← All CISA Flashcard Decks

Certified Information Systems Auditor MCQ Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Certified Information Systems Auditor MCQ flashcards as text
  1. An IS auditor reviewing a cloud environment finds that the organization has not classified its data before migrating to the cloud. The PRIMARY risk is:

    Answer: Sensitive data may be stored without appropriate security controls

    Without data classification, the organization cannot apply appropriate security controls, potentially exposing sensitive or regulated data in the cloud.

  2. During a follow-up audit, an IS auditor finds that management agreed to a corrective action but implemented a different, untested solution instead. The auditor should:

    Answer: Assess whether the alternative solution adequately addresses the original risk

    The auditor's responsibility is to verify that the original risk is addressed, regardless of whether the solution matches what was originally agreed upon.

  3. Which of the following BEST describes the role of an IS auditor when management asks for advice on selecting a new security tool?

    Answer: The auditor may provide general criteria but should avoid selecting specific products to preserve independence

    IS auditors can advise on criteria and frameworks without selecting specific products, preserving independence while still adding value.

  4. An IS auditor finds that a company uses a single sign-on (SSO) solution for all enterprise applications. The GREATEST risk associated with SSO is:

    Answer: A compromised SSO credential grants access to all connected applications

    SSO creates a single point of failure — if the credential is compromised, the attacker gains access to every application connected to the SSO system.

  5. When assessing IT general controls (ITGCs), an IS auditor is PRIMARILY concerned with controls over:

    Answer: Infrastructure, access management, change management, and operations

    ITGCs are entity-level controls covering the IT environment — including infrastructure security, logical access, change management, and IT operations — that support all applications.

  6. An IS auditor is reviewing a company's encryption practices and finds that encryption keys are stored in the same database as the encrypted data. This represents:

    Answer: A significant control weakness that negates the protection of encryption

    Storing encryption keys with encrypted data means anyone who gains access to the database has both the ciphertext and the key to decrypt it, rendering encryption ineffective.

  7. An organization conducts an annual IT risk assessment but does not update it when significant system changes occur. The MOST likely consequence is:

    Answer: New risks introduced by system changes will remain unidentified and unmitigated

    Risk assessments that are not updated after major changes fail to capture new threats, leaving the organization unaware of and unprepared for emerging risks.