ISACA Certification

CISA — Information Systems Auditor Study Guide

62 practice questions with correct answers and detailed explanations. Use this guide to review concepts before taking the practice exam.

▶ Take Practice Exam 62 questions  ·  Free  ·  No registration

About the CISA Exam

The ISACA Information Systems Auditor (CISA) certification validates professional expertise in ISACA technologies. This study guide covers all 62 practice questions from our CISA practice test, complete with correct answers and explanations to help you understand each concept thoroughly.

Review each question and explanation below, then test yourself with the full interactive practice exam to measure your readiness.

62 Practice Questions & Answers

Q1 Easy

Which of the following best describes the primary purpose of an IS audit charter?

  • A To establish the authority, responsibility, and reporting structure for the internal audit function ✓ Correct
  • B To outline specific control procedures for each business process
  • C To document all findings discovered during the annual audit
  • D To provide detailed test procedures for compliance auditing
Explanation

An IS audit charter formally establishes the internal audit function's authority, responsibility, independence, and organizational reporting relationships. It serves as the foundational governance document for the audit department.

Q2 Medium

An auditor discovers that system change logs are being overwritten after 30 days. Which of the following risks is GREATEST?

  • A Inability to detect unauthorized changes or forensic investigation limitations ✓ Correct
  • B Reduced system performance during peak usage periods
  • C Increased storage costs due to log accumulation
  • D Difficulty in scheduling routine maintenance windows
Explanation

Insufficient log retention periods severely compromises the ability to detect unauthorized changes, investigate security incidents, and perform forensic analysis. This directly impacts audit trails and compliance with regulatory requirements.

Q3 Medium

When evaluating the effectiveness of a disaster recovery plan, which factor should receive the HIGHEST priority from an auditor?

  • A The documented recovery time objective (RTO) for critical systems
  • B The geographic distance between primary and backup data centers
  • C Evidence that recovery procedures have been tested and validated ✓ Correct
  • D The number of backup copies maintained for each database
Explanation

Testing and validation of DR procedures provide empirical evidence of actual recovery capability. Without demonstrated testing, even well-documented plans may fail when needed, making actual test results more critical than theoretical targets.

Q4 Medium

Which approach is MOST effective for an auditor to assess the control environment in a large distributed organization?

  • A Audit all locations using the same standardized checklist regardless of risk profiles
  • B Review the organization chart and conduct interviews with senior management only
  • C Use risk-based sampling to evaluate control practices across multiple locations and levels ✓ Correct
  • D Rely on management's self-assessment questionnaires without independent verification
Explanation

Risk-based sampling allows auditors to allocate resources efficiently while obtaining sufficient evidence about the control environment across diverse locations. This approach recognizes that risk varies by location and business unit, requiring tailored evaluation strategies.

Q5 Hard

An organization implements a new cloud-based SaaS application for financial reporting. Which of the following represents the GREATEST audit challenge?

  • A Increased costs associated with obtaining SOC 2 audit reports from the vendor
  • B Difficulty in training internal IT staff on cloud infrastructure administration
  • C Limited ability to audit system-generated reports due to vendor access restrictions ✓ Correct
  • D The need to update audit procedures to accommodate cloud-based controls
Explanation

With SaaS applications, auditors have limited visibility into system controls, infrastructure, and processing logic. Vendor-imposed access restrictions often prevent detailed testing, requiring auditors to heavily rely on vendor-provided audit reports and compensating controls.

Q6 Medium

During a compliance audit, an auditor identifies that user access reviews are performed quarterly but management requests they be performed semi-annually. What should the auditor do?

  • A Document the control as a significant deficiency due to the deviation from best practices
  • B Immediately require the organization to implement semi-annual reviews before issuing the audit report
  • C Assess the risk and recommend the more frequent reviews while evaluating the current quarterly process ✓ Correct
  • D Accept the current quarterly review process as adequate if management provides documented justification
Explanation

An auditor should evaluate the adequacy of the current control environment against identified risks rather than mandate a specific frequency. If the quarterly reviews are effective at detecting and preventing unauthorized access, they may be sufficient; however, the auditor should document the recommendation and risk assessment.

Q7 Medium

Which of the following provides the STRONGEST evidence for validating the effectiveness of access controls?

  • A A review of the access control policy document and user role definitions
  • B Examination of system configuration settings that define access permissions
  • C Testing actual system access by attempting to perform unauthorized functions ✓ Correct
  • D Interviews with IT personnel responsible for managing user access
Explanation

Actual testing (penetration testing or access control testing) provides the strongest evidence of effectiveness by demonstrating whether controls actually prevent unauthorized actions. Policies, configurations, and interviews provide supporting evidence but not definitive proof of functional control effectiveness.

Q8 Hard

An auditor is developing an audit plan for a newly acquired subsidiary. Which information source should provide the PRIMARY basis for determining audit scope and resource allocation?

  • A Risk assessment considering the subsidiary's assets, business criticality, and control maturity ✓ Correct
  • B The audit committee's preferences based on their prior experience with similar organizations
  • C The subsidiary's existing internal audit plan from the past three years
  • D Regulatory compliance requirements applicable to the parent organization's industry
Explanation

A comprehensive risk assessment of the newly acquired subsidiary determines where audit resources are needed most. This should evaluate the subsidiary's unique risks, asset base, business processes, and current control environment rather than relying on prior audits or parent organization preferences.

Q9 Medium

When evaluating IT governance, which of the following BEST indicates strong alignment between IT strategy and business objectives?

  • A Documented evidence that major IT initiatives support approved strategic business goals ✓ Correct
  • B Chief Information Officer reports directly to the Chief Executive Officer
  • C IT infrastructure utilizes the latest cloud technologies and virtualization platforms
  • D IT department budget equals 8% of total organizational revenue
Explanation

Alignment is evidenced by a clear linkage between IT initiatives and documented business strategy. Budget percentage, technology choices, and reporting structure may support alignment but do not directly demonstrate it. Evidence of intentional support for business objectives provides the clearest indicator.

Q10 Hard

Which is the PRIMARY limitation of relying solely on continuous auditing tools to monitor control effectiveness?

  • A The tools cannot be configured to monitor all critical business transactions in real time
  • B The tools generate excessive alerts, reducing management's ability to respond effectively
  • C Continuous auditing requires continuous involvement of auditors, increasing costs significantly
  • D They provide high-frequency data but may not capture context about control design or compensating controls ✓ Correct
Explanation

While continuous auditing tools efficiently monitor transactions and flag anomalies, they cannot independently assess whether underlying control designs are appropriate or whether other compensating controls mitigate risks. Auditor judgment and context are still essential for comprehensive evaluation.

Q11 Medium

An organization uses a third-party vendor for payroll processing. What is the MOST appropriate audit procedure to verify the completeness and accuracy of payroll data transferred to the vendor?

  • A Request the vendor to provide a certification that all transmitted data was received and processed correctly
  • B Review the vendor's service organization control (SOC) audit report for relevant controls over data processing
  • C Test the organization's validation controls before payroll data is transmitted to the vendor ✓ Correct
  • D Perform a detailed reconciliation of transmitted payroll records to source documents for a sample of pay periods
Explanation

Testing the organization's own controls over data transmission before handoff to the vendor is the most direct way to verify completeness and accuracy of the data the organization is responsible for. While SOC reports and vendor reconciliations provide additional assurance, the organization's pre-transmission controls are foundational.

Q12 Medium

In evaluating information security incident response procedures, which element is CRITICAL for an auditor to verify?

  • A Documentation of all security incidents for at least two years in a centralized incident log
  • B Integration with law enforcement agencies for all detected cybersecurity incidents
  • C A defined escalation process with clear roles, responsibilities, and communication channels ✓ Correct
  • D Assignment of incident response duties exclusively to the chief information security officer
Explanation

A clear escalation process with defined roles and responsibilities ensures incidents are handled promptly and appropriately. While incident logging is important for trend analysis, centralized governance through documented procedures is more critical for effective response. Exclusive assignment to one person creates a single point of failure.

Q13 Medium

Which situation would MOST likely indicate a need to adjust audit procedures during the planning phase?

  • A Budget for the audit engagement increases due to additional audit hours becoming available
  • B Management indicates they expect audit recommendations to result in new policy documents
  • C The audit committee requests that the auditor obtain a SOC 2 report from all major service providers
  • D Preliminary risk assessment identifies that key business processes have undergone significant system changes since the last audit ✓ Correct
Explanation

Significant system changes create new control environments and risks that require auditors to adjust procedures to adequately test new systems and controls. The other options relate to expectations, documentation, or resource availability but don't indicate changes in audit risk or scope.

Q14 Hard

When auditing an organization's business continuity plan, which finding would represent the MOST CRITICAL deficiency?

  • A The plan was last updated 18 months ago and contains some outdated contact information
  • B No documented evidence exists that the plan has been tested under realistic failure scenario conditions ✓ Correct
  • C The business continuity coordinator position has experienced three personnel changes in the past two years
  • D The plan specifies a recovery time objective but does not include specific recovery procedures for all systems
Explanation

Untested plans create significant risk because they may not work when actually needed. This represents a fundamental gap in control effectiveness. While outdated information, incomplete procedures, and staff turnover are all concerning, the absence of testing is the most critical deficiency affecting overall reliability.

Q15 Hard

An auditor discovers that database administrator (DBA) passwords are stored in a shared spreadsheet accessible to multiple IT staff members. Which risk is NOT directly addressed by this finding?

  • A Inability to trace specific actions to individual accountability in audit trails
  • B Unauthorized access to production data and potential data modification
  • C Increased likelihood of accidental database configuration errors during routine maintenance ✓ Correct
  • D Compromise of credentials through malware targeting the spreadsheet file
Explanation

While the shared password practice creates multiple security risks related to access control, data breach, accountability, and credential compromise, it does not directly increase the risk of accidental configuration errors. Accidental errors result from insufficient change management or testing procedures, not password sharing.

Q16 Medium

Which approach should an IS auditor use when evaluating the adequacy of IT resource allocation for a newly established IT help desk?

  • A Compare staffing levels and budget allocation against industry benchmarks for similar organizations
  • B Interview IT management about their opinion regarding whether current resources are sufficient
  • C Analyze help desk ticket data to identify trends in request types and resolution times over the past quarter
  • D Review service level agreements to determine whether current staffing can meet documented response time targets ✓ Correct
Explanation

Service level agreements establish defined performance targets that help desk staffing must support. Evaluating whether current resources can realistically meet these targets provides objective evidence of adequacy. Benchmarks, ticket trends, and management opinions provide supporting information but SLA alignment is the most direct measure.

Q17 Hard

An organization implements a vendor management program requiring annual risk assessments of all critical vendors. An auditor identifies that risk assessments are performed but not documented. What is the appropriate audit conclusion?

  • A The control is operating effectively because management performs the risk assessments mentally based on experience
  • B The control has a design deficiency because lack of documentation prevents verification, repeat assessments, and audit trail maintenance ✓ Correct
  • C The control is operating effectively because there is no regulatory requirement to document vendor risk assessments
  • D The control has an operating effectiveness issue because documentation was omitted this year but may be restored next year
Explanation

Lack of documentation is a design deficiency because it prevents verifying that assessments were actually performed, ensures consistency in assessment methodology, enables review by second parties, and maintains an audit trail for compliance. This is independent of regulatory requirements or whether the control functioned this year.

Q18 Medium

When an auditor plans to use the work of another internal auditor from a different department, which factor is MOST important to verify?

  • A The other auditor reports to senior management independent from the area being audited
  • B The other auditor's work is relevant to the current audit objective and the auditor's competency is appropriate for the task ✓ Correct
  • C The other auditor has successfully completed similar audit work in previous engagements
  • D The other auditor has been employed by the organization for at least two years
Explanation

Before relying on another auditor's work, the primary auditor must verify that the work is relevant to current objectives and that the other auditor possesses sufficient competency. Tenure, reporting lines, and prior experience are supporting factors but relevance and competency are the critical prerequisites.

Q19 Hard

Which of the following BEST demonstrates that an organization has established effective information classification controls?

  • A Information security training is required annually for all employees who handle classified information
  • B Employees can identify the sensitivity level of the data they work with and apply appropriate protections accordingly ✓ Correct
  • C A documented information classification policy that categorizes data by sensitivity level
  • D The organization maintains separate servers for each classification level to prevent unauthorized access
Explanation

Effectiveness is demonstrated when employees consistently understand and apply appropriate protections based on data sensitivity. While policies, training, and infrastructure controls are important components, actual employee behavior and application of protections indicates whether the control is effective in practice.

Q20 Medium

An auditor is evaluating an organization's process for approving and deploying system patches. Which of the following identifies the GREATEST risk?

  • A The patch approval process requires sign-off from both IT operations and business system owners
  • B Patches are tested in a non-production environment before deployment to production systems
  • C Patch deployment occurs automatically every Sunday evening without requiring prior approval ✓ Correct
  • D Deployment timelines vary based on patch criticality and system availability requirements
Explanation

Automatic deployment without documented approval and testing creates significant risk of introducing unstable patches, causing unplanned outages, or bypassing necessary change control procedures. While the other options involve testing, approval, and scheduled deployment, automatic application without approval represents a control deficiency.

Q21 Hard

When evaluating the organization's approach to managing privileged access, which scenario represents the STRONGEST control design?

  • A System administrators have permanent privileged access to production systems with quarterly password changes
  • B Privileged access requires just-in-time provisioning with explicit approval, automatic session recording, and automatic de-provisioning after task completion ✓ Correct
  • C Privileged accounts are created only when absolutely necessary and are reviewed annually by management
  • D Privileged access is restricted to the chief information security officer who performs all system administration tasks
Explanation

Just-in-time provisioning, approval requirements, session recording, and automatic de-provisioning represent a robust control design that limits standing privileges, ensures accountability, and provides audit trails. Permanent access, single person concentrating privileges, or infrequent reviews create greater risks.

Q22 Medium

An IS auditor identifies that the organization lacks a formal process for decommissioning retired IT assets containing sensitive data. What is the PRIMARY risk of this control deficiency?

  • A Sensitive data on retired assets could be recovered and exploited by unauthorized parties ✓ Correct
  • B The organization may incur unexpected costs when disposing of obsolete equipment
  • C The organization may violate environmental regulations regarding electronic waste disposal
  • D IT staff may spend excessive time on informal decommissioning activities instead of planned projects
Explanation

The most significant risk is unauthorized access to sensitive data remaining on retired assets. Without formal decommissioning procedures including data destruction verification, sensitive information could be recovered through forensic techniques. While costs, staff time, and environmental compliance are important, data security is the primary concern.

Q23 Medium

Which of the following is the MOST reliable indicator that management has appropriately responded to prior audit findings?

  • A Management assigns responsibility for remediation to specific individuals with documented accountability targets
  • B The audit committee discusses audit findings and management's responses during their regular meetings
  • C Management provides written explanations in the audit finding response describing their intended remediation plan
  • D Auditor verification that corrective actions have been implemented and are functioning as designed ✓ Correct
Explanation

While written responses, committee discussion, and assigned accountability are all important components of the remediation process, auditor verification that corrective actions have actually been implemented and are operating effectively provides the most reliable evidence of response adequacy.

Q24 Hard

An organization's cybersecurity team detects a significant data breach affecting customer information. Which action should the IS auditor prioritize FIRST?

  • A Support management in communicating with affected customers and regulatory authorities as required ✓ Correct
  • B Document the breach as an audit finding for inclusion in the annual audit report
  • C Assess whether the breach was caused by control deficiencies and how existing controls failed
  • D Initiate a detailed forensic investigation to determine the root cause of the breach
Explanation

In an active incident, the auditor's first priority should support management's immediate response including required notifications to customers and regulators. Forensic investigation, control assessment, and documentation are important follow-up activities but come after stabilizing the immediate situation and meeting legal obligations.

Q25 Hard

When planning substantive testing of financial transactions processed through an automated system, which factor should most influence the auditor's sample size decision?

  • A The total dollar amount of transactions processed during the audit period
  • B The acceptable level of audit risk and detected error rates in similar systems
  • C The assessed level of control risk for the relevant transaction processing controls ✓ Correct
  • D The number of transactions processed annually by the system
Explanation

Lower assessed control risk (indicating strong controls) justifies smaller sample sizes because the auditor can rely on controls to prevent or detect errors. Conversely, higher control risk requires larger samples. While transaction volume, audit risk, and dollar amounts are relevant considerations, control risk directly determines the extent of substantive testing needed.

Q26 Medium

An auditor evaluates an organization's password policy and finds that it requires 12-character passwords with complexity requirements but allows passwords to remain unchanged for 18 months. Which assessment is MOST appropriate?

  • A The policy has a design deficiency because the password change frequency does not align with security best practices ✓ Correct
  • B The policy should be rejected entirely because complexity requirements are less important than change frequency
  • C The policy is appropriate because 18-month password change intervals provide adequate security while reducing user frustration
  • D The policy is adequate because 12-character complex passwords are difficult to crack regardless of change frequency
Explanation

While complex password requirements are important, lengthy change intervals create risk of credential compromise over time. Security best practices typically recommend more frequent changes (e.g., 90 days). The combination of strong complexity requirements but weak change frequency represents a design deficiency in the overall password policy.

Q27 Hard

Which situation BEST demonstrates that an organization has achieved maturity in its IT governance framework?

  • A The organization has documented all IT policies and procedures in a centralized knowledge management system
  • B IT decisions are consistently aligned with business strategy, risks are managed proactively, and performance is regularly measured against strategic objectives ✓ Correct
  • C The Chief Information Officer has been with the organization for more than five years and has established long-term IT strategic plans
  • D The organization has implemented industry-standard IT frameworks such as ITIL and COBIT in their operations
Explanation

Mature IT governance is characterized by alignment with business strategy, proactive risk management, and continuous measurement and improvement. While documentation, stable leadership, and framework adoption support maturity, the integration of strategy, risk, and performance demonstrates actual mature governance.

Q28 Easy

Which of the following best describes the primary objective of an IS audit?

  • A To identify all software bugs and security vulnerabilities in applications
  • B To provide independent assurance that IT controls are adequate to support organizational objectives ✓ Correct
  • C To ensure the organization's IT infrastructure is the most technologically advanced
  • D To replace the internal audit function within an organization
Explanation

IS auditors provide independent, objective assurance and advice on the adequacy and effectiveness of governance, risk management, and control processes related to information systems. This is the core mission of IS auditing, not technology advancement or bug identification.

Q29 Medium

An IS auditor is reviewing a company's disaster recovery plan. Which element is MOST critical to evaluate first?

  • A Whether the plan is aligned with the organization's recovery time objectives (RTO) and recovery point objectives (RPO) ✓ Correct
  • B The specific hardware models and vendors used in the recovery site
  • C The number of backup tapes stored in the secondary location
  • D The color coding scheme used in the disaster recovery documentation
Explanation

RTO and RPO are fundamental metrics that define what the organization actually needs to recover, making them the most critical element to evaluate before assessing specific technical implementations or resources.

Q30 Medium

During a control testing engagement, an IS auditor discovers that system access logs are retained for only 30 days due to storage constraints. Which risk is MOST significant?

  • A Inability to investigate suspected fraud or security incidents occurring beyond the 30-day window ✓ Correct
  • B Difficulty in training new IT personnel on audit procedures
  • C Excessive spending on storage infrastructure
  • D Incompatibility with the organization's email retention policy
Explanation

Short log retention periods severely limit the ability to investigate incidents, detect patterns of unauthorized activity, or comply with forensic investigation requirements. This is a fundamental control weakness with significant audit and compliance implications.

Q31 Medium

An IS auditor is assessing the maturity of an organization's change management process. Which characteristic indicates a MATURE implementation?

  • A A formal change advisory board evaluates risk, schedules changes, and maintains a complete change history ✓ Correct
  • B Emergency changes bypass the approval process to minimize downtime
  • C The CIO approves all changes without documented procedures
  • D Changes are approved by the help desk before implementation
Explanation

Mature change management includes formal governance structures (CAB), documented risk assessment, scheduling controls, and comprehensive audit trails. This prevents unauthorized changes while maintaining necessary system flexibility.

Q32 Easy

Which of the following BEST describes the auditor's role in an organization with a strong IT governance framework?

  • A To replace the audit committee's oversight responsibilities
  • B To provide independent assurance that governance mechanisms are operating effectively ✓ Correct
  • C To bypass governance procedures when efficiency is threatened
  • D To make final decisions on all IT investments and resource allocation
Explanation

Even in well-governed organizations, auditors provide an independent, objective perspective on whether governance structures are functioning as designed and achieving their intended objectives.

Q33 Medium

An IS auditor reviews a company's user access provisioning process and notes that terminated employees sometimes retain system access for several weeks. What is the PRIMARY audit concern?

  • A The company is not utilizing the most modern identity management technology
  • B The access review process is consuming too many audit hours
  • C Former employees may access, modify, or exfiltrate sensitive data ✓ Correct
  • D The HR department is not communicating effectively with the IT department
Explanation

Delayed removal of terminated employee access creates a significant security and compliance risk by allowing unauthorized individuals to access systems and data. This is a fundamental segregation of duties and access control weakness.

Q34 Medium

When conducting an audit of cloud-based services, an IS auditor should prioritize evaluating which control area?

  • A The frequency of the cloud provider's executive team meetings
  • B The geographic location of the cloud provider's marketing department
  • C The cloud provider's internal organizational structure and reporting hierarchy
  • D The client's ability to monitor, audit, and verify controls within the cloud environment ✓ Correct
Explanation

In cloud environments, the organization retains responsibility for oversight, even though the cloud provider manages infrastructure. Auditors must ensure the client can effectively monitor and audit the cloud provider's controls.

Q35 Medium

An IS auditor discovers that source code changes are not consistently reviewed before deployment to production. Which risk is MOST directly impacted?

  • A Increased costs for licensing development tools
  • B Malicious or erroneous code could be deployed to production systems ✓ Correct
  • C Difficulty in scheduling regular maintenance windows
  • D Reduced morale among the systems administration team
Explanation

Code review is a critical preventive control that catches defects, security vulnerabilities, and malicious code before they reach production. Without it, organizations face significant risks from unvetted changes.

Q36 Hard

Which of the following represents the STRONGEST indicator that an organization's information security strategy is aligned with business objectives?

  • A The organization uses the most expensive security solutions available
  • B Security controls are mapped to specific business risks and regularly reassessed for relevance ✓ Correct
  • C The security team reports directly to the IT director
  • D All employees complete annual security awareness training
Explanation

True alignment means security investments and controls are justified by actual business risks and are periodically evaluated for continued relevance. This demonstrates strategic thinking beyond mere compliance or technology adoption.

Q37 Medium

An IS auditor is evaluating database access controls and notes that application service accounts have the same elevated privileges as database administrators. What is the immediate audit recommendation?

  • A Require all application developers to obtain DBA certification
  • B Increase the frequency of database backups to compensate for elevated privileges
  • C Implement role-based access control with least privilege principles for service accounts ✓ Correct
  • D Implement additional network segmentation around the database server
Explanation

Service accounts should operate with only the minimum privileges necessary for their specific functions. Granting them DBA-level access violates the principle of least privilege and creates significant audit risk.

Q38 Hard

During an audit of incident response procedures, the IS auditor discovers that major security incidents are not being formally documented or reported. Which CISA domain is MOST directly affected?

  • A Protection of Information Assets ✓ Correct
  • B Information Systems Acquisition, Development, and Implementation
  • C Monitoring and Evaluation of IS Processes
  • D IT Service Delivery and Support
Explanation

Incident documentation and reporting are fundamental controls for protecting information assets and detecting ongoing threats. Lack of documentation prevents organizations from understanding their security posture and responding appropriately to incidents.

Q39 Medium

An IS auditor is reviewing encryption standards for data in transit. Which approach BEST represents current best practices?

  • A Encrypt all data using the strongest encryption available regardless of performance impact
  • B Use encryption standards approved by relevant regulatory bodies and industry consensus ✓ Correct
  • C Leave encryption decisions to application developers without IT governance oversight
  • D Only encrypt data containing social security numbers; other data is low risk
Explanation

Best practice encryption uses standards that have been independently vetted (such as NIST-approved algorithms) and are appropriate for the organization's industry and regulatory environment. This balances security with practicality.

Q40 Medium

An IS auditor observes that the organization's business continuity plan has not been tested in three years. Which statement MOST accurately reflects the audit implication?

  • A Testing should be performed annually but is ultimately a management decision
  • B The organization has effectively managed risk through documentation alone
  • C The plan is still valid because it was well-designed in the initial assessment
  • D The plan's effectiveness cannot be verified, creating uncertainty about recovery capabilities ✓ Correct
Explanation

Untested plans are largely theoretical; testing reveals gaps, outdated contact information, changed dependencies, and feasibility issues. Without periodic testing, the organization cannot have confidence in recovery capabilities.

Q41 Hard

Which of the following is the MOST important factor when evaluating the effectiveness of an organization's IS audit charter?

  • A The charter specifies which audit tools the IS auditor must use
  • B The charter clearly establishes auditor independence and scope while receiving board-level support ✓ Correct
  • C The charter requires the IS auditor to approve all IT expenditures
  • D The charter document is longer than 20 pages
Explanation

An effective audit charter must establish independence (reporting to audit committee or board), define scope to allow comprehensive auditing, and ensure organizational backing for audit work. These elements enable auditors to function effectively.

Q42 Hard

An IS auditor is testing vendor management controls and discovers that critical system vendors are not contractually obligated to notify the organization of security breaches. Which risk is MOST significant?

  • A The organization may be unable to detect and respond promptly to breaches affecting its systems ✓ Correct
  • B The vendor may increase pricing without adequate notice to the organization
  • C The organization's audit committee may request additional audit procedures
  • D Customers of the organization may switch to competitors during vendor incidents
Explanation

Without contractual breach notification requirements, the organization may not learn of compromises in a timely manner, delaying incident response and allowing broader exposure or data exfiltration.

Q43 Hard

Which scenario represents the MOST significant weakness in an organization's application development security controls?

  • A Developers undergo security training annually
  • B Code review is performed, but security testing is deferred until after production deployment ✓ Correct
  • C The organization uses a version control system for all application code
  • D Security requirements are captured at the beginning of the development lifecycle
Explanation

Security testing must occur BEFORE production deployment when vulnerabilities can still be remediated at reasonable cost. Testing only after deployment means vulnerable code is already in the production environment.

Q44 Hard

An IS auditor reviews the organization's approach to IT risk management and notes that risks are identified but prioritization is based solely on likelihood without considering potential impact. What is the PRIMARY audit concern?

  • A The auditor cannot complete the risk assessment documentation in the required timeframe
  • B The IT director will not receive adequate support from executive management
  • C The organization's insurance provider will require additional policy modifications
  • D The organization will spend excessive resources on very likely but low-impact risks ✓ Correct
Explanation

Effective risk prioritization requires evaluating both likelihood AND impact (risk = likelihood × impact). Focusing only on likelihood can result in misallocated resources, addressing frequent low-impact issues while ignoring potentially catastrophic low-probability risks.

Q45 Medium

During an audit of system availability, the IS auditor discovers that the organization lacks a defined recovery time objective (RTO) for critical systems. Which action should the auditor take?

  • A Recommend that management establish RTOs based on business impact assessment ✓ Correct
  • B Assume a standard 24-hour RTO applies to all systems
  • C Implement RTOs based on industry benchmarks without business input
  • D Skip the availability audit until RTOs are established by another department
Explanation

RTOs must be determined by business stakeholders based on the actual impact of system unavailability to the organization. The auditor's role is to recommend establishment of these critical metrics, not to assume or impose them.

Q46 Medium

An IS auditor discovers that the organization's password policy requires passwords to be changed every 30 days but does not prevent reuse of previous passwords. What is the audit implication?

  • A The organization is implementing compensating controls adequately
  • B Password changes are occurring too frequently, causing security fatigue
  • C The password policy is aligned with current NIST guidance
  • D Users can easily return to previously compromised passwords, reducing the effectiveness of password rotation ✓ Correct
Explanation

Password reuse history prevents users from cycling back through a few passwords, making password rotation controls ineffective. Modern guidance also questions frequent mandatory rotation, but reuse prevention is essential when rotation is required.

Q47 Hard

Which of the following would be the BEST indicator that an organization's information security metrics are effective?

  • A The metrics directly correlate to business outcomes and inform management decision-making ✓ Correct
  • B The metrics track the number of security tools deployed in the environment
  • C The metrics are updated by IT staff on a monthly basis
  • D The metrics include detailed counts of all user access requests processed
Explanation

Effective metrics are outcome-focused and actionable, helping leadership understand security posture relative to business objectives. Metrics should drive decisions about resource allocation and risk management priorities.

Q48 Medium

An IS auditor is evaluating controls over privileged user access and discovers that privileged accounts are not being monitored for unusual activity. Which control objective is NOT being achieved?

  • A Assurance that only qualified individuals can perform privileged operations
  • B Identification of potential insider threats and misuse of elevated privileges ✓ Correct
  • C Documentation that privileged accounts exist and are assigned to specific individuals
  • D Detection of unauthorized access attempts
Explanation

Without monitoring privileged accounts for anomalous behavior, the organization cannot detect when those accounts are being misused or exploited. This is a critical detective control that complements access restrictions.

Q49 Hard

An IS auditor is assessing the organization's backup and recovery procedures. Which finding would MOST likely result in a high audit risk rating?

  • A Backup restoration is never tested, and the organization assumes backups are usable if they complete without error messages ✓ Correct
  • B Backups are performed daily but recovery testing is conducted only quarterly
  • C The backup process requires a manual initiation by the database administrator each evening
  • D Backups are stored on-site to ensure quick recovery during emergencies
Explanation

Untested backups often cannot be successfully restored due to corruption, format incompatibilities, missing dependencies, or changed system configurations. Assuming completeness without testing is a critical weakness.

Q50 Hard

Which of the following BEST describes how an IS auditor should approach evaluating IT governance in a newly acquired subsidiary?

  • A Assume the subsidiary's existing IT governance model is inferior and replace it immediately
  • B Perform a comprehensive assessment of the subsidiary's governance, identify gaps relative to the parent organization, and develop an integration plan ✓ Correct
  • C Allow the subsidiary to continue with its existing governance without evaluation until a crisis occurs
  • D Require the subsidiary to adopt identical governance structures regardless of its business model or risk profile
Explanation

A thoughtful approach evaluates the subsidiary's existing governance structures, understands its business context, identifies gaps that create risk, and develops a phased integration plan. This balances consolidation with respecting organizational differences.

Q51 Hard

An IS auditor reviewing a financial system discovers that compensating controls compensate for inadequate system-enforced access restrictions. Which statement MOST accurately reflects the audit assessment?

  • A Compensating controls eliminate the need for system-enforced restrictions in this environment
  • B Compensating controls may be acceptable temporarily but should be replaced with system-enforced controls over time ✓ Correct
  • C The organization should immediately implement the strongest system-enforced controls regardless of cost
  • D Compensating controls are always preferable to system-enforced controls
Explanation

Compensating controls can provide temporary risk mitigation for critical gaps, but reliance on manual, procedural controls is less reliable long-term than system-enforced controls. A remediation plan toward stronger technical controls should be established.

Q52 Medium

During an audit of IT service level agreements (SLAs), the auditor notes that SLAs lack clearly defined measurements for system uptime and performance. What is the most significant audit concern?

  • A The service provider will face excessive fines for not meeting undefined requirements
  • B Customers will receive excessive notifications about system performance
  • C Service performance cannot be objectively measured or validated against agreed standards ✓ Correct
  • D The IT department will not have sufficient budget to meet performance goals
Explanation

Without specific, measurable SLA metrics, the organization cannot objectively determine if service providers are meeting expectations or hold them accountable. This creates ambiguity and potential disputes.

Q53 Medium

An IS auditor is reviewing access controls for a financial system. Which of the following is the MOST important factor when evaluating the effectiveness of role-based access control (RBAC)?

  • A The frequency of access control reviews
  • B The complexity of the role hierarchy structure
  • C The number of roles defined in the system
  • D Whether role assignments align with job responsibilities and follow the principle of least privilege ✓ Correct
Explanation

RBAC effectiveness depends on proper alignment between assigned roles and actual job duties, combined with least privilege principles. The number of roles or hierarchy complexity alone does not ensure effective access control.

Q54 Medium

During a business continuity audit, the IS auditor discovers that the organization's disaster recovery plan has not been tested in the past 18 months. What is the PRIMARY risk associated with this finding?

  • A The plan's procedures and system configurations may no longer be valid, reducing recovery effectiveness ✓ Correct
  • B Employees will lack familiarity with emergency procedures
  • C The backup systems will require immediate replacement
  • D The organization will incur unnecessary expenses for plan maintenance
Explanation

Untested disaster recovery plans cannot be relied upon because system changes, configuration updates, and procedural improvements may have rendered the plan obsolete or ineffective. Regular testing validates that recovery procedures will actually work when needed.

Q55 Medium

An auditor is assessing the organization's information security governance structure. Which element is MOST critical for ensuring that security initiatives align with business objectives?

  • A A security steering committee with representation from business and IT leadership ✓ Correct
  • B Regular security awareness training programs for all staff
  • C A dedicated chief information security officer position
  • D Formal security policies documented in a centralized repository
Explanation

A security steering committee with cross-functional representation ensures alignment between security initiatives and business objectives through governance and decision-making authority. While a CISO, policies, and training are important, the steering committee provides the essential governance structure for alignment.

Q56 Medium

When auditing application change management controls, the IS auditor identifies that emergency changes are frequently approved after implementation rather than before. What is the GREATEST risk of this control deficiency?

  • A The organization will spend more time documenting changes in the change log
  • B IT staff morale will decrease due to additional approval requirements
  • C Unauthorized or inadequately tested changes could be deployed to production systems, compromising data integrity and availability ✓ Correct
  • D The change management tool will not have adequate storage capacity for all changes
Explanation

Post-implementation approvals bypass the essential pre-deployment review and testing controls, allowing untested changes to affect production systems and potentially cause serious operational and security issues.

Q57 Medium

An IS auditor is evaluating the organization's IT vendor management practices. Which of the following represents the BEST approach to managing risks associated with outsourced IT services?

  • A Limit the scope of outsourced services to non-critical functions only
  • B Negotiate the lowest possible service fees to minimize organizational costs
  • C Establish detailed service level agreements with defined performance metrics and remediation procedures ✓ Correct
  • D Require vendors to maintain their own internal audit function
Explanation

Well-defined SLAs with measurable metrics and clear remediation procedures provide the foundation for vendor accountability and risk management. This enables the organization to monitor performance and enforce compliance with contractual obligations.

Q58 Medium

During an audit of database security controls, the auditor discovers that database administrator (DBA) accounts can perform both development and production activities without separation. What type of control deficiency is this?

  • A Inadequate physical security controls
  • B Inadequate authentication mechanisms
  • C Lack of segregation of duties between development and production environments ✓ Correct
  • D Insufficient encryption of data in transit
Explanation

Allowing the same accounts to perform both development and production activities violates the segregation of duties principle, which is a fundamental control to prevent errors and unauthorized modifications. DBAs should have separate accounts for development and production work.

Q59 Hard

An organization implements a new cloud-based SaaS application for customer relationship management. What is the IS auditor's PRIMARY responsibility regarding audit rights in the cloud service agreement?

  • A Verify that the agreement permits the organization to conduct its own audits of the cloud environment ✓ Correct
  • B Confirm that audit permissions are limited to financial data only
  • C Request that the cloud provider disable all audit logging to reduce costs
  • D Ensure the cloud provider only allows audits conducted by external third-party firms
Explanation

The organization must retain audit rights to assess controls and compliance in the cloud environment. The SaaS agreement should explicitly permit the organization and its auditors to access necessary information and systems for audit purposes.

Q60 Hard

When evaluating IT security metrics, an auditor notes that the organization tracks the number of security incidents reported but does not measure the time elapsed before incident detection. Why is this a significant control gap?

  • A Measuring detection time requires more sophisticated tools that most organizations cannot afford
  • B The organization may be experiencing longer dwell times, during which attackers can cause additional damage before being detected ✓ Correct
  • C Time-based metrics are only relevant for organizations with external security monitoring
  • D Detection time is irrelevant because the number of incidents is the only meaningful metric
Explanation

Mean time to detect (MTTD) is a critical security metric because a longer dwell time increases the potential for attackers to expand their access and cause greater damage. Tracking only incident count without detection time provides an incomplete security posture assessment.

Q61 Easy

An IS auditor is reviewing the organization's approach to managing IT infrastructure maintenance windows. Which of the following is the BEST practice for scheduling and controlling system maintenance?

  • A Establish a formal change control process with advance scheduling, testing plans, rollback procedures, and stakeholder notification ✓ Correct
  • B Schedule all maintenance during business hours to ensure IT staff availability and monitoring
  • C Allow system administrators to schedule maintenance without formal approval as long as it is documented afterward
  • D Perform all maintenance on production systems immediately without waiting for scheduled windows
Explanation

A formal change control process with advance scheduling, documented procedures, testing, and rollback plans minimizes the risk of unintended system disruptions and ensures proper communication across the organization.

Q62 Hard

When auditing an organization's incident response program, the auditor discovers that the organization has not conducted incident response drills in the past two years. What is the PRIMARY implication of this finding?

  • A The incident response team's actual ability to execute the documented plan remains unvalidated and unknown ✓ Correct
  • B Incident response procedures have automatically become obsolete and require complete redevelopment
  • C The organization must immediately hire new incident response staff
  • D The organization is non-compliant with all regulatory requirements
Explanation

Without regular incident response drills and simulations, the organization cannot verify that its incident response plan is practical and that personnel can execute it effectively when a real incident occurs. Drills are essential for validation and team readiness.

Ready to test your knowledge?

You've reviewed all 62 questions. Take the interactive practice exam to simulate the real test environment.

▶ Start Practice Exam — Free