62 Practice Questions & Answers
Which of the following best describes the primary purpose of an IS audit charter?
-
A
To establish the authority, responsibility, and reporting structure for the internal audit function
✓ Correct
-
B
To outline specific control procedures for each business process
-
C
To document all findings discovered during the annual audit
-
D
To provide detailed test procedures for compliance auditing
Explanation
An IS audit charter formally establishes the internal audit function's authority, responsibility, independence, and organizational reporting relationships. It serves as the foundational governance document for the audit department.
An auditor discovers that system change logs are being overwritten after 30 days. Which of the following risks is GREATEST?
-
A
Inability to detect unauthorized changes or forensic investigation limitations
✓ Correct
-
B
Reduced system performance during peak usage periods
-
C
Increased storage costs due to log accumulation
-
D
Difficulty in scheduling routine maintenance windows
Explanation
Insufficient log retention periods severely compromises the ability to detect unauthorized changes, investigate security incidents, and perform forensic analysis. This directly impacts audit trails and compliance with regulatory requirements.
When evaluating the effectiveness of a disaster recovery plan, which factor should receive the HIGHEST priority from an auditor?
-
A
The documented recovery time objective (RTO) for critical systems
-
B
The geographic distance between primary and backup data centers
-
C
Evidence that recovery procedures have been tested and validated
✓ Correct
-
D
The number of backup copies maintained for each database
Explanation
Testing and validation of DR procedures provide empirical evidence of actual recovery capability. Without demonstrated testing, even well-documented plans may fail when needed, making actual test results more critical than theoretical targets.
Which approach is MOST effective for an auditor to assess the control environment in a large distributed organization?
-
A
Audit all locations using the same standardized checklist regardless of risk profiles
-
B
Review the organization chart and conduct interviews with senior management only
-
C
Use risk-based sampling to evaluate control practices across multiple locations and levels
✓ Correct
-
D
Rely on management's self-assessment questionnaires without independent verification
Explanation
Risk-based sampling allows auditors to allocate resources efficiently while obtaining sufficient evidence about the control environment across diverse locations. This approach recognizes that risk varies by location and business unit, requiring tailored evaluation strategies.
An organization implements a new cloud-based SaaS application for financial reporting. Which of the following represents the GREATEST audit challenge?
-
A
Increased costs associated with obtaining SOC 2 audit reports from the vendor
-
B
Difficulty in training internal IT staff on cloud infrastructure administration
-
C
Limited ability to audit system-generated reports due to vendor access restrictions
✓ Correct
-
D
The need to update audit procedures to accommodate cloud-based controls
Explanation
With SaaS applications, auditors have limited visibility into system controls, infrastructure, and processing logic. Vendor-imposed access restrictions often prevent detailed testing, requiring auditors to heavily rely on vendor-provided audit reports and compensating controls.
During a compliance audit, an auditor identifies that user access reviews are performed quarterly but management requests they be performed semi-annually. What should the auditor do?
-
A
Document the control as a significant deficiency due to the deviation from best practices
-
B
Immediately require the organization to implement semi-annual reviews before issuing the audit report
-
C
Assess the risk and recommend the more frequent reviews while evaluating the current quarterly process
✓ Correct
-
D
Accept the current quarterly review process as adequate if management provides documented justification
Explanation
An auditor should evaluate the adequacy of the current control environment against identified risks rather than mandate a specific frequency. If the quarterly reviews are effective at detecting and preventing unauthorized access, they may be sufficient; however, the auditor should document the recommendation and risk assessment.
Which of the following provides the STRONGEST evidence for validating the effectiveness of access controls?
-
A
A review of the access control policy document and user role definitions
-
B
Examination of system configuration settings that define access permissions
-
C
Testing actual system access by attempting to perform unauthorized functions
✓ Correct
-
D
Interviews with IT personnel responsible for managing user access
Explanation
Actual testing (penetration testing or access control testing) provides the strongest evidence of effectiveness by demonstrating whether controls actually prevent unauthorized actions. Policies, configurations, and interviews provide supporting evidence but not definitive proof of functional control effectiveness.
An auditor is developing an audit plan for a newly acquired subsidiary. Which information source should provide the PRIMARY basis for determining audit scope and resource allocation?
-
A
Risk assessment considering the subsidiary's assets, business criticality, and control maturity
✓ Correct
-
B
The audit committee's preferences based on their prior experience with similar organizations
-
C
The subsidiary's existing internal audit plan from the past three years
-
D
Regulatory compliance requirements applicable to the parent organization's industry
Explanation
A comprehensive risk assessment of the newly acquired subsidiary determines where audit resources are needed most. This should evaluate the subsidiary's unique risks, asset base, business processes, and current control environment rather than relying on prior audits or parent organization preferences.
When evaluating IT governance, which of the following BEST indicates strong alignment between IT strategy and business objectives?
-
A
Documented evidence that major IT initiatives support approved strategic business goals
✓ Correct
-
B
Chief Information Officer reports directly to the Chief Executive Officer
-
C
IT infrastructure utilizes the latest cloud technologies and virtualization platforms
-
D
IT department budget equals 8% of total organizational revenue
Explanation
Alignment is evidenced by a clear linkage between IT initiatives and documented business strategy. Budget percentage, technology choices, and reporting structure may support alignment but do not directly demonstrate it. Evidence of intentional support for business objectives provides the clearest indicator.
Which is the PRIMARY limitation of relying solely on continuous auditing tools to monitor control effectiveness?
-
A
The tools cannot be configured to monitor all critical business transactions in real time
-
B
The tools generate excessive alerts, reducing management's ability to respond effectively
-
C
Continuous auditing requires continuous involvement of auditors, increasing costs significantly
-
D
They provide high-frequency data but may not capture context about control design or compensating controls
✓ Correct
Explanation
While continuous auditing tools efficiently monitor transactions and flag anomalies, they cannot independently assess whether underlying control designs are appropriate or whether other compensating controls mitigate risks. Auditor judgment and context are still essential for comprehensive evaluation.
An organization uses a third-party vendor for payroll processing. What is the MOST appropriate audit procedure to verify the completeness and accuracy of payroll data transferred to the vendor?
-
A
Request the vendor to provide a certification that all transmitted data was received and processed correctly
-
B
Review the vendor's service organization control (SOC) audit report for relevant controls over data processing
-
C
Test the organization's validation controls before payroll data is transmitted to the vendor
✓ Correct
-
D
Perform a detailed reconciliation of transmitted payroll records to source documents for a sample of pay periods
Explanation
Testing the organization's own controls over data transmission before handoff to the vendor is the most direct way to verify completeness and accuracy of the data the organization is responsible for. While SOC reports and vendor reconciliations provide additional assurance, the organization's pre-transmission controls are foundational.
In evaluating information security incident response procedures, which element is CRITICAL for an auditor to verify?
-
A
Documentation of all security incidents for at least two years in a centralized incident log
-
B
Integration with law enforcement agencies for all detected cybersecurity incidents
-
C
A defined escalation process with clear roles, responsibilities, and communication channels
✓ Correct
-
D
Assignment of incident response duties exclusively to the chief information security officer
Explanation
A clear escalation process with defined roles and responsibilities ensures incidents are handled promptly and appropriately. While incident logging is important for trend analysis, centralized governance through documented procedures is more critical for effective response. Exclusive assignment to one person creates a single point of failure.
Which situation would MOST likely indicate a need to adjust audit procedures during the planning phase?
-
A
Budget for the audit engagement increases due to additional audit hours becoming available
-
B
Management indicates they expect audit recommendations to result in new policy documents
-
C
The audit committee requests that the auditor obtain a SOC 2 report from all major service providers
-
D
Preliminary risk assessment identifies that key business processes have undergone significant system changes since the last audit
✓ Correct
Explanation
Significant system changes create new control environments and risks that require auditors to adjust procedures to adequately test new systems and controls. The other options relate to expectations, documentation, or resource availability but don't indicate changes in audit risk or scope.
When auditing an organization's business continuity plan, which finding would represent the MOST CRITICAL deficiency?
-
A
The plan was last updated 18 months ago and contains some outdated contact information
-
B
No documented evidence exists that the plan has been tested under realistic failure scenario conditions
✓ Correct
-
C
The business continuity coordinator position has experienced three personnel changes in the past two years
-
D
The plan specifies a recovery time objective but does not include specific recovery procedures for all systems
Explanation
Untested plans create significant risk because they may not work when actually needed. This represents a fundamental gap in control effectiveness. While outdated information, incomplete procedures, and staff turnover are all concerning, the absence of testing is the most critical deficiency affecting overall reliability.
An auditor discovers that database administrator (DBA) passwords are stored in a shared spreadsheet accessible to multiple IT staff members. Which risk is NOT directly addressed by this finding?
-
A
Inability to trace specific actions to individual accountability in audit trails
-
B
Unauthorized access to production data and potential data modification
-
C
Increased likelihood of accidental database configuration errors during routine maintenance
✓ Correct
-
D
Compromise of credentials through malware targeting the spreadsheet file
Explanation
While the shared password practice creates multiple security risks related to access control, data breach, accountability, and credential compromise, it does not directly increase the risk of accidental configuration errors. Accidental errors result from insufficient change management or testing procedures, not password sharing.
Which approach should an IS auditor use when evaluating the adequacy of IT resource allocation for a newly established IT help desk?
-
A
Compare staffing levels and budget allocation against industry benchmarks for similar organizations
-
B
Interview IT management about their opinion regarding whether current resources are sufficient
-
C
Analyze help desk ticket data to identify trends in request types and resolution times over the past quarter
-
D
Review service level agreements to determine whether current staffing can meet documented response time targets
✓ Correct
Explanation
Service level agreements establish defined performance targets that help desk staffing must support. Evaluating whether current resources can realistically meet these targets provides objective evidence of adequacy. Benchmarks, ticket trends, and management opinions provide supporting information but SLA alignment is the most direct measure.
An organization implements a vendor management program requiring annual risk assessments of all critical vendors. An auditor identifies that risk assessments are performed but not documented. What is the appropriate audit conclusion?
-
A
The control is operating effectively because management performs the risk assessments mentally based on experience
-
B
The control has a design deficiency because lack of documentation prevents verification, repeat assessments, and audit trail maintenance
✓ Correct
-
C
The control is operating effectively because there is no regulatory requirement to document vendor risk assessments
-
D
The control has an operating effectiveness issue because documentation was omitted this year but may be restored next year
Explanation
Lack of documentation is a design deficiency because it prevents verifying that assessments were actually performed, ensures consistency in assessment methodology, enables review by second parties, and maintains an audit trail for compliance. This is independent of regulatory requirements or whether the control functioned this year.
When an auditor plans to use the work of another internal auditor from a different department, which factor is MOST important to verify?
-
A
The other auditor reports to senior management independent from the area being audited
-
B
The other auditor's work is relevant to the current audit objective and the auditor's competency is appropriate for the task
✓ Correct
-
C
The other auditor has successfully completed similar audit work in previous engagements
-
D
The other auditor has been employed by the organization for at least two years
Explanation
Before relying on another auditor's work, the primary auditor must verify that the work is relevant to current objectives and that the other auditor possesses sufficient competency. Tenure, reporting lines, and prior experience are supporting factors but relevance and competency are the critical prerequisites.
Which of the following BEST demonstrates that an organization has established effective information classification controls?
-
A
Information security training is required annually for all employees who handle classified information
-
B
Employees can identify the sensitivity level of the data they work with and apply appropriate protections accordingly
✓ Correct
-
C
A documented information classification policy that categorizes data by sensitivity level
-
D
The organization maintains separate servers for each classification level to prevent unauthorized access
Explanation
Effectiveness is demonstrated when employees consistently understand and apply appropriate protections based on data sensitivity. While policies, training, and infrastructure controls are important components, actual employee behavior and application of protections indicates whether the control is effective in practice.
An auditor is evaluating an organization's process for approving and deploying system patches. Which of the following identifies the GREATEST risk?
-
A
The patch approval process requires sign-off from both IT operations and business system owners
-
B
Patches are tested in a non-production environment before deployment to production systems
-
C
Patch deployment occurs automatically every Sunday evening without requiring prior approval
✓ Correct
-
D
Deployment timelines vary based on patch criticality and system availability requirements
Explanation
Automatic deployment without documented approval and testing creates significant risk of introducing unstable patches, causing unplanned outages, or bypassing necessary change control procedures. While the other options involve testing, approval, and scheduled deployment, automatic application without approval represents a control deficiency.
When evaluating the organization's approach to managing privileged access, which scenario represents the STRONGEST control design?
-
A
System administrators have permanent privileged access to production systems with quarterly password changes
-
B
Privileged access requires just-in-time provisioning with explicit approval, automatic session recording, and automatic de-provisioning after task completion
✓ Correct
-
C
Privileged accounts are created only when absolutely necessary and are reviewed annually by management
-
D
Privileged access is restricted to the chief information security officer who performs all system administration tasks
Explanation
Just-in-time provisioning, approval requirements, session recording, and automatic de-provisioning represent a robust control design that limits standing privileges, ensures accountability, and provides audit trails. Permanent access, single person concentrating privileges, or infrequent reviews create greater risks.
An IS auditor identifies that the organization lacks a formal process for decommissioning retired IT assets containing sensitive data. What is the PRIMARY risk of this control deficiency?
-
A
Sensitive data on retired assets could be recovered and exploited by unauthorized parties
✓ Correct
-
B
The organization may incur unexpected costs when disposing of obsolete equipment
-
C
The organization may violate environmental regulations regarding electronic waste disposal
-
D
IT staff may spend excessive time on informal decommissioning activities instead of planned projects
Explanation
The most significant risk is unauthorized access to sensitive data remaining on retired assets. Without formal decommissioning procedures including data destruction verification, sensitive information could be recovered through forensic techniques. While costs, staff time, and environmental compliance are important, data security is the primary concern.
Which of the following is the MOST reliable indicator that management has appropriately responded to prior audit findings?
-
A
Management assigns responsibility for remediation to specific individuals with documented accountability targets
-
B
The audit committee discusses audit findings and management's responses during their regular meetings
-
C
Management provides written explanations in the audit finding response describing their intended remediation plan
-
D
Auditor verification that corrective actions have been implemented and are functioning as designed
✓ Correct
Explanation
While written responses, committee discussion, and assigned accountability are all important components of the remediation process, auditor verification that corrective actions have actually been implemented and are operating effectively provides the most reliable evidence of response adequacy.
An organization's cybersecurity team detects a significant data breach affecting customer information. Which action should the IS auditor prioritize FIRST?
-
A
Support management in communicating with affected customers and regulatory authorities as required
✓ Correct
-
B
Document the breach as an audit finding for inclusion in the annual audit report
-
C
Assess whether the breach was caused by control deficiencies and how existing controls failed
-
D
Initiate a detailed forensic investigation to determine the root cause of the breach
Explanation
In an active incident, the auditor's first priority should support management's immediate response including required notifications to customers and regulators. Forensic investigation, control assessment, and documentation are important follow-up activities but come after stabilizing the immediate situation and meeting legal obligations.
When planning substantive testing of financial transactions processed through an automated system, which factor should most influence the auditor's sample size decision?
-
A
The total dollar amount of transactions processed during the audit period
-
B
The acceptable level of audit risk and detected error rates in similar systems
-
C
The assessed level of control risk for the relevant transaction processing controls
✓ Correct
-
D
The number of transactions processed annually by the system
Explanation
Lower assessed control risk (indicating strong controls) justifies smaller sample sizes because the auditor can rely on controls to prevent or detect errors. Conversely, higher control risk requires larger samples. While transaction volume, audit risk, and dollar amounts are relevant considerations, control risk directly determines the extent of substantive testing needed.
An auditor evaluates an organization's password policy and finds that it requires 12-character passwords with complexity requirements but allows passwords to remain unchanged for 18 months. Which assessment is MOST appropriate?
-
A
The policy has a design deficiency because the password change frequency does not align with security best practices
✓ Correct
-
B
The policy should be rejected entirely because complexity requirements are less important than change frequency
-
C
The policy is appropriate because 18-month password change intervals provide adequate security while reducing user frustration
-
D
The policy is adequate because 12-character complex passwords are difficult to crack regardless of change frequency
Explanation
While complex password requirements are important, lengthy change intervals create risk of credential compromise over time. Security best practices typically recommend more frequent changes (e.g., 90 days). The combination of strong complexity requirements but weak change frequency represents a design deficiency in the overall password policy.
Which situation BEST demonstrates that an organization has achieved maturity in its IT governance framework?
-
A
The organization has documented all IT policies and procedures in a centralized knowledge management system
-
B
IT decisions are consistently aligned with business strategy, risks are managed proactively, and performance is regularly measured against strategic objectives
✓ Correct
-
C
The Chief Information Officer has been with the organization for more than five years and has established long-term IT strategic plans
-
D
The organization has implemented industry-standard IT frameworks such as ITIL and COBIT in their operations
Explanation
Mature IT governance is characterized by alignment with business strategy, proactive risk management, and continuous measurement and improvement. While documentation, stable leadership, and framework adoption support maturity, the integration of strategy, risk, and performance demonstrates actual mature governance.
Which of the following best describes the primary objective of an IS audit?
-
A
To identify all software bugs and security vulnerabilities in applications
-
B
To provide independent assurance that IT controls are adequate to support organizational objectives
✓ Correct
-
C
To ensure the organization's IT infrastructure is the most technologically advanced
-
D
To replace the internal audit function within an organization
Explanation
IS auditors provide independent, objective assurance and advice on the adequacy and effectiveness of governance, risk management, and control processes related to information systems. This is the core mission of IS auditing, not technology advancement or bug identification.
An IS auditor is reviewing a company's disaster recovery plan. Which element is MOST critical to evaluate first?
-
A
Whether the plan is aligned with the organization's recovery time objectives (RTO) and recovery point objectives (RPO)
✓ Correct
-
B
The specific hardware models and vendors used in the recovery site
-
C
The number of backup tapes stored in the secondary location
-
D
The color coding scheme used in the disaster recovery documentation
Explanation
RTO and RPO are fundamental metrics that define what the organization actually needs to recover, making them the most critical element to evaluate before assessing specific technical implementations or resources.
During a control testing engagement, an IS auditor discovers that system access logs are retained for only 30 days due to storage constraints. Which risk is MOST significant?
-
A
Inability to investigate suspected fraud or security incidents occurring beyond the 30-day window
✓ Correct
-
B
Difficulty in training new IT personnel on audit procedures
-
C
Excessive spending on storage infrastructure
-
D
Incompatibility with the organization's email retention policy
Explanation
Short log retention periods severely limit the ability to investigate incidents, detect patterns of unauthorized activity, or comply with forensic investigation requirements. This is a fundamental control weakness with significant audit and compliance implications.
An IS auditor is assessing the maturity of an organization's change management process. Which characteristic indicates a MATURE implementation?
-
A
A formal change advisory board evaluates risk, schedules changes, and maintains a complete change history
✓ Correct
-
B
Emergency changes bypass the approval process to minimize downtime
-
C
The CIO approves all changes without documented procedures
-
D
Changes are approved by the help desk before implementation
Explanation
Mature change management includes formal governance structures (CAB), documented risk assessment, scheduling controls, and comprehensive audit trails. This prevents unauthorized changes while maintaining necessary system flexibility.
Which of the following BEST describes the auditor's role in an organization with a strong IT governance framework?
-
A
To replace the audit committee's oversight responsibilities
-
B
To provide independent assurance that governance mechanisms are operating effectively
✓ Correct
-
C
To bypass governance procedures when efficiency is threatened
-
D
To make final decisions on all IT investments and resource allocation
Explanation
Even in well-governed organizations, auditors provide an independent, objective perspective on whether governance structures are functioning as designed and achieving their intended objectives.
An IS auditor reviews a company's user access provisioning process and notes that terminated employees sometimes retain system access for several weeks. What is the PRIMARY audit concern?
-
A
The company is not utilizing the most modern identity management technology
-
B
The access review process is consuming too many audit hours
-
C
Former employees may access, modify, or exfiltrate sensitive data
✓ Correct
-
D
The HR department is not communicating effectively with the IT department
Explanation
Delayed removal of terminated employee access creates a significant security and compliance risk by allowing unauthorized individuals to access systems and data. This is a fundamental segregation of duties and access control weakness.
When conducting an audit of cloud-based services, an IS auditor should prioritize evaluating which control area?
-
A
The frequency of the cloud provider's executive team meetings
-
B
The geographic location of the cloud provider's marketing department
-
C
The cloud provider's internal organizational structure and reporting hierarchy
-
D
The client's ability to monitor, audit, and verify controls within the cloud environment
✓ Correct
Explanation
In cloud environments, the organization retains responsibility for oversight, even though the cloud provider manages infrastructure. Auditors must ensure the client can effectively monitor and audit the cloud provider's controls.
An IS auditor discovers that source code changes are not consistently reviewed before deployment to production. Which risk is MOST directly impacted?
-
A
Increased costs for licensing development tools
-
B
Malicious or erroneous code could be deployed to production systems
✓ Correct
-
C
Difficulty in scheduling regular maintenance windows
-
D
Reduced morale among the systems administration team
Explanation
Code review is a critical preventive control that catches defects, security vulnerabilities, and malicious code before they reach production. Without it, organizations face significant risks from unvetted changes.
Which of the following represents the STRONGEST indicator that an organization's information security strategy is aligned with business objectives?
-
A
The organization uses the most expensive security solutions available
-
B
Security controls are mapped to specific business risks and regularly reassessed for relevance
✓ Correct
-
C
The security team reports directly to the IT director
-
D
All employees complete annual security awareness training
Explanation
True alignment means security investments and controls are justified by actual business risks and are periodically evaluated for continued relevance. This demonstrates strategic thinking beyond mere compliance or technology adoption.
An IS auditor is evaluating database access controls and notes that application service accounts have the same elevated privileges as database administrators. What is the immediate audit recommendation?
-
A
Require all application developers to obtain DBA certification
-
B
Increase the frequency of database backups to compensate for elevated privileges
-
C
Implement role-based access control with least privilege principles for service accounts
✓ Correct
-
D
Implement additional network segmentation around the database server
Explanation
Service accounts should operate with only the minimum privileges necessary for their specific functions. Granting them DBA-level access violates the principle of least privilege and creates significant audit risk.
During an audit of incident response procedures, the IS auditor discovers that major security incidents are not being formally documented or reported. Which CISA domain is MOST directly affected?
-
A
Protection of Information Assets
✓ Correct
-
B
Information Systems Acquisition, Development, and Implementation
-
C
Monitoring and Evaluation of IS Processes
-
D
IT Service Delivery and Support
Explanation
Incident documentation and reporting are fundamental controls for protecting information assets and detecting ongoing threats. Lack of documentation prevents organizations from understanding their security posture and responding appropriately to incidents.
An IS auditor is reviewing encryption standards for data in transit. Which approach BEST represents current best practices?
-
A
Encrypt all data using the strongest encryption available regardless of performance impact
-
B
Use encryption standards approved by relevant regulatory bodies and industry consensus
✓ Correct
-
C
Leave encryption decisions to application developers without IT governance oversight
-
D
Only encrypt data containing social security numbers; other data is low risk
Explanation
Best practice encryption uses standards that have been independently vetted (such as NIST-approved algorithms) and are appropriate for the organization's industry and regulatory environment. This balances security with practicality.
An IS auditor observes that the organization's business continuity plan has not been tested in three years. Which statement MOST accurately reflects the audit implication?
-
A
Testing should be performed annually but is ultimately a management decision
-
B
The organization has effectively managed risk through documentation alone
-
C
The plan is still valid because it was well-designed in the initial assessment
-
D
The plan's effectiveness cannot be verified, creating uncertainty about recovery capabilities
✓ Correct
Explanation
Untested plans are largely theoretical; testing reveals gaps, outdated contact information, changed dependencies, and feasibility issues. Without periodic testing, the organization cannot have confidence in recovery capabilities.
Which of the following is the MOST important factor when evaluating the effectiveness of an organization's IS audit charter?
-
A
The charter specifies which audit tools the IS auditor must use
-
B
The charter clearly establishes auditor independence and scope while receiving board-level support
✓ Correct
-
C
The charter requires the IS auditor to approve all IT expenditures
-
D
The charter document is longer than 20 pages
Explanation
An effective audit charter must establish independence (reporting to audit committee or board), define scope to allow comprehensive auditing, and ensure organizational backing for audit work. These elements enable auditors to function effectively.
An IS auditor is testing vendor management controls and discovers that critical system vendors are not contractually obligated to notify the organization of security breaches. Which risk is MOST significant?
-
A
The organization may be unable to detect and respond promptly to breaches affecting its systems
✓ Correct
-
B
The vendor may increase pricing without adequate notice to the organization
-
C
The organization's audit committee may request additional audit procedures
-
D
Customers of the organization may switch to competitors during vendor incidents
Explanation
Without contractual breach notification requirements, the organization may not learn of compromises in a timely manner, delaying incident response and allowing broader exposure or data exfiltration.
Which scenario represents the MOST significant weakness in an organization's application development security controls?
-
A
Developers undergo security training annually
-
B
Code review is performed, but security testing is deferred until after production deployment
✓ Correct
-
C
The organization uses a version control system for all application code
-
D
Security requirements are captured at the beginning of the development lifecycle
Explanation
Security testing must occur BEFORE production deployment when vulnerabilities can still be remediated at reasonable cost. Testing only after deployment means vulnerable code is already in the production environment.
An IS auditor reviews the organization's approach to IT risk management and notes that risks are identified but prioritization is based solely on likelihood without considering potential impact. What is the PRIMARY audit concern?
-
A
The auditor cannot complete the risk assessment documentation in the required timeframe
-
B
The IT director will not receive adequate support from executive management
-
C
The organization's insurance provider will require additional policy modifications
-
D
The organization will spend excessive resources on very likely but low-impact risks
✓ Correct
Explanation
Effective risk prioritization requires evaluating both likelihood AND impact (risk = likelihood × impact). Focusing only on likelihood can result in misallocated resources, addressing frequent low-impact issues while ignoring potentially catastrophic low-probability risks.
During an audit of system availability, the IS auditor discovers that the organization lacks a defined recovery time objective (RTO) for critical systems. Which action should the auditor take?
-
A
Recommend that management establish RTOs based on business impact assessment
✓ Correct
-
B
Assume a standard 24-hour RTO applies to all systems
-
C
Implement RTOs based on industry benchmarks without business input
-
D
Skip the availability audit until RTOs are established by another department
Explanation
RTOs must be determined by business stakeholders based on the actual impact of system unavailability to the organization. The auditor's role is to recommend establishment of these critical metrics, not to assume or impose them.
An IS auditor discovers that the organization's password policy requires passwords to be changed every 30 days but does not prevent reuse of previous passwords. What is the audit implication?
-
A
The organization is implementing compensating controls adequately
-
B
Password changes are occurring too frequently, causing security fatigue
-
C
The password policy is aligned with current NIST guidance
-
D
Users can easily return to previously compromised passwords, reducing the effectiveness of password rotation
✓ Correct
Explanation
Password reuse history prevents users from cycling back through a few passwords, making password rotation controls ineffective. Modern guidance also questions frequent mandatory rotation, but reuse prevention is essential when rotation is required.
Which of the following would be the BEST indicator that an organization's information security metrics are effective?
-
A
The metrics directly correlate to business outcomes and inform management decision-making
✓ Correct
-
B
The metrics track the number of security tools deployed in the environment
-
C
The metrics are updated by IT staff on a monthly basis
-
D
The metrics include detailed counts of all user access requests processed
Explanation
Effective metrics are outcome-focused and actionable, helping leadership understand security posture relative to business objectives. Metrics should drive decisions about resource allocation and risk management priorities.
An IS auditor is evaluating controls over privileged user access and discovers that privileged accounts are not being monitored for unusual activity. Which control objective is NOT being achieved?
-
A
Assurance that only qualified individuals can perform privileged operations
-
B
Identification of potential insider threats and misuse of elevated privileges
✓ Correct
-
C
Documentation that privileged accounts exist and are assigned to specific individuals
-
D
Detection of unauthorized access attempts
Explanation
Without monitoring privileged accounts for anomalous behavior, the organization cannot detect when those accounts are being misused or exploited. This is a critical detective control that complements access restrictions.
An IS auditor is assessing the organization's backup and recovery procedures. Which finding would MOST likely result in a high audit risk rating?
-
A
Backup restoration is never tested, and the organization assumes backups are usable if they complete without error messages
✓ Correct
-
B
Backups are performed daily but recovery testing is conducted only quarterly
-
C
The backup process requires a manual initiation by the database administrator each evening
-
D
Backups are stored on-site to ensure quick recovery during emergencies
Explanation
Untested backups often cannot be successfully restored due to corruption, format incompatibilities, missing dependencies, or changed system configurations. Assuming completeness without testing is a critical weakness.
Which of the following BEST describes how an IS auditor should approach evaluating IT governance in a newly acquired subsidiary?
-
A
Assume the subsidiary's existing IT governance model is inferior and replace it immediately
-
B
Perform a comprehensive assessment of the subsidiary's governance, identify gaps relative to the parent organization, and develop an integration plan
✓ Correct
-
C
Allow the subsidiary to continue with its existing governance without evaluation until a crisis occurs
-
D
Require the subsidiary to adopt identical governance structures regardless of its business model or risk profile
Explanation
A thoughtful approach evaluates the subsidiary's existing governance structures, understands its business context, identifies gaps that create risk, and develops a phased integration plan. This balances consolidation with respecting organizational differences.
An IS auditor reviewing a financial system discovers that compensating controls compensate for inadequate system-enforced access restrictions. Which statement MOST accurately reflects the audit assessment?
-
A
Compensating controls eliminate the need for system-enforced restrictions in this environment
-
B
Compensating controls may be acceptable temporarily but should be replaced with system-enforced controls over time
✓ Correct
-
C
The organization should immediately implement the strongest system-enforced controls regardless of cost
-
D
Compensating controls are always preferable to system-enforced controls
Explanation
Compensating controls can provide temporary risk mitigation for critical gaps, but reliance on manual, procedural controls is less reliable long-term than system-enforced controls. A remediation plan toward stronger technical controls should be established.
During an audit of IT service level agreements (SLAs), the auditor notes that SLAs lack clearly defined measurements for system uptime and performance. What is the most significant audit concern?
-
A
The service provider will face excessive fines for not meeting undefined requirements
-
B
Customers will receive excessive notifications about system performance
-
C
Service performance cannot be objectively measured or validated against agreed standards
✓ Correct
-
D
The IT department will not have sufficient budget to meet performance goals
Explanation
Without specific, measurable SLA metrics, the organization cannot objectively determine if service providers are meeting expectations or hold them accountable. This creates ambiguity and potential disputes.
An IS auditor is reviewing access controls for a financial system. Which of the following is the MOST important factor when evaluating the effectiveness of role-based access control (RBAC)?
-
A
The frequency of access control reviews
-
B
The complexity of the role hierarchy structure
-
C
The number of roles defined in the system
-
D
Whether role assignments align with job responsibilities and follow the principle of least privilege
✓ Correct
Explanation
RBAC effectiveness depends on proper alignment between assigned roles and actual job duties, combined with least privilege principles. The number of roles or hierarchy complexity alone does not ensure effective access control.
During a business continuity audit, the IS auditor discovers that the organization's disaster recovery plan has not been tested in the past 18 months. What is the PRIMARY risk associated with this finding?
-
A
The plan's procedures and system configurations may no longer be valid, reducing recovery effectiveness
✓ Correct
-
B
Employees will lack familiarity with emergency procedures
-
C
The backup systems will require immediate replacement
-
D
The organization will incur unnecessary expenses for plan maintenance
Explanation
Untested disaster recovery plans cannot be relied upon because system changes, configuration updates, and procedural improvements may have rendered the plan obsolete or ineffective. Regular testing validates that recovery procedures will actually work when needed.
An auditor is assessing the organization's information security governance structure. Which element is MOST critical for ensuring that security initiatives align with business objectives?
-
A
A security steering committee with representation from business and IT leadership
✓ Correct
-
B
Regular security awareness training programs for all staff
-
C
A dedicated chief information security officer position
-
D
Formal security policies documented in a centralized repository
Explanation
A security steering committee with cross-functional representation ensures alignment between security initiatives and business objectives through governance and decision-making authority. While a CISO, policies, and training are important, the steering committee provides the essential governance structure for alignment.
When auditing application change management controls, the IS auditor identifies that emergency changes are frequently approved after implementation rather than before. What is the GREATEST risk of this control deficiency?
-
A
The organization will spend more time documenting changes in the change log
-
B
IT staff morale will decrease due to additional approval requirements
-
C
Unauthorized or inadequately tested changes could be deployed to production systems, compromising data integrity and availability
✓ Correct
-
D
The change management tool will not have adequate storage capacity for all changes
Explanation
Post-implementation approvals bypass the essential pre-deployment review and testing controls, allowing untested changes to affect production systems and potentially cause serious operational and security issues.
An IS auditor is evaluating the organization's IT vendor management practices. Which of the following represents the BEST approach to managing risks associated with outsourced IT services?
-
A
Limit the scope of outsourced services to non-critical functions only
-
B
Negotiate the lowest possible service fees to minimize organizational costs
-
C
Establish detailed service level agreements with defined performance metrics and remediation procedures
✓ Correct
-
D
Require vendors to maintain their own internal audit function
Explanation
Well-defined SLAs with measurable metrics and clear remediation procedures provide the foundation for vendor accountability and risk management. This enables the organization to monitor performance and enforce compliance with contractual obligations.
During an audit of database security controls, the auditor discovers that database administrator (DBA) accounts can perform both development and production activities without separation. What type of control deficiency is this?
-
A
Inadequate physical security controls
-
B
Inadequate authentication mechanisms
-
C
Lack of segregation of duties between development and production environments
✓ Correct
-
D
Insufficient encryption of data in transit
Explanation
Allowing the same accounts to perform both development and production activities violates the segregation of duties principle, which is a fundamental control to prevent errors and unauthorized modifications. DBAs should have separate accounts for development and production work.
An organization implements a new cloud-based SaaS application for customer relationship management. What is the IS auditor's PRIMARY responsibility regarding audit rights in the cloud service agreement?
-
A
Verify that the agreement permits the organization to conduct its own audits of the cloud environment
✓ Correct
-
B
Confirm that audit permissions are limited to financial data only
-
C
Request that the cloud provider disable all audit logging to reduce costs
-
D
Ensure the cloud provider only allows audits conducted by external third-party firms
Explanation
The organization must retain audit rights to assess controls and compliance in the cloud environment. The SaaS agreement should explicitly permit the organization and its auditors to access necessary information and systems for audit purposes.
When evaluating IT security metrics, an auditor notes that the organization tracks the number of security incidents reported but does not measure the time elapsed before incident detection. Why is this a significant control gap?
-
A
Measuring detection time requires more sophisticated tools that most organizations cannot afford
-
B
The organization may be experiencing longer dwell times, during which attackers can cause additional damage before being detected
✓ Correct
-
C
Time-based metrics are only relevant for organizations with external security monitoring
-
D
Detection time is irrelevant because the number of incidents is the only meaningful metric
Explanation
Mean time to detect (MTTD) is a critical security metric because a longer dwell time increases the potential for attackers to expand their access and cause greater damage. Tracking only incident count without detection time provides an incomplete security posture assessment.
An IS auditor is reviewing the organization's approach to managing IT infrastructure maintenance windows. Which of the following is the BEST practice for scheduling and controlling system maintenance?
-
A
Establish a formal change control process with advance scheduling, testing plans, rollback procedures, and stakeholder notification
✓ Correct
-
B
Schedule all maintenance during business hours to ensure IT staff availability and monitoring
-
C
Allow system administrators to schedule maintenance without formal approval as long as it is documented afterward
-
D
Perform all maintenance on production systems immediately without waiting for scheduled windows
Explanation
A formal change control process with advance scheduling, documented procedures, testing, and rollback plans minimizes the risk of unintended system disruptions and ensures proper communication across the organization.
When auditing an organization's incident response program, the auditor discovers that the organization has not conducted incident response drills in the past two years. What is the PRIMARY implication of this finding?
-
A
The incident response team's actual ability to execute the documented plan remains unvalidated and unknown
✓ Correct
-
B
Incident response procedures have automatically become obsolete and require complete redevelopment
-
C
The organization must immediately hire new incident response staff
-
D
The organization is non-compliant with all regulatory requirements
Explanation
Without regular incident response drills and simulations, the organization cannot verify that its incident response plan is practical and that personnel can execute it effectively when a real incident occurs. Drills are essential for validation and team readiness.