Certified Information Systems Auditor Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Information Systems Auditor flashcards as text
During an IS audit, an auditor discovers that a control is functioning as intended but the risk it mitigates has already been accepted by management. What is the BEST course of action?
Answer: Document the accepted risk and note the control as redundant in the report
Auditors should document management-accepted risks and flag controls that may be redundant relative to the risk posture.
Which of the following BEST describes the purpose of a control self-assessment (CSA)?
Answer: To allow management and staff to assess controls collaboratively
CSA is a technique where management and staff work together to assess the effectiveness of controls in their own areas.
An organization uses a third-party cloud provider for critical data processing. Which audit approach is MOST appropriate to assess the provider's controls?
Answer: Obtain and evaluate a SOC 2 Type II report
A SOC 2 Type II report provides an independent assessment of a service organization's controls over a period of time.
When evaluating IT governance, an IS auditor should PRIMARILY focus on whether:
Answer: IT strategy is aligned with business objectives
IT governance ensures that IT investments and strategies are aligned with and support overall business objectives.
A residual risk is BEST defined as:
Answer: Risk that remains after controls have been applied
Residual risk is the level of risk remaining after management has implemented controls and other risk responses.
Which sampling technique is MOST appropriate when an auditor wants to give every transaction an equal chance of being selected?
Answer: Random sampling
Random sampling ensures every item in the population has an equal probability of selection, reducing selection bias.
During a post-implementation review of an ERP system, an auditor finds that user acceptance testing (UAT) was skipped. What is the PRIMARY risk?
Answer: The system may not meet business requirements
UAT validates that the system meets business requirements; skipping it increases the risk of deploying a system that does not satisfy user needs.