CISA Practice Test.
159 free practice questions with answers and explanations.
No signup required. Choose a topic and review each answer.
Start practicing →About these practice questions
These are original study questions written from published exam objectives—not recalled, copied, or confidential live-exam items. Always confirm current coverage with the official sources linked on this page.
Exam format and study resources
The CISA is administered by ISACA, with 150 scored questions, a 4 hours time limit and a 450 on a scale of 200-800 result.
This free CISA practice test has 159 original questions written to ISACA's official content outline, last checked against it on July 18, 2026. Every question shows a worked explanation, and nothing here requires a signup.
As of 2026, the CISA exam fee is $575 (ISACA members; $760 non-members).
Browse all questions & answers
1. During the planning phase of an IS audit, an IS auditor discovers that a business process has never been formally risk-assessed. What should the auditor do FIRST?
- A. Perform a risk assessment of the process to determine audit scope and priority
- B. Exclude the process from the audit since no risk assessment exists
- C. Immediately report the missing risk assessment to the audit committee as a finding
- D. Ask management to sign off on the process as low risk before proceeding
Show answer & explanation
Answer: A
A risk-based audit approach requires the auditor to assess risk to determine scope, depth, and resource allocation; performing the assessment lets the auditor make an informed scoping decision. Excluding the process ignores potential exposure, reporting prematurely skips the auditor's own analysis, and asking management to self-certify risk undermines auditor independence and objectivity.2. An IS auditor is evaluating evidence gathered during fieldwork. Which characteristic of evidence is MOST important when the auditor must rely on it to support a significant audit finding?
- A. The evidence was easy and inexpensive to obtain
- B. The evidence confirms the auditor's initial expectations
- C. The evidence was provided directly by the process owner
- D. The evidence is sufficient, reliable, and relevant to the audit objective
Show answer & explanation
Answer: D
Audit evidence must be sufficient (enough in quantity), reliable (from a trustworthy source, ideally independently corroborated), and relevant (directly related to the objective) to support a conclusion. Ease of collection is irrelevant to quality, evidence solely from the process owner may lack independence, and evidence should be evaluated objectively rather than selected to confirm preconceptions, which introduces bias.3. An IS auditor finds that a control was operating effectively for 10 of 12 months tested, with two months showing exceptions due to a since-corrected configuration error. What is the MOST appropriate conclusion?
- A. The control can be rated fully effective because it is now corrected
- B. The control exceptions should be reported along with root cause, remediation, and residual risk during the exception period
- C. The finding should be dropped since the issue is already fixed
- D. The sample size is too small to draw any conclusion
Show answer & explanation
Answer: B
Auditors must report control exceptions even when subsequently remediated, because the risk existed during the exception window and stakeholders need to understand root cause and residual exposure. Marking it fully effective or dropping the finding hides real risk that occurred, and a 12-month sample with two exceptions is generally sufficient to support a conclusion, not too small.4. Which sampling method is MOST appropriate when an IS auditor wants every item in the population to have an equal chance of selection, without bias from the auditor's judgment?
- A. Discovery sampling only
- B. Haphazard sampling
- C. Judgmental sampling
- D. Statistical (random) sampling
Show answer & explanation
Answer: D
Statistical sampling uses random selection so every item has a known, equal probability of being chosen, allowing the auditor to mathematically project results and evaluate sampling risk. Judgmental sampling relies on auditor discretion and introduces bias, haphazard sampling is not truly random and cannot be statistically evaluated, and discovery sampling is a specific technique aimed at detecting at least one occurrence of a critical exception, not general unbiased selection.5. During an audit, management disagrees with a draft finding and provides additional documentation not previously available to the auditor. What is the BEST course of action?
- A. Escalate immediately to the audit committee without reviewing the documentation
- B. Ignore the new documentation since the audit fieldwork is complete
- C. Remove the finding automatically to maintain a good working relationship with management
- D. Evaluate the new evidence objectively and revise the finding if warranted before finalizing the report
Show answer & explanation
Answer: D
An IS auditor must remain objective and consider all relevant evidence before finalizing conclusions; if new documentation is credible and relevant it should be evaluated and the finding adjusted as warranted. Ignoring evidence or removing a finding to preserve relationships compromises independence and integrity, and escalating without review skips due professional care.6. An organization's internal audit charter grants the CISA-certified auditor authority to review all IT systems but is silent on access to third-party service providers used for payroll processing. What is the BEST way to address this gap?
- A. Assume authority extends automatically to any vendor touching company data
- B. Rely solely on the vendor's own internal audit reports without independent verification
- C. Update the audit charter or contractual right-to-audit clauses to explicitly cover third-party providers
- D. Decline to audit any process that involves a third party
Show answer & explanation
Answer: C
Audit authority should be clearly documented; when third parties are in scope, the charter or vendor contracts should include explicit right-to-audit clauses so the scope of authority is unambiguous. Assuming authority is risky without documentation, relying only on vendor self-reported audits lacks independent assurance, and simply declining to audit ignores real risk in outsourced processes.7. An IT steering committee is reviewing whether a proposed enterprise system project aligns with the organization's strategic objectives. This activity is a core function of which governance concept?
- A. Configuration management
- B. Change management
- C. IT governance and strategic alignment
- D. IT service level management
Show answer & explanation
Answer: C
IT governance ensures IT investments and initiatives are aligned with and support enterprise strategic objectives, typically overseen by bodies like an IT steering committee. Service level management concerns ongoing service performance agreements, change management concerns controlled implementation of changes, and configuration management tracks the state of IT assets and configurations, none of which address strategic project alignment.8. A company's IT risk register lists a risk as 'high likelihood, high impact' but no owner or treatment plan is assigned. From a governance perspective, what is the MOST significant concern?
- A. The risk register format does not use a heat map
- B. Without an assigned owner and treatment plan, accountability for managing the risk to an acceptable level is unclear
- C. The risk should be removed from the register since it lacks an owner
- D. High likelihood and high impact risks cannot coexist in a valid register
Show answer & explanation
Answer: B
Effective risk governance requires that each identified risk have a clearly assigned owner accountable for treatment decisions and monitoring; absent this, high risks may go unmanaged. Heat-map formatting is a presentation preference, not a control gap; removing an unmanaged risk from the register hides rather than resolves the exposure; and high-likelihood/high-impact risks are a valid and common combination requiring urgent attention.9. Which of the following BEST describes the purpose of segregation of duties (SoD) within an IT organization's governance structure?
- A. To eliminate the need for management review of transactions
- B. To reduce the number of employees required to run IT operations
- C. To ensure no single individual can both perform and conceal an error or irregularity through incompatible functions
- D. To guarantee compliance with all software licensing agreements
Show answer & explanation
Answer: C
Segregation of duties splits incompatible responsibilities (e.g., initiating, authorizing, recording, and reconciling) across different people so that no one person can both commit and conceal an error or fraudulent act without collusion. It is not aimed at reducing headcount, does not itself address software licensing compliance, and does not eliminate the need for management oversight — SoD complements, not replaces, review.10. An organization outsources its data center operations. Under an effective IT governance framework, which statement about accountability is MOST accurate?
- A. Accountability for the outsourced function transfers entirely to the service provider
- B. The organization retains ultimate accountability for outcomes even though operational responsibility is delegated to the provider
- C. No governance oversight is needed once a contract is signed
- D. Accountability is shared equally and cannot be defined further
Show answer & explanation
Answer: B
A foundational governance principle is that accountability cannot be outsourced — while day-to-day operational responsibility can be delegated to a third party, the organization remains ultimately accountable for outcomes, risk, and compliance. Believing accountability transfers entirely, assuming no oversight is needed post-contract, or leaving accountability undefined all create governance gaps and regulatory exposure.11. A CIO wants to measure whether IT investments are delivering expected business value. Which approach BEST supports this governance objective?
- A. Tracking IT spend against budget only
- B. Establishing a benefits realization framework with defined metrics tied to business objectives
- C. Counting the number of IT projects completed each year
- D. Relying on vendor satisfaction surveys
Show answer & explanation
Answer: B
Value delivery, a key governance focus area, requires linking IT investments to measurable business benefits through a defined benefits realization framework, not just financial or activity metrics. Tracking spend to budget measures cost control, not value; counting completed projects measures throughput, not benefit; and vendor satisfaction surveys reflect the vendor relationship, not business value delivered to the organization.12. An IS auditor is reviewing a new system development project and notes that user acceptance testing (UAT) was skipped due to schedule pressure. What is the MOST significant risk of this omission?
- A. The project may be delivered slightly under budget
- B. System documentation will automatically be more accurate
- C. Business requirements may not be validated, increasing the risk the system fails to meet user needs in production
- D. The development team will need to write less code
Show answer & explanation
Answer: C
UAT is the phase where business users validate that the system meets functional requirements before go-live; skipping it significantly raises the risk of deploying a system that does not meet actual business needs, potentially requiring costly post-implementation fixes. The other options describe unrelated or implausible outcomes not caused by omitting UAT.13. During a post-implementation review, an IS auditor finds that the project's original business case benefits were never re-measured after go-live. What should the auditor recommend?
- A. No action is needed since the system is functioning technically
- B. Cancel the project retroactively
- C. Perform a benefits realization assessment comparing actual outcomes to the original business case
- D. Rewrite the business case to match whatever was delivered
Show answer & explanation
Answer: C
Post-implementation review should include comparing actual realized benefits against the original business case to confirm the investment delivered expected value and to capture lessons learned; technical functionality alone does not confirm business value was achieved. Retroactive cancellation is not meaningful after go-live, and rewriting the business case to match delivery defeats the purpose of accountability and would misrepresent the original justification.14. Which system development life cycle (SDLC) phase is MOST critical for identifying and documenting security requirements to avoid costly rework later?
- A. Requirements definition
- B. Post-implementation support
- C. Decommissioning
- D. Final user training
Show answer & explanation
Answer: A
Security requirements should be defined during the requirements phase so that security is designed into the system from the start; addressing security late in the lifecycle is far more expensive and often incomplete. Post-implementation support and user training occur after the system is built and cannot retroactively embed foundational design decisions, and decommissioning addresses end-of-life disposal, not development.15. An organization is migrating from a legacy system to a new ERP. Which data conversion control provides the STRONGEST assurance that all records were migrated completely and accurately?
- A. A verbal confirmation from the project manager that migration is complete
- B. Independent reconciliation of record counts and control totals between the old and new systems
- C. Reviewing the migration tool's marketing documentation
- D. Confirming the new system's user interface looks similar to the old one
Show answer & explanation
Answer: B
Reconciling record counts and control totals (e.g., financial balances, transaction counts) between source and target systems provides objective, verifiable evidence of completeness and accuracy of data conversion. Verbal confirmation lacks evidentiary support, vendor marketing material is not audit evidence of what actually occurred, and UI similarity says nothing about underlying data integrity.16. A project team wants to select a system development methodology that allows for iterative delivery and frequent stakeholder feedback on a project with evolving requirements. Which approach is MOST appropriate?
- A. Traditional waterfall model with a single delivery at project end
- B. Agile methodology with iterative sprints and regular stakeholder review
- C. A big-bang cutover with no phased releases
- D. A methodology with no defined requirements process
Show answer & explanation
Answer: B
Agile methodologies use short iterative cycles (sprints) with frequent stakeholder feedback, making them well suited to projects with evolving or unclear requirements. Waterfall assumes requirements are fixed upfront and delivers only at the end, a big-bang cutover concerns deployment strategy rather than requirements evolution, and a methodology lacking any requirements process would create significant risk regardless of requirement stability.17. An IS auditor reviewing change management for a production ERP system notes that emergency changes are deployed without prior testing but are documented after the fact. What is the BEST recommendation?
- A. Allow emergency changes to bypass all documentation requirements permanently
- B. Eliminate the emergency change process entirely
- C. Require the same multi-week testing cycle for emergency changes as standard changes
- D. Require post-implementation review and retrospective approval with documented justification for each emergency change
Show answer & explanation
Answer: D
Emergency change processes exist precisely because full standard testing isn't feasible under time pressure, but a well-controlled process requires retrospective review, approval, and documented justification to ensure accountability and to identify any issues introduced. Eliminating the process removes a legitimate business need, permanently skipping documentation removes accountability entirely, and requiring standard multi-week testing defeats the purpose of an emergency process.18. An organization's business continuity plan (BCP) specifies a recovery time objective (RTO) of 4 hours for its order-processing system. What does this RTO represent?
- A. The frequency at which backups must be taken
- B. The total time allotted for annual disaster recovery testing
- C. The maximum acceptable amount of data loss measured in time
- D. The maximum acceptable time the system can be unavailable before causing unacceptable business impact
Show answer & explanation
Answer: D
Recovery Time Objective (RTO) defines the maximum tolerable downtime — how quickly a system or process must be restored after a disruption to avoid unacceptable business impact. Maximum acceptable data loss is described by the Recovery Point Objective (RPO), not RTO; backup frequency is a control used to help meet RPO/RTO targets but isn't itself the RTO; and DR test duration is a separate operational planning detail.19. During a review of an organization's incident management process, an IS auditor finds that security incidents are resolved but root cause analysis is rarely performed. What is the MOST significant long-term risk?
- A. Recurring incidents from the same underlying cause, since the true source of the problem is never addressed
- B. Faster incident closure times going forward
- C. Increased helpdesk ticket volume in the short term only
- D. Improved compliance with service level agreements
Show answer & explanation
Answer: A
Without root cause analysis, underlying weaknesses that caused an incident remain unaddressed, leading to recurrence of the same or similar incidents — this is the core rationale for problem management within IT service management. Ticket volume in isolation isn't the central risk, and neither faster closure nor better SLA compliance would logically result from skipping root cause analysis; if anything, recurring incidents tend to degrade both.20. An organization performs full backups weekly and incremental backups daily. If a server fails on a Thursday (3 days after the last full backup), what is required to fully restore data to the most recent point?
- A. Only the original full backup from initial system setup
- B. Only the most recent incremental backup
- C. No backups are needed if the system has RAID storage
- D. The last full backup plus each incremental backup taken since, applied in sequence
Show answer & explanation
Answer: D
With a full-plus-incremental backup strategy, restoring to the most recent point requires the last full backup followed by every incremental backup taken since, applied in chronological order, because each incremental captures only changes since the previous backup. Using only the latest incremental omits earlier changes, the original setup backup is far too outdated, and RAID protects against disk-level hardware failure but does not substitute for backups against data corruption, deletion, or logical errors.21. Which of the following is the PRIMARY reason organizations conduct periodic disaster recovery (DR) testing rather than relying solely on a documented DR plan?
- A. To satisfy an annual budget requirement
- B. To validate that the plan actually works in practice and to identify gaps before a real disaster occurs
- C. To reduce the need for a documented plan going forward
- D. To replace the need for offsite data backups
Show answer & explanation
Answer: B
A documented plan alone does not guarantee recoverability; testing validates assumptions, uncovers gaps (e.g., outdated contact lists, untested dependencies, insufficient capacity), and builds team readiness, which is the primary rationale for DR testing. Budget justification is not the driving purpose, testing does not eliminate the need for documentation, and it does not substitute for maintaining offsite backups, which testing itself typically relies on.22. An IS auditor reviewing capacity management notes that a critical database server has consistently run at 95% CPU utilization for the past quarter with no capacity plan in place. What is the MOST significant risk?
- A. Users will need additional training on the application
- B. The server may be under warranty expiration soon
- C. Performance degradation or an outage as demand grows, potentially disrupting critical business operations
- D. The vendor may increase software licensing costs
Show answer & explanation
Answer: C
Sustained near-maximum utilization without a capacity plan risks performance degradation or outright failure as workload grows further, directly threatening availability of a critical business system — the core concern of capacity and availability management. Warranty status, licensing costs, and user training are unrelated secondary considerations that do not address the immediate operational risk of resource exhaustion.23. Which access control model grants permissions based on a user's assigned job function rather than granting permissions to each individual user directly?
- A. Role-based access control (RBAC)
- B. Mandatory access control (MAC)
- C. Discretionary access control (DAC)
- D. Rule-based routing
Show answer & explanation
Answer: A
RBAC assigns permissions to roles that correspond to job functions, and users inherit access by being assigned to a role, simplifying administration and supporting least privilege and segregation of duties. DAC lets resource owners grant access at their discretion to individual users, MAC enforces access based on fixed security labels/classifications set by a central authority rather than job function, and 'rule-based routing' is a networking concept, not an access control model.24. An IS auditor discovers that terminated employees' network accounts remain active for an average of 30 days after departure. What is the MOST significant risk this presents?
- A. Increased software licensing costs only
- B. Slower network performance due to unused accounts
- C. Unauthorized access to systems and data by former employees or others using their still-active credentials
- D. Increased helpdesk password reset requests
Show answer & explanation
Answer: C
Active accounts for departed employees represent a direct access control failure, creating risk of unauthorized access, data theft, or sabotage by the former employee or anyone who obtains their credentials — this is why timely deprovisioning is a fundamental logical access control. Licensing cost, network performance, and helpdesk volume are minor or unrelated secondary effects compared to the core security exposure.25. An organization wants to evaluate IT performance from multiple perspectives, including financial return, internal process efficiency, customer satisfaction, and organizational learning, rather than relying on financial metrics alone. Which management tool is BEST suited to this objective?
- A. A balanced scorecard incorporating multiple performance perspectives
- B. A single return-on-investment calculation for the IT department
- C. A capability maturity model assessment of IT processes
- D. An annual IT budget variance report
Show answer & explanation
Answer: A
A balanced scorecard is specifically designed to evaluate performance across several perspectives simultaneously, giving a rounded view of value delivery beyond pure financial return. A single ROI figure or a budget variance report each capture only a financial dimension, and a maturity model assessment measures process capability rather than the multi-dimensional performance outcomes the organization is asking to evaluate.26. During system development, a project manager wants to estimate the relative size and effort of a proposed application based on the number and complexity of its inputs, outputs, inquiries, and internal data structures, independent of the programming language to be used. Which estimation technique is being applied?
- A. Program evaluation and review technique
- B. Earned value management
- C. Critical path method
- D. Function point analysis
Show answer & explanation
Answer: D
Function point analysis estimates application size and effort based on counting functional components such as inputs, outputs, inquiries, and files, which makes it independent of the underlying programming language or technology. The other three techniques are project scheduling and cost-performance tools used once a project is underway, not techniques for estimating functional size from requirements.27. A software delivery organization distinguishes between activities that build quality into its development process and activities that inspect deliverables for defects before release. Which pairing correctly labels these two sets of activities?
- A. Quality control for process design; quality assurance for defect inspection
- B. Both are quality assurance; quality control applies only to manufacturing
- C. Quality assurance for process-focused prevention; quality control for product-focused detection
- D. Both are quality control; quality assurance is a governance-board activity only
Show answer & explanation
Answer: C
Quality assurance is process-oriented and preventive, aiming to ensure the methods used will produce quality outputs, while quality control is product-oriented and detective, examining actual deliverables for defects. Reversing the two labels is the classic trap, and neither term is restricted to manufacturing or to board-level governance — both are standard functions within software delivery organizations and are frequently examined by IS auditors reviewing the development life cycle.28. An organization is acquiring a smaller competitor and plans to integrate its systems within a year. From an IT governance perspective, what should due diligence PRIMARILY assess before the deal closes?
- A. Whether the target's staff prefer the acquirer's collaboration tools
- B. The target's IT risks, including security posture, licensing obligations, and integration compatibility
- C. Whether the acquirer's data center has spare rack space for the target's servers
- D. Whether the target's brand colors can be applied to the acquirer's intranet
Show answer & explanation
Answer: B
IT due diligence exists to surface risks that affect deal value and integration cost — such as security weaknesses, non-transferable or non-compliant software licenses, technical debt, and architectural incompatibility — before the organization is contractually committed. Staff tool preferences and cosmetic concerns are trivial relative to these exposures, and physical hosting capacity is a narrow logistics question that can be solved later, whereas undiscovered security or licensing liabilities can materially change the economics of the acquisition.29. A financial services firm requires employees in sensitive treasury-system roles to take an uninterrupted two-week vacation each year, during which their duties are performed by others. What is the PRIMARY control rationale for this requirement?
- A. It reduces payroll costs by spreading work across more employees
- B. It allows managers to evaluate whether the role can be eliminated
- C. It ensures compliance with occupational health regulations on rest periods
- D. It increases the chance that concealed irregularities or fraud will surface while another person performs the duties
Show answer & explanation
Answer: D
Mandatory vacations and job rotation are detective controls: schemes that depend on an individual's continuous, exclusive control of a process — such as suppressing exceptions or manipulating records — tend to be exposed when someone else must perform the duties for a sustained period. The measure is not primarily about cost, staffing efficiency, or labor-law rest requirements; its audit significance lies in breaking the perpetrator's uninterrupted custody that concealment requires.30. An organization is negotiating a service level agreement with a cloud provider for a business-critical application. Which SLA characteristic MOST enables effective ongoing governance of the provider's performance?
- A. A statement that the provider will use its best efforts to maintain availability
- B. A commitment to industry-leading service expressed in the marketing schedule
- C. Objectively measurable service targets with regular performance reporting and defined remedies for misses
- D. A clause allowing the customer to terminate for convenience at any time
Show answer & explanation
Answer: C
Governance over an outsourced service depends on the ability to measure performance against defined targets, receive evidence of results, and invoke consequences when commitments are missed — which is exactly what quantified service levels, reporting obligations, and remedies provide. Best-efforts and marketing language are unenforceable because they set no measurable threshold, and termination rights are a last-resort exit mechanism rather than a tool for managing day-to-day service quality.31. An IS auditor is planning an engagement and must decide how much testing to perform. What primarily drives that decision?
- A. The preferences of the audited business unit
- B. The number of staff available in the audit function
- C. The size of the department's budget
- D. The assessed risk of the area under review, since audit effort is allocated where misstatement or control failure would matter most
Show answer & explanation
Answer: D
Risk-based audit planning directs finite effort toward areas where control failure has the greatest consequence, which is what makes an audit opinion meaningful rather than merely thorough. Resource constraints affect what can be covered in a cycle, but they inform scheduling rather than justify testing a low-risk area at the expense of a high-risk one.32. An IS auditor gathers evidence through several methods on the same control. Which evidence is generally considered most reliable?
- A. Evidence the auditor obtains directly through independent observation or reperformance
- B. A written representation from the process owner
- C. A system-generated report supplied by the auditee without validation
- D. An internal procedure document describing how the control should operate
Show answer & explanation
Answer: A
Reliability rises with auditor independence from the source, so directly obtained evidence outranks auditee assertions, and a report the auditee generated is only as reliable as the auditor's assurance over the reporting system itself. A procedure document evidences design intent rather than operating effectiveness, which is a separate question the auditor must test.33. What distinguishes a test of control design from a test of operating effectiveness?
- A. Design testing asks whether a properly functioning control would address the risk, while effectiveness testing asks whether it actually operated as intended over the period
- B. Design testing is performed by the auditee and effectiveness testing by the auditor
- C. Design testing uses sampling and effectiveness testing uses inquiry
- D. The two are interchangeable descriptions of the same procedure
Show answer & explanation
Answer: A
A control can be well designed but never performed, or diligently performed yet incapable of addressing the risk, so both questions must be answered separately. Concluding on effectiveness without first establishing that the design addresses the risk produces assurance over an activity that was never going to help.34. An auditor uses attribute sampling to test whether change approvals were obtained. What is being measured?
- A. The average time taken to approve a change
- B. The monetary value of unapproved changes
- C. The total number of changes in the population
- D. The rate of deviation from the control, expressed as a proportion of items lacking the attribute
Show answer & explanation
Answer: D
Attribute sampling answers a yes-or-no question about the presence of a control attribute and yields a deviation rate, which is why it suits control testing. Variable sampling measures amounts and suits substantive testing of balances, so choosing the wrong technique produces a statistic that does not answer the audit question.35. An auditor discovers a control deficiency mid-engagement. What is the appropriate immediate action?
- A. Withhold the finding until the report is issued in all cases
- B. Correct the deficiency personally to demonstrate the remediation
- C. Document the condition, criteria, cause and effect, and communicate significant matters to management on a timely basis rather than only in the final report
- D. Expand the engagement scope to every adjacent system
Show answer & explanation
Answer: C
Findings are built from condition, criteria, cause and effect, and significant issues warrant timely communication so management can act rather than learning of them months later. An auditor who fixes the deficiency impairs independence and cannot then provide assurance over the remediated control.36. An internal audit function reports administratively to the chief information officer and functionally to the audit committee. Why does the functional reporting line matter?
- A. Because independence requires that audit conclusions and resourcing are not controlled by the management whose activities are audited
- B. Because administrative reporting is prohibited
- C. Because the audit committee performs the fieldwork
- D. Because the audit committee approves individual audit test steps
Show answer & explanation
Answer: A
Functional reporting to an independent body protects the audit plan, budget and conclusions from the influence of audited management, which is the structural basis of internal audit independence. The committee approves the plan and charter rather than test steps, and day-to-day administrative reporting inside the organization is normal.37. An auditor is asked to review a system they helped configure two years ago. What is the concern?
- A. There is no concern once two years have passed
- B. The concern applies only to external auditors
- C. The prior involvement makes the auditor the best-qualified reviewer
- D. Self-review impairs objectivity, so the assignment should be reallocated or the impairment disclosed and mitigated
Show answer & explanation
Answer: D
Reviewing one's own prior work creates a self-review threat because an adverse finding would be a criticism of the auditor's own judgment. Familiarity is real value, but it is captured by consulting the auditor rather than assigning the review, and impairments must be disclosed to those charged with governance.38. An organization uses continuous auditing techniques. What capability does this add?
- A. Automated testing of transactions or configurations as they occur, shortening the interval between a control failure and its detection
- B. Elimination of the need for an annual audit plan
- C. A guarantee that no control failures occur
- D. Replacement of management's own monitoring responsibilities
Show answer & explanation
Answer: A
Continuous auditing compresses detection latency by testing at or near the time of the transaction, which matters most where a periodic sample would surface a problem long after the damage. It complements rather than replaces planning, and it does not transfer management's monitoring duty to the audit function.39. An IT governance framework assigns decision rights for technology investment. Who should hold ultimate accountability?
- A. The IT department, which understands the technology
- B. The external service provider delivering the systems
- C. The internal audit function
- D. The board and executive management, since IT investment allocates enterprise resources against enterprise objectives
Show answer & explanation
Answer: D
Governance concerns direction and accountability rather than execution, so technology investment decisions belong with those accountable for enterprise resources. Delegating them entirely to IT produces technically sound choices misaligned with business priorities, and audit's involvement in decisions would compromise its later assurance role.40. An enterprise architecture is maintained and kept current. What audit-relevant benefit does it provide?
- A. A documented view of systems, data flows and dependencies that supports impact analysis, scoping and identification of single points of failure
- B. A guarantee that all systems are patched
- C. Automatic compliance with data protection regulation
- D. Elimination of the need for a business impact analysis
Show answer & explanation
Answer: A
Knowing what exists and how it connects is the precondition for scoping an audit, assessing the blast radius of a change and locating concentration risk. It supports but does not substitute for a business impact analysis, which adds the criticality and recovery timing judgments architecture alone does not supply.41. An organization outsources application hosting to a third party. Where does accountability for the controls reside?
- A. With the regulator that approved the arrangement
- B. Accountability is shared equally regardless of the contract
- C. With the organization, which can delegate the activity but not the accountability, and must obtain assurance over the provider's controls
- D. With the provider, which assumes full accountability under the contract
Show answer & explanation
Answer: C
Outsourcing transfers execution while accountability stays with the organization, which is why third-party assurance reports, right-to-audit clauses and defined service levels are essential contract terms. Relying on a provider's reputation without evidence over the relevant control objectives leaves an unassessed dependency in the control environment.42. An auditor reviews a third-party assurance report covering a service provider. What must be checked beyond the opinion?
- A. Whether the report's scope, period and control objectives cover the services relied upon, and how complementary user entity controls are addressed
- B. Only whether the opinion is unqualified
- C. Only the identity of the reporting auditor
- D. Only the report's issue date
Show answer & explanation
Answer: A
A clean opinion over the wrong scope or a period not overlapping the audit period provides no assurance for the reliance intended. Complementary user entity controls matter especially, because the report's conclusions assume the customer performs specified controls that the customer may not know about.43. Management accepts a risk that exceeds the organization's stated appetite. What should the auditor do?
- A. Remove the finding, since management has accepted the risk
- B. Report the matter externally to the regulator immediately
- C. Override the decision and require remediation
- D. Confirm the acceptance was made at an appropriate authority level and documented, and escalate to the audit committee if the residual risk remains unacceptable
Show answer & explanation
Answer: D
Risk acceptance is management's prerogative, but the auditor's role is to verify it was made knowingly at sufficient authority and to escalate where the accepted residual risk remains beyond appetite. Neither overriding the decision nor silently dropping the finding is consistent with the assurance function.44. An organization defines key performance indicators and key risk indicators for IT. What is the distinction?
- A. The two are the same metrics reported to different audiences
- B. Performance indicators measure achievement of objectives, while risk indicators are forward-looking signals that exposure is rising
- C. Risk indicators measure past performance and performance indicators predict the future
- D. Risk indicators apply only to financial risk
Show answer & explanation
Answer: B
Performance indicators look backward at whether objectives were met, while risk indicators are chosen because they move before a loss event does, giving time to intervene. Confusing them produces a dashboard that reports what already happened while providing no early warning.45. A project delivers a system that meets its specification but not the business need. What control weakness does this most likely indicate?
- A. Inadequate requirements definition and stakeholder involvement at the outset
- B. Insufficient unit testing during construction
- C. Weak production change management
- D. Inadequate backup procedures
Show answer & explanation
Answer: A
Building the wrong thing correctly is a requirements failure, since testing verifies conformance to the specification rather than the specification's fitness for purpose. This is why the cost of a defect rises so steeply with the phase in which it is introduced, and why user involvement during requirements is a primary control in systems development.46. What is the purpose of user acceptance testing in a system implementation?
- A. To verify that individual code modules function correctly
- B. To measure system performance under peak load
- C. To confirm the vendor has been paid
- D. To confirm the system meets business requirements from the user's perspective before it is accepted into production
Show answer & explanation
Answer: D
User acceptance testing is the business's own verification against its requirements, which is distinct from unit testing of modules, integration testing of interfaces and stress testing of capacity. Approval by users is the acceptance decision, and an implementation proceeding without it removes the business's control over what it is being given.47. An organization plans a parallel changeover from an old system to a new one. What is the principal advantage over a direct cutover?
- A. It eliminates the need for data conversion
- B. It is the least costly changeover approach
- C. It requires no user training on the new system
- D. Both systems run concurrently so results can be compared and the old system remains available as a fallback, reducing implementation risk
Show answer & explanation
Answer: D
Parallel running buys risk reduction at the cost of operating two systems and reconciling their output, which is why it is the most expensive approach and is reserved for high-criticality changeovers. Direct cutover is cheapest and riskiest, while phased and pilot approaches sit between them.48. An auditor reviews a data conversion from a legacy system. What control most directly addresses conversion completeness?
- A. Retaining a backup of the legacy database
- B. Restricting access to the conversion tool
- C. Reconciliation of record counts and control totals between source and target, with documented investigation of differences
- D. Encryption of the data in transit during conversion
Show answer & explanation
Answer: C
Completeness is demonstrated by reconciling counts and totals across the boundary, which detects records silently dropped or duplicated. Encryption addresses confidentiality, access restriction addresses unauthorized change, and a backup enables recovery, so each addresses a real risk but none evidences that everything arrived.49. A developer requires access to the production environment to resolve an urgent defect. What compensating control is appropriate?
- A. Time-limited, approved and logged emergency access with independent review of the actions taken afterward
- B. Permanent production access for the development team
- C. Granting access without logging to avoid slowing the fix
- D. Allowing the developer to disable audit logging during the change
Show answer & explanation
Answer: A
Segregation between development and production exists to prevent unreviewed code reaching live systems, and where operational necessity overrides it the compensating control is a bounded, approved and reviewed exception. Emergency access that is neither time-limited nor reviewed simply removes the segregation permanently under an urgent label.50. A change management process requires approval before deployment. What does an auditor test to conclude the control operated?
- A. A sample of production changes traced back to documented approval, plus a search for changes that reached production without a corresponding record
- B. Only the change management policy document
- C. Only the list of approved change requests
- D. Only the number of changes deployed in the period
Show answer & explanation
Answer: A
Sampling from the approval log tests only that approved changes were approved, which proves nothing about unapproved changes. Testing must also start from the population of what actually reached production, since the risk being controlled is precisely the change that bypassed the process.51. An organization uses agile development. How does this affect the auditor's approach to controls?
- A. The control objectives remain the same while the evidence changes form, appearing in backlogs, automated pipeline gates and iteration records rather than phase-gate documents
- B. The auditor should require the organization to adopt a waterfall method
- C. Only the final release requires any control evidence
- D. Control objectives no longer apply in an agile environment
Show answer & explanation
Answer: A
Requirements traceability, testing, approval and segregation still matter regardless of methodology, but in agile environments the evidence lives in tooling rather than in signed documents. An auditor who insists on phase-gate artefacts either reports false deficiencies or pushes the organization toward ceremony that adds no control value.52. A business impact analysis has been completed. What does it establish that a risk assessment does not?
- A. The criticality of each process and the maximum tolerable outage, which drive recovery objectives
- B. The likelihood of each threat occurring
- C. The technical configuration of recovery infrastructure
- D. The cost of cyber insurance premiums
Show answer & explanation
Answer: A
A business impact analysis measures consequence over time regardless of cause, producing the criticality ranking and tolerable outage that set recovery objectives. Threat likelihood belongs to the risk assessment, and the technical recovery design is what the objectives then drive rather than what the analysis produces.53. A system has a recovery point objective of four hours and a recovery time objective of eight hours. What do these mean?
- A. Up to four hours of data may be lost, and the system must be restored to service within eight hours of the disruption
- B. The system must be restored within four hours and may lose eight hours of data
- C. Backups run every eight hours and are retained for four hours
- D. The system may be unavailable for four hours per month
Show answer & explanation
Answer: A
The recovery point objective bounds acceptable data loss and therefore drives backup or replication frequency, while the recovery time objective bounds acceptable downtime and drives the recovery architecture. A four-hour recovery point cannot be met by nightly backups, which is the most common inconsistency between stated objectives and actual capability.54. An organization maintains a hot site for disaster recovery. What characterizes it relative to a cold site?
- A. It is an empty facility with power and connectivity only
- B. It requires no testing because it mirrors production
- C. It costs less than a cold site because it is shared
- D. It is fully equipped and current, enabling resumption within a short period, at substantially higher cost than an empty facility requiring build-out
Show answer & explanation
Answer: D
Hot, warm and cold sites trade cost against recovery speed, with a hot site holding current equipment and data and a cold site providing only the shell. Mirroring does not remove the need to test, since untested failover routinely reveals dependencies, credentials and data synchronization gaps that only an exercise exposes.55. A disaster recovery plan is tested using a walkthrough rather than a full interruption test. What is the limitation?
- A. It validates understanding and documentation but does not demonstrate that the technical recovery actually works under real conditions
- B. It is more disruptive than a full interruption test
- C. It cannot involve business stakeholders
- D. It provides equivalent assurance to a full test at lower cost
Show answer & explanation
Answer: A
Testing methods form a progression from checklist and walkthrough through simulation and parallel to full interruption, with assurance and disruption rising together. A walkthrough surfaces documentation and role gaps cheaply but cannot reveal whether restoration completes within the recovery time objective.56. An auditor reviews backup practices and finds backups run nightly and complete successfully. What further evidence is essential?
- A. Evidence that restoration from those backups has been tested successfully, since a backup that cannot be restored provides no recovery capability
- B. The brand of backup software in use
- C. The physical size of the backup media
- D. The number of backup jobs configured
Show answer & explanation
Answer: A
A successful backup job indicates data was written, not that it can be read back into a working system, and media faults, encryption key loss and incomplete scope routinely surface only at restoration. Periodic documented restore tests are what convert a backup process into a recovery capability.57. An organization applies capacity management to its infrastructure. What is the audit-relevant objective?
- A. Reducing the number of servers regardless of demand
- B. Ensuring resources meet current and projected demand so availability commitments are met without unnecessary expenditure
- C. Eliminating the need for performance monitoring
- D. Ensuring all systems run at maximum utilization
Show answer & explanation
Answer: B
Capacity management balances availability against cost by matching provisioned resources to forecast demand, so both shortage and persistent overprovisioning are failures. Running at maximum utilization removes the headroom that absorbs spikes, which converts a capacity plan into an availability incident waiting for a busy day.58. An incident and a problem are distinguished in service management. What is the difference?
- A. An incident is an unplanned interruption requiring restoration of service, while a problem is the underlying cause requiring elimination
- B. An incident is more severe than a problem by definition
- C. A problem is a customer complaint and an incident is a system fault
- D. The two terms are interchangeable
Show answer & explanation
Answer: A
Incident management restores service as quickly as possible, which may mean a workaround, while problem management removes the cause so the incident stops recurring. Organizations that only run incident management resolve the same interruption repeatedly, which shows up in audit as a high rate of recurring incidents.59. An auditor evaluates logical access controls. What does the principle of least privilege require?
- A. Each account holds only the access necessary for its function, and no more, for as long as it is needed
- B. Administrators require no access restrictions
- C. All users share a common access profile for consistency
- D. Access is granted broadly and revoked when misuse is detected
Show answer & explanation
Answer: A
Least privilege limits the damage any single compromised or misused account can cause, and the temporal element matters as much as the scope, since access accumulated through role changes is a common finding. Privilege creep, dormant accounts and standing administrative rights are the recurring failures of this principle in practice.60. An auditor reviews user access recertification. What is the control's purpose?
- A. Periodic confirmation by an accountable owner that each user's access remains appropriate, catching accumulation from role changes and departures
- B. Confirming that the access management system is licensed
- C. Testing whether users can access systems from remote locations
- D. Verifying that users remember their passwords
Show answer & explanation
Answer: A
Provisioning controls address the moment access is granted, but neither detects the access a long-tenured employee accumulated across three role changes. Recertification is the detective control closing that gap, and its effectiveness depends entirely on reviewers who understand what the entitlements actually permit rather than approving lists reflexively.61. Data is classified into sensitivity levels. What does classification primarily enable?
- A. Automatic encryption of all organizational data
- B. Proportionate application of controls, so protection effort matches the consequence of disclosure or loss
- C. Elimination of the need for access controls
- D. Compliance with all applicable regulations by itself
Show answer & explanation
Answer: B
Uniform controls either overprotect routine data at unacceptable cost or underprotect sensitive data, so classification is what makes proportionate protection possible. Its value depends on an accountable data owner making the classification and on the classification actually driving control selection rather than sitting in a register.62. An organization encrypts data at rest in a database. What risk does this address, and what does it not?
- A. It protects against exposure of the underlying storage media or files, but not against an attacker or user operating through an authorized application session
- B. It removes the need for access controls on the database
- C. It protects data in transit across the network
- D. It protects against all forms of unauthorized data access
Show answer & explanation
Answer: A
Encryption at rest defends against theft of disks, files or backups, since the data is decrypted transparently for authorized sessions, which means it does nothing against credential compromise or excessive application privilege. Transport encryption and access control address those separate exposures, and treating encryption as a general answer leaves the most common attack path open.63. An auditor reviews the physical security of a data centre. Which control best addresses tailgating?
- A. A mantrap or interlocking door arrangement permitting one authenticated person through at a time
- B. A visitor sign-in log at reception
- C. Closed circuit television covering the entrance
- D. A door alarm sounding when held open
Show answer & explanation
Answer: A
Tailgating defeats badge controls because the door is legitimately open, so the effective control physically enforces single-person entry. Cameras and logs are detective, identifying the event after it occurred, which matters for investigation but does not prevent the unauthorized entry.64. Media containing sensitive data is decommissioned. What disposal control is appropriate?
- A. Deleting the files and reformatting the drive
- B. Sanitization or destruction appropriate to the media type and data sensitivity, with documented evidence of completion
- C. Storing the media indefinitely in a locked room
- D. Returning the media to the original vendor without further action
Show answer & explanation
Answer: B
Deletion and formatting leave recoverable data, so sanitization must match the media technology, and certificates of destruction provide the evidence an auditor needs. Indefinite retention converts a disposal problem into a storage and retention problem rather than resolving it, and unverified vendor return transfers the data without transferring accountability.65. An auditor examines security event logging. Beyond generating logs, what is essential?
- A. That logs are generated at the highest verbosity for all systems
- B. That logs are protected from alteration, retained for an adequate period and actually reviewed or monitored for indicators requiring action
- C. That logs are stored on the same system that generates them
- D. That log files are deleted regularly to control storage cost
Show answer & explanation
Answer: B
Unreviewed logs provide forensic material after an incident but no detection during one, and logs stored only on the originating system are alterable by whoever compromises it. Maximum verbosity on everything typically produces volume that defeats review, so tuning to meaningful events is part of making the control work.66. An organization deploys multi-factor authentication. What makes an authentication scheme genuinely multi-factor?
- A. The factors come from different categories such as something known, something possessed and something inherent
- B. The password must exceed a minimum length
- C. Authentication is required at more than one system
- D. Two separate passwords are required
Show answer & explanation
Answer: A
Two secrets of the same category share a failure mode, since a phishing attack or credential dump captures both, which is why category diversity rather than count defines the control. This also explains why the strength of a second factor depends heavily on its resistance to interception and relay rather than on its existence.67. An auditor assesses a data loss prevention deployment. What limits its effectiveness?
- A. Its inability to inspect any network traffic
- B. Its incompatibility with encryption of any kind
- C. Its dependence on accurate data identification and on covering the channels actually used, since unclassified data or an uncovered channel passes unexamined
- D. The requirement that it be deployed only on servers
Show answer & explanation
Answer: C
Data loss prevention can only act on what it recognizes as sensitive and only where it sits in the path, so classification quality and channel coverage bound its value more than detection technology does. Encrypted or personally controlled channels are the common blind spots, which is why the control is evaluated alongside rather than in place of access restriction.68. An auditor is asked to provide an opinion where testing was limited because records were unavailable. What is the appropriate reporting treatment?
- A. Disclose the scope limitation and its effect on the conclusion rather than issuing an unqualified opinion
- B. Issue an unqualified opinion based on the testing that was possible
- C. Omit the affected area from the report without comment
- D. Delay the report indefinitely until records appear
Show answer & explanation
Answer: A
A conclusion must be supported by sufficient appropriate evidence, so where that was unobtainable the reader must be told what could not be examined and what it means. Silently omitting the area misleads by implying coverage that did not occur, which is a more serious failing than the limitation itself.69. An auditor uses computer-assisted audit techniques to test an entire population rather than a sample. What is the primary benefit?
- A. Management review of the results becomes unnecessary
- B. The need to understand the control is removed
- C. Sampling risk is eliminated for that test, since every item is examined rather than an inference drawn from a subset
- D. The reliability of the source data no longer matters
Show answer & explanation
Answer: C
Full population testing removes the risk that a sample was unrepresentative, which is the principal statistical limitation of sampling. It does not remove the need to establish the completeness and accuracy of the data extracted, since testing everything in an incomplete extract is thorough examination of the wrong population.70. Management proposes a remediation action for an audit finding. What should the auditor evaluate before accepting it?
- A. Whether the action addresses the root cause rather than the symptom, and whether the owner and target date are specific enough to be followed up
- B. Whether the action is the least expensive option available
- C. Whether the action was proposed by senior rather than junior management
- D. Whether the action can be completed before the report is issued
Show answer & explanation
Answer: A
A remediation targeting the symptom leaves the condition to recur, so the finding's cause element is what the action must address. Specific ownership and dates are what make follow-up possible, and an action too vague to verify effectively closes the finding without changing anything.71. An organization's control self-assessment programme is in place. How does it relate to internal audit's work?
- A. It engages process owners in evaluating their own controls, and internal audit may rely on it only after validating its quality and objectivity
- B. It is performed by internal audit on behalf of process owners
- C. It has no relationship to the audit plan
- D. It replaces the need for internal audit testing entirely
Show answer & explanation
Answer: A
Control self-assessment increases ownership and coverage but is inherently a self-review, so reliance requires validation of methodology, evidence quality and candour before it reduces audit testing. Treating it as a substitute without that validation transfers assurance to the party being assured about.72. An auditor finds that a critical vendor has no documented exit plan. Why is this a governance concern?
- A. Because concentration in a provider without a transition path leaves the organization unable to exit on acceptable terms if service or the relationship deteriorates
- B. Because it prevents the vendor from being paid
- C. Because it invalidates the vendor's assurance report
- D. Because exit plans are required by all data protection regulation
Show answer & explanation
Answer: A
Without a transition plan covering data return, format, knowledge and alternative providers, the practical cost of leaving can exceed the cost of tolerating poor service, which removes the organization's leverage. The dependency is a governance issue because it constrains future decisions rather than because any single control has failed.73. An organization measures IT value delivery. What does an auditor look for beyond project delivery metrics?
- A. Whether the project team was the largest available
- B. Whether the project used the most current technology available
- C. Whether the project finished under budget regardless of scope
- D. Whether expected benefits were defined, tracked and realized after implementation, since on-time delivery of an unused system creates no value
Show answer & explanation
Answer: D
Delivery metrics measure the project rather than the investment, and benefits realization is the step organizations most often omit because it occurs after the project team has disbanded. Without defined and tracked benefits there is no basis to conclude the investment was worthwhile or to inform the next one.74. While planning an IS audit of a payment-processing application, an IS auditor must decide which potential control weaknesses would be significant enough to warrant reporting to senior management if confirmed. Which audit concept PRIMARILY guides this determination?
- A. Materiality, because it defines the threshold at which a weakness or error becomes significant to stakeholders
- B. Inherent risk, because it reflects the susceptibility of the process to error before controls are considered
- C. Detection risk, because it reflects the chance that audit procedures fail to identify an existing error
- D. Sampling risk, because it measures the chance that the sample is not representative of the population
Show answer & explanation
Answer: A
Materiality is the concept auditors use to judge whether a weakness or misstatement is significant enough to influence the decisions of report users, so it directly drives what gets escalated to senior management. Inherent risk describes exposure before controls and helps scope the audit, but it does not set the significance threshold for reporting; sampling and detection risk concern the reliability of the auditor's own procedures rather than the importance of a finding.75. An IS auditor wants to estimate the total monetary value of errors in a population of automatically generated customer invoices. Which sampling approach is MOST appropriate for this objective?
- A. Attribute sampling, because it measures the rate of deviation from a prescribed control
- B. Variable sampling, because it estimates the monetary amount or quantitative value of a population characteristic
- C. Judgmental sampling, because the auditor can focus on the invoices most likely to contain errors
- D. Discovery sampling, because it is designed to find at least one example of a rare event
Show answer & explanation
Answer: B
Variable sampling techniques are designed to estimate quantitative amounts, such as the total dollar value of misstatement in a population, which matches the auditor's objective here. Attribute sampling is the tempting alternative but it only measures how often a condition occurs, expressed as a rate, and cannot express results in monetary terms; discovery sampling targets rare events, and judgmental selection produces results that cannot be statistically projected to the population.76. An audit manager reviews a completed IS audit file and finds procedures, evidence obtained, and conclusions recorded for each objective. What is the PRIMARY purpose served by this audit documentation?
- A. To satisfy the auditee that the audit was conducted with minimal disruption to operations
- B. To transfer ownership of identified control weaknesses from management to the audit function
- C. To eliminate the need for an exit meeting by making all findings self-explanatory
- D. To provide a defensible record that supports the audit conclusions and enables supervisory review of the work performed
Show answer & explanation
Answer: D
Workpapers exist chiefly to evidence the basis for the auditor's conclusions and to allow reviewers to verify that the work supports the reported results, which also protects the audit function if findings are challenged. Ownership of control weaknesses always remains with management regardless of documentation, and documentation complements rather than replaces communication steps such as the exit meeting, so the other purposes are incidental at best.77. During fieldwork, the operations manager verbally assures an IS auditor that failed overnight batch jobs are always remediated the same day. Before relying on this assertion to close the audit objective, what should the auditor do?
- A. Corroborate the assertion with independent evidence such as job logs and incident records
- B. Include the assertion in the report as a management representation requiring no further work
- C. Accept the assertion because it was provided by the manager accountable for the process
- D. Escalate the matter to the audit committee as an unsupported management claim
Show answer & explanation
Answer: A
Inquiry alone is among the weakest forms of audit evidence, so a verbal assertion about remediation timeliness should be corroborated with independent, objective sources such as scheduler logs and ticket histories before the auditor relies on it. Accepting the claim because of the manager's accountability confuses authority with evidence quality, and escalating to the audit committee is premature because nothing yet suggests the assertion is false — it is simply unverified.78. A prior-year audit reported that database administrators shared a single privileged login. During the follow-up review, management states that the issue has been fully remediated. What should the IS auditor do NEXT?
- A. Close the finding, because management has formally confirmed remediation
- B. Reopen the entire prior audit to revalidate all of its original findings
- C. Perform testing to verify that individual accounts are now in use and the shared login is disabled
- D. Downgrade the finding's risk rating to reflect management's attention to the issue
Show answer & explanation
Answer: C
Follow-up procedures require the auditor to obtain evidence that corrective action was actually implemented and is effective, which here means testing that unique privileged accounts exist and the shared credential can no longer be used. Closing the finding on management's word alone substitutes assertion for evidence, while reopening the whole prior audit is disproportionate because only the remediation of this specific finding is in question.79. An audit director is building the annual IS audit plan and must choose which auditable areas to cover with limited resources. Which factor should MOST influence the prioritization?
- A. The preferences expressed by the managers of each business unit
- B. The length of time since each area was last audited
- C. The availability of auditors with prior experience in each area
- D. The relative risk each area poses to the organization's objectives
Show answer & explanation
Answer: D
A risk-based audit plan directs scarce audit resources to the areas whose failure would most harm the organization's objectives, which is the accepted basis for annual planning. Time since last audit is a legitimate input to the risk assessment but is only a proxy — a low-risk area does not become a priority simply because it is overdue — and staffing convenience or auditee preference would systematically divert coverage away from the highest exposures.80. An IS auditor concludes that the IT general controls supporting a financial reporting application are poorly designed and unreliable. How should this conclusion affect the remainder of the audit approach?
- A. Discontinue the audit until management redesigns the control environment
- B. Reduce total testing, because weak controls make further procedures unlikely to change the conclusion
- C. Rely on analytical procedures alone, since detailed testing would duplicate the control weaknesses
- D. Increase substantive testing of the data and transactions, because control reliance is not justified
Show answer & explanation
Answer: D
When controls cannot be relied upon, the auditor must obtain assurance directly about the information itself, which means expanding substantive procedures over transactions and balances. Reducing work or stopping the audit would leave the objective unmet, and analytical procedures alone are generally too imprecise to compensate for an unreliable control environment; the correct response is to shift the evidence mix, not to shrink it.81. For a given audit area, the IS auditor assesses both inherent risk and control risk as high. To keep overall audit risk at an acceptable level, what must the auditor do?
- A. Accept a higher overall audit risk, since inherent and control risk are outside the auditor's influence
- B. Reassess inherent risk downward to offset the elevated control risk
- C. Lower detection risk by performing more extensive and more reliable audit procedures
- D. Transfer the engagement to an external audit firm with greater resources
Show answer & explanation
Answer: C
Audit risk is a function of inherent, control, and detection risk, and only detection risk is within the auditor's direct control; when the first two are high, the auditor must drive detection risk down through more extensive, more reliable procedures. Simply accepting higher audit risk defeats the engagement's purpose, and adjusting the inherent risk assessment to compensate would misstate the risk model rather than respond to it — the assessments must reflect conditions, not desired outcomes.82. An IS auditor lacks the specialized knowledge needed to evaluate a complex actuarial model and engages an external expert to assess it. Which statement BEST describes the auditor's remaining responsibility?
- A. The auditor remains responsible for the audit conclusions and must assess the expert's competence, objectivity, and the reasonableness of the work
- B. Responsibility for that portion of the audit transfers to the expert once the engagement letter is signed
- C. The auditor must disclaim any opinion on areas where expert work was used
- D. The auditor may rely on the expert only if the expert is employed by the same firm
Show answer & explanation
Answer: A
Using an expert does not delegate professional responsibility: the auditor must evaluate the expert's qualifications and independence, understand the methods used, and judge whether the results reasonably support the audit conclusions. Responsibility cannot be transferred by contract, a disclaimer is unnecessary when the expert's work is properly evaluated, and there is no requirement that the expert belong to the auditor's own organization.83. An IS auditor wants ongoing assurance that a live claims-processing system handles transactions correctly, and arranges for fictitious transactions belonging to a dummy business unit to flow through production processing alongside real data. Which technique is being used?
- A. Integrated test facility, which processes fictitious entities' transactions within the production system
- B. Test data method, which runs prepared transactions through a copy of the application
- C. Snapshot technique, which captures transaction images at defined processing points
- D. Parallel simulation, which reprocesses real data through auditor-controlled software
Show answer & explanation
Answer: A
An integrated test facility embeds a dummy entity inside the production application so auditor-created transactions are processed by the same code and environment as live data, giving direct evidence of real processing behavior. Parallel simulation inverts this by running real data through the auditor's own program, the classic test data method uses a separate test run rather than live processing, and snapshots record images of transactions rather than injecting them — the distinguishing feature here is fictitious data inside production.84. An IS auditor needs to identify potential duplicate vendor payments across an entire year of accounts payable transactions held in a large database. Which approach is MOST efficient and effective?
- A. Review the application's user manual to confirm a duplicate-check feature exists
- B. Use generalized audit software to analyze the full population for matching invoice numbers, amounts, and vendors
- C. Interview accounts payable staff about their procedures for preventing duplicates
- D. Select a random sample of payments and manually trace each to supporting invoices
Show answer & explanation
Answer: B
Generalized audit software can examine every transaction in the population and flag records sharing key attributes such as vendor, amount, and invoice number, making it far more effective at finding duplicates than any sample-based or inquiry-based approach. Sampling may miss the very duplicates being sought because they are typically rare, while interviews and manual reviews of documentation provide evidence about intended controls rather than about whether duplicates actually occurred.85. At the conclusion of fieldwork, the IS audit team schedules a closing meeting with auditee management before the report is issued. What is the PRIMARY purpose of this meeting?
- A. To obtain management's signature accepting responsibility for all identified risks
- B. To confirm the factual accuracy of findings and give management an opportunity to respond
- C. To negotiate which findings will be removed from the final report
- D. To assign remediation deadlines that the audit function will enforce
Show answer & explanation
Answer: B
The closing meeting exists to validate that the facts underlying each finding are accurate and to capture management's perspective and planned actions before the report is finalized, which improves report quality and reduces later disputes. It is not a negotiation to delete findings — valid findings remain regardless of auditee preference — and while management responses and action dates are discussed, enforcement of remediation belongs to management and governance bodies, not to the audit team.86. A draft audit finding states that quarterly user access reviews were not performed for a core banking application, but the finding does not describe what could happen as a result. Which element of a well-structured finding is missing?
- A. The criteria, which state what should have occurred
- B. The condition, which states what was actually observed
- C. The cause, which explains why the deviation happened
- D. The effect, which explains the risk or consequence of the deviation
Show answer & explanation
Answer: D
A complete finding links criteria, condition, cause, and effect; here the standard (reviews required quarterly) and the observation (reviews not performed) are present, but the consequence — for example, that inappropriate access could persist undetected — is absent, and that is the effect. Without a stated effect, management cannot judge the finding's significance or prioritize remediation, which is why the effect element is what transforms an observation into a risk-based finding.87. Based on a sample of change tickets, an IS auditor concluded that a change-approval control was operating effectively. Later, full-population analysis showed the control actually failed frequently. Assuming the sampled items were evaluated correctly, which risk materialized?
- A. Inherent risk, because the process was naturally prone to failure
- B. Non-sampling risk, because the auditor misapplied the audit procedure
- C. Fraud risk, because the exceptions were deliberately concealed from the auditor
- D. Sampling risk, because the sample drawn was not representative of the population
Show answer & explanation
Answer: D
Sampling risk is the possibility that a properly executed conclusion drawn from a sample differs from the conclusion that testing the whole population would produce, which is exactly what happened when a representative-looking sample led to an incorrect acceptance of the control. Non-sampling risk is the tempting alternative but it involves auditor error in performing or interpreting procedures, which the scenario explicitly rules out; nothing in the facts indicates concealment or an inherently failure-prone process.88. An IS auditor evaluating an organization's control environment wants to identify the single strongest influence on whether employees take internal controls seriously. Which factor should the auditor examine?
- A. The frequency of disciplinary actions recorded by human resources
- B. The number of control-related policies published on the intranet
- C. The demonstrated commitment of senior leadership to ethical conduct and control compliance
- D. The sophistication of the automated monitoring tools in use
Show answer & explanation
Answer: C
The tone set at the top — leadership visibly following the rules it imposes and acting on violations — shapes the culture that determines whether controls are respected in practice, and it is recognized as the foundation of the control environment. Policy volume means little if leaders ignore the policies, tooling cannot compensate for a culture of workarounds, and disciplinary frequency is an ambiguous signal that may reflect either strong enforcement or a failing culture.89. To demonstrate that a reconciliation control operates daily, management gives the IS auditor a report generated from the application by the same team that performs the control. Applying professional skepticism, what should the auditor do before using this report as evidence?
- A. Accept the report because system-generated output is inherently reliable
- B. Evaluate the integrity of the report by verifying its source, parameters, and completeness
- C. Ask the team to certify the report's accuracy in writing before relying on it
- D. Reject the report outright because it originates from the auditee
Show answer & explanation
Answer: B
System-generated reports are only as reliable as the logic, parameters, and data that produce them, so the auditor should verify how the report was generated, whether the query criteria capture the full population, and whether it could have been altered by the control owner. Rejecting all auditee-provided evidence would make auditing impractical, while blanket acceptance or a written certification from the same interested party fails to address the underlying reliability question.90. An IT steering committee is documented as responsible for approving major technology investments, but in practice the CIO regularly approves large projects unilaterally without committee review. From a governance perspective, what is the MOST significant concern?
- A. The steering committee meets too infrequently to be useful
- B. The CIO lacks sufficient technical expertise to approve projects alone
- C. Decision rights defined in governance documentation are not being followed in practice
- D. Technology investment decisions are being made too quickly for the organization's needs
Show answer & explanation
Answer: C
Effective IT governance depends on decision rights being exercised as designed; when actual practice diverges from documented authority, accountability becomes unclear and the checks the structure was meant to provide are bypassed, regardless of how capable the individual making unilateral decisions may be. The committee's meeting frequency or the speed of decisions are secondary issues that do not address the core governance breakdown of authority not matching documented responsibility.91. A newly appointed audit committee member asks whether the upcoming IS audit will guarantee that no material control failures exist in the environment being reviewed. Which response BEST reflects professional audit standards?
- A. An audit provides reasonable assurance, not absolute assurance, due to factors such as sampling and the nature of evidence
- B. An audit guarantees detection of all material failures if the budget is sufficient
- C. An audit provides no assurance; it only documents processes as they exist
- D. An audit's assurance level depends entirely on whether management cooperates
Show answer & explanation
Answer: A
Audits are designed to provide reasonable assurance because evidence is often persuasive rather than conclusive, testing frequently relies on samples, and controls can be circumvented or overridden; no level of budget removes these inherent limitations. Claiming a guarantee overstates what any audit can deliver, while claiming no assurance understates the value of a properly executed engagement — the standard position is the middle ground of reasonable assurance.92. Management asks the IS audit function to help strengthen access controls for a new system that the function expects to audit next year. Which arrangement BEST preserves audit independence?
- A. Auditors advise on control objectives and good practice, while management designs, implements, and owns the controls
- B. Auditors implement the access rules themselves to guarantee they meet audit expectations
- C. Auditors take temporary operational responsibility for the system until the first audit is finished
- D. Auditors decline any contact with the project until it is complete
Show answer & explanation
Answer: A
Audit independence is preserved when auditors act in an advisory capacity — sharing control objectives and good practice — while management retains all design, implementation, and operational decisions, because the function then never audits its own work. Implementing or operating controls creates a self-review threat in the later audit, but refusing all engagement forfeits the chance to prevent costly control gaps; advice without ownership is the recognized balance.93. An organization wants to translate its IT strategy into measurable objectives spanning financial results, customer satisfaction, internal process quality, and staff learning and growth. Which management tool is designed for this purpose?
- A. A capability maturity assessment of IT processes
- B. A total cost of ownership analysis for the IT portfolio
- C. A heat map of the IT risk register
- D. An IT balanced scorecard linking strategy to metrics across multiple perspectives
Show answer & explanation
Answer: D
The balanced scorecard was created precisely to express strategy as a linked set of measurable objectives across financial, customer, internal process, and learning perspectives, making it the fit for this requirement. A maturity assessment benchmarks process capability at a point in time, cost-of-ownership analysis addresses economics only, and a risk heat map visualizes exposures — none of these connects strategic intent to a balanced, multi-perspective set of performance measures.94. A board formally states the overall level and types of risk the organization is willing to accept in pursuit of its strategy, while operating management defines acceptable variation around specific performance targets. Which terms describe these two concepts, respectively?
- A. Risk capacity and risk appetite
- B. Risk tolerance and residual risk
- C. Risk appetite and risk tolerance
- D. Residual risk and inherent risk
Show answer & explanation
Answer: C
Risk appetite is the broad, board-level expression of how much risk the organization will accept in pursuing its objectives, while risk tolerance sets the acceptable deviation around specific objectives or metrics at an operational level — matching the two statements in order. Risk capacity is the maximum risk the organization can absorb regardless of willingness, and residual versus inherent risk describes exposure after and before controls, which is a different axis entirely.95. An IS auditor reviews a corporate document that mandates minimum password length and complexity settings that every system must enforce. In a well-structured documentation hierarchy, what type of document is this?
- A. A policy, because it states management's high-level intent for security
- B. A guideline, because it suggests recommended practices for administrators
- C. A standard, because it specifies mandatory settings that implement policy intent
- D. A procedure, because it lists steps for configuring authentication
Show answer & explanation
Answer: C
Standards translate high-level policy intent into specific, mandatory requirements — such as required password parameters — that apply uniformly across systems. A policy would state the broad objective (for example, that access must be authenticated commensurate with risk) without technical specifics, a guideline is advisory rather than mandatory, and a procedure gives step-by-step instructions for performing a task rather than defining the required configuration values themselves.96. Several proposed IT initiatives compete for a limited investment budget, and executives disagree about which to fund. Which governance mechanism BEST supports a defensible selection decision?
- A. Letting the infrastructure team select initiatives based on technical elegance
- B. Portfolio management that evaluates initiatives on value, risk, and strategic alignment using consistent criteria
- C. Allocating the budget proportionally to each department's headcount
- D. Funding initiatives in the order their business cases were submitted
Show answer & explanation
Answer: B
Portfolio management provides a structured, criteria-based comparison of competing initiatives — weighing expected value, risk, resource demands, and alignment with strategy — so funding decisions are transparent and defensible. First-come ordering rewards timing rather than merit, headcount-based allocation ignores value entirely, and technical preference substitutes the judgment of one function for enterprise priorities; only the portfolio approach connects investment to strategic outcomes.97. A marketing analyst requests read access to a customer data set maintained on a shared platform. Under a sound data governance model, who should APPROVE this access request?
- A. The database administrator, because they can technically grant the access
- B. The requesting analyst's direct manager, because they know the analyst's duties
- C. The data owner, because they are accountable for how the data is used and by whom
- D. The IT help desk, because access requests flow through its ticketing system
Show answer & explanation
Answer: C
The data owner holds business accountability for the data's classification and appropriate use, so authorization decisions belong to the owner, while custodians such as database administrators implement the approved access technically. The requester's manager can confirm business need as an input, but cannot authorize use of data belonging to another function, and the help desk merely routes tickets — treating routing or technical capability as approval authority breaks the accountability chain.98. An organization has run a mandatory annual security-awareness course for three years. Which measure would give management the BEST evidence that the program is actually changing employee behavior?
- A. Course completion rates across all departments
- B. The number of hours of training content produced each year
- C. Employee satisfaction scores for the training modules
- D. A declining click rate on simulated phishing campaigns over successive tests
Show answer & explanation
Answer: D
Behavioral outcome measures, such as fewer employees falling for simulated phishing over time, show whether training is translating into safer actions, which is the program's real objective. Completion rates, content volume, and satisfaction scores are activity or perception metrics: employees can complete and even enjoy training without changing how they respond to real threats, so those measures demonstrate participation rather than effectiveness.99. An IT organization assesses its processes against a recognized capability maturity model and receives ratings for each process area. What is the PRIMARY benefit of this exercise?
- A. It removes the need for internal audit to test those processes
- B. It identifies capability gaps and provides a roadmap for prioritized process improvement
- C. It certifies the organization as compliant with applicable regulations
- D. It guarantees that higher-rated processes contain no control failures
Show answer & explanation
Answer: B
Maturity assessments show where each process stands relative to a target state, revealing gaps and enabling management to sequence improvement investments where they matter most. Maturity ratings are not regulatory certifications, and a high rating describes process capability rather than guaranteeing that individual controls never fail; likewise audit testing remains necessary because maturity models assess how processes are defined and managed, not whether specific controls operated on specific occasions.100. A board of directors receives cybersecurity information solely through a brief annual verbal update from the security officer, with no supporting metrics or independent validation. From a governance standpoint, what is the MOST significant concern?
- A. The update consumes valuable time on the board agenda
- B. Verbal delivery prevents the update from being translated for overseas directors
- C. The security officer may feel micromanaged by board attention
- D. The board cannot exercise informed oversight without regular, metric-based, and independently validated reporting
Show answer & explanation
Answer: D
Effective board oversight of cyber risk requires reporting that is frequent enough to track a fast-moving threat landscape, grounded in objective metrics, and subject to independent challenge — a single unverified verbal briefing per year provides none of these, leaving directors unable to judge whether risk is within appetite. Agenda time, translation logistics, and executive comfort are peripheral issues that do not go to the board's ability to discharge its oversight duty.101. A single senior engineer is the only person who understands and maintains a legacy application that supports a revenue-critical process, and no current documentation exists. What is the MOST appropriate management response to this situation?
- A. Increase the engineer's compensation to reduce the likelihood of resignation
- B. Restrict the engineer's other duties so the application receives full attention
- C. Purchase key-person insurance to compensate the organization if the engineer leaves
- D. Institute cross-training, current documentation, and succession planning to remove the single point of knowledge
Show answer & explanation
Answer: D
The exposure is a key-person dependency: the organization loses the ability to operate a critical system if one individual becomes unavailable for any reason, so the fix must transfer knowledge — through documentation, cross-training, and succession planning — rather than merely retain the person. Higher pay and workload protection reduce only voluntary departure risk, not illness or accident, and insurance provides money without restoring the operational capability the business actually needs.102. An IS auditor draws a statistical sample of purchase orders above a dollar threshold to test whether approvals were obtained. The sample shows zero exceptions, yet a data analysis run afterward on the full population reveals several unapproved purchase orders that were not selected. Which risk does this outcome illustrate?
- A. Inherent risk in the purchasing process
- B. Control risk arising from a poorly designed approval control
- C. Detection risk caused by an inappropriate audit procedure
- D. Sampling risk, because the sample did not represent the population
Show answer & explanation
Answer: D
Sampling risk is the chance that a conclusion drawn from a sample differs from the conclusion that would result from testing the entire population; here, an otherwise valid statistical sample simply failed to capture the exceptions that existed elsewhere in the population. Attributing the miss to the control's design conflates a sampling outcome with control risk, which concerns whether the control itself is capable of preventing or detecting errors, not whether the auditor's sample happened to include evidence of failure.103. An IS auditor is determining the extent of substantive testing required for a revenue-recognition interface between an order system and the general ledger. Which factor should PRIMARILY drive the auditor's judgment on sample size and testing depth?
- A. The number of IT staff available to support the audit during fieldwork
- B. The preference of the audit committee for a specific testing methodology
- C. The materiality of the account balance and the assessed level of combined risk
- D. The total number of transactions processed by the interface annually
Show answer & explanation
Answer: C
Materiality and the auditor's assessment of combined inherent and control risk determine how much assurance is needed and therefore how extensive testing must be; higher materiality or higher assessed risk calls for more extensive procedures. Transaction volume alone does not indicate financial or operational significance, and staffing availability or committee preference are practical or governance considerations that should not override a risk-based determination of testing scope.104. Six months after an audit report was issued, an IS auditor performs a follow-up review to determine whether management implemented agreed remediation actions for a previously reported access control weakness. Management states the actions were completed but the auditor finds no supporting evidence during the review. What should the auditor do?
- A. Accept management's verbal assurance and close the finding, since remediation was previously agreed
- B. Remove the finding from the follow-up report because responsibility now rests with management
- C. Escalate the matter directly to external regulators without further internal review
- D. Report the finding as unresolved and note that management's claim could not be corroborated
Show answer & explanation
Answer: D
A follow-up review exists to verify, not merely record, that agreed actions were actually taken; when the auditor cannot obtain corroborating evidence, the finding must be reported as open with that limitation explained, preserving the integrity of the audit trail. Closing the item on an unverified verbal claim, dropping it from reporting, or bypassing the organization's own escalation channels to go straight to a regulator are all inconsistent with an evidence-based follow-up process.105. An IS auditor has gathered audit evidence from three sources regarding the same access-review control: a system-generated log, a signed paper attestation obtained directly from an independent reviewer, and a verbal description of the process from the control owner. Ranking reliability from most to least reliable, which ordering is MOST appropriate?
- A. Independent signed attestation, system-generated log, verbal description from the control owner
- B. Verbal description, system log, independent signed attestation
- C. System log, verbal description, independent signed attestation
- D. All three sources are equally reliable once corroborated by audit working papers
Show answer & explanation
Answer: A
Evidence obtained directly from an independent party in documented form is generally the most reliable, followed by system-generated evidence produced automatically by a process with adequate general controls, with verbal representations from the party responsible for the control being the least reliable because they are self-reported and unverified. Treating all evidence as equally reliable ignores well-established evidence-hierarchy principles that guide how much weight an auditor can place on a finding.106. An audit manager is finalizing the annual IS audit plan and must allocate limited staff hours across dozens of candidate audit areas identified through a risk assessment. Which approach BEST ensures the plan focuses audit resources appropriately?
- A. Audit every area with any identified risk exposure, spreading hours evenly across all of them
- B. Select audit areas based on which business unit leaders request an audit be performed
- C. Audit only the areas that were audited in the prior year to maintain year-over-year comparability
- D. Prioritize areas with the highest combination of business impact and likelihood of risk materializing
Show answer & explanation
Answer: D
A risk-based audit plan directs finite audit resources to the areas where the combination of impact and likelihood is greatest, maximizing the assurance value delivered to the organization. Spreading effort evenly regardless of risk level dilutes coverage of high-risk areas, repeating the prior year's scope ignores how risk profiles change over time, and letting business unit requests drive selection substitutes stakeholder preference for an objective risk assessment.107. During planning, an IS auditor must decide between judgmental sampling and statistical sampling to test a control over vendor master file changes. Which factor would MOST justify choosing statistical sampling over judgmental sampling in this case?
- A. The auditor wants to mathematically quantify sampling risk and project results to the population
- B. The population of vendor master file changes is very small and easy to review in full
- C. Management prefers that the auditor use professional judgment to target known problem areas
- D. The control has never previously been tested by internal or external auditors
Show answer & explanation
Answer: A
Statistical sampling allows the auditor to quantify sampling risk and objectively project sample results to the full population, which is valuable when a defensible, mathematically supportable conclusion is needed. A very small population would typically call for full population testing rather than either sampling method, and choosing a method based on management's stated preference or on prior testing history substitutes those factors for the actual methodological reason to select statistical over judgmental sampling.108. An organization has a document stating that all production password changes must use a minimum of twelve characters, and a separate document describing the exact configuration steps to enforce this in the identity management system. How should these two documents be correctly classified within a governance framework?
- A. Both documents are policies, since they both relate to the same control objective
- B. Both documents are guidelines, since neither is mandatory under the framework
- C. The first is a procedure; the second is a standard that policies must reference
- D. The first is a policy setting a mandatory requirement; the second is a procedure describing how to implement it
Show answer & explanation
Answer: D
A policy states a mandatory, high-level requirement that the organization must satisfy, while a procedure provides the detailed, step-by-step instructions for how that requirement is actually carried out in a specific system; the twelve-character rule is the mandatory requirement and the configuration steps are how it gets implemented. Labeling both as policies, reversing the classification, or calling both merely optional guidelines all misrepresent the mandatory nature of the password rule and the operational nature of the configuration steps.109. Executive management wants to confirm that the organization's IT strategic plan remains aligned with overall business strategy as business priorities shift over time. Which practice BEST supports ongoing alignment rather than a one-time check?
- A. Delegating all strategic technology decisions permanently to the IT department without executive involvement
- B. Approving the IT strategic plan once and revisiting it only when a major system failure occurs
- C. Periodically reviewing and updating the IT strategy against evolving business objectives on a defined cycle
- D. Relying on the annual external audit to flag misalignment between IT and business strategy
Show answer & explanation
Answer: C
Strategic alignment is not a one-time event; it requires a defined, recurring review cycle in which the IT strategy is compared against current business objectives and adjusted as those objectives evolve. Waiting for a system failure or an external audit to surface misalignment is reactive and likely to occur too late, and permanently delegating strategy to IT without executive involvement removes the business perspective that alignment depends on.110. An organization negotiating an outsourcing contract for its help desk function includes financial penalties for missed service levels but no defined process for how service performance will be measured, reported, or disputed. From a governance standpoint, what is the MOST significant weakness in this arrangement?
- A. The penalties are not large enough to motivate the vendor
- B. Without agreed measurement, reporting, and dispute mechanics, the penalty clause cannot be reliably enforced
- C. Help desk functions should never be outsourced regardless of contract terms
- D. The contract does not specify which programming languages the vendor's staff must know
Show answer & explanation
Answer: B
A penalty clause is only enforceable in practice if both parties agree on how performance will be objectively measured, how results will be reported, and how disagreements will be resolved; without that mechanics, the organization has little practical ability to invoke the penalty even when service levels are missed. The size of the penalty, a blanket objection to outsourcing help desk work, and a requirement about programming languages are unrelated to the actual governance gap of unmeasurable, unenforceable service levels.111. A project team builds a matrix linking each documented business requirement to the corresponding design specification and the test case that will verify it. Which project risk does this technique PRIMARILY address?
- A. The risk that the project will exceed its approved budget
- B. The risk that a requirement is dropped or left unverified as the project moves through design and testing
- C. The risk that the project schedule will slip due to resource constraints
- D. The risk that the wrong development methodology was chosen for the project
Show answer & explanation
Answer: B
A requirements traceability matrix links each requirement forward to design and test artifacts, making it possible to confirm that every requirement is addressed and actually verified rather than silently dropped as the project progresses; this is a coverage and completeness control, not a budget, schedule, or methodology-selection control. Budget overruns and schedule slippage are managed through separate project controls such as cost and schedule tracking, and methodology choice is a planning decision made before this technique is even applied.112. After fixing a defect in a shared calculation module used by multiple parts of an application, the development team re-executes a broad set of previously passed test cases across the application before releasing the fix. What is the PRIMARY purpose of this practice?
- A. To confirm that the fix did not introduce new defects in previously working functionality
- B. To reduce the total number of test cases that will be needed in future releases
- C. To satisfy a mandatory step required before any code can be committed to version control
- D. To measure the performance of the application under peak transaction load
Show answer & explanation
Answer: A
Regression testing re-runs previously passed tests after a change to confirm that the change has not broken functionality elsewhere in the application, which is especially important when a shared module used by multiple features is modified. It does not reduce the future test case count, is not inherently a version-control commit gate, and is unrelated to load or performance testing, which is a distinct testing activity.113. A change control board reviews a proposed enhancement to a production financial system and must decide whether to approve, defer, or reject the change before it proceeds to development. Which of the following is the board's PRIMARY responsibility in this review?
- A. Writing the technical specification for how the enhancement will be coded
- B. Assessing the business justification, risk, and impact of the proposed change before authorizing it to proceed
- C. Personally performing the testing of the change once development is complete
- D. Approving the annual budget for the entire development department
Show answer & explanation
Answer: B
A change control board exists to evaluate the business case, risk, and potential impact of a proposed change and to formally authorize whether it should proceed, providing an independent check before resources are committed to development. Writing the technical specification and performing testing are execution activities carried out by the project or development team, and approving departmental budgets is a separate governance function outside the scope of change authorization.114. A quality function within a development organization defines coding standards and reviews finished deliverables for defects before release, while a separate quality function is embedded throughout the development process to prevent defects from occurring in the first place. Which pairing correctly labels these two functions?
- A. The first is quality assurance; the second is quality control
- B. The first is quality control; the second is quality assurance
- C. Both functions described are quality assurance, performed at different project stages
- D. Both functions described are quality control, performed by different teams
Show answer & explanation
Answer: B
Quality control is typically a detective activity that inspects finished deliverables against defined standards to catch defects, while quality assurance is a preventive activity embedded throughout the process to reduce the likelihood that defects occur in the first place; the description reviewing finished deliverables matches quality control and the process-embedded prevention activity matches quality assurance. Describing both functions as the same discipline collapses this important distinction between preventive and detective quality activities.115. An organization migrating to a new ERP system has completed the technical data conversion but has not defined what will happen if critical post-conversion validation reveals unacceptable data errors after go-live. What should the project team have established BEFORE go-live to address this gap?
- A. A documented fallback and rollback plan for reverting to the legacy system if conversion problems are discovered
- B. A marketing communication plan announcing the new system to external customers
- C. A help desk staffing schedule for the first week after go-live
- D. A long-term decommissioning schedule for legacy hardware five years in the future
Show answer & explanation
Answer: A
A fallback or rollback plan defines how the organization will revert to the legacy system and data if post-conversion validation uncovers unacceptable errors, providing a safety net for the highest-risk period of a conversion; without it, the organization has no defined path to recover if the migration fails. Customer communications, help desk staffing, and long-range hardware decommissioning are all reasonable project activities but do not address the specific risk of an unrecoverable failed data conversion.116. A project is migrating users to a new claims-processing system location by location, with each site cutting over on a staggered schedule rather than all at once. Which system conversion strategy is being used, and what is its key advantage?
- A. Direct cutover; it eliminates any dual-running cost by switching everyone off the old system on the same day
- B. Parallel changeover; it runs both systems simultaneously for every site until testing is complete
- C. Phased (or pilot) conversion; it limits exposure by allowing issues to be identified and corrected before wider rollout
- D. Abort conversion; it allows the project to be cancelled if early sites report problems
Show answer & explanation
Answer: C
A phased or pilot conversion rolls a new system out incrementally, typically to a subset of locations first, so that problems can be identified and corrected on a limited scale before the remaining sites cut over, reducing overall exposure compared to switching everyone at once. Direct cutover switches all users simultaneously rather than in stages, parallel changeover runs both systems concurrently rather than staggering sites, and there is no formal conversion approach called an abort conversion.117. A large systems integration project has multiple interdependent activities. The project manager identifies the sequence of dependent tasks that determines the shortest possible time to complete the project, and any delay to a task in that sequence delays the entire project. What is this sequence called?
- A. The critical path
- B. The change freeze window
- C. The scope baseline
- D. The stakeholder register
Show answer & explanation
Answer: A
The critical path is the sequence of dependent tasks that determines the minimum project duration; because there is no slack in this sequence, any delay to one of its tasks directly delays the overall project completion date. A change freeze window restricts changes during a defined period, a scope baseline documents the agreed project scope, and a stakeholder register lists project stakeholders, none of which describe the schedule-determining task sequence.118. An organization completed a major system implementation eighteen months ago and is only now conducting its post-implementation review. What is the MOST significant limitation of performing this review so long after go-live?
- A. The system's vendor will refuse to provide support once a post-implementation review is delayed
- B. Key project staff, documentation, and institutional knowledge about early implementation issues may no longer be available or accurate
- C. Post-implementation reviews are only valid if performed within thirty days of go-live under any circumstances
- D. The review will take longer to complete than if it had been done immediately
Show answer & explanation
Answer: B
The primary value of a post-implementation review depends on accurately capturing lessons learned, benefits realization, and early operational issues, but staff turnover, fading institutional memory, and stale documentation over an extended delay make it much harder to reconstruct an accurate picture of what actually happened. There is no fixed rule requiring the review within thirty days, vendor support obligations are unrelated to when an internal review is performed, and simply taking longer is a minor administrative issue compared to the loss of reliable evidence and recollection.119. During system testing, developers use a copy of the production environment's configuration but with a completely separate database instance and network segment from live production. What is the PRIMARY control objective served by this separation?
- A. To allow developers unrestricted, unmonitored access to production data for realistic testing
- B. To prevent test activities, including invalid or malformed data, from affecting live production data and operations
- C. To eliminate the need for a formal user acceptance testing phase
- D. To reduce the total cost of software licensing across environments
Show answer & explanation
Answer: B
Segregating test and production environments prevents test transactions, defect conditions, or invalid data introduced during testing from corrupting or disrupting live production data and operations, which is a fundamental control objective for change and environment management. It does not eliminate the need for user acceptance testing, nor is it intended to grant unrestricted production data access; reducing licensing cost may be a side effect for some organizations but is not the control objective the separation is designed to achieve.120. An organization is selecting a vendor for a new customer relationship management system and issues a request for proposal (RFP) to several candidates. Which practice BEST ensures the selection process remains objective and defensible?
- A. Selecting the vendor recommended informally by an existing employee's prior employer
- B. Allowing each business stakeholder to independently choose their preferred vendor
- C. Selecting the vendor that offers the lowest price regardless of other factors
- D. Defining weighted evaluation criteria in advance and scoring all proposals consistently against them
Show answer & explanation
Answer: D
Defining evaluation criteria and their relative weighting before proposals are reviewed, and then scoring every vendor consistently against those criteria, keeps the selection process objective, comparable across vendors, and defensible if later questioned. Choosing solely on lowest price ignores functional fit and vendor viability, letting each stakeholder choose independently produces no consistent organizational decision, and relying on an informal personal recommendation bypasses a structured evaluation entirely.121. During a code review of a web application, a reviewer flags that user-supplied input is concatenated directly into database query strings without validation or parameterization. What is the PRIMARY risk this practice introduces?
- A. Increased licensing costs for the database platform
- B. Injection attacks that could allow unauthorized access to or manipulation of data
- C. Slower application performance under normal user load
- D. Difficulty in translating the application into other languages
Show answer & explanation
Answer: B
Concatenating unvalidated user input directly into query strings is a classic injection vulnerability, allowing an attacker to manipulate the query logic to access, modify, or delete data beyond what the application intends to permit. This coding practice is a security defect, not primarily a performance, licensing, or localization concern, though poorly secured applications can certainly have other quality issues as well.122. A new order-management system must exchange data in real time with an existing inventory system and a separate billing system. Beyond testing each system individually, what additional testing is essential before go-live?
- A. Interface testing to confirm data is correctly transmitted, received, and interpreted between the connected systems
- B. Usability testing limited to the order-management system's screens
- C. A code-freeze period with no testing activity at all
- D. Testing only the billing system, since it is the final system in the data flow
Show answer & explanation
Answer: A
When systems exchange data, interface testing is essential to confirm that data formats, timing, and content are correctly transmitted, received, and interpreted across the connection points, since defects at the boundary between systems will not be caught by testing each system in isolation. Limiting testing to one system's usability, imposing a code freeze with no testing, or testing only the last system in the flow would all leave the actual points of integration risk unverified.123. A development team uses a tool that tracks every change made to source code files, records who made each change, and allows any prior version to be retrieved if needed. What primary control does this tool provide?
- A. Configuration and version control over source code changes
- B. Automated functional testing of the application
- C. Real-time monitoring of production system performance
- D. Enforcement of segregation of duties between developers and end users
Show answer & explanation
Answer: A
A source code version control tool provides configuration management by tracking who changed what, when, and enabling recovery of prior versions, which supports accountability and the ability to reverse unwanted changes. It does not itself perform functional testing, monitor production performance, or enforce segregation of duties between developers and end users, each of which requires separate controls beyond simple change tracking.124. Business stakeholders have reviewed a system's functional specifications and formally documented their agreement that the specifications accurately capture what the business needs. What is the PRIMARY purpose of obtaining this sign-off before development begins?
- A. To establish an agreed baseline of requirements, reducing the risk of scope disputes and rework later in the project
- B. To eliminate the need for user acceptance testing once the system is built
- C. To satisfy a requirement that only applies to government-sector system implementations
- D. To transfer legal liability for the entire project from the vendor to the business stakeholders
Show answer & explanation
Answer: A
Formal sign-off on requirements establishes an agreed baseline that both business and development teams can refer back to, reducing later disagreement over what was actually requested and limiting costly rework caused by shifting or misunderstood requirements. It does not eliminate the later need for user acceptance testing, is not limited to government-sector projects, and does not by itself transfer overall legal liability for the project.125. A development team using an agile methodology holds a session at the end of each sprint to discuss what went well, what did not, and what process changes to make in the next sprint. Which agile practice is being described?
- A. Sprint retrospective
- B. Sprint planning
- C. Daily stand-up
- D. Product backlog grooming
Show answer & explanation
Answer: A
A sprint retrospective is the recurring session held at the end of each sprint specifically to reflect on what worked, what did not, and what process improvements the team will make going forward. Sprint planning occurs at the start of a sprint to select and plan the work, the daily stand-up is a brief daily synchronization on progress and blockers, and backlog grooming refines and prioritizes upcoming work items, none of which match the end-of-sprint reflection described.126. During data migration to a new system, the project team runs record counts and control totals on both the source and target data sets and compares them before allowing the new system to go live. What does this control PRIMARILY provide assurance over?
- A. That the new system's user interface meets usability standards
- B. That end users have been adequately trained on the new system
- C. That the new system has adequate processing capacity for future growth
- D. That the migrated data is complete, with no records lost or unaccounted for during conversion
Show answer & explanation
Answer: D
Comparing record counts and control totals between the source and target data sets after migration directly addresses completeness, confirming that no records were dropped, duplicated, or otherwise lost during the conversion process. It says nothing about interface usability, future processing capacity, or the adequacy of user training, each of which would require separate, unrelated evaluation methods.127. An overnight batch job that loads sales data into a data warehouse depends on an upstream job that extracts data from the point-of-sale system. One night, the extract job fails silently, but the load job still runs on schedule and processes stale data without any alert being raised. What control weakness does this scenario MOST clearly illustrate?
- A. Job scheduling lacks dependency checks and failure notifications between related jobs
- B. The point-of-sale system was not adequately load tested before deployment
- C. The data warehouse lacks sufficient storage capacity for daily loads
- D. The organization has not documented a data retention policy for warehouse data
Show answer & explanation
Answer: A
Effective job scheduling should prevent a dependent job from running against incomplete or missing input, and should generate an alert when an upstream job fails, so that operations staff are aware before stale or incomplete data is processed further; the described outcome shows both the dependency check and the failure alert were missing. Storage capacity, load testing of the source system, and retention policy are unrelated to the specific breakdown of an unmonitored, undetected job dependency failure.128. An operations team implements a tool that aggregates log events from servers, network devices, and applications into a single console and correlates related events to surface a single operational incident rather than dozens of separate alerts. What is the PRIMARY operational benefit of this capability?
- A. It eliminates the need for any manual system administration
- B. It reduces alert fatigue and speeds incident detection by correlating related events into a single actionable signal
- C. It guarantees one hundred percent system uptime going forward
- D. It automatically fixes the underlying cause of any detected incident
Show answer & explanation
Answer: B
Correlating related log events from multiple sources into a single incident reduces the volume of disconnected alerts operations staff must triage individually, helping them detect and respond to genuine incidents faster; this is a detection and efficiency benefit, not a guarantee of uptime or an automatic remediation capability. Manual administration is still required to investigate and resolve the underlying cause once an incident is identified.129. An organization's backup scheme retains the most recent daily backup, the most recent weekly backup, and the most recent monthly backup, cycling older media out as newer backups are created. What is this backup rotation scheme commonly called?
- A. Continuous data protection
- B. Mirrored backup
- C. Snapshot replication
- D. Grandfather-father-son rotation
Show answer & explanation
Answer: D
A grandfather-father-son rotation scheme retains backups at daily (son), weekly (father), and monthly (grandfather) tiers, cycling out the oldest media in each tier as newer backups are created, which balances recovery granularity against media and storage costs. Continuous data protection captures changes in near real time rather than at fixed daily, weekly, and monthly intervals, mirrored backup maintains a live duplicate rather than a tiered rotation, and snapshot replication captures point-in-time images without necessarily following this specific tiered retention structure.130. A critical order-processing application runs across two active servers behind a load balancer, configured so that if one server fails, the other automatically continues processing all transactions without interruption to users. What availability design does this describe?
- A. A cold standby recovery configuration
- B. High-availability clustering with automatic failover
- C. A scheduled maintenance window strategy
- D. A manual disaster recovery invocation procedure
Show answer & explanation
Answer: B
High-availability clustering with automatic failover allows a second active server to continue processing transactions immediately if one server fails, avoiding the extended downtime associated with recovery approaches that depend on standby infrastructure being manually or gradually brought online. A cold standby configuration requires infrastructure to be built up before it can process transactions, a maintenance window strategy is a planned downtime practice rather than a resilience design, and a manual invocation procedure implies human intervention rather than automatic continuity.131. An organization conducts a disaster recovery exercise in which staff actually shift live production processing to the alternate recovery site for several hours to validate that recovery procedures work under real operating conditions, rather than simply talking through the plan in a conference room. Which type of DR test is being performed, and how does it differ from a structured walkthrough?
- A. A tabletop discussion, which is functionally identical to a structured walkthrough
- B. A checklist review, which only confirms that recovery documentation exists
- C. A parallel or simulation test, which exercises actual recovery procedures and processing rather than only discussing them
- D. A paper-based audit, which relies solely on reviewing prior test reports
Show answer & explanation
Answer: C
A parallel or simulation test physically exercises the recovery procedures, systems, and processing at the alternate site, providing much stronger assurance that recovery will work in a genuine disaster than a structured walkthrough, which only involves participants talking through the plan's steps without actually performing them. A tabletop discussion and a structured walkthrough are essentially the same lower-assurance exercise, a checklist review merely confirms documentation exists, and a paper-based audit of prior reports does not test current recovery capability at all.132. An organization has a business continuity plan covering people, facilities, and manual workaround procedures for critical business processes, and separately maintains a plan focused specifically on restoring IT systems and data supporting those processes. How do these two plans relate to one another?
- A. The IT-focused disaster recovery plan is a supporting component that enables the broader business continuity plan's process-recovery objectives
- B. The two plans address entirely unrelated risks and are never coordinated
- C. They are identical documents required to be maintained separately only for regulatory formality
- D. The business continuity plan is unnecessary once an IT disaster recovery plan exists
Show answer & explanation
Answer: A
An IT disaster recovery plan is a technical component that supports the broader business continuity plan by restoring the systems and data that business processes depend on, meaning the two must be coordinated so that IT recovery timeframes actually enable the business process recovery objectives set out in the BCP. Treating the plans as identical, assuming one makes the other unnecessary, or assuming they address unrelated risks all misunderstand the dependency between IT recovery and overall business process continuity.133. A database administrator explains that if the database server crashes mid-transaction, the database engine can use records of every change made since the last checkpoint to restore the database to a consistent state without needing to restore from a full backup. Which database feature is being described?
- A. Data partitioning
- B. Index rebuilding
- C. Schema normalization
- D. Transaction (redo) logs
Show answer & explanation
Answer: D
Transaction logs, often called redo logs, record every change made to the database since the last checkpoint, allowing the database engine to reapply or roll back changes to restore a consistent state after a crash without requiring a full restore from backup. Data partitioning organizes how data is physically distributed, index rebuilding improves query performance, and schema normalization reduces data redundancy in table design, none of which provide the crash-recovery capability described.134. Operations staff notice that the message queue feeding an overnight settlement process has been steadily growing in backlog over several weeks, with messages taking progressively longer to be processed even though no errors are being logged. What is the MOST significant risk if this trend is not addressed?
- A. The message queue software license will expire automatically
- B. Growing backlog may eventually cause the settlement process to miss its processing deadline or fail under peak load
- C. The trend indicates a network cabling fault that requires physical replacement
- D. The organization will be unable to add new message types to the queue
Show answer & explanation
Answer: B
A steadily growing, unaddressed backlog signals that processing capacity is not keeping pace with incoming volume, and if the trend continues the settlement process risks missing its required completion deadline or failing outright once volume spikes during a peak period; this is fundamentally a capacity and throughput risk. Licensing expiration, a physical cabling fault, and an inability to add new message types are not indicated by a growing processing backlog and would present through entirely different symptoms.135. A service desk receives an average of two hundred tickets per day covering issues ranging from a single user's forgotten password to a complete outage of the customer-facing website. Which practice BEST ensures that limited support staff address the most business-critical issues first?
- A. Resolving tickets strictly in the order they were received, regardless of impact
- B. Assigning severity levels based on business impact and urgency, and prioritizing response accordingly
- C. Assigning all tickets to the most senior support staff member regardless of complexity
- D. Closing any ticket not resolved within one hour, regardless of its status
Show answer & explanation
Answer: B
Categorizing tickets by severity based on business impact and urgency, such as treating a full website outage as higher priority than an individual password reset, ensures that limited support capacity is directed first toward the issues causing the greatest business harm. Strict first-in-first-out handling ignores relative impact, routing every ticket to the most senior staff member regardless of complexity wastes specialized capacity on trivial issues, and closing unresolved tickets after an arbitrary time limit abandons issues rather than resolving them.136. A nightly batch process that updates customer account balances calculates a control total of all transaction amounts before processing and compares it to a control total calculated after processing completes. What does a match between these two totals PRIMARILY provide assurance of?
- A. That the batch job completed and processed the input data without unexplained loss or duplication
- B. That the customer account balances are accurate as of the date of processing
- C. That no unauthorized person accessed the batch processing server
- D. That the application code contains no logical defects
Show answer & explanation
Answer: A
A run-to-run control total comparison confirms that the amounts entering a batch process match the amounts reflected after processing, providing assurance that no records were unexpectedly lost, dropped, or duplicated during that specific run; it is a completeness and integrity check over the batch run itself. It does not, by itself, confirm that underlying account balances are substantively accurate, that access to the server was authorized, or that the application logic is free of defects, each of which requires separate controls.137. A finance team maintains a complex spreadsheet with embedded macros that calculates quarterly revenue recognition figures reported to executive management, developed and maintained entirely by one analyst outside of any formal change control or version history. What is the MOST significant risk this end-user computing application presents?
- A. The spreadsheet software license may be more expensive than a database license
- B. Undetected calculation errors or unauthorized changes could affect figures reported to executive management without any independent review
- C. The spreadsheet will automatically stop functioning after a fixed number of uses
- D. Executive management will be unable to open the file on their own computers
Show answer & explanation
Answer: B
End-user computing applications like spreadsheets often operate outside formal IT change control, testing, and version history, so errors in formulas or macros, or unauthorized changes by the sole developer, can silently affect figures relied upon by executive management with no independent review to catch the problem. Licensing cost comparisons, an artificial usage limit, and a file-compatibility concern are not the substantive risk that this lack of independent control and review over a financially significant calculation represents.138. An organization moves an application from on-premises infrastructure to a cloud provider's infrastructure-as-a-service offering. Under the shared responsibility model typically used by such providers, which party is generally responsible for securing the guest operating system and application running on the provisioned virtual machines?
- A. The customer remains responsible for the guest operating system, application, and data, while the provider secures the underlying physical infrastructure
- B. Neither party is responsible until a security incident actually occurs
- C. Responsibility is transferred entirely to any third-party auditor engaged to review the environment
- D. The cloud provider is solely responsible for all layers, including the guest operating system
Show answer & explanation
Answer: A
Under a typical infrastructure-as-a-service shared responsibility model, the cloud provider secures the underlying physical infrastructure, virtualization layer, and network, while the customer remains responsible for securing the guest operating system, middleware, applications, and data running on top of that infrastructure. Neither the sole-provider-responsibility view nor the idea that an auditor or an incident triggers responsibility reflects how shared responsibility actually allocates security duties between the parties on an ongoing basis.139. Over time, an organization's virtualized data center has accumulated hundreds of virtual machines, many created for short-term projects and never decommissioned, with no complete inventory of what is running or why. What is the PRIMARY risk this situation creates?
- A. Cloud computing costs are always higher than on-premises computing regardless of utilization
- B. The hypervisor software will refuse to run additional virtual machines once a fixed limit is reached
- C. Virtual machines cannot be created faster than physical servers under any circumstances
- D. Unmanaged, unpatched virtual machines increase the attack surface and may go unmonitored for security and compliance issues
Show answer & explanation
Answer: D
Virtual machine sprawl, where instances proliferate without a complete inventory or decommissioning process, means forgotten machines often remain unpatched and unmonitored, expanding the attack surface and creating blind spots for security and compliance oversight. The other options describe unrelated or overstated claims about VM creation speed, an arbitrary hypervisor limit, and a blanket cost comparison that are not the substantive risk this scenario presents.140. An organization's vulnerability management program identifies a critical operating system vulnerability with an available vendor-issued fix, but the fix has not yet been applied to production servers three months after release. What is the MOST significant risk of this delay?
- A. The operating system will automatically revert to an earlier, unsupported version
- B. The vendor will terminate all technical support for the affected product
- C. Server hardware warranties will be voided by the delay
- D. The known, unpatched vulnerability remains exploitable, increasing the window of exposure to attack
Show answer & explanation
Answer: D
An extended delay in applying a known, available fix leaves the vulnerability exploitable for a longer period, directly increasing the organization's window of exposure to attackers who are often aware of and actively targeting recently disclosed vulnerabilities. Support termination, automatic version reversion, and hardware warranty voidance are not consequences of a delayed patch and do not capture the actual security exposure created by leaving a known vulnerability unremediated.141. An IS auditor reviewing endpoint protection finds that antivirus software is installed on all workstations but signature updates have not been applied in over four months due to a misconfigured update service. What is the MOST significant consequence of this finding?
- A. Users will be unable to log in to their workstations until updates resume
- B. Workstations will run noticeably faster without frequent signature updates
- C. The antivirus software will automatically uninstall itself after a period of inactivity
- D. Endpoints have reduced ability to detect malware variants identified since the last update, increasing infection risk
Show answer & explanation
Answer: D
Antivirus effectiveness depends heavily on current signature definitions; without updates for an extended period, endpoints lose the ability to recognize malware variants and threats identified after the last successful update, meaningfully increasing the risk of undetected infection. Claims about improved performance, automatic uninstallation, or a login lockout are not accurate consequences of stale signatures and do not reflect the actual security exposure created by the misconfiguration.142. A data center's environmental monitoring system tracks temperature, humidity, and airflow, and automatically triggers alerts and a gaseous fire suppression system rather than a traditional water-based sprinkler system in the server room. What is the PRIMARY reason a data center would choose gaseous suppression over a water-based system?
- A. Gaseous suppression extinguishes fire while minimizing the risk of water damage to sensitive electronic equipment
- B. Gaseous suppression systems cost less to install than any water-based alternative in every case
- C. Water-based systems are prohibited by law in all commercial data centers
- D. Gaseous suppression eliminates the need for temperature and humidity monitoring entirely
Show answer & explanation
Answer: A
Gaseous fire suppression systems extinguish fire by displacing oxygen or interrupting the combustion process without discharging water, which protects sensitive electronic equipment from the water damage that a traditional sprinkler system could cause during activation. Cost is not universally lower in every case, water-based systems are not categorically prohibited by law, and suppression systems do not eliminate the ongoing need for environmental monitoring of temperature and humidity.143. An organization's tape media library maintains a log of every tape's location, contents, retention period, and chain of custody as it moves between on-site storage, an off-site vault, and eventual destruction. What is the PRIMARY audit-relevant purpose of this log?
- A. To calculate the total electricity cost of running the tape library
- B. To provide accountability and traceability over physical media, supporting recoverability and preventing unauthorized loss or access
- C. To satisfy a requirement that applies only to media used for marketing materials
- D. To eliminate the need for encrypting data stored on the tapes
Show answer & explanation
Answer: B
A media library log that tracks location, contents, retention, and custody supports accountability and traceability over physical backup media, which is essential both for locating media reliably during a restore and for preventing unauthorized access or unexplained loss of media containing sensitive data. It has no relationship to electricity cost calculations or marketing-material requirements, and maintaining a location log does not eliminate the separate need to encrypt sensitive data on the media itself.144. In the weeks leading up to its highest-volume sales period, a retail organization implements a temporary freeze on all non-emergency changes to its e-commerce platform. What is the PRIMARY objective of this change freeze?
- A. To permanently replace the organization's normal change management process
- B. To reduce the risk of instability or outages during the period when the platform's availability is most critical to the business
- C. To allow developers to make changes without any testing during the freeze period
- D. To satisfy a requirement that applies only once every five years
Show answer & explanation
Answer: B
A temporary change freeze during a peak business period reduces the risk that a routine change introduces instability or an outage precisely when system availability matters most to the business, reserving deployments for only emergency situations until the high-risk period passes. It is not a permanent replacement for change management, does not relax testing standards during the freeze, and is a recurring risk-based practice tied to business cycles rather than an infrequent regulatory formality.145. An organization encrypts sensitive data using symmetric encryption keys but stores those keys in a plaintext configuration file on the same server as the encrypted data, with no defined process for rotating keys periodically. What is the MOST significant weakness in this approach?
- A. Encryption always significantly degrades application performance regardless of implementation
- B. Storing keys alongside the data they protect, without rotation, undermines the protection encryption is meant to provide
- C. Symmetric encryption is inherently weaker than asymmetric encryption in all circumstances
- D. Symmetric keys cannot be used to encrypt data stored in a database
Show answer & explanation
Answer: B
Effective key management requires that encryption keys be stored and protected separately from the data they encrypt, with a defined rotation process, because anyone who gains access to a plaintext key stored alongside the data can trivially decrypt it, defeating the purpose of encrypting the data in the first place. Symmetric encryption is not inherently weaker than asymmetric encryption for this purpose, the performance claim is an overgeneralization, and symmetric keys are commonly and appropriately used to encrypt database data.146. A web application presents a digital certificate to browsers to establish an encrypted connection, and the browser validates that certificate against a chain of trust leading back to a recognized certificate authority. What is the PRIMARY purpose of this certificate validation?
- A. To measure how quickly the web application responds to user requests
- B. To confirm the identity of the server and enable a trusted encrypted connection between the browser and server
- C. To automatically back up the website's content to a secondary location
- D. To determine how much bandwidth the website is permitted to consume
Show answer & explanation
Answer: B
Certificate validation against a trusted certificate authority chain confirms that the server presenting the certificate is who it claims to be, which allows the browser to establish an encrypted connection with confidence that it is not communicating with an impersonating party. Validating a certificate has no bearing on response time measurement, does not back up website content, and does not govern bandwidth allocation, none of which relate to the identity and trust function certificates serve.147. An IS auditor reviewing a corporate firewall's rule base finds numerous rules with no documented business justification, several that permit broad, unrestricted traffic between network segments, and rules referencing systems that were decommissioned years ago. What should the auditor recommend as the MOST appropriate response?
- A. Leave the rules in place since removing any rule risks breaking an unknown dependency
- B. Disable the firewall entirely until a replacement can be procured
- C. Add additional broad rules to compensate for the lack of documentation
- D. Conduct a periodic firewall rule review to remove unjustified, overly permissive, or obsolete rules
Show answer & explanation
Answer: D
A periodic firewall rule review process identifies and removes rules that lack documented business justification, are overly permissive, or reference systems that no longer exist, reducing unnecessary attack surface while confirming that remaining rules still serve a legitimate, current purpose. Leaving undocumented rules in place indefinitely out of caution, disabling the firewall entirely, or adding further broad rules would each leave the network more exposed rather than reducing the excessive access the finding describes.148. A security team deploys a device that not only detects suspicious network traffic patterns but can also automatically block or drop malicious traffic in real time before it reaches its intended target, rather than only generating an alert for later review. Which type of security control does this describe, and how does it differ from a detection-only device?
- A. An intrusion prevention system, which actively blocks malicious traffic rather than only alerting on it like an intrusion detection system
- B. An intrusion detection system, which is functionally identical to a firewall in every respect
- C. A data loss prevention system, which only classifies data without any network traffic function
- D. A vulnerability scanner, which identifies weaknesses but never interacts with live network traffic
Show answer & explanation
Answer: A
An intrusion prevention system sits in line with network traffic and can actively block or drop malicious traffic in real time, whereas an intrusion detection system passively monitors and alerts on suspicious activity without taking direct action to stop it, making active blocking the key functional distinction. A data loss prevention system and a vulnerability scanner serve entirely different purposes, classifying sensitive data and identifying weaknesses respectively, and neither performs the real-time traffic-blocking function described.149. After several employees fell for a simulated phishing email during a security awareness campaign, the organization now sends similar simulations quarterly and tracks click rates over time, along with providing immediate targeted training to anyone who fails a simulation. What is the PRIMARY value of continuing this practice over time rather than running it once?
- A. It guarantees that no employee will ever fall for an actual phishing attack again
- B. It satisfies a one-time training requirement that never needs to be repeated
- C. It transfers all responsibility for phishing losses from the organization to individual employees
- D. It measures whether awareness is improving over time and reinforces behavior through repeated, targeted reinforcement
Show answer & explanation
Answer: D
Recurring phishing simulations with tracked click-rate trends and immediate targeted follow-up training allow the organization to measure whether awareness is genuinely improving and to reinforce secure behavior continuously, since a single training event tends to fade in effectiveness over time. No training program can guarantee zero future susceptibility, awareness training does not transfer legal or financial responsibility away from the organization, and treating it as a one-time requirement would forgo the ongoing reinforcement value the recurring approach provides.150. A development team needs realistic data to test a new application feature but is prohibited from using actual customer records due to privacy requirements. The team instead uses a process that replaces sensitive values, such as names and account numbers, with fictitious but realistically formatted substitutes while preserving the data's structure and referential integrity. What technique is being used?
- A. Data masking (or de-identification) of test data
- B. Data compression to reduce test environment storage requirements
- C. Data replication to synchronize test and production environments
- D. Data archiving to move records to long-term storage
Show answer & explanation
Answer: A
Data masking replaces sensitive values with realistic but fictitious substitutes while preserving the data's format and relationships, allowing test teams to work with structurally valid data without exposing actual sensitive customer information. Data compression reduces storage size without altering sensitivity, data replication would actually copy the real sensitive data into the test environment rather than protecting it, and data archiving relocates records for retention purposes rather than de-identifying them for safe testing use.151. An organization allows employees to access corporate email and internal applications from personally owned smartphones, and enrolls each device in a platform that can enforce passcode requirements, encrypt corporate data, and remotely wipe only the corporate data if the device is lost or the employee departs. What capability is being described?
- A. A virtual private network client installed without any device enrollment
- B. Mobile device management (MDM), enforcing security policy and enabling selective remote wipe of corporate data
- C. A guest wireless network with no access to internal systems
- D. A firewall rule restricting smartphone access entirely
Show answer & explanation
Answer: B
Mobile device management platforms enroll personally or corporately owned devices to enforce security policies such as passcode requirements and encryption, and enable selective remote wipe of corporate data specifically, without necessarily erasing the employee's personal data. A bare VPN client without enrollment would not provide policy enforcement or selective wipe capability, a guest wireless network with no internal access would not support the described corporate application use, and a blanket firewall rule blocking smartphone access entirely contradicts the described scenario of employees actively using their devices.152. An organization evaluates a biometric fingerprint authentication system and is comparing two configurations: one tuned to more readily accept a scanned fingerprint as a match, and one tuned to be more conservative before accepting a match. Which tradeoff does adjusting this sensitivity setting PRIMARILY create?
- A. A tradeoff between the false acceptance rate and the false rejection rate of the system
- B. A tradeoff between the cost of the biometric hardware and its expected physical lifespan
- C. A tradeoff between the number of supported biometric modalities and network bandwidth usage
- D. A tradeoff between the biometric system's color display resolution and its battery life
Show answer & explanation
Answer: A
Adjusting a biometric system's matching sensitivity directly trades off the false acceptance rate, the likelihood of wrongly accepting an unauthorized person, against the false rejection rate, the likelihood of wrongly rejecting a legitimate authorized user, and tuning toward one generally worsens the other. Hardware cost and lifespan, the number of supported biometric modalities and bandwidth usage, and display resolution and battery life are unrelated to the specific matching-sensitivity tradeoff the scenario describes.153. An organization runs an automated tool that scans its network and systems for known weaknesses and misconfigurations, producing a report listing hundreds of potential findings ranked by severity. Separately, the organization engages a team to actively attempt to exploit those and other weaknesses to determine whether an attacker could actually gain unauthorized access. How do these two activities differ?
- A. They are the same activity performed by different job titles with no meaningful difference
- B. A vulnerability assessment identifies potential weaknesses, while a penetration test actively attempts to exploit weaknesses to demonstrate real-world impact
- C. A vulnerability assessment always costs more than a penetration test in every organization
- D. A penetration test only examines physical security controls and never network-based weaknesses
Show answer & explanation
Answer: B
A vulnerability assessment systematically identifies and catalogs potential weaknesses and misconfigurations, typically through automated scanning, while a penetration test goes further by actively attempting to exploit identified and other weaknesses to demonstrate whether an attacker could realistically achieve unauthorized access and what impact that would have. The two are meaningfully different in depth and objective rather than interchangeable job titles, relative cost varies by engagement rather than following a fixed rule, and penetration tests commonly assess network and application weaknesses in addition to, or instead of, physical controls.154. An organization stores customer transaction records indefinitely on production systems because no policy specifies when data should be archived or deleted, resulting in databases that are far larger than operationally necessary and that retain data well beyond any legitimate business or legal need. What should the organization implement to address this issue?
- A. A defined data retention policy specifying how long different data types must be kept and when they should be archived or securely deleted
- B. A requirement that all data be duplicated across three additional data centers
- C. A policy prohibiting any future collection of customer transaction data
- D. A rule requiring all employees to manually back up data to personal storage devices
Show answer & explanation
Answer: A
A defined data retention policy specifies how long each type of data must be kept to satisfy business and legal requirements, and when it should subsequently be archived or securely deleted, directly addressing the problem of indefinite retention beyond any legitimate need. Requiring additional duplication across data centers increases storage and risk rather than resolving the retention gap, prohibiting all future data collection would be operationally unworkable, and requiring manual backups to personal devices would create new security and control risks rather than solving the underlying retention problem.155. A software development team building a new customer-facing application decides to identify what personal data the application will collect, minimize collection to only what is strictly necessary, and build in default privacy protections before writing any code, rather than adding privacy controls after the application is complete. What principle does this approach reflect?
- A. Privacy by design, embedding privacy protections into a system from the earliest stages of development
- B. Defense in depth, layering multiple unrelated security controls regardless of data sensitivity
- C. Least privilege, restricting employee access rights based on job function
- D. Separation of duties, dividing incompatible functions among different individuals
Show answer & explanation
Answer: A
Privacy by design is the principle of embedding privacy protections, including data minimization and default privacy-protective settings, into a system from the earliest stages of development rather than retrofitting them after the system is built. Defense in depth concerns layering multiple security controls generally, least privilege concerns restricting individual access rights, and separation of duties concerns dividing incompatible functions among different people, none of which describe designing privacy protections into a system from inception.156. An organization's access provisioning process requires that the person requesting new system access, the manager who approves the request, and the administrator who actually grants the access in the system all be different individuals, with no single person able to perform more than one of these roles for the same request. What risk does this design PRIMARILY mitigate?
- A. The risk that a single individual could request, approve, and grant themselves unauthorized access without independent oversight
- B. The risk that access requests will take longer to process than a single-step approval
- C. The risk that the system will run out of available user account licenses
- D. The risk that the help desk will receive too many password reset requests
Show answer & explanation
Answer: A
Dividing the request, approval, and granting steps among different individuals prevents any single person from requesting access for themselves, approving their own request, and then granting it, which would otherwise allow unauthorized or excessive access to be self-provisioned without independent oversight. License availability, processing time, and password reset volume are operational or capacity concerns unrelated to the specific segregation-of-duties risk this three-way division of responsibility is designed to address.157. An organization's password policy requires a minimum length and a mix of character types but does not check submitted passwords against lists of commonly used or previously breached passwords, and does not limit the number of failed login attempts. Even though the policy appears strong on paper, what risk remains significant?
- A. Users could still choose common, predictable, or previously compromised passwords, and accounts remain exposed to unlimited automated guessing attempts
- B. The policy is too strict and will make it impossible for any user to remember a valid password
- C. Complex passwords always take longer to type than simple ones, reducing productivity
- D. The organization will be unable to enforce the length and complexity requirements technically
Show answer & explanation
Answer: A
Meeting length and complexity rules alone does not prevent users from choosing common or previously breached passwords that technically satisfy the rules, and without a limit on failed login attempts, accounts remain exposed to automated brute-force or credential-stuffing attacks that can attempt many password guesses in succession. The claim that the policy is unenforceably strict, a general productivity concern about typing time, or a technical inability to enforce the stated rules do not reflect the actual gap in this scenario, which is the missing breach-list checking and attempt-limiting controls.158. An organization discovers that an unauthorized wireless access point, not part of its approved network infrastructure, was connected to a network jack in a conference room, potentially allowing outsiders within range to bypass perimeter controls and access the internal network. What is this unauthorized device commonly called, and what control would MOST directly help detect it?
- A. A honeypot; detected through analysis of email phishing simulation results
- B. A rogue access point; detected through periodic wireless network scanning to identify unauthorized devices broadcasting on the network
- C. A load balancer; detected through reviewing application response time metrics
- D. A proxy server; detected through reviewing physical visitor sign-in logs
Show answer & explanation
Answer: B
An unauthorized wireless access point connected to the internal network is commonly called a rogue access point, and periodic wireless network scanning that inventories devices broadcasting in range of the organization's facilities is the control most directly suited to detecting such unauthorized devices before they can be exploited. A honeypot is an intentionally deployed decoy system rather than an unauthorized device, a load balancer and a proxy server serve entirely different network functions, and neither phishing simulation results nor visitor sign-in logs would reliably surface an unauthorized wireless device.159. A security operations center subscribes to external feeds that provide up-to-date information on newly identified attack indicators, malicious IP addresses, and emerging attack techniques, and automatically correlates this information against the organization's own network traffic to flag potential matches. What is the PRIMARY benefit this integration provides?
- A. It guarantees that the organization will never experience a successful cyberattack
- B. It eliminates the need for the organization to maintain any internal security staff
- C. It enables faster identification of known threats affecting the organization by leveraging external knowledge of current attack activity
- D. It automatically negotiates lower cyber-insurance premiums with the organization's insurer
Show answer & explanation
Answer: C
Integrating external threat intelligence feeds allows a security operations center to correlate current, externally sourced knowledge of malicious indicators and attack techniques against the organization's own traffic, enabling faster identification of known threats than relying solely on internally generated data. No feed can guarantee immunity from successful attacks, internal security staff remain necessary to investigate and respond to flagged matches, and insurance premium negotiation is a separate business process unrelated to the technical function threat intelligence integration provides.
More in this family
Explore more Technology & IT Certifications
In the same family
More in this category
- ISC2 Certified in Cybersecurity (CC)Practice questions →
- Project Management Professional (PMP)Practice questions →
- Microsoft Certified: Power BI Data Analyst Associate (Exam PL-300)Practice questions →
- Salesforce Certified Platform AdministratorPractice questions →
- HashiCorp Certified: Terraform Associate (004)Practice questions →
- AWS Certified AI PractitionerPractice questions →
- AWS Certified Cloud PractitionerPractice questions →
- AWS Certified Developer - AssociatePractice questions →
- AWS Certified Solutions Architect – AssociatePractice questions →
- Microsoft Certified: Azure Administrator Associate (Exam AZ-104)Practice questions →
- Microsoft Azure AI FundamentalsPractice questions →
2026 statistics
Key facts: CISA exam
Every free resource for this exam
Get a free CISA study plan
A week-by-week plan plus new practice questions, straight to your inbox.
Official sources
Primary documents used to verify the exam details shown on this page.
- CISA Exam Content OutlineISACAisaca.org
- CISA Certification OverviewISACAisaca.org
- ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024)ISACAisaca.org
- Certification Exam Candidate GuidesISACAisaca.org
- CISA ExamISACAisaca.org
Last verified against the official exam content outline:
Frequently asked questions
How much does the CISA exam cost and how long do I have to test?
The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Once you register, your exam eligibility period is 6 months from the date of registration, so plan your study timeline to sit for the exam within that window. If you don't schedule and take the exam before the eligibility period ends, you would generally need to re-register — so it's smart to only register once you're confident you can be exam-ready within six months.
How is the CISA exam structured and what score do I need to pass?
The CISA exam consists of 150 questions and is built around 5 job practice domains, with a total testing time of 240 minutes (4 hours). To pass, you need a scaled score of 450 or higher. With 150 questions across 240 minutes, that works out to roughly 1.6 minutes per question on average — a comfortable pace that still leaves time to flag and review tougher items before you submit.
Which CISA domains should I study the most?
The five content domains are the Information Systems Auditing Process, Governance and Management of Information Technology, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. They aren't weighted equally: Domain 1 (Information Systems Auditing Process) is 18%, Domain 2 (Governance and Management of IT) is 18%, Domain 3 (IS Acquisition, Development and Implementation) is 12%, Domain 4 (IS Operations and Business Resilience) is 26%, and Domain 5 (Protection of Information Assets) is 26%. Because Domains 4 and 5 together account for 52% of the exam content, prioritizing those two areas gives you the highest return on your study time, while Domain 3 at just 12% carries the least weight.
After I pass the exam, how do I get certified and keep the credential?
Passing the exam is not the final step. Candidates have 5 years from the date of passing the exam to apply for CISA certification, so don't let that window lapse after you pass. Once certified, professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential — meaning CISA is not a one-and-done certification but requires ongoing professional education to stay active. It also helps to know the exam is current: the updated CISA exam became available on 1 August 2024 and emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices, so study from up-to-date materials aligned to that revision.