Skip to main content

CISA Real Exam Questions

Certified Information Systems Auditor

1,641 questions available · Page 1 of 165

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

During an IT general controls audit of a high-risk area where both internal and external audit teams are reviewing the same approach to optimize resources?

  1. A

    Leverage the work performed by external audit for the internal audit testing.

  2. B

    Ensure both the internal and external auditors perform the work simultaneously.

  3. C

    Request that the external audit team leverage the internal audit work.

  4. D

    Roll forward the general controls audit to the subsequent audit year.

Show answer and explanation

Correct answer: A

Explanation

The best approach to optimize resources when both internal and external audit teams are reviewing the same IT general controls area is to leverage the work performed by external audit for the internal audit testing. This can avoid duplication of efforts, reduce audit costs and enhance coordination between the audit teams. The internal audit team should evaluate the quality and reliability of the external audit work before relying on it. Ensuring both the internal and external auditors perform the work simultaneously is not an efficient use of resources, as it would create redundancy and possible interference. Requesting that the external audit team leverage the internal audit work may not be feasible or acceptable, as the external audit team may have different objectives, standards and independence requirements. Rolling forward the general controls audit to the subsequent audit year is not a good practice, as it would delay the identification and remediation of any control weaknesses in a high-risk area.

References:
ISACA, CISA Review Manual, 27th Edition, 2018, page 247

Question 2 Single choice

A manager Identifies active privileged accounts belonging to staff who have left the organization.

Which of the following is the threat actor In this scenario?

  1. A

    Terminated staff

  2. B

    Unauthorized access

  3. C

    Deleted log data

  4. D

    Hacktivists

Show answer and explanation

Correct answer: A

Explanation

A threat actor is an entity or individual that poses a potential harm or danger to an organization's information systems or data. Terminated staff are the threat actors in this scenario, as they are former employees who may still have active privileged accounts that grant them access to sensitive or critical information or resources of the organization. Terminated staff may abuse their access privileges or credentials to compromise the confidentiality, integrity, or availability of the information systems or data, either intentionally or unintentionally. Unauthorized access is a threat event or action that occurs when an unauthorized entity or individual gains access to an organization's information systems or data without permission or authorization. Unauthorized access is not a threat actor, but rather a result of a threat actor's activity. Deleted log data is a threat consequence or impact that occurs when log data, which are records of events or activities that occur on an information system or network, are erased or corrupted by a threat actor. Deleted log data can affect the auditability, accountability, and visibility of the information system or network, and prevent detection or investigation of security incidents. Deleted log data is not a threat actor, but rather a result of a threat actor's activity. Hacktivists are threat actors who use hacking techniques to promote a political or social cause or agenda. Hacktivists are not the threat actors in this scenario, as there is no indication that they are involved in this case.

Question 3 Single choice

Which of the following will invalidate the authenticity of digital evidence in a forensic investigation?

  1. A

    The investigator installed forensic software on the original drive that contained the evidence.

  2. B

    A software write blocker was used in the collection of the evidence.

  3. C

    The investigator collected the evidence while the machine was still powered on.

  4. D

    The evidence was collected from analysis of a copy of the disk data.

Show answer and explanation

Correct answer: A

Question 4 Single choice

Which of the following should an IS auditor review when evaluating information systems governance for a large organization?

  1. A

    Approval processes for new system implementations

  2. B

    Procedures for adding a new user to the invoice processing system

  3. C

    Approval processes for updating the corporate website

  4. D

    Procedures for regression testing system changes

Show answer and explanation

Correct answer: A

Explanation

Information systems governance is the set of policies, processes, structures, and practices that ensure the alignment of IT with business objectives, the delivery of value from IT investments, the management of IT risks, and the optimization of IT resources 1. Information systems governance is a strategic and high-level function that covers the entire organization and its IT portfolio. Therefore, an IS auditor should review the aspects of information systems governance that are relevant to the organization's vision, mission, goals, and strategies.

One of the aspects that an IS auditor should review when evaluating information systems governance for a large organization is the approval processes for new system implementations. This is because new system implementations are significant IT investments that require careful planning, analysis, design,development, testing, deployment, and evaluation to ensure that they meet the business requirements, deliver the expected benefits, comply with the relevant standards and regulations, and minimize the potential risks 2. The approval processes fornew system implementations should involve the appropriate stakeholders, such as senior management, business owners, IT managers,project managers, users, and auditors, who have the authority and responsibility to approve or reject the proposed system implementations based on predefined criteria and metrics 3. The approval processes for new system implementations should also be documented, transparent, consistent, and timely to ensure accountability and traceability 4. Therefore, an IS auditor should review the approval processes for new system implementations to assess whether they are aligned with the information systems governance framework and objectives.

The other possible options are: Procedures for adding a new user to the invoice processing system: This is an operational task that involves granting access rights and permissions to a specific user for a specific system based on the principle of least privilege. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.

Approval processes for updating the corporate website: This is a tactical task that involves making changes or enhancements to the content or design of the corporate website based on the business needs and feedback. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.

Procedures for regression testing system changes: This is a technical task that involves verifying that existing system functionalities are not adversely affected by new system changes or updates. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.

References:
1: What is IT Governance? - Definition from Techopedia
2: System Implementation - an overview | ScienceDirect Topics
3: Project Approval Process - Project Management Knowledge
4: 5
Best Practices For A Successful Project Approval Process | Kissflow Project: Principle of Least Privilege (POLP) | Imperva: How to Update Your Website Content - 7
Step Guide | HostGator Blog: What Is Regression Testing? Definition and Best Practices | BrowserStack

Question 5 Single choice

Which of the following applications has the MOST inherent risk and should be prioritized during audit planning?

  1. A

    A decommissioned legacy application

  2. B

    An onsite application that is unsupported

  3. C

    An outsourced accounting application

  4. D

    An internally developed application

Show answer and explanation

Correct answer: C

Explanation

An outsourced accounting application has the most inherent risk and should be prioritized during audit planning because it involves external parties, sensitive data, and complex transactions that are susceptible to material misstatement, error, or fraud 12. An outsourced accounting application also requires more oversight and monitoring from the internal audit department to ensure compliance with the service level agreement and the organization's policies and standards 3.

References:
1: Inherent Risk: Definition, Examples, and 3 Types of Audit Risks
2: 3 Types of Audit Risk - Inherent, Control and Detection - Accountinguide
3: IS Audit Basics: The Core of IT Auditing

Question 6 Single choice

Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?

  1. A

    Conduct a data inventory and classification exercise.

  2. B

    Identify approved data workflows across the enterprise_

  3. C

    Conduct a threat analysis against sensitive data usage.

  4. D

    Create the DLP policies and templates

Show answer and explanation

Correct answer: A

Explanation

The first step when developing a DLP solution for a large organization is to conduct a data inventory and classification exercise. This step involves identifying and locating all the data assets that the organization owns, generates, or handles, and assigning them to different categories based on their sensitivity, value, and regulatory requirements 1. Data inventory and classification is essential for DLP because it helps to determine the scope and objectives of the DLP solution, as well as the appropriate level of protection and monitoring for each data category 2. Data inventory and classification also enables the organization to prioritize its DLP efforts based on the risk and impact of data loss or leakage 3.

Option B is not correct because identifying approved data workflows across the enterprise is a subsequent step after conducting data inventory and classification. Data workflows are the processes and channels through which data are created, stored, accessed, shared, or transmitted within or outside the organization 4. Identifying approved data workflows helps to define the normal and legitimate use of data, as well as to detect and prevent unauthorized or anomalous data activities 5. However, before identifying approved data workflows, the organization needs to know what data it has and how it should be classified.

Option C is not correct because conducting a threat analysis against sensitive data usage is another subsequent step after conducting data inventory and classification. Threat analysis is the process of identifying and assessing the potential sources, methods, and impacts of data loss or leakage incidents. Threat analysis helps to design and implement effective DLP controls and countermeasures based on the risk profile of each data category. However, before conducting threat analysis, the organization needs to know what data it has and how it should be classified.

Option D is not correct because creating the DLP policies and templates is the final step after conducting data inventory and classification, identifying approved data workflows, and conducting threat analysis. DLP policies and templates are the rules and configurations that specify how the DLP solution should monitor, detect, report, and respond to data loss or leakage events. DLP policies and templates should be aligned with the organization's business needs, regulatory obligations, and risk appetite. However, before creating the DLP policies and templates, the organization needs to know what data it has, how it should be classified, how it should be used, and what threats it faces.

References:
Data Inventory and Classification: The First Step in Data Protection1
Data Classification: What It Is And Why You Need It2
How to Prioritize Your Data Loss Prevention Strategy in 20203
What Is Data Workflow? Definition and Examples4
How to Identify Data Workflows for Your Business5
Threat Analysis: A Comprehensive Guide for Beginners
How to Conduct a Threat Assessment for Your Business What Is Data Loss Prevention (DLP)? Definition and Examples
How to Create Effective Data Loss Prevention Policies

Question 7 Single choice

Which of the following is necessary for effective risk management in IT governance?

  1. A

    Local managers are solely responsible for risk evaluation.

  2. B

    IT risk management is separate from corporate risk management.

  3. C

    Risk management strategy is approved by the audit committee.

  4. D

    Risk evaluation is embedded in management processes.

Show answer and explanation

Correct answer: D

Explanation

The necessary condition for effective risk management in IT governance is that risk evaluation is embedded in management processes. Risk evaluation is the process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. Risk evaluation should be integrated into the management processes of planning, implementing, monitoring, and reviewing the IT activities and resources. This will ensure that risk management is aligned with the business objectives, strategies, and values, and that risk responses are timely, appropriate, and effective.

References:
CISA Review Manual (Digital Version)
CISA Questions, Answers and ExplanationsDatabase

Question 8 Single choice

A finance department has a multi-year project to upgrade the enterprise resource planning (ERP) system hosting the general ledger. and in year one, the system version upgrade will be applied.

Which of the following should be the PRIMARY focus of the IS auditor reviewing the first year of the project?

  1. A

    unit testing

  2. B

    Network performance

  3. C

    User acceptance testing (UAT)

  4. D

    Regression testing

Show answer and explanation

Correct answer: D

Explanation

The primary focus of the IS auditor reviewing the first year of the project should be regression testing. Regression testing is a type of testing that ensures that the existing functionality of the system is not affected by the changes or upgrades made to the system. Since the project involves upgrading the ERP system hosting the general ledger, which is a critical and complex component of the finance department, it is important to verify that the upgrade does not introduce any errors or defects that could compromise the accuracy, completeness, and reliability of the financial data and reports. Regression testing can help identify and resolve any issues before they affect the users and the business processes.

Unit testing, network performance, and user acceptance testing (UAT) are also important aspects of the project, but they are not the primary focus of the IS auditor in the first year. Unit testing is a type of testing that verifies that each individual module or component of the system works as expected. Network performance is a measure of how well the system can communicate and exchange data with other systems and devices over a network. User acceptance testing (UAT) is a type of testing that validates that the system meets the user requirements and expectations. These aspects are more relevant in later stages of the project, when the system is more developed and ready for deployment.

References:
ERP Upgrade: The Path to Modernization | SAP
ERP System Validation: Your Guide To Successfully Validating ERP Systems
The role of internal auditors in ERP#based organizations.
What is Regression Testing? Definition, Tools and Examples.
What is Unit Testing? Definition, Tools and Examples.
What is Network Performance? Definition, Metrics and Examples.
What is User Acceptance Testing (UAT)? Definition, Process and Examples

Question 9 Single choice

An IS auditor is reviewing a data conversion project

Which of the following is the auditor ' s BEST recommendation prior to go-live?

  1. A

    Review test procedures and scenarios

  2. B

    Conduct a mock conversion test

  3. C

    Establish a configuration baseline

  4. D

    Automate the test scripts

Show answer and explanation

Correct answer: B

Explanation

The auditor's best recommendation prior to go-live is to conduct a mock conversion test. This is because a mock conversion test can help to verify the accuracy, completeness, and validity of the data conversion process. A mock conversion test can also help to identify and resolve any issues or errors before the actual conversion takes place. A mock conversion test can also provide assurance that the converted data meets the business requirements and expectations.

References:
CISA Review Manual (Digital Version), Chapter 3, Section 3.3.21
CISAOnline Review Course, Domain 2, Module 2, Lesson 22

Question 10 Single choice

Which of the following is the GREATEST concern related to an organization ' s data classification processes?

  1. A

    Users responsible for managing records are unaware of the data classification processes.

  2. B

    Systems used to manage the data classification processes are not synchronized.

  3. C

    The data classification processes have not been updated in the last year.

  4. D

    The data classification processes are not aligned with industry standards.

Show answer and explanation

Correct answer: A