Every Exam PrepFREE EXAM PREP
Ask AI

CISA Practice Test

159 free CISA practice questions with answers and explanations.

No signup required.

The CISA exam is administered by ISACA, with 150 scored questions and a time limit of 4 hours.

About these practice questions
Verified against the official content outline

These are original study questions written from published exam objectives—not recalled, copied, or confidential live-exam items. Always confirm current coverage with the official sources linked on this page.

Difficulty
QUESTION 1 / 100Information Systems Auditing ProcessEasy0/0
During the planning phase of an IS audit, an IS auditor discovers that a business process has never been formally risk-assessed. What should the auditor do FIRST?
0/0session
Browse all questions & answers

Loading the remaining 59 questions…

Information Systems Auditing Process

34 questions
  1. 1. During the planning phase of an IS audit, an IS auditor discovers that a business process has never been formally risk-assessed. What should the auditor do FIRST?

    • A. Perform a risk assessment of the process to determine audit scope and priority
    • B. Exclude the process from the audit since no risk assessment exists
    • C. Immediately report the missing risk assessment to the audit committee as a finding
    • D. Ask management to sign off on the process as low risk before proceeding
    Show answer & explanation

    Answer: A
    A risk-based audit approach requires the auditor to assess risk to determine scope, depth, and resource allocation; performing the assessment lets the auditor make an informed scoping decision. Excluding the process ignores potential exposure, reporting prematurely skips the auditor's own analysis, and asking management to self-certify risk undermines auditor independence and objectivity.

  2. 2. An IS auditor is evaluating evidence gathered during fieldwork. Which characteristic of evidence is MOST important when the auditor must rely on it to support a significant audit finding?

    • A. The evidence was easy and inexpensive to obtain
    • B. The evidence confirms the auditor's initial expectations
    • C. The evidence was provided directly by the process owner
    • D. The evidence is sufficient, reliable, and relevant to the audit objective
    Show answer & explanation

    Answer: D
    Audit evidence must be sufficient (enough in quantity), reliable (from a trustworthy source, ideally independently corroborated), and relevant (directly related to the objective) to support a conclusion. Ease of collection is irrelevant to quality, evidence solely from the process owner may lack independence, and evidence should be evaluated objectively rather than selected to confirm preconceptions, which introduces bias.

  3. 3. An IS auditor finds that a control was operating effectively for 10 of 12 months tested, with two months showing exceptions due to a since-corrected configuration error. What is the MOST appropriate conclusion?

    • A. The control can be rated fully effective because it is now corrected
    • B. The control exceptions should be reported along with root cause, remediation, and residual risk during the exception period
    • C. The finding should be dropped since the issue is already fixed
    • D. The sample size is too small to draw any conclusion
    Show answer & explanation

    Answer: B
    Auditors must report control exceptions even when subsequently remediated, because the risk existed during the exception window and stakeholders need to understand root cause and residual exposure. Marking it fully effective or dropping the finding hides real risk that occurred, and a 12-month sample with two exceptions is generally sufficient to support a conclusion, not too small.

  4. 4. Which sampling method is MOST appropriate when an IS auditor wants every item in the population to have an equal chance of selection, without bias from the auditor's judgment?

    • A. Discovery sampling only
    • B. Haphazard sampling
    • C. Judgmental sampling
    • D. Statistical (random) sampling
    Show answer & explanation

    Answer: D
    Statistical sampling uses random selection so every item has a known, equal probability of being chosen, allowing the auditor to mathematically project results and evaluate sampling risk. Judgmental sampling relies on auditor discretion and introduces bias, haphazard sampling is not truly random and cannot be statistically evaluated, and discovery sampling is a specific technique aimed at detecting at least one occurrence of a critical exception, not general unbiased selection.

  5. 5. During an audit, management disagrees with a draft finding and provides additional documentation not previously available to the auditor. What is the BEST course of action?

    • A. Escalate immediately to the audit committee without reviewing the documentation
    • B. Ignore the new documentation since the audit fieldwork is complete
    • C. Remove the finding automatically to maintain a good working relationship with management
    • D. Evaluate the new evidence objectively and revise the finding if warranted before finalizing the report
    Show answer & explanation

    Answer: D
    An IS auditor must remain objective and consider all relevant evidence before finalizing conclusions; if new documentation is credible and relevant it should be evaluated and the finding adjusted as warranted. Ignoring evidence or removing a finding to preserve relationships compromises independence and integrity, and escalating without review skips due professional care.

  6. 6. An organization's internal audit charter grants the CISA-certified auditor authority to review all IT systems but is silent on access to third-party service providers used for payroll processing. What is the BEST way to address this gap?

    • A. Assume authority extends automatically to any vendor touching company data
    • B. Rely solely on the vendor's own internal audit reports without independent verification
    • C. Update the audit charter or contractual right-to-audit clauses to explicitly cover third-party providers
    • D. Decline to audit any process that involves a third party
    Show answer & explanation

    Answer: C
    Audit authority should be clearly documented; when third parties are in scope, the charter or vendor contracts should include explicit right-to-audit clauses so the scope of authority is unambiguous. Assuming authority is risky without documentation, relying only on vendor self-reported audits lacks independent assurance, and simply declining to audit ignores real risk in outsourced processes.

  7. 7. An IS auditor is planning an engagement and must decide how much testing to perform. What primarily drives that decision?

    • A. The preferences of the audited business unit
    • B. The number of staff available in the audit function
    • C. The size of the department's budget
    • D. The assessed risk of the area under review, since audit effort is allocated where misstatement or control failure would matter most
    Show answer & explanation

    Answer: D
    Risk-based audit planning directs finite effort toward areas where control failure has the greatest consequence, which is what makes an audit opinion meaningful rather than merely thorough. Resource constraints affect what can be covered in a cycle, but they inform scheduling rather than justify testing a low-risk area at the expense of a high-risk one.

  8. 8. An IS auditor gathers evidence through several methods on the same control. Which evidence is generally considered most reliable?

    • A. Evidence the auditor obtains directly through independent observation or reperformance
    • B. A written representation from the process owner
    • C. A system-generated report supplied by the auditee without validation
    • D. An internal procedure document describing how the control should operate
    Show answer & explanation

    Answer: A
    Reliability rises with auditor independence from the source, so directly obtained evidence outranks auditee assertions, and a report the auditee generated is only as reliable as the auditor's assurance over the reporting system itself. A procedure document evidences design intent rather than operating effectiveness, which is a separate question the auditor must test.

  9. 9. What distinguishes a test of control design from a test of operating effectiveness?

    • A. Design testing asks whether a properly functioning control would address the risk, while effectiveness testing asks whether it actually operated as intended over the period
    • B. Design testing is performed by the auditee and effectiveness testing by the auditor
    • C. Design testing uses sampling and effectiveness testing uses inquiry
    • D. The two are interchangeable descriptions of the same procedure
    Show answer & explanation

    Answer: A
    A control can be well designed but never performed, or diligently performed yet incapable of addressing the risk, so both questions must be answered separately. Concluding on effectiveness without first establishing that the design addresses the risk produces assurance over an activity that was never going to help.

  10. 10. An auditor uses attribute sampling to test whether change approvals were obtained. What is being measured?

    • A. The average time taken to approve a change
    • B. The monetary value of unapproved changes
    • C. The total number of changes in the population
    • D. The rate of deviation from the control, expressed as a proportion of items lacking the attribute
    Show answer & explanation

    Answer: D
    Attribute sampling answers a yes-or-no question about the presence of a control attribute and yields a deviation rate, which is why it suits control testing. Variable sampling measures amounts and suits substantive testing of balances, so choosing the wrong technique produces a statistic that does not answer the audit question.

  11. 11. An auditor discovers a control deficiency mid-engagement. What is the appropriate immediate action?

    • A. Withhold the finding until the report is issued in all cases
    • B. Correct the deficiency personally to demonstrate the remediation
    • C. Document the condition, criteria, cause and effect, and communicate significant matters to management on a timely basis rather than only in the final report
    • D. Expand the engagement scope to every adjacent system
    Show answer & explanation

    Answer: C
    Findings are built from condition, criteria, cause and effect, and significant issues warrant timely communication so management can act rather than learning of them months later. An auditor who fixes the deficiency impairs independence and cannot then provide assurance over the remediated control.

  12. 12. An internal audit function reports administratively to the chief information officer and functionally to the audit committee. Why does the functional reporting line matter?

    • A. Because independence requires that audit conclusions and resourcing are not controlled by the management whose activities are audited
    • B. Because administrative reporting is prohibited
    • C. Because the audit committee performs the fieldwork
    • D. Because the audit committee approves individual audit test steps
    Show answer & explanation

    Answer: A
    Functional reporting to an independent body protects the audit plan, budget and conclusions from the influence of audited management, which is the structural basis of internal audit independence. The committee approves the plan and charter rather than test steps, and day-to-day administrative reporting inside the organization is normal.

  13. 13. An auditor is asked to review a system they helped configure two years ago. What is the concern?

    • A. There is no concern once two years have passed
    • B. The concern applies only to external auditors
    • C. The prior involvement makes the auditor the best-qualified reviewer
    • D. Self-review impairs objectivity, so the assignment should be reallocated or the impairment disclosed and mitigated
    Show answer & explanation

    Answer: D
    Reviewing one's own prior work creates a self-review threat because an adverse finding would be a criticism of the auditor's own judgment. Familiarity is real value, but it is captured by consulting the auditor rather than assigning the review, and impairments must be disclosed to those charged with governance.

  14. 14. An organization uses continuous auditing techniques. What capability does this add?

    • A. Automated testing of transactions or configurations as they occur, shortening the interval between a control failure and its detection
    • B. Elimination of the need for an annual audit plan
    • C. A guarantee that no control failures occur
    • D. Replacement of management's own monitoring responsibilities
    Show answer & explanation

    Answer: A
    Continuous auditing compresses detection latency by testing at or near the time of the transaction, which matters most where a periodic sample would surface a problem long after the damage. It complements rather than replaces planning, and it does not transfer management's monitoring duty to the audit function.

  15. 15. An auditor is asked to provide an opinion where testing was limited because records were unavailable. What is the appropriate reporting treatment?

    • A. Disclose the scope limitation and its effect on the conclusion rather than issuing an unqualified opinion
    • B. Issue an unqualified opinion based on the testing that was possible
    • C. Omit the affected area from the report without comment
    • D. Delay the report indefinitely until records appear
    Show answer & explanation

    Answer: A
    A conclusion must be supported by sufficient appropriate evidence, so where that was unobtainable the reader must be told what could not be examined and what it means. Silently omitting the area misleads by implying coverage that did not occur, which is a more serious failing than the limitation itself.

  16. 16. An auditor uses computer-assisted audit techniques to test an entire population rather than a sample. What is the primary benefit?

    • A. Management review of the results becomes unnecessary
    • B. The need to understand the control is removed
    • C. Sampling risk is eliminated for that test, since every item is examined rather than an inference drawn from a subset
    • D. The reliability of the source data no longer matters
    Show answer & explanation

    Answer: C
    Full population testing removes the risk that a sample was unrepresentative, which is the principal statistical limitation of sampling. It does not remove the need to establish the completeness and accuracy of the data extracted, since testing everything in an incomplete extract is thorough examination of the wrong population.

  17. 17. Management proposes a remediation action for an audit finding. What should the auditor evaluate before accepting it?

    • A. Whether the action addresses the root cause rather than the symptom, and whether the owner and target date are specific enough to be followed up
    • B. Whether the action is the least expensive option available
    • C. Whether the action was proposed by senior rather than junior management
    • D. Whether the action can be completed before the report is issued
    Show answer & explanation

    Answer: A
    A remediation targeting the symptom leaves the condition to recur, so the finding's cause element is what the action must address. Specific ownership and dates are what make follow-up possible, and an action too vague to verify effectively closes the finding without changing anything.

  18. 18. While planning an IS audit of a payment-processing application, an IS auditor must decide which potential control weaknesses would be significant enough to warrant reporting to senior management if confirmed. Which audit concept PRIMARILY guides this determination?

    • A. Materiality, because it defines the threshold at which a weakness or error becomes significant to stakeholders
    • B. Inherent risk, because it reflects the susceptibility of the process to error before controls are considered
    • C. Detection risk, because it reflects the chance that audit procedures fail to identify an existing error
    • D. Sampling risk, because it measures the chance that the sample is not representative of the population
    Show answer & explanation

    Answer: A
    Materiality is the concept auditors use to judge whether a weakness or misstatement is significant enough to influence the decisions of report users, so it directly drives what gets escalated to senior management. Inherent risk describes exposure before controls and helps scope the audit, but it does not set the significance threshold for reporting; sampling and detection risk concern the reliability of the auditor's own procedures rather than the importance of a finding.

  19. 19. An IS auditor wants to estimate the total monetary value of errors in a population of automatically generated customer invoices. Which sampling approach is MOST appropriate for this objective?

    • A. Attribute sampling, because it measures the rate of deviation from a prescribed control
    • B. Variable sampling, because it estimates the monetary amount or quantitative value of a population characteristic
    • C. Judgmental sampling, because the auditor can focus on the invoices most likely to contain errors
    • D. Discovery sampling, because it is designed to find at least one example of a rare event
    Show answer & explanation

    Answer: B
    Variable sampling techniques are designed to estimate quantitative amounts, such as the total dollar value of misstatement in a population, which matches the auditor's objective here. Attribute sampling is the tempting alternative but it only measures how often a condition occurs, expressed as a rate, and cannot express results in monetary terms; discovery sampling targets rare events, and judgmental selection produces results that cannot be statistically projected to the population.

  20. 20. An audit manager reviews a completed IS audit file and finds procedures, evidence obtained, and conclusions recorded for each objective. What is the PRIMARY purpose served by this audit documentation?

    • A. To satisfy the auditee that the audit was conducted with minimal disruption to operations
    • B. To transfer ownership of identified control weaknesses from management to the audit function
    • C. To eliminate the need for an exit meeting by making all findings self-explanatory
    • D. To provide a defensible record that supports the audit conclusions and enables supervisory review of the work performed
    Show answer & explanation

    Answer: D
    Workpapers exist chiefly to evidence the basis for the auditor's conclusions and to allow reviewers to verify that the work supports the reported results, which also protects the audit function if findings are challenged. Ownership of control weaknesses always remains with management regardless of documentation, and documentation complements rather than replaces communication steps such as the exit meeting, so the other purposes are incidental at best.

  21. 21. During fieldwork, the operations manager verbally assures an IS auditor that failed overnight batch jobs are always remediated the same day. Before relying on this assertion to close the audit objective, what should the auditor do?

    • A. Corroborate the assertion with independent evidence such as job logs and incident records
    • B. Include the assertion in the report as a management representation requiring no further work
    • C. Accept the assertion because it was provided by the manager accountable for the process
    • D. Escalate the matter to the audit committee as an unsupported management claim
    Show answer & explanation

    Answer: A
    Inquiry alone is among the weakest forms of audit evidence, so a verbal assertion about remediation timeliness should be corroborated with independent, objective sources such as scheduler logs and ticket histories before the auditor relies on it. Accepting the claim because of the manager's accountability confuses authority with evidence quality, and escalating to the audit committee is premature because nothing yet suggests the assertion is false — it is simply unverified.

  22. 22. A prior-year audit reported that database administrators shared a single privileged login. During the follow-up review, management states that the issue has been fully remediated. What should the IS auditor do NEXT?

    • A. Close the finding, because management has formally confirmed remediation
    • B. Reopen the entire prior audit to revalidate all of its original findings
    • C. Perform testing to verify that individual accounts are now in use and the shared login is disabled
    • D. Downgrade the finding's risk rating to reflect management's attention to the issue
    Show answer & explanation

    Answer: C
    Follow-up procedures require the auditor to obtain evidence that corrective action was actually implemented and is effective, which here means testing that unique privileged accounts exist and the shared credential can no longer be used. Closing the finding on management's word alone substitutes assertion for evidence, while reopening the whole prior audit is disproportionate because only the remediation of this specific finding is in question.

  23. 23. An audit director is building the annual IS audit plan and must choose which auditable areas to cover with limited resources. Which factor should MOST influence the prioritization?

    • A. The preferences expressed by the managers of each business unit
    • B. The length of time since each area was last audited
    • C. The availability of auditors with prior experience in each area
    • D. The relative risk each area poses to the organization's objectives
    Show answer & explanation

    Answer: D
    A risk-based audit plan directs scarce audit resources to the areas whose failure would most harm the organization's objectives, which is the accepted basis for annual planning. Time since last audit is a legitimate input to the risk assessment but is only a proxy — a low-risk area does not become a priority simply because it is overdue — and staffing convenience or auditee preference would systematically divert coverage away from the highest exposures.

  24. 24. An IS auditor concludes that the IT general controls supporting a financial reporting application are poorly designed and unreliable. How should this conclusion affect the remainder of the audit approach?

    • A. Discontinue the audit until management redesigns the control environment
    • B. Reduce total testing, because weak controls make further procedures unlikely to change the conclusion
    • C. Rely on analytical procedures alone, since detailed testing would duplicate the control weaknesses
    • D. Increase substantive testing of the data and transactions, because control reliance is not justified
    Show answer & explanation

    Answer: D
    When controls cannot be relied upon, the auditor must obtain assurance directly about the information itself, which means expanding substantive procedures over transactions and balances. Reducing work or stopping the audit would leave the objective unmet, and analytical procedures alone are generally too imprecise to compensate for an unreliable control environment; the correct response is to shift the evidence mix, not to shrink it.

  25. 25. For a given audit area, the IS auditor assesses both inherent risk and control risk as high. To keep overall audit risk at an acceptable level, what must the auditor do?

    • A. Accept a higher overall audit risk, since inherent and control risk are outside the auditor's influence
    • B. Reassess inherent risk downward to offset the elevated control risk
    • C. Lower detection risk by performing more extensive and more reliable audit procedures
    • D. Transfer the engagement to an external audit firm with greater resources
    Show answer & explanation

    Answer: C
    Audit risk is a function of inherent, control, and detection risk, and only detection risk is within the auditor's direct control; when the first two are high, the auditor must drive detection risk down through more extensive, more reliable procedures. Simply accepting higher audit risk defeats the engagement's purpose, and adjusting the inherent risk assessment to compensate would misstate the risk model rather than respond to it — the assessments must reflect conditions, not desired outcomes.

  26. 26. An IS auditor lacks the specialized knowledge needed to evaluate a complex actuarial model and engages an external expert to assess it. Which statement BEST describes the auditor's remaining responsibility?

    • A. The auditor remains responsible for the audit conclusions and must assess the expert's competence, objectivity, and the reasonableness of the work
    • B. Responsibility for that portion of the audit transfers to the expert once the engagement letter is signed
    • C. The auditor must disclaim any opinion on areas where expert work was used
    • D. The auditor may rely on the expert only if the expert is employed by the same firm
    Show answer & explanation

    Answer: A
    Using an expert does not delegate professional responsibility: the auditor must evaluate the expert's qualifications and independence, understand the methods used, and judge whether the results reasonably support the audit conclusions. Responsibility cannot be transferred by contract, a disclaimer is unnecessary when the expert's work is properly evaluated, and there is no requirement that the expert belong to the auditor's own organization.

  27. 27. An IS auditor wants ongoing assurance that a live claims-processing system handles transactions correctly, and arranges for fictitious transactions belonging to a dummy business unit to flow through production processing alongside real data. Which technique is being used?

    • A. Integrated test facility, which processes fictitious entities' transactions within the production system
    • B. Test data method, which runs prepared transactions through a copy of the application
    • C. Snapshot technique, which captures transaction images at defined processing points
    • D. Parallel simulation, which reprocesses real data through auditor-controlled software
    Show answer & explanation

    Answer: A
    An integrated test facility embeds a dummy entity inside the production application so auditor-created transactions are processed by the same code and environment as live data, giving direct evidence of real processing behavior. Parallel simulation inverts this by running real data through the auditor's own program, the classic test data method uses a separate test run rather than live processing, and snapshots record images of transactions rather than injecting them — the distinguishing feature here is fictitious data inside production.

  28. 28. An IS auditor needs to identify potential duplicate vendor payments across an entire year of accounts payable transactions held in a large database. Which approach is MOST efficient and effective?

    • A. Review the application's user manual to confirm a duplicate-check feature exists
    • B. Use generalized audit software to analyze the full population for matching invoice numbers, amounts, and vendors
    • C. Interview accounts payable staff about their procedures for preventing duplicates
    • D. Select a random sample of payments and manually trace each to supporting invoices
    Show answer & explanation

    Answer: B
    Generalized audit software can examine every transaction in the population and flag records sharing key attributes such as vendor, amount, and invoice number, making it far more effective at finding duplicates than any sample-based or inquiry-based approach. Sampling may miss the very duplicates being sought because they are typically rare, while interviews and manual reviews of documentation provide evidence about intended controls rather than about whether duplicates actually occurred.

  29. 29. At the conclusion of fieldwork, the IS audit team schedules a closing meeting with auditee management before the report is issued. What is the PRIMARY purpose of this meeting?

    • A. To obtain management's signature accepting responsibility for all identified risks
    • B. To confirm the factual accuracy of findings and give management an opportunity to respond
    • C. To negotiate which findings will be removed from the final report
    • D. To assign remediation deadlines that the audit function will enforce
    Show answer & explanation

    Answer: B
    The closing meeting exists to validate that the facts underlying each finding are accurate and to capture management's perspective and planned actions before the report is finalized, which improves report quality and reduces later disputes. It is not a negotiation to delete findings — valid findings remain regardless of auditee preference — and while management responses and action dates are discussed, enforcement of remediation belongs to management and governance bodies, not to the audit team.

  30. 30. A draft audit finding states that quarterly user access reviews were not performed for a core banking application, but the finding does not describe what could happen as a result. Which element of a well-structured finding is missing?

    • A. The criteria, which state what should have occurred
    • B. The condition, which states what was actually observed
    • C. The cause, which explains why the deviation happened
    • D. The effect, which explains the risk or consequence of the deviation
    Show answer & explanation

    Answer: D
    A complete finding links criteria, condition, cause, and effect; here the standard (reviews required quarterly) and the observation (reviews not performed) are present, but the consequence — for example, that inappropriate access could persist undetected — is absent, and that is the effect. Without a stated effect, management cannot judge the finding's significance or prioritize remediation, which is why the effect element is what transforms an observation into a risk-based finding.

  31. 31. Based on a sample of change tickets, an IS auditor concluded that a change-approval control was operating effectively. Later, full-population analysis showed the control actually failed frequently. Assuming the sampled items were evaluated correctly, which risk materialized?

    • A. Inherent risk, because the process was naturally prone to failure
    • B. Non-sampling risk, because the auditor misapplied the audit procedure
    • C. Fraud risk, because the exceptions were deliberately concealed from the auditor
    • D. Sampling risk, because the sample drawn was not representative of the population
    Show answer & explanation

    Answer: D
    Sampling risk is the possibility that a properly executed conclusion drawn from a sample differs from the conclusion that testing the whole population would produce, which is exactly what happened when a representative-looking sample led to an incorrect acceptance of the control. Non-sampling risk is the tempting alternative but it involves auditor error in performing or interpreting procedures, which the scenario explicitly rules out; nothing in the facts indicates concealment or an inherently failure-prone process.

  32. 32. To demonstrate that a reconciliation control operates daily, management gives the IS auditor a report generated from the application by the same team that performs the control. Applying professional skepticism, what should the auditor do before using this report as evidence?

    • A. Accept the report because system-generated output is inherently reliable
    • B. Evaluate the integrity of the report by verifying its source, parameters, and completeness
    • C. Ask the team to certify the report's accuracy in writing before relying on it
    • D. Reject the report outright because it originates from the auditee
    Show answer & explanation

    Answer: B
    System-generated reports are only as reliable as the logic, parameters, and data that produce them, so the auditor should verify how the report was generated, whether the query criteria capture the full population, and whether it could have been altered by the control owner. Rejecting all auditee-provided evidence would make auditing impractical, while blanket acceptance or a written certification from the same interested party fails to address the underlying reliability question.

  33. 33. A newly appointed audit committee member asks whether the upcoming IS audit will guarantee that no material control failures exist in the environment being reviewed. Which response BEST reflects professional audit standards?

    • A. An audit provides reasonable assurance, not absolute assurance, due to factors such as sampling and the nature of evidence
    • B. An audit guarantees detection of all material failures if the budget is sufficient
    • C. An audit provides no assurance; it only documents processes as they exist
    • D. An audit's assurance level depends entirely on whether management cooperates
    Show answer & explanation

    Answer: A
    Audits are designed to provide reasonable assurance because evidence is often persuasive rather than conclusive, testing frequently relies on samples, and controls can be circumvented or overridden; no level of budget removes these inherent limitations. Claiming a guarantee overstates what any audit can deliver, while claiming no assurance understates the value of a properly executed engagement — the standard position is the middle ground of reasonable assurance.

  34. 34. Management asks the IS audit function to help strengthen access controls for a new system that the function expects to audit next year. Which arrangement BEST preserves audit independence?

    • A. Auditors advise on control objectives and good practice, while management designs, implements, and owns the controls
    • B. Auditors implement the access rules themselves to guarantee they meet audit expectations
    • C. Auditors take temporary operational responsibility for the system until the first audit is finished
    • D. Auditors decline any contact with the project until it is complete
    Show answer & explanation

    Answer: A
    Audit independence is preserved when auditors act in an advisory capacity — sharing control objectives and good practice — while management retains all design, implementation, and operational decisions, because the function then never audits its own work. Implementing or operating controls creates a self-review threat in the later audit, but refusing all engagement forfeits the chance to prevent costly control gaps; advice without ownership is the recognized balance.

Governance and Management of IT

29 questions
  1. 35. An IT steering committee is reviewing whether a proposed enterprise system project aligns with the organization's strategic objectives. This activity is a core function of which governance concept?

    • A. Configuration management
    • B. Change management
    • C. IT governance and strategic alignment
    • D. IT service level management
    Show answer & explanation

    Answer: C
    IT governance ensures IT investments and initiatives are aligned with and support enterprise strategic objectives, typically overseen by bodies like an IT steering committee. Service level management concerns ongoing service performance agreements, change management concerns controlled implementation of changes, and configuration management tracks the state of IT assets and configurations, none of which address strategic project alignment.

  2. 36. A company's IT risk register lists a risk as 'high likelihood, high impact' but no owner or treatment plan is assigned. From a governance perspective, what is the MOST significant concern?

    • A. The risk register format does not use a heat map
    • B. Without an assigned owner and treatment plan, accountability for managing the risk to an acceptable level is unclear
    • C. The risk should be removed from the register since it lacks an owner
    • D. High likelihood and high impact risks cannot coexist in a valid register
    Show answer & explanation

    Answer: B
    Effective risk governance requires that each identified risk have a clearly assigned owner accountable for treatment decisions and monitoring; absent this, high risks may go unmanaged. Heat-map formatting is a presentation preference, not a control gap; removing an unmanaged risk from the register hides rather than resolves the exposure; and high-likelihood/high-impact risks are a valid and common combination requiring urgent attention.

  3. 37. Which of the following BEST describes the purpose of segregation of duties (SoD) within an IT organization's governance structure?

    • A. To eliminate the need for management review of transactions
    • B. To reduce the number of employees required to run IT operations
    • C. To ensure no single individual can both perform and conceal an error or irregularity through incompatible functions
    • D. To guarantee compliance with all software licensing agreements
    Show answer & explanation

    Answer: C
    Segregation of duties splits incompatible responsibilities (e.g., initiating, authorizing, recording, and reconciling) across different people so that no one person can both commit and conceal an error or fraudulent act without collusion. It is not aimed at reducing headcount, does not itself address software licensing compliance, and does not eliminate the need for management oversight — SoD complements, not replaces, review.

  4. 38. An organization outsources its data center operations. Under an effective IT governance framework, which statement about accountability is MOST accurate?

    • A. Accountability for the outsourced function transfers entirely to the service provider
    • B. The organization retains ultimate accountability for outcomes even though operational responsibility is delegated to the provider
    • C. No governance oversight is needed once a contract is signed
    • D. Accountability is shared equally and cannot be defined further
    Show answer & explanation

    Answer: B
    A foundational governance principle is that accountability cannot be outsourced — while day-to-day operational responsibility can be delegated to a third party, the organization remains ultimately accountable for outcomes, risk, and compliance. Believing accountability transfers entirely, assuming no oversight is needed post-contract, or leaving accountability undefined all create governance gaps and regulatory exposure.

  5. 39. A CIO wants to measure whether IT investments are delivering expected business value. Which approach BEST supports this governance objective?

    • A. Tracking IT spend against budget only
    • B. Establishing a benefits realization framework with defined metrics tied to business objectives
    • C. Counting the number of IT projects completed each year
    • D. Relying on vendor satisfaction surveys
    Show answer & explanation

    Answer: B
    Value delivery, a key governance focus area, requires linking IT investments to measurable business benefits through a defined benefits realization framework, not just financial or activity metrics. Tracking spend to budget measures cost control, not value; counting completed projects measures throughput, not benefit; and vendor satisfaction surveys reflect the vendor relationship, not business value delivered to the organization.

  6. 40. An organization wants to evaluate IT performance from multiple perspectives, including financial return, internal process efficiency, customer satisfaction, and organizational learning, rather than relying on financial metrics alone. Which management tool is BEST suited to this objective?

    • A. A balanced scorecard incorporating multiple performance perspectives
    • B. A single return-on-investment calculation for the IT department
    • C. A capability maturity model assessment of IT processes
    • D. An annual IT budget variance report
    Show answer & explanation

    Answer: A
    A balanced scorecard is specifically designed to evaluate performance across several perspectives simultaneously, giving a rounded view of value delivery beyond pure financial return. A single ROI figure or a budget variance report each capture only a financial dimension, and a maturity model assessment measures process capability rather than the multi-dimensional performance outcomes the organization is asking to evaluate.

  7. 41. A software delivery organization distinguishes between activities that build quality into its development process and activities that inspect deliverables for defects before release. Which pairing correctly labels these two sets of activities?

    • A. Quality control for process design; quality assurance for defect inspection
    • B. Both are quality assurance; quality control applies only to manufacturing
    • C. Quality assurance for process-focused prevention; quality control for product-focused detection
    • D. Both are quality control; quality assurance is a governance-board activity only
    Show answer & explanation

    Answer: C
    Quality assurance is process-oriented and preventive, aiming to ensure the methods used will produce quality outputs, while quality control is product-oriented and detective, examining actual deliverables for defects. Reversing the two labels is the classic trap, and neither term is restricted to manufacturing or to board-level governance — both are standard functions within software delivery organizations and are frequently examined by IS auditors reviewing the development life cycle.

  8. 42. An organization is acquiring a smaller competitor and plans to integrate its systems within a year. From an IT governance perspective, what should due diligence PRIMARILY assess before the deal closes?

    • A. Whether the target's staff prefer the acquirer's collaboration tools
    • B. The target's IT risks, including security posture, licensing obligations, and integration compatibility
    • C. Whether the acquirer's data center has spare rack space for the target's servers
    • D. Whether the target's brand colors can be applied to the acquirer's intranet
    Show answer & explanation

    Answer: B
    IT due diligence exists to surface risks that affect deal value and integration cost — such as security weaknesses, non-transferable or non-compliant software licenses, technical debt, and architectural incompatibility — before the organization is contractually committed. Staff tool preferences and cosmetic concerns are trivial relative to these exposures, and physical hosting capacity is a narrow logistics question that can be solved later, whereas undiscovered security or licensing liabilities can materially change the economics of the acquisition.

  9. 43. A financial services firm requires employees in sensitive treasury-system roles to take an uninterrupted two-week vacation each year, during which their duties are performed by others. What is the PRIMARY control rationale for this requirement?

    • A. It reduces payroll costs by spreading work across more employees
    • B. It allows managers to evaluate whether the role can be eliminated
    • C. It ensures compliance with occupational health regulations on rest periods
    • D. It increases the chance that concealed irregularities or fraud will surface while another person performs the duties
    Show answer & explanation

    Answer: D
    Mandatory vacations and job rotation are detective controls: schemes that depend on an individual's continuous, exclusive control of a process — such as suppressing exceptions or manipulating records — tend to be exposed when someone else must perform the duties for a sustained period. The measure is not primarily about cost, staffing efficiency, or labor-law rest requirements; its audit significance lies in breaking the perpetrator's uninterrupted custody that concealment requires.

  10. 44. An organization is negotiating a service level agreement with a cloud provider for a business-critical application. Which SLA characteristic MOST enables effective ongoing governance of the provider's performance?

    • A. A statement that the provider will use its best efforts to maintain availability
    • B. A commitment to industry-leading service expressed in the marketing schedule
    • C. Objectively measurable service targets with regular performance reporting and defined remedies for misses
    • D. A clause allowing the customer to terminate for convenience at any time
    Show answer & explanation

    Answer: C
    Governance over an outsourced service depends on the ability to measure performance against defined targets, receive evidence of results, and invoke consequences when commitments are missed — which is exactly what quantified service levels, reporting obligations, and remedies provide. Best-efforts and marketing language are unenforceable because they set no measurable threshold, and termination rights are a last-resort exit mechanism rather than a tool for managing day-to-day service quality.

  11. 45. An IT governance framework assigns decision rights for technology investment. Who should hold ultimate accountability?

    • A. The IT department, which understands the technology
    • B. The external service provider delivering the systems
    • C. The internal audit function
    • D. The board and executive management, since IT investment allocates enterprise resources against enterprise objectives
    Show answer & explanation

    Answer: D
    Governance concerns direction and accountability rather than execution, so technology investment decisions belong with those accountable for enterprise resources. Delegating them entirely to IT produces technically sound choices misaligned with business priorities, and audit's involvement in decisions would compromise its later assurance role.

  12. 46. An enterprise architecture is maintained and kept current. What audit-relevant benefit does it provide?

    • A. A documented view of systems, data flows and dependencies that supports impact analysis, scoping and identification of single points of failure
    • B. A guarantee that all systems are patched
    • C. Automatic compliance with data protection regulation
    • D. Elimination of the need for a business impact analysis
    Show answer & explanation

    Answer: A
    Knowing what exists and how it connects is the precondition for scoping an audit, assessing the blast radius of a change and locating concentration risk. It supports but does not substitute for a business impact analysis, which adds the criticality and recovery timing judgments architecture alone does not supply.

  13. 47. An organization outsources application hosting to a third party. Where does accountability for the controls reside?

    • A. With the regulator that approved the arrangement
    • B. Accountability is shared equally regardless of the contract
    • C. With the organization, which can delegate the activity but not the accountability, and must obtain assurance over the provider's controls
    • D. With the provider, which assumes full accountability under the contract
    Show answer & explanation

    Answer: C
    Outsourcing transfers execution while accountability stays with the organization, which is why third-party assurance reports, right-to-audit clauses and defined service levels are essential contract terms. Relying on a provider's reputation without evidence over the relevant control objectives leaves an unassessed dependency in the control environment.

  14. 48. An auditor reviews a third-party assurance report covering a service provider. What must be checked beyond the opinion?

    • A. Whether the report's scope, period and control objectives cover the services relied upon, and how complementary user entity controls are addressed
    • B. Only whether the opinion is unqualified
    • C. Only the identity of the reporting auditor
    • D. Only the report's issue date
    Show answer & explanation

    Answer: A
    A clean opinion over the wrong scope or a period not overlapping the audit period provides no assurance for the reliance intended. Complementary user entity controls matter especially, because the report's conclusions assume the customer performs specified controls that the customer may not know about.

  15. 49. Management accepts a risk that exceeds the organization's stated appetite. What should the auditor do?

    • A. Remove the finding, since management has accepted the risk
    • B. Report the matter externally to the regulator immediately
    • C. Override the decision and require remediation
    • D. Confirm the acceptance was made at an appropriate authority level and documented, and escalate to the audit committee if the residual risk remains unacceptable
    Show answer & explanation

    Answer: D
    Risk acceptance is management's prerogative, but the auditor's role is to verify it was made knowingly at sufficient authority and to escalate where the accepted residual risk remains beyond appetite. Neither overriding the decision nor silently dropping the finding is consistent with the assurance function.

  16. 50. An organization defines key performance indicators and key risk indicators for IT. What is the distinction?

    • A. The two are the same metrics reported to different audiences
    • B. Performance indicators measure achievement of objectives, while risk indicators are forward-looking signals that exposure is rising
    • C. Risk indicators measure past performance and performance indicators predict the future
    • D. Risk indicators apply only to financial risk
    Show answer & explanation

    Answer: B
    Performance indicators look backward at whether objectives were met, while risk indicators are chosen because they move before a loss event does, giving time to intervene. Confusing them produces a dashboard that reports what already happened while providing no early warning.

  17. 51. An organization's control self-assessment programme is in place. How does it relate to internal audit's work?

    • A. It engages process owners in evaluating their own controls, and internal audit may rely on it only after validating its quality and objectivity
    • B. It is performed by internal audit on behalf of process owners
    • C. It has no relationship to the audit plan
    • D. It replaces the need for internal audit testing entirely
    Show answer & explanation

    Answer: A
    Control self-assessment increases ownership and coverage but is inherently a self-review, so reliance requires validation of methodology, evidence quality and candour before it reduces audit testing. Treating it as a substitute without that validation transfers assurance to the party being assured about.

  18. 52. An auditor finds that a critical vendor has no documented exit plan. Why is this a governance concern?

    • A. Because concentration in a provider without a transition path leaves the organization unable to exit on acceptable terms if service or the relationship deteriorates
    • B. Because it prevents the vendor from being paid
    • C. Because it invalidates the vendor's assurance report
    • D. Because exit plans are required by all data protection regulation
    Show answer & explanation

    Answer: A
    Without a transition plan covering data return, format, knowledge and alternative providers, the practical cost of leaving can exceed the cost of tolerating poor service, which removes the organization's leverage. The dependency is a governance issue because it constrains future decisions rather than because any single control has failed.

  19. 53. An organization measures IT value delivery. What does an auditor look for beyond project delivery metrics?

    • A. Whether the project team was the largest available
    • B. Whether the project used the most current technology available
    • C. Whether the project finished under budget regardless of scope
    • D. Whether expected benefits were defined, tracked and realized after implementation, since on-time delivery of an unused system creates no value
    Show answer & explanation

    Answer: D
    Delivery metrics measure the project rather than the investment, and benefits realization is the step organizations most often omit because it occurs after the project team has disbanded. Without defined and tracked benefits there is no basis to conclude the investment was worthwhile or to inform the next one.

  20. 54. An IS auditor evaluating an organization's control environment wants to identify the single strongest influence on whether employees take internal controls seriously. Which factor should the auditor examine?

    • A. The frequency of disciplinary actions recorded by human resources
    • B. The number of control-related policies published on the intranet
    • C. The demonstrated commitment of senior leadership to ethical conduct and control compliance
    • D. The sophistication of the automated monitoring tools in use
    Show answer & explanation

    Answer: C
    The tone set at the top — leadership visibly following the rules it imposes and acting on violations — shapes the culture that determines whether controls are respected in practice, and it is recognized as the foundation of the control environment. Policy volume means little if leaders ignore the policies, tooling cannot compensate for a culture of workarounds, and disciplinary frequency is an ambiguous signal that may reflect either strong enforcement or a failing culture.

  21. 55. An IT steering committee is documented as responsible for approving major technology investments, but in practice the CIO regularly approves large projects unilaterally without committee review. From a governance perspective, what is the MOST significant concern?

    • A. The steering committee meets too infrequently to be useful
    • B. The CIO lacks sufficient technical expertise to approve projects alone
    • C. Decision rights defined in governance documentation are not being followed in practice
    • D. Technology investment decisions are being made too quickly for the organization's needs
    Show answer & explanation

    Answer: C
    Effective IT governance depends on decision rights being exercised as designed; when actual practice diverges from documented authority, accountability becomes unclear and the checks the structure was meant to provide are bypassed, regardless of how capable the individual making unilateral decisions may be. The committee's meeting frequency or the speed of decisions are secondary issues that do not address the core governance breakdown of authority not matching documented responsibility.

  22. 56. An organization wants to translate its IT strategy into measurable objectives spanning financial results, customer satisfaction, internal process quality, and staff learning and growth. Which management tool is designed for this purpose?

    • A. A capability maturity assessment of IT processes
    • B. A total cost of ownership analysis for the IT portfolio
    • C. A heat map of the IT risk register
    • D. An IT balanced scorecard linking strategy to metrics across multiple perspectives
    Show answer & explanation

    Answer: D
    The balanced scorecard was created precisely to express strategy as a linked set of measurable objectives across financial, customer, internal process, and learning perspectives, making it the fit for this requirement. A maturity assessment benchmarks process capability at a point in time, cost-of-ownership analysis addresses economics only, and a risk heat map visualizes exposures — none of these connects strategic intent to a balanced, multi-perspective set of performance measures.

  23. 57. A board formally states the overall level and types of risk the organization is willing to accept in pursuit of its strategy, while operating management defines acceptable variation around specific performance targets. Which terms describe these two concepts, respectively?

    • A. Risk capacity and risk appetite
    • B. Risk tolerance and residual risk
    • C. Risk appetite and risk tolerance
    • D. Residual risk and inherent risk
    Show answer & explanation

    Answer: C
    Risk appetite is the broad, board-level expression of how much risk the organization will accept in pursuing its objectives, while risk tolerance sets the acceptable deviation around specific objectives or metrics at an operational level — matching the two statements in order. Risk capacity is the maximum risk the organization can absorb regardless of willingness, and residual versus inherent risk describes exposure after and before controls, which is a different axis entirely.

  24. 58. An IS auditor reviews a corporate document that mandates minimum password length and complexity settings that every system must enforce. In a well-structured documentation hierarchy, what type of document is this?

    • A. A policy, because it states management's high-level intent for security
    • B. A guideline, because it suggests recommended practices for administrators
    • C. A standard, because it specifies mandatory settings that implement policy intent
    • D. A procedure, because it lists steps for configuring authentication
    Show answer & explanation

    Answer: C
    Standards translate high-level policy intent into specific, mandatory requirements — such as required password parameters — that apply uniformly across systems. A policy would state the broad objective (for example, that access must be authenticated commensurate with risk) without technical specifics, a guideline is advisory rather than mandatory, and a procedure gives step-by-step instructions for performing a task rather than defining the required configuration values themselves.

  25. 59. Several proposed IT initiatives compete for a limited investment budget, and executives disagree about which to fund. Which governance mechanism BEST supports a defensible selection decision?

    • A. Letting the infrastructure team select initiatives based on technical elegance
    • B. Portfolio management that evaluates initiatives on value, risk, and strategic alignment using consistent criteria
    • C. Allocating the budget proportionally to each department's headcount
    • D. Funding initiatives in the order their business cases were submitted
    Show answer & explanation

    Answer: B
    Portfolio management provides a structured, criteria-based comparison of competing initiatives — weighing expected value, risk, resource demands, and alignment with strategy — so funding decisions are transparent and defensible. First-come ordering rewards timing rather than merit, headcount-based allocation ignores value entirely, and technical preference substitutes the judgment of one function for enterprise priorities; only the portfolio approach connects investment to strategic outcomes.

  26. 60. A marketing analyst requests read access to a customer data set maintained on a shared platform. Under a sound data governance model, who should APPROVE this access request?

    • A. The database administrator, because they can technically grant the access
    • B. The requesting analyst's direct manager, because they know the analyst's duties
    • C. The data owner, because they are accountable for how the data is used and by whom
    • D. The IT help desk, because access requests flow through its ticketing system
    Show answer & explanation

    Answer: C
    The data owner holds business accountability for the data's classification and appropriate use, so authorization decisions belong to the owner, while custodians such as database administrators implement the approved access technically. The requester's manager can confirm business need as an input, but cannot authorize use of data belonging to another function, and the help desk merely routes tickets — treating routing or technical capability as approval authority breaks the accountability chain.

  27. 61. An organization has run a mandatory annual security-awareness course for three years. Which measure would give management the BEST evidence that the program is actually changing employee behavior?

    • A. Course completion rates across all departments
    • B. The number of hours of training content produced each year
    • C. Employee satisfaction scores for the training modules
    • D. A declining click rate on simulated phishing campaigns over successive tests
    Show answer & explanation

    Answer: D
    Behavioral outcome measures, such as fewer employees falling for simulated phishing over time, show whether training is translating into safer actions, which is the program's real objective. Completion rates, content volume, and satisfaction scores are activity or perception metrics: employees can complete and even enjoy training without changing how they respond to real threats, so those measures demonstrate participation rather than effectiveness.

  28. 62. An IT organization assesses its processes against a recognized capability maturity model and receives ratings for each process area. What is the PRIMARY benefit of this exercise?

    • A. It removes the need for internal audit to test those processes
    • B. It identifies capability gaps and provides a roadmap for prioritized process improvement
    • C. It certifies the organization as compliant with applicable regulations
    • D. It guarantees that higher-rated processes contain no control failures
    Show answer & explanation

    Answer: B
    Maturity assessments show where each process stands relative to a target state, revealing gaps and enabling management to sequence improvement investments where they matter most. Maturity ratings are not regulatory certifications, and a high rating describes process capability rather than guaranteeing that individual controls never fail; likewise audit testing remains necessary because maturity models assess how processes are defined and managed, not whether specific controls operated on specific occasions.

  29. 63. A board of directors receives cybersecurity information solely through a brief annual verbal update from the security officer, with no supporting metrics or independent validation. From a governance standpoint, what is the MOST significant concern?

    • A. The update consumes valuable time on the board agenda
    • B. Verbal delivery prevents the update from being translated for overseas directors
    • C. The security officer may feel micromanaged by board attention
    • D. The board cannot exercise informed oversight without regular, metric-based, and independently validated reporting
    Show answer & explanation

    Answer: D
    Effective board oversight of cyber risk requires reporting that is frequent enough to track a fast-moving threat landscape, grounded in objective metrics, and subject to independent challenge — a single unverified verbal briefing per year provides none of these, leaving directors unable to judge whether risk is within appetite. Agenda time, translation logistics, and executive comfort are peripheral issues that do not go to the board's ability to discharge its oversight duty.

Information Systems Acquisition, Development and Implementation

13 questions
  1. 64. An IS auditor is reviewing a new system development project and notes that user acceptance testing (UAT) was skipped due to schedule pressure. What is the MOST significant risk of this omission?

    • A. The project may be delivered slightly under budget
    • B. System documentation will automatically be more accurate
    • C. Business requirements may not be validated, increasing the risk the system fails to meet user needs in production
    • D. The development team will need to write less code
    Show answer & explanation

    Answer: C
    UAT is the phase where business users validate that the system meets functional requirements before go-live; skipping it significantly raises the risk of deploying a system that does not meet actual business needs, potentially requiring costly post-implementation fixes. The other options describe unrelated or implausible outcomes not caused by omitting UAT.

  2. 65. During a post-implementation review, an IS auditor finds that the project's original business case benefits were never re-measured after go-live. What should the auditor recommend?

    • A. No action is needed since the system is functioning technically
    • B. Cancel the project retroactively
    • C. Perform a benefits realization assessment comparing actual outcomes to the original business case
    • D. Rewrite the business case to match whatever was delivered
    Show answer & explanation

    Answer: C
    Post-implementation review should include comparing actual realized benefits against the original business case to confirm the investment delivered expected value and to capture lessons learned; technical functionality alone does not confirm business value was achieved. Retroactive cancellation is not meaningful after go-live, and rewriting the business case to match delivery defeats the purpose of accountability and would misrepresent the original justification.

  3. 66. Which system development life cycle (SDLC) phase is MOST critical for identifying and documenting security requirements to avoid costly rework later?

    • A. Requirements definition
    • B. Post-implementation support
    • C. Decommissioning
    • D. Final user training
    Show answer & explanation

    Answer: A
    Security requirements should be defined during the requirements phase so that security is designed into the system from the start; addressing security late in the lifecycle is far more expensive and often incomplete. Post-implementation support and user training occur after the system is built and cannot retroactively embed foundational design decisions, and decommissioning addresses end-of-life disposal, not development.

  4. 67. An organization is migrating from a legacy system to a new ERP. Which data conversion control provides the STRONGEST assurance that all records were migrated completely and accurately?

    • A. A verbal confirmation from the project manager that migration is complete
    • B. Independent reconciliation of record counts and control totals between the old and new systems
    • C. Reviewing the migration tool's marketing documentation
    • D. Confirming the new system's user interface looks similar to the old one
    Show answer & explanation

    Answer: B
    Reconciling record counts and control totals (e.g., financial balances, transaction counts) between source and target systems provides objective, verifiable evidence of completeness and accuracy of data conversion. Verbal confirmation lacks evidentiary support, vendor marketing material is not audit evidence of what actually occurred, and UI similarity says nothing about underlying data integrity.

  5. 68. A project team wants to select a system development methodology that allows for iterative delivery and frequent stakeholder feedback on a project with evolving requirements. Which approach is MOST appropriate?

    • A. Traditional waterfall model with a single delivery at project end
    • B. Agile methodology with iterative sprints and regular stakeholder review
    • C. A big-bang cutover with no phased releases
    • D. A methodology with no defined requirements process
    Show answer & explanation

    Answer: B
    Agile methodologies use short iterative cycles (sprints) with frequent stakeholder feedback, making them well suited to projects with evolving or unclear requirements. Waterfall assumes requirements are fixed upfront and delivers only at the end, a big-bang cutover concerns deployment strategy rather than requirements evolution, and a methodology lacking any requirements process would create significant risk regardless of requirement stability.

  6. 69. During system development, a project manager wants to estimate the relative size and effort of a proposed application based on the number and complexity of its inputs, outputs, inquiries, and internal data structures, independent of the programming language to be used. Which estimation technique is being applied?

    • A. Program evaluation and review technique
    • B. Earned value management
    • C. Critical path method
    • D. Function point analysis
    Show answer & explanation

    Answer: D
    Function point analysis estimates application size and effort based on counting functional components such as inputs, outputs, inquiries, and files, which makes it independent of the underlying programming language or technology. The other three techniques are project scheduling and cost-performance tools used once a project is underway, not techniques for estimating functional size from requirements.

  7. 70. A project delivers a system that meets its specification but not the business need. What control weakness does this most likely indicate?

    • A. Inadequate requirements definition and stakeholder involvement at the outset
    • B. Insufficient unit testing during construction
    • C. Weak production change management
    • D. Inadequate backup procedures
    Show answer & explanation

    Answer: A
    Building the wrong thing correctly is a requirements failure, since testing verifies conformance to the specification rather than the specification's fitness for purpose. This is why the cost of a defect rises so steeply with the phase in which it is introduced, and why user involvement during requirements is a primary control in systems development.

  8. 71. What is the purpose of user acceptance testing in a system implementation?

    • A. To verify that individual code modules function correctly
    • B. To measure system performance under peak load
    • C. To confirm the vendor has been paid
    • D. To confirm the system meets business requirements from the user's perspective before it is accepted into production
    Show answer & explanation

    Answer: D
    User acceptance testing is the business's own verification against its requirements, which is distinct from unit testing of modules, integration testing of interfaces and stress testing of capacity. Approval by users is the acceptance decision, and an implementation proceeding without it removes the business's control over what it is being given.

  9. 72. An organization plans a parallel changeover from an old system to a new one. What is the principal advantage over a direct cutover?

    • A. It eliminates the need for data conversion
    • B. It is the least costly changeover approach
    • C. It requires no user training on the new system
    • D. Both systems run concurrently so results can be compared and the old system remains available as a fallback, reducing implementation risk
    Show answer & explanation

    Answer: D
    Parallel running buys risk reduction at the cost of operating two systems and reconciling their output, which is why it is the most expensive approach and is reserved for high-criticality changeovers. Direct cutover is cheapest and riskiest, while phased and pilot approaches sit between them.

  10. 73. An auditor reviews a data conversion from a legacy system. What control most directly addresses conversion completeness?

    • A. Retaining a backup of the legacy database
    • B. Restricting access to the conversion tool
    • C. Reconciliation of record counts and control totals between source and target, with documented investigation of differences
    • D. Encryption of the data in transit during conversion
    Show answer & explanation

    Answer: C
    Completeness is demonstrated by reconciling counts and totals across the boundary, which detects records silently dropped or duplicated. Encryption addresses confidentiality, access restriction addresses unauthorized change, and a backup enables recovery, so each addresses a real risk but none evidences that everything arrived.

  11. 74. A developer requires access to the production environment to resolve an urgent defect. What compensating control is appropriate?

    • A. Time-limited, approved and logged emergency access with independent review of the actions taken afterward
    • B. Permanent production access for the development team
    • C. Granting access without logging to avoid slowing the fix
    • D. Allowing the developer to disable audit logging during the change
    Show answer & explanation

    Answer: A
    Segregation between development and production exists to prevent unreviewed code reaching live systems, and where operational necessity overrides it the compensating control is a bounded, approved and reviewed exception. Emergency access that is neither time-limited nor reviewed simply removes the segregation permanently under an urgent label.

  12. 75. A change management process requires approval before deployment. What does an auditor test to conclude the control operated?

    • A. A sample of production changes traced back to documented approval, plus a search for changes that reached production without a corresponding record
    • B. Only the change management policy document
    • C. Only the list of approved change requests
    • D. Only the number of changes deployed in the period
    Show answer & explanation

    Answer: A
    Sampling from the approval log tests only that approved changes were approved, which proves nothing about unapproved changes. Testing must also start from the population of what actually reached production, since the risk being controlled is precisely the change that bypassed the process.

  13. 76. An organization uses agile development. How does this affect the auditor's approach to controls?

    • A. The control objectives remain the same while the evidence changes form, appearing in backlogs, automated pipeline gates and iteration records rather than phase-gate documents
    • B. The auditor should require the organization to adopt a waterfall method
    • C. Only the final release requires any control evidence
    • D. Control objectives no longer apply in an agile environment
    Show answer & explanation

    Answer: A
    Requirements traceability, testing, approval and segregation still matter regardless of methodology, but in agile environments the evidence lives in tooling rather than in signed documents. An auditor who insists on phase-gate artefacts either reports false deficiencies or pushes the organization toward ceremony that adds no control value.

Information Systems Operations and Business Resilience

13 questions
  1. 77. An IS auditor reviewing change management for a production ERP system notes that emergency changes are deployed without prior testing but are documented after the fact. What is the BEST recommendation?

    • A. Allow emergency changes to bypass all documentation requirements permanently
    • B. Eliminate the emergency change process entirely
    • C. Require the same multi-week testing cycle for emergency changes as standard changes
    • D. Require post-implementation review and retrospective approval with documented justification for each emergency change
    Show answer & explanation

    Answer: D
    Emergency change processes exist precisely because full standard testing isn't feasible under time pressure, but a well-controlled process requires retrospective review, approval, and documented justification to ensure accountability and to identify any issues introduced. Eliminating the process removes a legitimate business need, permanently skipping documentation removes accountability entirely, and requiring standard multi-week testing defeats the purpose of an emergency process.

  2. 78. An organization's business continuity plan (BCP) specifies a recovery time objective (RTO) of 4 hours for its order-processing system. What does this RTO represent?

    • A. The frequency at which backups must be taken
    • B. The total time allotted for annual disaster recovery testing
    • C. The maximum acceptable amount of data loss measured in time
    • D. The maximum acceptable time the system can be unavailable before causing unacceptable business impact
    Show answer & explanation

    Answer: D
    Recovery Time Objective (RTO) defines the maximum tolerable downtime — how quickly a system or process must be restored after a disruption to avoid unacceptable business impact. Maximum acceptable data loss is described by the Recovery Point Objective (RPO), not RTO; backup frequency is a control used to help meet RPO/RTO targets but isn't itself the RTO; and DR test duration is a separate operational planning detail.

  3. 79. During a review of an organization's incident management process, an IS auditor finds that security incidents are resolved but root cause analysis is rarely performed. What is the MOST significant long-term risk?

    • A. Recurring incidents from the same underlying cause, since the true source of the problem is never addressed
    • B. Faster incident closure times going forward
    • C. Increased helpdesk ticket volume in the short term only
    • D. Improved compliance with service level agreements
    Show answer & explanation

    Answer: A
    Without root cause analysis, underlying weaknesses that caused an incident remain unaddressed, leading to recurrence of the same or similar incidents — this is the core rationale for problem management within IT service management. Ticket volume in isolation isn't the central risk, and neither faster closure nor better SLA compliance would logically result from skipping root cause analysis; if anything, recurring incidents tend to degrade both.

  4. 80. An organization performs full backups weekly and incremental backups daily. If a server fails on a Thursday (3 days after the last full backup), what is required to fully restore data to the most recent point?

    • A. Only the original full backup from initial system setup
    • B. Only the most recent incremental backup
    • C. No backups are needed if the system has RAID storage
    • D. The last full backup plus each incremental backup taken since, applied in sequence
    Show answer & explanation

    Answer: D
    With a full-plus-incremental backup strategy, restoring to the most recent point requires the last full backup followed by every incremental backup taken since, applied in chronological order, because each incremental captures only changes since the previous backup. Using only the latest incremental omits earlier changes, the original setup backup is far too outdated, and RAID protects against disk-level hardware failure but does not substitute for backups against data corruption, deletion, or logical errors.

  5. 81. Which of the following is the PRIMARY reason organizations conduct periodic disaster recovery (DR) testing rather than relying solely on a documented DR plan?

    • A. To satisfy an annual budget requirement
    • B. To validate that the plan actually works in practice and to identify gaps before a real disaster occurs
    • C. To reduce the need for a documented plan going forward
    • D. To replace the need for offsite data backups
    Show answer & explanation

    Answer: B
    A documented plan alone does not guarantee recoverability; testing validates assumptions, uncovers gaps (e.g., outdated contact lists, untested dependencies, insufficient capacity), and builds team readiness, which is the primary rationale for DR testing. Budget justification is not the driving purpose, testing does not eliminate the need for documentation, and it does not substitute for maintaining offsite backups, which testing itself typically relies on.

  6. 82. An IS auditor reviewing capacity management notes that a critical database server has consistently run at 95% CPU utilization for the past quarter with no capacity plan in place. What is the MOST significant risk?

    • A. Users will need additional training on the application
    • B. The server may be under warranty expiration soon
    • C. Performance degradation or an outage as demand grows, potentially disrupting critical business operations
    • D. The vendor may increase software licensing costs
    Show answer & explanation

    Answer: C
    Sustained near-maximum utilization without a capacity plan risks performance degradation or outright failure as workload grows further, directly threatening availability of a critical business system — the core concern of capacity and availability management. Warranty status, licensing costs, and user training are unrelated secondary considerations that do not address the immediate operational risk of resource exhaustion.

  7. 83. A business impact analysis has been completed. What does it establish that a risk assessment does not?

    • A. The criticality of each process and the maximum tolerable outage, which drive recovery objectives
    • B. The likelihood of each threat occurring
    • C. The technical configuration of recovery infrastructure
    • D. The cost of cyber insurance premiums
    Show answer & explanation

    Answer: A
    A business impact analysis measures consequence over time regardless of cause, producing the criticality ranking and tolerable outage that set recovery objectives. Threat likelihood belongs to the risk assessment, and the technical recovery design is what the objectives then drive rather than what the analysis produces.

  8. 84. A system has a recovery point objective of four hours and a recovery time objective of eight hours. What do these mean?

    • A. Up to four hours of data may be lost, and the system must be restored to service within eight hours of the disruption
    • B. The system must be restored within four hours and may lose eight hours of data
    • C. Backups run every eight hours and are retained for four hours
    • D. The system may be unavailable for four hours per month
    Show answer & explanation

    Answer: A
    The recovery point objective bounds acceptable data loss and therefore drives backup or replication frequency, while the recovery time objective bounds acceptable downtime and drives the recovery architecture. A four-hour recovery point cannot be met by nightly backups, which is the most common inconsistency between stated objectives and actual capability.

  9. 85. An organization maintains a hot site for disaster recovery. What characterizes it relative to a cold site?

    • A. It is an empty facility with power and connectivity only
    • B. It requires no testing because it mirrors production
    • C. It costs less than a cold site because it is shared
    • D. It is fully equipped and current, enabling resumption within a short period, at substantially higher cost than an empty facility requiring build-out
    Show answer & explanation

    Answer: D
    Hot, warm and cold sites trade cost against recovery speed, with a hot site holding current equipment and data and a cold site providing only the shell. Mirroring does not remove the need to test, since untested failover routinely reveals dependencies, credentials and data synchronization gaps that only an exercise exposes.

  10. 86. A disaster recovery plan is tested using a walkthrough rather than a full interruption test. What is the limitation?

    • A. It validates understanding and documentation but does not demonstrate that the technical recovery actually works under real conditions
    • B. It is more disruptive than a full interruption test
    • C. It cannot involve business stakeholders
    • D. It provides equivalent assurance to a full test at lower cost
    Show answer & explanation

    Answer: A
    Testing methods form a progression from checklist and walkthrough through simulation and parallel to full interruption, with assurance and disruption rising together. A walkthrough surfaces documentation and role gaps cheaply but cannot reveal whether restoration completes within the recovery time objective.

  11. 87. An auditor reviews backup practices and finds backups run nightly and complete successfully. What further evidence is essential?

    • A. Evidence that restoration from those backups has been tested successfully, since a backup that cannot be restored provides no recovery capability
    • B. The brand of backup software in use
    • C. The physical size of the backup media
    • D. The number of backup jobs configured
    Show answer & explanation

    Answer: A
    A successful backup job indicates data was written, not that it can be read back into a working system, and media faults, encryption key loss and incomplete scope routinely surface only at restoration. Periodic documented restore tests are what convert a backup process into a recovery capability.

  12. 88. An organization applies capacity management to its infrastructure. What is the audit-relevant objective?

    • A. Reducing the number of servers regardless of demand
    • B. Ensuring resources meet current and projected demand so availability commitments are met without unnecessary expenditure
    • C. Eliminating the need for performance monitoring
    • D. Ensuring all systems run at maximum utilization
    Show answer & explanation

    Answer: B
    Capacity management balances availability against cost by matching provisioned resources to forecast demand, so both shortage and persistent overprovisioning are failures. Running at maximum utilization removes the headroom that absorbs spikes, which converts a capacity plan into an availability incident waiting for a busy day.

  13. 89. An incident and a problem are distinguished in service management. What is the difference?

    • A. An incident is an unplanned interruption requiring restoration of service, while a problem is the underlying cause requiring elimination
    • B. An incident is more severe than a problem by definition
    • C. A problem is a customer complaint and an incident is a system fault
    • D. The two terms are interchangeable
    Show answer & explanation

    Answer: A
    Incident management restores service as quickly as possible, which may mean a workaround, while problem management removes the cause so the incident stops recurring. Organizations that only run incident management resolve the same interruption repeatedly, which shows up in audit as a high rate of recurring incidents.

Protection of Information Assets

11 questions
  1. 90. Which access control model grants permissions based on a user's assigned job function rather than granting permissions to each individual user directly?

    • A. Role-based access control (RBAC)
    • B. Mandatory access control (MAC)
    • C. Discretionary access control (DAC)
    • D. Rule-based routing
    Show answer & explanation

    Answer: A
    RBAC assigns permissions to roles that correspond to job functions, and users inherit access by being assigned to a role, simplifying administration and supporting least privilege and segregation of duties. DAC lets resource owners grant access at their discretion to individual users, MAC enforces access based on fixed security labels/classifications set by a central authority rather than job function, and 'rule-based routing' is a networking concept, not an access control model.

  2. 91. An IS auditor discovers that terminated employees' network accounts remain active for an average of 30 days after departure. What is the MOST significant risk this presents?

    • A. Increased software licensing costs only
    • B. Slower network performance due to unused accounts
    • C. Unauthorized access to systems and data by former employees or others using their still-active credentials
    • D. Increased helpdesk password reset requests
    Show answer & explanation

    Answer: C
    Active accounts for departed employees represent a direct access control failure, creating risk of unauthorized access, data theft, or sabotage by the former employee or anyone who obtains their credentials — this is why timely deprovisioning is a fundamental logical access control. Licensing cost, network performance, and helpdesk volume are minor or unrelated secondary effects compared to the core security exposure.

  3. 92. An auditor evaluates logical access controls. What does the principle of least privilege require?

    • A. Each account holds only the access necessary for its function, and no more, for as long as it is needed
    • B. Administrators require no access restrictions
    • C. All users share a common access profile for consistency
    • D. Access is granted broadly and revoked when misuse is detected
    Show answer & explanation

    Answer: A
    Least privilege limits the damage any single compromised or misused account can cause, and the temporal element matters as much as the scope, since access accumulated through role changes is a common finding. Privilege creep, dormant accounts and standing administrative rights are the recurring failures of this principle in practice.

  4. 93. An auditor reviews user access recertification. What is the control's purpose?

    • A. Periodic confirmation by an accountable owner that each user's access remains appropriate, catching accumulation from role changes and departures
    • B. Confirming that the access management system is licensed
    • C. Testing whether users can access systems from remote locations
    • D. Verifying that users remember their passwords
    Show answer & explanation

    Answer: A
    Provisioning controls address the moment access is granted, but neither detects the access a long-tenured employee accumulated across three role changes. Recertification is the detective control closing that gap, and its effectiveness depends entirely on reviewers who understand what the entitlements actually permit rather than approving lists reflexively.

  5. 94. Data is classified into sensitivity levels. What does classification primarily enable?

    • A. Automatic encryption of all organizational data
    • B. Proportionate application of controls, so protection effort matches the consequence of disclosure or loss
    • C. Elimination of the need for access controls
    • D. Compliance with all applicable regulations by itself
    Show answer & explanation

    Answer: B
    Uniform controls either overprotect routine data at unacceptable cost or underprotect sensitive data, so classification is what makes proportionate protection possible. Its value depends on an accountable data owner making the classification and on the classification actually driving control selection rather than sitting in a register.

  6. 95. An organization encrypts data at rest in a database. What risk does this address, and what does it not?

    • A. It protects against exposure of the underlying storage media or files, but not against an attacker or user operating through an authorized application session
    • B. It removes the need for access controls on the database
    • C. It protects data in transit across the network
    • D. It protects against all forms of unauthorized data access
    Show answer & explanation

    Answer: A
    Encryption at rest defends against theft of disks, files or backups, since the data is decrypted transparently for authorized sessions, which means it does nothing against credential compromise or excessive application privilege. Transport encryption and access control address those separate exposures, and treating encryption as a general answer leaves the most common attack path open.

  7. 96. An auditor reviews the physical security of a data centre. Which control best addresses tailgating?

    • A. A mantrap or interlocking door arrangement permitting one authenticated person through at a time
    • B. A visitor sign-in log at reception
    • C. Closed circuit television covering the entrance
    • D. A door alarm sounding when held open
    Show answer & explanation

    Answer: A
    Tailgating defeats badge controls because the door is legitimately open, so the effective control physically enforces single-person entry. Cameras and logs are detective, identifying the event after it occurred, which matters for investigation but does not prevent the unauthorized entry.

  8. 97. Media containing sensitive data is decommissioned. What disposal control is appropriate?

    • A. Deleting the files and reformatting the drive
    • B. Sanitization or destruction appropriate to the media type and data sensitivity, with documented evidence of completion
    • C. Storing the media indefinitely in a locked room
    • D. Returning the media to the original vendor without further action
    Show answer & explanation

    Answer: B
    Deletion and formatting leave recoverable data, so sanitization must match the media technology, and certificates of destruction provide the evidence an auditor needs. Indefinite retention converts a disposal problem into a storage and retention problem rather than resolving it, and unverified vendor return transfers the data without transferring accountability.

  9. 98. An auditor examines security event logging. Beyond generating logs, what is essential?

    • A. That logs are generated at the highest verbosity for all systems
    • B. That logs are protected from alteration, retained for an adequate period and actually reviewed or monitored for indicators requiring action
    • C. That logs are stored on the same system that generates them
    • D. That log files are deleted regularly to control storage cost
    Show answer & explanation

    Answer: B
    Unreviewed logs provide forensic material after an incident but no detection during one, and logs stored only on the originating system are alterable by whoever compromises it. Maximum verbosity on everything typically produces volume that defeats review, so tuning to meaningful events is part of making the control work.

  10. 99. An organization deploys multi-factor authentication. What makes an authentication scheme genuinely multi-factor?

    • A. The factors come from different categories such as something known, something possessed and something inherent
    • B. The password must exceed a minimum length
    • C. Authentication is required at more than one system
    • D. Two separate passwords are required
    Show answer & explanation

    Answer: A
    Two secrets of the same category share a failure mode, since a phishing attack or credential dump captures both, which is why category diversity rather than count defines the control. This also explains why the strength of a second factor depends heavily on its resistance to interception and relay rather than on its existence.

  11. 100. An auditor assesses a data loss prevention deployment. What limits its effectiveness?

    • A. Its inability to inspect any network traffic
    • B. Its incompatibility with encryption of any kind
    • C. Its dependence on accurate data identification and on covering the channels actually used, since unclassified data or an uncovered channel passes unexamined
    • D. The requirement that it be deployed only on servers
    Show answer & explanation

    Answer: C
    Data loss prevention can only act on what it recognizes as sensitive and only where it sits in the path, so classification quality and channel coverage bound its value more than detection technology does. Encrypted or personally controlled channels are the common blind spots, which is why the control is evaluated alongside rather than in place of access restriction.

2026 statistics

Key facts: CISA exam

Questions
150
Time limit
4h
Passing score
450 on a scale of 200-800
Exam fee
$575
Governing body
ISACA

This free CISA practice test has 159 original questions written to ISACA's official content outline, last checked against it on July 18, 2026, 100 of them listed on this page and the rest loaded by the drill. Every question shows a worked explanation, and nothing here requires a signup.

The questions are grouped under five outline areas: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience and Protection of Information Assets.

As of 2026, the CISA exam fee is $575 (ISACA members; $760 non-members).

How the CISA practice bank covers the outline

159 questions across 5 outline areas — the same areas the page's sections use.

Counts are the live question bank, grouped by the outline area each question was written to.

159 questions across five outline areas. The largest, Information Systems Auditing Process, holds 40 questions (25%); the page's sections follow the same split.
Exam format and study resources

Get a free CISA study plan

A week-by-week plan plus new practice questions, straight to your inbox.

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the official exam content outline:

Frequently asked questions

How much does the CISA exam cost and how long do I have to test?

The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Once you register, your exam eligibility period is 6 months from the date of registration, so plan your study timeline to sit for the exam within that window. If you don't schedule and take the exam before the eligibility period ends, you would generally need to re-register — so it's smart to only register once you're confident you can be exam-ready within six months.

How is the CISA exam structured and what score do I need to pass?

The CISA exam consists of 150 questions and is built around 5 job practice domains, with a total testing time of 240 minutes (4 hours). To pass, you need a scaled score of 450 or higher. With 150 questions across 240 minutes, that works out to roughly 1.6 minutes per question on average — a comfortable pace that still leaves time to flag and review tougher items before you submit.

Which CISA domains should I study the most?

The five content domains are the Information Systems Auditing Process, Governance and Management of Information Technology, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. They aren't weighted equally: Domain 1 (Information Systems Auditing Process) is 18%, Domain 2 (Governance and Management of IT) is 18%, Domain 3 (IS Acquisition, Development and Implementation) is 12%, Domain 4 (IS Operations and Business Resilience) is 26%, and Domain 5 (Protection of Information Assets) is 26%. Because Domains 4 and 5 together account for 52% of the exam content, prioritizing those two areas gives you the highest return on your study time, while Domain 3 at just 12% carries the least weight.

After I pass the exam, how do I get certified and keep the credential?

Passing the exam is not the final step. Candidates have 5 years from the date of passing the exam to apply for CISA certification, so don't let that window lapse after you pass. Once certified, professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential — meaning CISA is not a one-and-done certification but requires ongoing professional education to stay active. It also helps to know the exam is current: the updated CISA exam became available on 1 August 2024 and emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices, so study from up-to-date materials aligned to that revision.