Mixed Deck — All CISA Topics Flashcards
100 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CISA Topics flashcards as text
During IS audit planning, which of the following is the BEST source for understanding an organization's IT risk posture?
Answer: The organization's enterprise risk management (ERM) framework and IT risk register
The ERM framework and IT risk register document the organization's identified risks, their likelihood and impact, and existing mitigations — making them the primary source for risk-based audit planning.
Which of the following BEST describes data sovereignty?
Answer: The legal principle that data is subject to the laws of the country in which it is stored
Data sovereignty means that data stored in a particular country is governed by that country's laws and regulations.
Which of the following BEST describes the purpose of a Key Risk Indicator (KRI) in IT risk management?
Answer: To serve as an early warning signal that a risk is emerging or exceeding its threshold.
Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposures in various areas of the enterprise. They are forward-looking and designed to alert management before a risk materializes into a loss event, allowing for proactive risk mitigation.
Which logical access control approach would BEST prevent an insider from exfiltrating bulk customer records from a database?
Answer: Implementing query result row-count limits and data loss prevention controls
Row-count limits on query results and DLP controls detect and restrict bulk data extraction, targeting the exfiltration method directly.
What could happen if an IS auditor breaks the ISACA Code of Professional Ethics when they are members of ISACA and CISA certified?
Answer: Loss of ISACA certifications
The ISACA Code of Professional Ethics outlines the mandatory standards of professional conduct for all ISACA members and certification holders. A violation of this code can lead to disciplinary actions, with the most severe consequence for certified individuals being the suspension or revocation of their ISACA certifications, such as CISA. This ensures the integrity and credibility of the ISACA professional community.
An IS auditor is assessing controls over privileged access management (PAM). Which of the following represents the BEST practice for managing privileged accounts?
Answer: Issuing just-in-time privileged access that is time-limited and fully logged
Just-in-time (JIT) privileged access minimizes the attack surface by granting elevated rights only when needed and for a limited time, with full audit logging.
An IS auditor is reviewing the change management process for a critical financial application. It is noted that developers are able to promote their own code changes directly into the production environment. This practice represents a failure of which fundamental control principle?
Answer: Segregation of duties (SoD)
Segregation of duties (SoD) is a fundamental internal control concept that involves separating tasks and responsibilities among different people to prevent fraud and errors. Allowing a developer to write code and also promote it to production without independent oversight violates SoD, as it creates an opportunity for unauthorized or untested changes to be implemented.
Which of the following is the MOST effective control to prevent SQL injection attacks against a web application?
Answer: Using parameterized queries and prepared statements in application code
Parameterized queries separate SQL code from user-supplied input at the code level, eliminating the root cause of SQL injection vulnerabilities.
In the context of CISA, what is the primary purpose of an IS audit charter?
Answer: Define the authority, scope, and responsibilities of the IS audit function
An IS audit charter formally establishes the mandate, independence, authority, and scope of the internal IS audit function.
Which testing type validates that a new system does not adversely affect existing integrated systems?
Answer: Regression testing
Regression testing re-runs prior test cases to confirm that new changes have not broken existing functionality in interconnected systems.
During the audit planning phase for a financial institution, an IS auditor discovers that a new online banking platform was implemented without a formal risk assessment. Which of the following is the MOST appropriate action for the auditor to take?
Answer: Expand the audit scope to include a thorough risk assessment of the new platform.
The discovery of a significant change to the IT environment, especially one implemented without a risk assessment, requires the auditor to adjust the audit plan. Expanding the scope to assess the risks associated with the new platform is the most proactive and responsible action to ensure potential vulnerabilities are identified and evaluated.
Which of the following BEST describes the purpose of a Business Impact Analysis (BIA)?
Answer: To quantify the impact of disruptions and prioritize recovery of critical functions
A BIA quantifies financial and operational impacts of disruptions and prioritizes which functions must be restored first.
An IS auditor discovers that an organization has a data classification policy but has not assigned an owner to each information asset. Which of the following represents the GREATEST risk associated with this finding?
Answer: Lack of accountability for ensuring information assets are appropriately protected.
The primary role of an information asset owner is to be accountable for the protection of that asset. This includes responsibilities like determining the data's classification level and ensuring that adequate security controls are implemented and maintained. Without a designated owner, there is no clear line of accountability, which often leads to assets being unprotected or under-protected.
Which of the following BEST describes a risk scenario used in IT risk management frameworks like COBIT?
Answer: A narrative that connects a threat actor, event, and business impact
A risk scenario in COBIT combines a threat source, vulnerability, and resulting business impact into a coherent narrative for assessment purposes.
Which of the following BEST represents the relationship between risk tolerance and risk appetite?
Answer: Risk appetite sets the strategic boundary; risk tolerance defines acceptable deviation from it
Risk appetite is the overall level of risk an organization is willing to pursue, while risk tolerance is the acceptable variance around that appetite for specific risks.
Which of the following BEST demonstrates integration between information security and business continuity planning?
Answer: Recovery procedures include requirements to maintain security controls and access restrictions during restoration
True integration means security controls—authentication, encryption, access controls—are actively maintained and enforced throughout the recovery process.
In IS auditing, what is the term for the probability that a material error exists and will not be detected by controls?
Answer: Audit risk
Audit risk is the overall risk that the auditor may issue an incorrect opinion; it combines inherent, control, and detection risks.
During a DR tabletop exercise, the team discovers the backup media restoration procedure references a tool no longer installed on recovery servers. This finding BEST illustrates the importance of:
Answer: Keeping DR documentation current with production changes
The gap between documented procedures and the actual recovery environment shows that DR documentation must be updated whenever production systems change.
An IS auditor finds that network infrastructure devices have not received security patches in 18 months. The BEST recommendation is to:
Answer: Implement a formal patch management process with defined SLAs for critical devices
A formal patch management process with defined timelines ensures vulnerabilities are addressed systematically without unnecessary disruption.
When auditing a DevOps environment, which control is MOST critical to verify regarding the deployment pipeline?
Answer: That automated security scans and approval gates are embedded in the CI/CD pipeline
Embedding automated security scans and approval gates in the CI/CD pipeline ensures every deployment is vetted for vulnerabilities and authorized before reaching production.