answer: Recovery procedures have been tested and results documented

    An untested BCP cannot be relied upon; testing with documented results is the only way to verify recovery procedures will actually work.

  5. Which of the following is a key characteristic that distinguishes an IS audit from a general financial audit?

    Answer: IS audits focus on IT-related controls supporting information integrity and availability

    IS audits specifically assess IT controls around data integrity, confidentiality, and availability, whereas financial audits focus on the accuracy of financial statements.

  6. When reviewing a software development lifecycle (SDLC), an IS auditor should verify that security requirements are addressed:

    Answer: During the requirements and design phases as early as possible

    Addressing security in the requirements and design phases is far less costly and more effective than finding vulnerabilities after deployment.

  7. An IS auditor is assessing the maturity of an organization's IT risk management process using CMMI levels. A process that is documented, standardized, and consistently applied organization-wide BEST corresponds to which maturity level?

    Answer: Level 3 – Defined

    CMMI Level 3 (Defined) is characterized by processes that are documented, standardized, and consistently applied across the entire organization.