Certified Information Systems Auditor Flashcards
Browse all 30 cards
How many domains make up the CISA job practice, and what is the total exam duration?
The CISA exam covers 5 job practice domains and has a total testing time of 240 minutes (4 hours) across 150 questions.
Which two CISA domains carry the highest combined weighting, and what is that weighting?
Domain 4 (Information Systems Operations and Business Resilience) and Domain 5 (Protection of Information Assets) together account for 52% of exam content, each weighted at 26%.
What scaled score is needed to pass the CISA exam?
A scaled score of 450 or higher (on ISACA's 200-800 scale) is required to pass.
What is the primary objective of an IS audit charter?
An audit charter formally documents the audit function's purpose, authority, and responsibility, and it should be approved by senior management and the audit committee/board.
Define audit risk.
Audit risk is the risk that the auditor may issue an incorrect opinion because material errors or misstatements went undetected; it combines inherent risk, control risk, and detection risk.
What is the difference between inherent risk and control risk?
Inherent risk is the susceptibility of a process to material error assuming no controls exist; control risk is the risk that a control will fail to prevent or detect such an error in a timely manner.
What is detection risk in an audit context?
Detection risk is the risk that an auditor's procedures will fail to detect a material error or misstatement that exists.
What is the purpose of a risk-based audit approach?
A risk-based approach directs audit resources and testing toward the areas of highest risk to the organization, rather than treating all areas equally, maximizing audit value and coverage efficiency.
What is segregation of duties (SoD) and why does it matter to an IS auditor?
SoD divides critical tasks (e.g., authorization, custody, recordkeeping) among different individuals so no single person can commit and conceal fraud or errors; auditors test for SoD violations as a key control weakness.
Distinguish preventive, detective, and corrective controls.
Preventive controls stop an undesirable event before it occurs (e.g., access controls); detective controls identify an event after it happens (e.g., log monitoring); corrective controls remediate the impact after detection (e.g., restoring from backup).
What is a compensating control?
A compensating control is an alternative control that reduces risk to an acceptable level when a primary control cannot be implemented, e.g., manager review substituting for automated SoD enforcement.
What is the role of COBIT in IT governance?
COBIT is ISACA's framework for the governance and management of enterprise IT, aligning IT goals with business objectives and providing a structure for control, risk, and performance evaluation.
What is IT governance, broadly defined?
IT governance is the leadership, organizational structures, and processes that ensure an organization's IT sustains and extends its strategies and objectives, tying IT investment to business value and risk management.
What is a Business Impact Analysis (BIA)?
A BIA identifies critical business processes and the impact of their disruption over time, establishing recovery priorities, Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO).
Define Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
RTO is the maximum acceptable time to restore a process/system after a disruption; RPO is the maximum acceptable amount of data loss measured in time (how far back data must be recoverable).
What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
A BCP addresses continuing critical business operations during and after a disruption across the whole organization; a DRP is a narrower, technical subset focused on restoring IT systems and infrastructure.
What is a change management process meant to control?
Change management ensures that changes to systems, applications, and infrastructure are requested, assessed, approved, tested, and documented before deployment to minimize unintended impact and maintain integrity.
What is the System Development Life Cycle (SDLC), and why is auditor involvement important early?
The SDLC is the structured process of planning, analyzing, designing, developing, testing, implementing, and maintaining systems; early auditor involvement ensures controls and requirements are built in rather than retrofitted.
What is the purpose of user acceptance testing (UAT)?
UAT validates that a system meets business requirements and functions correctly from the end user's perspective before it is moved into production.
What does the principle of least privilege mean?
Least privilege means users and processes are granted only the minimum access rights necessary to perform their required functions, reducing the attack surface and potential for misuse.
What is defense in depth?
Defense in depth is a security strategy that layers multiple, overlapping controls (physical, technical, administrative) so that if one control fails, others still provide protection.
What is the difference between authentication and authorization?
Authentication verifies the identity of a user or system (who you are); authorization determines what actions or resources that verified identity is permitted to access (what you can do).
What is a firewall's primary function in a network security architecture?
A firewall enforces access control policy by filtering network traffic between zones of differing trust levels based on defined rules.
What is encryption at rest versus encryption in transit?
Encryption at rest protects stored data on disks or media; encryption in transit protects data as it moves across a network, typically via protocols like TLS.
What is a digital signature used to provide?
A digital signature provides authentication, integrity, and non-repudiation by using asymmetric cryptography to prove a message originated from a specific sender and was not altered.
What is the purpose of a vulnerability assessment versus a penetration test?
A vulnerability assessment identifies and catalogs known weaknesses in systems, while a penetration test actively attempts to exploit those weaknesses to demonstrate real-world impact.
What is data classification and why is it a foundational control?
Data classification categorizes information (e.g., public, internal, confidential, restricted) based on sensitivity and value, driving proportionate handling, access, and protection requirements.
What is an audit evidence sufficiency and appropriateness standard used for?
Sufficiency refers to the quantity of evidence needed to support a conclusion; appropriateness refers to its relevance and reliability; auditors must gather evidence meeting both criteria to support findings.
What is CoBIT's relationship to CISA exam content?
COBIT provides the governance and control framework referenced throughout CISA domains, especially Domain 2 (Governance and Management of IT), for aligning IT processes with enterprise goals.
What is the purpose of continuous auditing/continuous monitoring techniques?
These techniques use automated tools to test controls and transactions on an ongoing or near-real-time basis, enabling earlier detection of anomalies compared to periodic manual audits.