Certified Information Systems Auditor MCQ Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Information Systems Auditor MCQ flashcards as text
The management is starting to wonder about the timeline and completion of an audit project that is going far too long. This audit might be deficient in:
Answer: Effective project management
When an audit project extends beyond its expected timeline and management expresses concern, it indicates a breakdown in the audit's planning, execution, or monitoring. Effective project management for an audit involves clearly defining scope, setting realistic timelines, allocating resources efficiently, and consistently tracking progress. A deficiency in these areas leads to delays and concerns about the project's completion.
Which statement regarding the ISACA Audit Standards and Audit Guidelines is accurate?
Answer: ISACA Audit Standards are mandatory
ISACA's IT Audit and Assurance Standards are mandatory requirements for all ISACA members and certification holders, including CISA-certified professionals. These standards provide the foundational principles and requirements for conducting professional IS audits. While ISACA Audit Guidelines offer helpful advice and best practices, they are not mandatory.
Can an auditor depend on the audit client's risk estimate for audit planning?
Answer: Yes, if the risk assessment was performed by a qualified external entity
An auditor can rely on a client's risk assessment for audit planning, but only under specific conditions. The assessment must have been performed by a qualified external entity, ensuring objectivity and adherence to professional standards. However, the auditor must still exercise professional skepticism and evaluate the adequacy and appropriateness of the client's assessment before incorporating it into their own audit plan.
The user account request and fulfillment process is being audited by an auditor. The auditor cannot inspect every transaction in the event population because there are hundreds of them. A random sample of transactions and some of the transactions for privileged access requests are wanted by the auditor. This kind of sampling is referred to as:
Answer: Judgmental sampling
Judgmental sampling involves the auditor using their professional expertise and knowledge to select specific items for examination. In this scenario, the auditor is not only taking a random sample but also specifically choosing transactions related to privileged access requests due to their higher risk. This deliberate selection based on auditor judgment, rather than purely statistical methods or stratification, characterizes judgmental sampling.
A plan for an audit is being created by an auditor for the accounts payment function. The auditor wishes to choose transactions from low, medium, and big payment amounts rather than randomly choosing transactions to investigate. Which example methodology fits this approach the best?
Answer: Stratified sampling
Stratified sampling involves dividing the entire population into distinct, homogeneous subgroups (strata) based on specific characteristics, and then drawing samples from each stratum. By choosing transactions from low, medium, and big payment amounts, the auditor is creating strata based on transaction value. This method ensures that all relevant categories are represented in the sample, providing a more comprehensive and targeted review.
What is the purpose of the ISACA organizational independence audit standard?
Answer: The auditor's placement in the organization should ensure the auditor can act independently.
The ISACA organizational independence audit standard aims to ensure that the IS audit function is positioned within the organization in a way that allows auditors to perform their duties objectively and without undue influence. This typically means the audit function reports to a high level, such as the audit committee or board, to maintain both the appearance and the reality of independence. It's about the structural arrangement that enables unbiased audit work.
Which of the following audit types would be suitable for a provider of financial services, like a payroll service?
Answer: SSAE18
SSAE 18 (Statement on Standards for Attestation Engagements No. 18) is the current professional standard for reporting on controls at service organizations. A payroll service provider is a service organization, and its clients would typically request a SOC 1 (Service Organization Control 1) report, which falls under SSAE 18, to understand the effectiveness of controls relevant to financial reporting. SAS 70 was the predecessor standard.