CISA — Frequently Asked Questions

Community-vetted answers to 207 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

When to First Communicate Audit Observations

While formal findings are discussed then, 'first' communication implies the initial sharing of observations, which occurs continuously during fieldwork to allow for immediate fact-checking and issue resolution.

It primarily refers to informal or preliminary communication of observations as they arise, ensuring accuracy before the formal report is drafted.

Event Log Aggregation System Risk Management

Encryption protects data at rest/transit, but if logs are incomplete, you cannot detect breaches or meet compliance. Integrity/availability is the primary goal of logging.

Batch processing can introduce latency but does not inherently compromise integrity. It is a design choice, whereas missing logs (incompleteness) is a critical control failure.

Document Owner Role in Data Classification Policy

Classification is a task; the owner's role is governance. They must ensure that once classified, the document is actually protected and handled correctly.

While owners enforce them, the conditions are typically defined by the data classification policy itself or senior management, not solely by the individual document owner.

Ensuring Project Plan Adherence in IS Auditing

Design reviews check technical specs, not overall project plan adherence like schedule or budget.

No, it compromises independence as they become part of the operational quality assurance process.

Auditor Next Step After Release-Related Production Incident

Incident management handles response and recovery, but the question explicitly ties the defect to a recent release. Auditors prioritize tracing the root cause to change controls for prevention.

Yes. CISA classifies requirement analysis, code review, user acceptance testing, and deployment approvals under the change management lifecycle, making it the correct audit focus here.

Which Risk Type Most Influences Sampling Methodology?

Inherent risk describes natural vulnerability before controls, but it does not directly dictate sampling mechanics. Auditors use sampling to manage detection risk, making it the direct driver for methodology selection.

Acceptable detection risk inversely determines sample size. Lower acceptable detection risk requires larger samples and more rigorous selection methods to ensure material misstatements are caught.

What Is the Most Important Action Before an Application Data Protection Audit?

Threat assessment informs risk analysis, but you cannot evaluate threats effectively until the audit’s specific goals and boundaries are formally defined.

Penetration testing is a validation technique executed during the fieldwork phase, only after planning, scoping, and control objectives are approved.

Greatest Risk in Cloud SaaS Data Backup and Retrieval?

RTO measures system uptime duration, not data recoverability. If backups fail completely, timing metrics become irrelevant to the organization's survival.

Auditors rely on independent SOC 2 Type II reports, verified SLAs, and periodic restoration testing rather than physical data center inspections.

How to Understand Risk Reduction in CISA Assessments?

Residual risk only shows the remaining exposure after treatments. It represents the outcome, not the actual methods used to achieve reduction.

Mitigation efforts cover the full range of risk treatment actions and strategies. Control effectiveness narrowly measures whether a single control operates as designed.

Which Sampling Method Deems a Sample Irregular After One Error?

Stop-or-go sampling uses sequential testing to accept or reject a population based on preset risk levels, not to instantly invalidate the entire sample upon one error.

Use it when the audit objective is detecting rare events like fraud or critical control failures, where even one occurrence signals a material population issue.

Which Interface Feature Ensures Funds Reach the Correct Bank?

Nonrepudiation is a business outcome, not a technical feature. Digital signatures are the actual control that enforces nonrepudiation while validating the destination account.

They bind the exact transaction data to the sender’s private key, detecting any alterations to the beneficiary account number during transmission.

Greatest Concern in Outsourced Payroll Audit

Access reviews protect data confidentiality, but without a legally valid contract, you have no enforceable right to demand those reviews or audit the vendor.

C is an internal policy violation, while D is a fundamental legal exposure. Legal review ensures the contract is enforceable and compliant with laws, which is prerequisite for any reliance.

Environmental Detector Placement Risks in Data Centers

Duct smoke detectors are a standard, code-compliant requirement for early air-stream contamination warning and are actively monitored by building management systems.

Raised floors allow direct visual inspection and targeted leak detection, whereas overhead plenums hide cables and enable rapid horizontal fire spread before alarms trigger.

How to Ensure Cyber Crime Computer Evidence Is Admissible in Court?

Immediate shutdown risks losing volatile RAM data and does not establish legal admissibility. Courts require documented chain of custody rather than just physical preservation.

Law enforcement handles investigations, but the auditor must still document every handover. Without tracked possession, evidence becomes inadmissible regardless of police involvement.

Greatest Fraud Risk: Mandatory Leave vs Access Reviews

Mandatory leave forces a handover where others perform duties, often revealing hidden fraud. Access reviews check permissions but don't necessarily detect ongoing illicit transactions.

It indicates poor change management and potential security breaches, but it is not a direct indicator of financial fraud unless linked to data theft or manipulation.

Mitigating SaaS Provider Bankruptcy Risk

Escrow requires sharing source code, which SaaS vendors never provide to subscribers. Customers only license usage rights, making escrow legally and technically unfeasible.

No. SLAs define uptime and performance targets during normal operations but cannot enforce service delivery once a company ceases financial existence.

Next Step When Periodic Access Reviews Are Missing | CISA

Audits prioritize process validation over individual data checks. Confirming documented approvals addresses the systemic control gap directly.

Only if properly governed and risk-assessed. The auditor must verify written authorization exists before classifying the gap as a deficiency.

How to Verify Inter-System Transaction Completeness?

Aggregate reconciliation only verifies mathematical balance, allowing individual missing or duplicated transactions to mask discrepancies. Direct tracing catches these gaps at the record level.

Sampling is acceptable when populations are large, provided the statistical method targets high-risk transfers. Full population testing is ideal but often impractical in live environments.

What Should an Outsourcing Contract Always Include?

Contractors often treat specific security procedures as proprietary or subject to rapid change. Mandating audits verifies compliance with standards without exposing sensitive IP or requiring constant updates.

Staffing details are operational and prone to turnover, making them unsuitable for fixed contractual mandates. Focus instead on competency requirements and audit rights to ensure quality delivery.

Which Network Access Poses the Highest Risk in a CISA Review?

Firewalls are standard protective layers designed to filter internet traffic. Without qualifiers like 'unrestricted,' they represent normal architecture, not a vulnerability.

No. Routers manage traffic routing and typically sit behind firewalls. Direct PC access bypasses all intermediate controls, enabling malware spread and data exfiltration.

Most Important Process in a Data Classification Policy?

Access auditing supports enforcement but falls under access control policies. Classification specifically mandates handling and destruction rules.

Each classification tier dictates specific sanitization techniques, ensuring sensitive data meets regulatory destruction standards before retirement.

Greatest Concern in Unsuccessful DR Test

Root cause analysis improves future tests, but if procedures are outdated, the current test is invalid and the organization remains at risk.

No, testing during non-peak hours is a best practice to minimize disruption and is not a concern regarding the test's success or failure.

Best Backup Scheme for Rapid Data Restoration?

Incremental requires restoring the full backup plus every subsequent incremental file sequentially, whereas differential only needs the full backup and the latest differential file.

Mirror backup suits real-time disaster recovery where zero RPO is critical, but differential remains better for auditable, scheduled backups that balance storage costs with acceptable recovery times.

What Should an IS Auditor Do Next After Finding SDLC Deficiencies?

Audit standards require validating facts with management first to ensure accuracy and allow immediate remediation before formal reporting.

Escalation is reserved for severe compliance breaches or uncooperative management, not initial deficiency identification.

What Must an IS Auditor Verify During an Audit Closing Meeting?

Executive communication occurs after the formal audit report is issued. The closing meeting's immediate goal is securing mutual agreement on findings and deadlines before documentation is finalized.

Resource assessment belongs in the audit planning phase or during the follow-up audit. It is not verified during the exit conference, which focuses solely on acknowledging findings and agreed timelines.

Which Document Includes an Audit's Quality Assurance Process?

Post-audit review is an operational activity within the QA program, not the foundational document that mandates the entire framework. The charter legally authorizes and establishes the QA process.

No, it only states the mandate to maintain a QA program and comply with IIA standards. Detailed testing steps belong in QA manuals or standard operating procedures.

Which Sampling Method Reviews Balance Sheets for Material Transactions?

Judgmental sampling relies on auditor discretion rather than statistical quantification. Variable sampling is required when testing monetary account balances for precise misstatement detection.

What Most Effectively Reduces Brute Force Attack Success?

Longer passwords increase cracking time but do not stop active guessing attempts. Lockout policies immediately block further trials, making them operationally superior for real-time prevention.

MFA prevents brute force entirely, but this question focuses on traditional password controls. Among the given options, lockout provides the most direct and immediate interruption.

What Best Identifies Threats in Proposed Virtualization Techniques?

Logs only capture data after deployment; they cannot analyze threats for unimplemented vendor proposals.

Architecture design focuses on structural components and workflows, not systematic threat identification or mitigation planning.

What is the First Step in a Data Classification Program?

Without a policy, categorization lacks standardized criteria, ownership definitions, and executive backing required by ISACA.

Process maps are created after the policy and categorization phases to document how classified data flows through systems.

How to Isolate IoT Devices from Corporate Traffic in Healthcare

Firewalls provide static segmentation but lack identity-aware policies and continuous verification needed for dynamic IoT environments. Zero Trust natively incorporates segmentation with stricter access controls.

It uses micro-segmentation and least-privilege access to ensure each IoT device authenticates continuously and can only communicate with authorized services, blocking lateral movement.

What is the Primary Benefit of Operational Log Management

Security monitoring uses SIEM tools, whereas operational logging focuses on system health and uptime. CISA prioritizes availability and performance as foundational before layering security controls.

Storage only aggregates raw data without processing it. Operational log management adds structure, filtering, and analysis to convert storage into actionable performance insights.

What Creates the Greatest Business-IT Alignment Challenge?

Information security is a functional subset of IT strategy, whereas board-level CIO participation dictates overarching business-IT alignment.

Yes, it is a recognized best practice that facilitates cross-functional coordination and ensures IT initiatives match business priorities.

What Should an IS Auditor Prioritize in a Financial App RFP?

Audit trails are a vital control but represent only one component of system design. Business requirement alignment encompasses functionality, security, compliance, and operational needs, making it the foundational priority.

Vendor vetting is important for risk mitigation, but without clear organizational requirements driving the RFP, even thoroughly screened vendors may deliver an unsuitable solution.

Primary Reason for Internal Network Data Classification

Policies are administrative frameworks created to enforce protection standards. Classification identifies what needs protecting, making protection the foundational objective rather than compliance itself.

No, classification determines sensitivity and handling requirements first. Retention schedules are developed later based on regulatory and operational needs identified during the classification process.

Most Effective Audit Sampling Method for Suspected Unauthorized Credits?

Variable sampling measures monetary misstatement amounts, not binary fraud occurrences. Discovery sampling is required when the audit objective is simply proving an irregularity exists.

Stop-or-go sampling quickly verifies control effectiveness and halts testing early. Discovery sampling calculates larger samples specifically to guarantee detection of rare fraud events.

Which IS Auditor Concern Takes Priority in BCP Reviews?

Tabletop exercises are training tools, not actual disaster responses, so their length can be adjusted without impacting real recovery capabilities. Auditors prioritize structural gaps like missing dependencies first.

RPO and RTO define acceptable data loss and downtime limits, but they cannot be met if critical application relationships are unmapped during restoration.

Best Way for Auditors to Assess Automated Control Design?

Configuration reviews validate operating effectiveness and runtime behavior, not the original architectural design or control specifications.

Interviews supplement documentation reviews to clarify ambiguities but lack the objective, auditable evidence required for formal design assessment.

Primary Reason for Internal Audit Quality Assurance?

Governance involves board oversight and policy adoption, while QA specifically tests day-to-day compliance with audit standards and methodology.

Internal QA focuses on continuous monitoring and immediate corrective actions, whereas external peer reviews occur periodically to assess overall maturity.

Most Important Consideration for Vulnerability Scanning Critical Infrastructure?

Off-peak scheduling is a mitigation tactic, not the primary control. Even during low-traffic windows, aggressive scans can still crash legacy systems or spike latency, making performance preservation the foundational requirement.

No. ISACA prioritizes business continuity and risk mitigation over budget constraints. Financial efficiency cannot justify risking operational downtime on critical assets.

How to Validate VM Replication Adequacy for Critical Server Recovery?

Offsite storage prevents geographic loss but does not prove the replicated environment can actually boot, sync, or meet RTOs during an outage.

No, network access controls enhance security but do not validate technical recoverability or data consistency after a failure event.

Does an IT Strategic Plan Identify Major Initiatives or Tactical Links?

Strategic plans set long-term direction; tactical and operational plans are derived from them, so the hierarchy flows downward rather than upward.

Auditors cross-reference proposed initiatives against business goals, budget constraints, and risk appetite to ensure feasible, value-driven execution.

How to Prevent Invoice Splitting to Bypass Approval Thresholds?

Continuous scripts typically flag individual transactions in real time, missing structured claims that span months or fall below automated suspicion thresholds.

No. Termination policies act as post-fraud deterrents rather than active detection or prevention mechanisms for ongoing transaction manipulation.

Which Process Best Ensures Forensic Data Integrity?

Hashing only verifies file alterations at a specific moment, whereas chain of custody tracks the entire evidence lifecycle and proves legal admissibility to auditors.

Prioritize chain of custody whenever the question emphasizes evidence handling, legal compliance, or audit trails, as ISACA values procedural accountability over isolated tools.

Which Incident Management Change Concerns an IS Auditor?

It enhances management visibility and accountability for unresolved tickets, which auditors view as a positive monitoring control rather than a risk.

Only when applied to complex or security-sensitive cases; limiting it to low-complexity types maintains proper scope and control boundaries.

Who Verifies Application Changes Are Authorized?

Business leaders approve requirements and business cases, but they delegate the technical verification of deployment approvals to operational release functions.

Release management focuses on packaging, scheduling, and verifying authorizations for production deployment, while CABs primarily assess risk and approve change requests.

Why Should IS Auditors Discuss Observations With Management Before Reporting?

Advisory support occurs after findings are confirmed. Pre-report discussions focus strictly on verifying facts to maintain auditor independence.

Corrective actions are documented after validation and management agreement. They represent the remediation phase, not the initial verification step.

Need for End-User Testing in Packaged Software?

Vendors only test standard functionality. You must still validate integration, workflows, and business-specific requirements through acceptance testing.

No. While User Acceptance Testing remains mandatory, overall testing volume drops significantly since core code and bug fixes are handled by the vendor.

Ensuring Data Recovery from Backup Media During Disasters | CISA

Offsite storage protects against physical destruction but does not verify that backups are readable, complete, or compatible with current systems.

At least annually for full restores, with quarterly or monthly partial tests recommended by ISACA to validate ongoing data integrity and procedures.

What is the primary benefit of risk assessments for audit planning?

Risk mitigation is management's responsibility after risks are identified; the audit plan focuses the auditor's resources on evaluating those risks, not implementing mitigation.

Timeliness can result from better planning, but it is not the primary reason for using risk assessments; optimal resource allocation is the core benefit.

How should an auditor test an automated daily data flow for completeness?

Because it only proves the interface is set up and one output looks correct; it does not verify that complete, accurate data is exchanged every day over time.

Data reconciliation over 25 sample days tests actual daily transfer outcomes, while code review only checks design and build and cannot detect operational data loss.

What Is the Greatest Security Concern Specific to Virtualized Environments?

Data exposure is a broad consequence that can result from many threats, while option B identifies a unique virtualization risk: data leaking between guest systems.

It means one virtual machine may read remnants of data from another guest that previously used the same physical memory, breaking VM isolation.

What Is the Greatest Advantage of Outsourcing an E-Banking Solution Without In-House Expertise?

Because the organisation cannot develop or maintain the system without costly new hires, the vendor's existing expertise saves the initial investment. Adaptability usually suffers under outsourcing since changes depend on vendor contracts.

Yes. Customization or change requests must go through the vendor, create additional fees and negotiation time, and the client has less direct control than it would with internal staff.

Which Audit Evidence Source Is Most Reliable?

Third-party data lacks guaranteed independence unless specifically verified; direct auditor observation bypasses potential intermediary bias.

ISACA prioritizes direct auditor knowledge, followed by external independent confirmations, internal records, and finally verbal inquiries.

Best Enabler for Balancing Value Delivery and Risk Management

A risk assessment focuses on threats and vulnerabilities and does not integrate business objectives and value delivery; it is one component inside a governance framework.

Yes, they identify process capability gaps, but they do not decide how to balance competing priorities; an IT governance framework provides the overarching mechanism.

What Should an IS Auditor Review When BCP Misses Extended System Outages?

ERM provides a broad organizational view, but the auditor needs to immediately verify IT-specific recovery steps when system outages are missing from the BCP.

BCP covers overall business operations and processes, while DRP focuses specifically on restoring IT infrastructure and data after a disruption.

Best Approach for Low-Risk Anomalies in CISA Audits

Documentation is mandatory but generic; CISA prioritizes risk-based resource allocation, making strategic deprioritization the superior fieldwork decision.

No. Low-risk items are typically summarized in the final audit report without demanding urgent remediation, preserving auditor independence and management ownership.

Which threat is greatest to an organization's entire virtual infrastructure?

Local authentication can weaken one guest's identity management, but an unstandardized image may contain insecure configurations that are copied to many VMs, spreading risk across the virtual environment.

Yes, but inefficient change management is a process weakness, not an immediate infrastructure defect; the exam's 'greatest' threat is the non-standard image that all VMs inherit.

Until when should an IS business case remain available for review?

Retirement happens after benefits have already been realized and reviewed, so keeping the business case until retirement is unnecessary and not the intended control point.

It is reviewed at the formal investment decision, at key project stages, and especially during post-implementation review after benefits have been fully realized.

Which sampling methodology is primarily used to detect significant deficiencies?

Discovery sampling is a special attribute sampling use case: it is designed to give a high chance of detecting at least one instance when the population exception rate is very low, such as fraud or a critical control deficiency.

No. It is mainly a detection tool, not an estimator of occurrence rate. Because it targets rare, significant exceptions, a finding in the sample triggers further investigation rather than a reliable rate estimate.

Which practice best supports effectiveness of a compliance program?

A GRC tool only stores and tracks data; effectiveness comes from assessing audit findings and acting on remediation, which the tool alone does not guarantee.

Monitoring applicable regulations is only scoping; it does not prove that the organization actually follows them. Audit finding assessment closes that gap.

Which Option Best Demonstrates IT Alignment with the Corporate Mission?

Functional analysis shows how IT is organized, efficient and capable, but it does not connect IT plans and decisions to the corporate mission; alignment requires dialogue and direction from the business.

It regularly brings business and IT leaders together to review IT initiatives and allocate resources so that IT actions and investments support the organization's strategy and mission.

Best Tool for Detailed Testing of Application Data and Configuration Files?

Utility software handles routine system maintenance and basic file operations but lacks automated validation, baseline comparison, and compliance reporting capabilities.

Analytics tools process large datasets and configuration files to detect anomalies, while audit hooks are embedded code fragments that capture real-time transaction logs.

When Should Metrics Be Selected for Benefits Realization?

Historical data supports the initial business case and approval phase, but it does not create the operational mechanism needed to monitor and track value during execution.

No. Without baseline metrics established during planning, there is no objective standard to measure progress or confirm whether the intended outcomes were achieved.

Which Audit Artifact Is Most Useful for New Data Protection Regulations?

Flow diagrams map technical data movement but do not assess whether implemented security controls meet specific regulatory requirements.

Benchmarking compares performance against industry peers, but it cannot substitute for direct internal compliance verification against legal mandates.

Best Way to Test Data Center Physical Security Controls?

Badge logs capture only one access layer; they cannot verify barriers, surveillance, environmental controls, or whether tailgating or badge sharing occurs.

Comparing to best practices evaluates control design or compliance, while onsite inspection verifies whether controls actually operate and protect the data center.

When to Schedule Follow-Up Audits for Corrective Actions?

Progress updates only confirm execution plans, not sustained control performance or actual risk mitigation over time.

No, administrative completion lacks the necessary observation period to prove the control operates effectively in production.

Which procedure is most appropriate for classifying organizational data?

Owner questionnaires capture local knowledge, but they don't standardize the impact criteria needed for classification; BIA gives an objective, business-wide basis.

No, but BIA is the preferred source of impact evidence because it quantifies confidentiality, integrity, and availability requirements for data.

What Must an IS Auditor Verify in Log Management Across Locations?

Because logs from different geographic locations must share a consistent time basis for correlation; encryption and signatures protect integrity but not chronological order.

Only if timestamps were already proven consistent; otherwise signed logs from separate places cannot reliably prove event sequence or detect missing records.

What is the greatest concern when key UAT scenarios are untested?

Security is normally validated through dedicated security testing and risk assessments, while UAT specifically validates business requirements and user acceptance. Untested UAT cases point most directly to unmet business requirements.

The auditor should assess the impact of the missing scenarios, especially for critical business processes, and recommend additional testing or compensating controls before allowing full reliance on the system.

IT Steering vs. Strategy Committee Roles in CISA

Risk-return analysis belongs to the IT strategy committee, which evaluates long-term investment portfolios rather than day-to-day project execution.

No, tracking strategic objective achievement falls under the strategy committee's purview. The steering committee focuses on tactical delivery and resource assignment.

How to Eliminate Bias in Vendor Proposal Reviews?

Auditors provide independent assurance and verify compliance after or during reviews, but they do not manage daily vendor interactions or enforce standardized communication protocols that prevent initial bias.

No, that control only mitigates conflicts of interest regarding self-dealing. It does not address how external evaluators might favor or disfavor outside vendors during the scoring process.

Next Step for Improperly Tested Controls in Control Self-Assessment

Guidance addresses future prevention, but auditors must first validate current control effectiveness through independent testing to establish factual baseline data.

No. CSA relies on management's self-evaluation, while independent testing provides objective, third-party evidence required for audit assurance.

Which Business Case Component Best Indicates Vendor Due Diligence?

Cost-benefit analysis only quantifies financial viability for the chosen option. It does not prove that other vendors were researched and compared, which is the true essence of due diligence.

ISACA expects auditors to verify that organizations systematically evaluate multiple alternatives against technical, security, and operational criteria before committing resources.

First Step Auditing IT Portfolio Management Process

Walk-throughs rely on existing documentation; if the portfolio is outdated, interviews will address irrelevant or missing projects, wasting audit time.

No, ROI calculations require verified project data and funding records, making them dependent on prior portfolio validation.

Primary Reason for Daily Network Admin Management Reviews?

Intrusion detection relies on real-time technical controls like IDS/IPS. Management reviews are supervisory audits focused on verifying changes and compliance, not live threat hunting.

Network configurations change rapidly. Daily reviews catch unauthorized or erroneous modifications quickly, preventing configuration drift and reducing the window of exposure compared to quarterly checks.

Smoke Detector Certification Standards | CISA Answer & Explanation

Audible alerts are basic functionality, but without certification, detectors may suffer from high failure rates, false positives, or silent malfunctions that undermine audit reliability.

Data centers typically avoid water-based suppression due to equipment damage risks, preferring clean-agent systems. Suppression linkage is secondary to validated detection performance.

Which Process Best Ensures Vendor Software Remains Up to Date?

Version management only logs installed builds. It lacks the enforcement mechanisms required to push vendor fixes, validate compatibility, or track end-of-support dates.

No. SAM focuses on inventory, licensing, and cost optimization. Patch management handles the actual deployment and validation of vendor updates to maintain system currency.

Missing Access Logs in Secure Communication Closets

Audit methodology requires evaluating compensating controls before launching incident-specific investigations.

Policy approval is a governance matter; the immediate priority is assessing operational monitoring gaps to determine residual risk.

Best Indicator of Change Management Process Concerns?

Emergency changes follow a documented expedited workflow to resolve critical incidents. Their presence reflects business urgency rather than inherent process failure.

Auditors should analyze rollback frequency relative to total changes over a defined period. Trending this ratio highlights testing deficiencies and improvement opportunities.

What Is the Greatest Audit Concern in Patch Management?

Quarantine is a containment tactic that depends on prior discovery. Without scanning to identify vulnerable assets, isolation processes cannot be triggered or managed.

Yes, if the organization defines an acceptable risk threshold. Auditors focus on foundational controls like discovery rather than enforcing uniform patching.

Which Characteristic Applies to Digital Signatures in Email?

The sender encrypts the message with the recipient's public key, so only the recipient's private key can decrypt it. Public keys only verify signatures.

No, signatures only guarantee authenticity, integrity, and non-repudiation. Confidentiality requires separate symmetric or asymmetric encryption of the message body.

Greatest Concern for Information Security Governance Effectiveness

Risk assessment is an operational management activity focused on identifying vulnerabilities. Governance requires executive oversight, policy approval, and strategic direction.

No. Both are necessary, but governance evaluates leadership accountability first. Risk assessments continue regardless of how they are categorized.

What Control Type Is Implemented by Security Baseline Policies?

Baselines are technical standards, but when implemented via a mandatory policy, the control type becomes directive. Preventive controls rely on active technical mechanisms like firewalls.

Directive controls set mandatory rules and baselines to guide behavior, while compensating controls substitute for missing primary controls. CISA focuses on policy mandates versus technical workarounds.

Unrecorded IT Device Invoices in Asset Audit Follow-Up

Direct questioning lacks formal documentation and may trigger defensive behavior or incomplete disclosures. Proper protocol requires escalating findings to management for structured investigation.

No. Material discrepancies like unrecorded purchases pose ongoing financial and security risks that require immediate reporting and corrective action rather than future deferral.

Which SLA Component Ensures Prompt Issue Resolution?

Audits verify historical compliance but lack immediate enforcement power, whereas penalties create real-time financial motivation to fix problems quickly.

Indemnity addresses post-incident liability and damages, while penalties incentivize proactive, rapid remediation before significant downtime occurs.

Most Important RFP Requirement for Application Acquisition?

UAT is a client-led validation phase executed after the vendor delivers the application, not a vendor capability evaluated during procurement.

Financial health is verified through independent credit reports and due diligence, not submitted as part of the technical RFP response.

Greatest Access Control Concern in Accounts Payable Module

Writable shared drives risk file tampering, but they lack the direct, high-impact fraud vector of unauthorized vendor bank updates that bypass segregation of duties.

Yes, but it affects audit objectivity rather than the AP module's operational access controls. The question specifically targets finance system risks.

What Determines the Strategy for IT Portfolio Management?

Cost-benefit analysis evaluates individual project viability rather than establishing the overarching strategic framework needed for portfolio planning.

Dashboards track historical and current performance data, while roadmaps provide forward-looking strategic guidance for future investments and initiatives.

Greatest Concern in Post-Implementation Audit of Job Scheduler

Encryption protects data confidentiality, but a generic account destroys accountability and breaks the audit trail for all administrative actions. CISA prioritizes non-repudiation for privileged access.

It creates support and compliance issues, but lacks the immediate security and accountability risks of shared privileged credentials. Vendor approval workflows are secondary to core access controls.

What Should an Auditor Verify First When Reviewing a CASB Solution?

Centralized identity management supports authentication but cannot dictate CASB policies without first knowing which cloud apps handle sensitive data. Classification drives the actual security controls.

Resilience testing validates business continuity, but auditors must first verify how the CASB identifies and categorizes services to apply the right threat protections and compliance rules.

Which Evidence Best Plans an Audit of Untested Data Transfers?

Change logs track configuration updates but do not validate whether data integrity controls functioned correctly during those modifications.

They reveal original validation methods, known defect patterns, and residual risks, allowing auditors to prioritize regression testing efforts.

Which SDLC Quality Elements Must an IS Auditor Review?

Developers utilize standards during coding; auditors independently verify compliance against them.

No, defining attributes occurs during project initiation, not during the retrospective audit review.

How Does Database Replication Benefit Business Hours Operations?

Transaction rollback or forward recovery requires continuous log shipping or synchronous clustering, not simple asynchronous replication.

No, replication targets are strictly read-only to prevent data conflicts and ensure production stability during active operations.

How to Confirm Change Log Completeness in CISA Audits?

That direction tests existence or accuracy, not completeness. Completeness requires proving nothing was omitted by starting with the actual event.

It validates that the logging process is active and capturing updates in real time, which satisfies the immediate audit objective for completeness.

What Is Most Important When Outsourcing Customer Statement Printing?

Data retention is critical but falls under the broader umbrella of information security controls. Auditors require full control alignment first to address access, encryption, and disposal comprehensively.

Contractual remedies handle performance failures but do not prevent data breaches. Security alignment proactively mitigates the highest risk associated with outsourcing sensitive print jobs.

When is the Waterfall Software Lifecycle Model Best Suited?

OOP is a programming paradigm, not a project management framework. It can be applied within Agile, Scrum, or Waterfall depending on how the project is structured.

No. New technology introduces high uncertainty and likely requirement changes, making iterative models like Agile far more appropriate for managing risk and learning curves.

What Should Server Start-Up Procedure Audit Trails Track?

Execution logs only record automated script runs. They do not capture manual interventions or unauthorized changes to the start-up sequence itself.

It demonstrates accountability for procedural changes, ensuring auditors can verify that boot configurations match approved baselines without hidden modifications.

How to Protect PII in Dev/Test Environments | CISA

Tokenization breaks referential integrity and lacks semantic consistency, causing foreign key errors and failing validation logic that relies on predictable data formats.

Encryption protects data at rest but prevents direct querying and debugging, making it operationally unsuitable for functional software testing.

Best Evidence of IT Strategy Alignment to Business Objectives

Responsiveness shows adaptability, not initial strategic fit. Alignment requires upfront validation against business goals, not just reactive updates.

ISACA doctrine states business strategy leads and IT strategy follows to support it. Claiming IT impacts business reverses the proper governance hierarchy.

When Should Data Cleansing Be Performed in Data Conversion?

Extraction retrieves raw source data first. Cleansing requires the extracted dataset to identify and remove duplicates, invalid entries, or formatting issues.

Validation checks rules while cleansing fixes or removes bad data. Both often occur together before transformation, but cleansing directly addresses quality defects.

Most Appropriate Indicator of Change Management Effectiveness?

Documentation lag tracks administrative compliance and timeliness, not whether changes successfully met their objectives or maintained system stability.

Compliance metrics verify that procedures were followed, while effectiveness metrics measure actual business outcomes and risk reduction.

What is the Primary Benefit of an IT Maturity Model?

Benchmarking compares your organization against peers, but maturity models focus inward on assessing and improving your own process capabilities over time.

A standard tool measures a point-in-time status, while a maturity model provides a phased roadmap to evolve processes and build sustained organizational capability.

What should an IS auditor do first when using data analytics for an audit?

Source identification depends on knowing exactly what data supports the audit objectives, which requires defining needs first.

Clear data requirements dictate which analytical techniques and models are appropriate, preventing mismatched testing approaches.

Ready to practice?

Access 400 CISA questions with instant feedback and detailed explanations.

View CISA Practice Questions →

← Back to CISA Certified Information Systems Auditor Study Guide