โ† All CISA Flashcard Decks

Certified Information Systems Auditor MCQ Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Information Systems Auditor MCQ flashcards as text
  1. During an IS audit, an auditor discovers that change management procedures are not being followed for emergency fixes. What is the MOST significant risk?

    Answer: Unauthorized or erroneous changes introduced to production

    Bypassing change management for emergency fixes creates the highest risk of introducing unauthorized or erroneous changes that can compromise system integrity.

  2. An IS auditor is reviewing access controls and finds that terminated employees still have active accounts 30 days after separation. The PRIMARY concern is:

    Answer: Potential unauthorized access to sensitive systems

    Active accounts for terminated employees represent a direct threat of unauthorized access, which is the primary security risk to address.

  3. Which control type BEST describes a system that automatically locks a user account after five failed login attempts?

    Answer: Preventive control

    Account lockout after failed attempts is a preventive control because it stops further unauthorized access attempts before a breach occurs.

  4. An IS auditor is evaluating a company's disaster recovery plan. Which metric defines the maximum acceptable period of data loss following a disruption?

    Answer: Recovery Point Objective (RPO)

    Recovery Point Objective (RPO) defines the maximum age of data that must be recovered after a disaster to resume normal operations.

  5. When auditing an ERP system, an IS auditor should be MOST concerned with which of the following segregation of duties conflicts?

    Answer: An accounts payable clerk who can also approve payments

    An accounts payable clerk who can also approve payments creates a direct conflict that enables fraud without detection.

  6. During a penetration test scoping meeting, the client insists the auditor must not test the payroll system. The IS auditor should:

    Answer: Proceed without testing payroll and note the scope limitation in the report

    Auditors must respect client-defined scope limitations and document them clearly so report readers understand coverage constraints.

  7. Which sampling technique is MOST appropriate when an IS auditor wants to give every transaction an equal chance of being selected for testing?

    Answer: Random sampling

    Random sampling ensures every item in the population has an equal probability of selection, eliminating auditor bias.