CISA — ISACA Certified Information Systems Auditor
ISACA

ISACA Certified Information Systems Auditor (CISA) Practice Questions

★★★★★ 5.0 160 verified reviews
400 questions
2026-06-21 updated
✓ Online quiz simulator

Domain coverage

  • Information System Auditing Process (21%)
  • Governance & Management of IT (17%)
  • Information Systems Acquisition, Development & Implementation (12%)
  • Information Systems Operations & Business Resilience (23%)
  • Protection of Information Assets (27%)

Sample Questions (40 of 400 shown)

Q1
Which of the following should be the role of internal audit in an organization’s move to the cloud?
  1. Identifying and mitigating risk to an acceptable level
  2. Identifying impacts to organizational budgets and resources
  3. Implementing security controls for data prior to migration
  4. Serving as a trusted partner and advisor
✓ Correct Answer: B
The internal audit function should act as an independent advisor during a cloud migration. Identifying budget and resource impacts (B) is a key advisory responsibility that doesn't impair independence. Options A and C are operational activities (risk mitigation and implementing controls) that would compromise audit independence. Option D is too vague and doesn't specifically define the audit role in a cloud migration context.
Q2
An IS auditor is providing input to an RFP to acquire a financial application system. Which of the following is MOST important for the auditor to recommend?
  1. The application should meet the organization's requirements.
  2. Vendor employee background checks should be conducted regularly.
  3. Audit trails should be included in the design.
  4. Potential suppliers should have experience in the relevant area.
✓ Correct Answer: A
When providing input to an RFP (Request for Proposal), the IS auditor's primary focus should be ensuring the application meets the organization's business and technical requirements. This is fundamental to ensuring the system will support business objectives and comply with relevant standards. While audit trails (C) are important for control and compliance, they are a subset of overall requirements. Vendor background checks (B) and experience (D) are important evaluation criteria but are secondary to ensuring the application fulfills organizational needs.
Q3
Which of the following provides the GREATEST assurance that a middleware application compiling data from multiple sales transaction databases for forecasting is operating effectively?
  1. Automated reconciliations
  2. Exception reporting
  3. Manual checks
  4. Continuous auditing
✓ Correct Answer: D
Continuous auditing provides the greatest assurance for a middleware application compiling data from multiple databases because it involves automated testing and monitoring throughout the reporting period, providing real-time or near-real-time assurance. Automated reconciliations (A) and exception reporting (B) are components of continuous auditing but are not as comprehensive on their own. Manual checks (C) are the least reliable and efficient method for ensuring effectiveness of automated systems.
Q4
Audit observations should be FIRST communicated with the auditee:
  1. during fieldwork.
  2. at the end of fieldwork.
  3. within the audit report.
  4. when drafting the report.
✓ Correct Answer: A
Audit observations should be FIRST communicated to the auditee during fieldwork. This allows for immediate clarification, discussion, and agreement on findings while the auditor is still on-site and has direct access to evidence and personnel. Early communication also helps build rapport and ensures accuracy before formal reporting. Options B, C, and D represent later stages in the audit process (end of fieldwork, draft report, final report) which are too late for initial communication.
Q5
A bank performed minor changes to the interest calculation computer program. Which of the following techniques would provide the STRONGEST evidence to determine whether the interest calculations are correct?
  1. Review of the quality assurance (QA) test results
  2. Manual verification of a sample of the results
  3. Source code review
  4. Parallel simulation using audit software
✓ Correct Answer: D
Parallel simulation using audit software provides the strongest evidence because it involves the auditor writing programs to process the same data as the application and then comparing the results. This independently verifies the calculation logic and can cover 100% of transactions. It's more reliable than QA test results (A) which may not cover all scenarios or use production data, manual verification (B) which is sample-based and may miss errors, or source code review (C) which verifies the code but doesn't verify actual output with real data.
Q6
An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?
  1. Completeness testing has not been performed on the log data.
  2. Log feeds are uploaded via batch process.
  3. The log data is not normalized.
  4. Data encryption standards have not been considered.
✓ Correct Answer: A
The MOST concern should be that completeness testing has not been performed on the log data. Without completeness testing, there's no assurance that all relevant events are being captured by the log aggregation system, which severely undermines its effectiveness for risk management and incident detection. Options B, C, and D are important considerations but secondary to ensuring the system captures complete and accurate log data.
Q7
Which of the following is MOST likely to increase if an organization increases its risk appetite?
  1. Audit findings
  2. Key controls
  3. Opportunities
  4. Security incidents
✓ Correct Answer: D
If an organization increases its risk appetite, it becomes more willing to accept risk, which MOST likely increases security incidents (D). Risk appetite defines the amount and type of risk an organization is willing to accept to achieve its objectives. A higher risk appetite means weaker controls or more relaxed security measures, leading to more security incidents. Options A, B, and C may change but are not directly and immediately impacted by risk appetite changes.
Q8
What should an IS auditor recommend to management as the MOST important action before selecting a Software as a Service (SaaS) vendor?
  1. Determine service level requirements.
  2. Perform a business impact analysis (BIA).
  3. Complete a risk assessment.
  4. Conduct a vendor audit.
✓ Correct Answer: C
Before selecting a SaaS vendor, the MOST important action is to complete a risk assessment (C). This identifies potential risks associated with the vendor and the cloud service, enabling informed decision-making. Determining service level requirements (A) is important but should be done after understanding the risks. BIA (B) and vendor audit (D) are also important but come after initial risk assessment.
Q9
During an audit of payment services of a branch based in a foreign country, a large global bank's audit team identifies an opportunity to use data analytics techniques to identify abnormal payments. Which of the following is the team's MOST important course of action?
  1. Request the data from the branch as the team audit charter covers the country where it is based.
  2. Conduct a walk through of the analytical strategy with stakeholders of the audited branch to obtain their buy-in.
  3. Consult the legal department to understand the procedure for requesting data from a different jurisdiction.
  4. Agree on a data extraction and sharing strategy with the IT team of the audited branch.
✓ Correct Answer: C
When dealing with data across jurisdictions (foreign country), the MOST important action is to consult the legal department to understand data privacy laws, cross-border data transfer regulations, and proper procedures for requesting data from a different jurisdiction. This ensures compliance with legal and regulatory requirements. Options A, B, and D are important but secondary to ensuring legal compliance.
Q10
Which of the following is the BEST way for an IS auditor to assess the design of an automated application control?
  1. Interview the application developer.
  2. Obtain management attestation and sign-off.
  3. Review system configuration parameters and output.
  4. Review the application implementation documents.
✓ Correct Answer: C
The BEST way to assess the design of an automated application control is to review system configuration parameters and output (C). This allows the auditor to directly examine how the control is configured and verify its effectiveness through actual system output. Interviewing the developer (A) provides only theoretical understanding. Management attestation (B) is not sufficient evidence. Implementation documents (D) describe intended design but don't verify actual implementation.
Q11
The PRIMARY reason to perform internal quality assurance (QA) for an internal audit function is to ensure:
  1. inherent risk in audits is minimized.
  2. audit resources are used most effectively.
  3. internal audit activity conforms with audit standards and methodology.
  4. the audit function is adequately governed and meets performance metrics.
✓ Correct Answer: C
The PRIMARY reason for internal quality assurance (QA) for an internal audit function is to ensure the internal audit activity conforms with audit standards and methodology (C). This ensures consistency, quality, and compliance with professional standards (e.g., IIA Standards). While effective resource use (B) and performance metrics (D) are important, they are not the primary purpose of QA. Inherent risk (A) is not minimized by QA.
Q12
An audit program indicates that a specific number of transactions are to be sampled for testing a particular control. However, it has been determined that the control design is deficient. What should the IS auditor do in response to this information?
  1. Recommend a change to the audit program to increase the sample size.
  2. Recommend a change to the audit program and testing methodology used.
  3. Document the observation and the testing methodology used.
  4. Notify audit management and continue to use the sample size.
✓ Correct Answer: B
If the control design is deficient, the auditor should recommend a change to the audit program and testing methodology used (B). Testing a deficient control design is wasteful and doesn't provide meaningful assurance. The auditor should focus on documenting the design deficiency and testing the design itself, not on testing operating effectiveness. Increasing sample size (A) won't help if the control design is flawed. Simply documenting (C) without changing approach is insufficient.
Q13
Which of the following is an example of inherent risk?
  1. Quality assurance (QA) processes may not effectively reduce errors.
  2. An approval process may not detect significant errors.
  3. The organization may not comply with regulations.
  4. Projects may still be delayed despite management controls.
✓ Correct Answer: C
Inherent risk exists before considering internal controls. 'The organization may not comply with regulations' (C) is an example of inherent risk - it's the risk that exists in the environment regardless of controls. Options A and B describe control risks (risks that controls won't work effectively). Option D describes a risk that might occur despite controls (residual risk).
Q14
Which of the following is the MOST significant risk when an application uses individual end-user accounts to access the underlying database?
  1. Users may be able to circumvent application controls.
  2. Application may not capture a complete audit trail.
  3. User accounts may remain active after a termination.
  4. Multiple connects to the database are used and slow the process.
✓ Correct Answer: B
When an application uses individual end-user accounts to access the underlying database, the MOST significant risk is that the application may not capture a complete audit trail (B). Individual accounts mean each user connects directly to the database, making it difficult to track through the application layer what actions were performed. The application's audit trail may not capture the actual database activities. Options A, C, and D are concerns but not as significant as the loss of audit trail.
Q15
An IS auditor is performing a project review and finds that scope reductions have been made without proper authorization. The IS auditor should be MOST concerned that:
  1. there could be significant delays in project completion.
  2. the project has not followed project management standards.
  3. project costs could increase above the original project budget.
  4. anticipated business functionality may not be delivered.
✓ Correct Answer: D
The IS auditor should be MOST concerned that anticipated business functionality may not be delivered (D). Unauthorized scope reductions mean the project may not deliver the expected business benefits and functionality that justified the project investment. While delays (A), not following standards (B), and cost increases (C) are concerns, the primary concern is that the project may fail to deliver expected business value.
Q16
In reviewing the IT strategic plan, the IS auditor should consider whether it identifies the:
  1. project management methodologies used.
  2. allocation of IT staff.
  3. major IT initiatives.
  4. links to operational tactical plans.
✓ Correct Answer: D
When reviewing the IT strategic plan, the IS auditor should consider whether it identifies links to operational tactical plans (D). The IT strategic plan should align with and support the organization's overall strategic objectives and link to operational plans. While major IT initiatives (C) are important, they should be derived from strategic alignment. Project management methodologies (A) and IT staff allocation (B) are tactical/operational details, not strategic plan components.
Q17
Which of the following would the IS auditor MOST likely review to determine whether modifications to the operating system parameters were authorized?
  1. Change control log
  2. Documentation of exit routines
  3. Security system parameters
  4. System initialization logs
✓ Correct Answer: A
To determine whether modifications to operating system parameters were authorized, the IS auditor would MOST likely review the change control log (A). The change control log records all changes, including who requested them, who approved them, and when they were implemented. This provides evidence of authorization. Options B, C, and D don't provide information about change authorization.
Q18
An organization is disposing of removable onsite media which contains sensitive information. Which of the following is the MOST effective method to prevent disclosure of sensitive data?
  1. Wiping and rewriting three times
  2. Software formatting
  3. Encrypting and destroying keys
  4. Machine shredding
✓ Correct Answer: D
Machine shredding (D) is the MOST effective method to prevent disclosure of sensitive data on removable media because it physically destroys the media, making data recovery virtually impossible. Wiping and rewriting (A) and software formatting (B) can leave recoverable data. Encrypting and destroying keys (C) is effective if encryption is strong, but shredding provides the highest assurance.
Q19
The BEST way to provide assurance that a project is adhering to the project plan is to:
  1. conduct compliance audits at major system milestones.
  2. require design reviews at appropriate points in the life cycle.
  3. have an IS auditor participate on the quality assurance (QA) team.
  4. have an IS auditor participate on the steering committee.
✓ Correct Answer: A
The BEST way to provide assurance that a project is adhering to the project plan is to conduct compliance audits at major system milestones (A). This provides independent verification at critical points in the project lifecycle. Design reviews (B) are important but may not cover all aspects of plan adherence. Having an auditor on the QA team (C) or steering committee (D) provides oversight but not independent assurance.
Q20
An organization requires any travel and entertainment expenses over $10,000 to be approved by senior management. Which of the following is the MOST effective way to mitigate the risk that employees will split invoices to avoid the approval process?
  1. Develop computer-assisted audit techniques (CAATs) to check the full year's transactions.
  2. Adopt a zero-tolerance policy that requires termination of employees who submitted fraudulent claims.
  3. Establish a whistle-blowing policy that allows employees to report suspicious activity anonymously.
  4. Review alerts generated from continuous auditing scripts for suspicious claims submitted.
✓ Correct Answer: A
The MOST effective way to mitigate the risk of invoice splitting (splitting a large invoice into smaller ones to avoid approval threshold) is to develop computer-assisted audit techniques (CAATs) to check the full year's transactions (A). CAATs can identify patterns and related transactions that suggest splitting. Zero-tolerance policy (B) is deterrent but not detective. Whistle-blowing (C) relies on employees reporting. Continuous auditing scripts (D) are good but may not catch sophisticated splitting schemes as effectively as comprehensive CAATs.
Q21
During an audit, an IT finding is agreed upon by all IT teams involved, but no team wants to be responsible for remediation or considers the finding within its area of responsibility. Which of the following is the IS auditor's BEST course of action?
  1. Determine the most appropriate team and assign accordingly.
  2. Issue the finding without identifying an owner.
  3. Escalate to IT management for resolution.
  4. Assign shared responsibility to all IT teams.
✓ Correct Answer: C
When an IT finding is agreed upon by all teams but no team wants to take responsibility, the IS auditor's BEST course of action is to escalate to IT management for resolution (C). IT management is responsible for assigning ownership and ensuring remediation. The auditor shouldn't assign responsibility (A) as that's management's role. Issuing the finding without an owner (B) is ineffective. Assigning shared responsibility (D) may dilute accountability.
Q22
An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor's NEXT step?
  1. Evaluate developer training.
  2. Evaluate secure code practices.
  3. Evaluate the incident management process.
  4. Evaluate the change management process.
✓ Correct Answer: C
The NEXT step after noting a production incident caused by a defect from a recent release should be to evaluate the incident management process (C). This determines whether the incident was properly detected, reported, and resolved. Evaluating developer training (A) and secure code practices (B) may be subsequent steps but not the immediate next step. Evaluating change management (D) is important but incident management should be evaluated first to understand if the incident was properly handled.
Q23
Which of the following changes intended to improve and streamline an organization's incident management process would be a potential concern to an IS auditor?
  1. Implementing automatic reporting for all open incidents over three months old
  2. Enabling the capability for the individual reporting the incident to assign priority to a ticket
  3. Configuring automated messaging to service lines notifying them of the status of the ticket
  4. Introducing self-service functions for selected low-complexity incident types
✓ Correct Answer: B
Enabling the individual reporting the incident to assign priority to a ticket (B) would be a potential concern because priority should be assigned based on business impact and urgency, not by the person reporting. This could lead to inappropriate prioritization. Options A, C, and D are improvements to the incident management process.
Q24
Which type of risk would MOST influence the selection of a sampling methodology?
  1. Inherent
  2. Residual
  3. Control
  4. Detection
✓ Correct Answer: A
Inherent risk (A) would MOST influence the selection of a sampling methodology. Inherent risk is the susceptibility of an assertion to a material misstatement before considering internal controls. Higher inherent risk requires more rigorous sampling methods and larger sample sizes. Residual risk (B) is after controls. Control risk (C) and detection risk (D) are audit risks, not inherent risks.
Q25
Which of the following is the PRIMARY reason an IS auditor should discuss observations with management before delivering a final report?
  1. Identify business risks associated with the observations.
  2. Validate the audit observations.
  3. Assist the management with control enhancements.
  4. Record the proposed course of corrective action.
✓ Correct Answer: B
The PRIMARY reason to discuss observations with management before delivering a final report is to validate the audit observations (B). This ensures accuracy, completeness, and fairness of the findings. It also provides management an opportunity to clarify or provide additional context. Identifying business risks (A), assisting with control enhancements (C), and recording corrective actions (D) are important but secondary to validation.
Q26
An IS auditor is reviewing an organization's overall incident response capability following recovery from a cybersecurity incident. Which of the following findings should be of MOST concern to the auditor?
  1. Risk analysis errors were identified as part of the post-incident review.
  2. Logs were only collected as part of the post-incident review.
  3. The incident was caused by a known vulnerability with a documented risk acceptance.
  4. Lessons learned were not documented after the incident.
✓ Correct Answer: B
Logs were only collected as part of the post-incident review (B) should be the MOST concern because it indicates that logging and evidence collection are not part of the standard incident response process. This means critical evidence may be lost or not properly preserved during the incident. Options A, C, and D are findings but not as critical as the lack of proper logging procedures.
Q27
During the walk-through procedures for an upcoming audit, an IS auditor notes that the key application in scope is part of a Software as a Service (SaaS) agreement. What should the auditor do NEXT?
  1. Verify whether a third-party security attestation exists.
  2. Verify whether IT management monitors the effectiveness of the environment.
  3. Verify whether a right-to-audit clause exists.
  4. Verify whether service level agreements (SLAs) are defined and monitored.
✓ Correct Answer: D
When an application is part of a SaaS agreement, the NEXT step should be to verify whether service level agreements (SLAs) are defined and monitored (D). SLAs define the expected service levels, responsibilities, and metrics for the SaaS provider. This is fundamental to ensuring the service meets organizational needs. Third-party security attestation (A), monitoring by IT management (B), and right-to-audit clause (C) are important but come after establishing SLAs.
Q28
Halfway through an enterprise-wide project to implement business solutions, an IS auditor is called in to do a project risk evaluation. The results from this audit are to be communicated directly to the project steering committee. What should the auditor do FIRST?
  1. Assess the project organization and actual cost incurred.
  2. Interview the project manager about the project scope and current status.
  3. Review the organization's project management framework.
  4. Perform a risk assessment of the project based on best practices.
✓ Correct Answer: C
When called in for a project risk evaluation, the auditor should FIRST review the organization's project management framework (C). This provides the baseline and standards against which the project should be evaluated. Without understanding the framework, the auditor cannot properly assess the project. Interviewing the project manager (B) and assessing the project organization (A) are subsequent steps. Performing risk assessment (D) should be based on the framework.
Q29
Which of the following is the BEST way for senior audit leadership to be engaged during the planning phase of an audit in order to improve audit quality?
  1. Meet with auditee leadership.
  2. Prepare audit planning documents.
  3. Review the proposed audit scope.
  4. Attend planning walk-throughs.
✓ Correct Answer: C
The BEST way for senior audit leadership to be engaged during planning to improve audit quality is to review the proposed audit scope (C). This ensures the scope is appropriate, comprehensive, and aligned with risks and objectives. Meeting with auditee leadership (A), preparing planning documents (B), and attending walk-throughs (D) are important but not as impactful as scope review for improving audit quality.
Q30
In which of the following sampling methods is the entire sample considered to be irregular if a single error is found?
  1. Discovery sampling
  2. Stop-or-go sampling
  3. Variable sampling
  4. Judgmental sampling
✓ Correct Answer: A
In discovery sampling, the entire sample is considered irregular if a single error is found (A). Discovery sampling is used when the objective is to discover at least one instance of a rare or critical error (e.g., fraud). If any error is found, it indicates a potential systemic problem. Stop-or-go sampling (B) allows early termination if no errors are found. Variable sampling (C) estimates numerical quantities. Judgemental sampling (D) is based on auditor judgment.
Q31
An organization uses system interfaces to disburse money to various banks. Which of the following features in the system interfaces is MOST important to provide assurance that the money is going to the right bank account?
  1. Audit logging
  2. Nonrepudiation
  3. Encryption
  4. Digital signature
✓ Correct Answer: D
Digital signature (D) is the MOST important feature to provide assurance that money is going to the right bank account. Digital signatures provide authentication (verifying the identity of the sender), integrity (ensuring the transaction hasn't been altered), and non-repudiation (preventing the sender from denying the transaction). Audit logging (A) provides a record but doesn't prevent errors. Non-repudiation (B) is a component of digital signatures. Encryption (C) provides confidentiality but not necessarily assurance of correct recipient.
Q32
An IS auditor is asked to review an organization's technology relationships, interfaces, and data. Which of the following enterprise architecture (EA) areas is MOST appropriate for this review?
  1. Application architecture
  2. Infrastructure architecture
  3. Reference architecture
  4. Information security architecture
✓ Correct Answer: C
Reference architecture (C) is the MOST appropriate EA area for reviewing an organization's technology relationships, interfaces, and data. Reference architecture provides a blueprint or template for how systems should be structured and integrated, including relationships and data flows. Application architecture (A) focuses on individual applications. Infrastructure architecture (B) focuses on technical infrastructure. Information security architecture (D) focuses on security controls.
Q33
An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required, which of the following is the BEST action for the IS auditor to take?
  1. Obtain approval from audit management to submit the report.
  2. Obtain approval from auditee management to release the report.
  3. Obtain approval from both audit and auditee management to release the report.
  4. Submit the report to appropriate regulators immediately.
✓ Correct Answer: A
If reporting to external authorities is required due to irregularities that management is ignoring, the BEST action is to obtain approval from audit management to submit the report (A). The internal audit activity should follow its own protocols and obtain appropriate approvals before external reporting. Obtaining approval from auditee management (B) or both (C) is inappropriate when management is ignoring the irregularities. Submitting immediately (D) without proper internal approvals is premature and may violate audit protocols.
Q34
Which of the following is the MOST appropriate control to have in place after data migration?
  1. Review of representative samples of migrated data
  2. Clearly defined and documented data migration roles
  3. Formal sign-off by senior management after completion
  4. Mapping of transactions from source to receiving system
✓ Correct Answer: A
The MOST appropriate control after data migration is to review representative samples of migrated data (A). This provides direct evidence that data was accurately and completely migrated from the source to the target system. Defined roles (B) and formal sign-off (C) are important but don't provide direct assurance of data quality. Mapping of transactions (D) is important during migration planning but doesn't verify actual migration quality.
Q35
Which of the following should be the GREATEST concern for an IS auditor reviewing the implementation of a security information and event management (SIEM) system?
  1. SIEM rule tuning is only reviewed annually.
  2. Network monitoring events are not aggregated into the SIEM.
  3. Only the last seven days of logs from the SIEM are maintained for review.
  4. Security operations center (SOC) staff have not been fully trained on how to use the SIEM.
✓ Correct Answer: B
The GREATEST concern for a SIEM implementation is that network monitoring events are not aggregated into the SIEM (B). SIEM's effectiveness depends on having comprehensive visibility across the network. Without network monitoring events, the SIEM has blind spots and can't effectively detect threats. Annual rule tuning (A), seven days of log retention (C), and staff training (D) are concerns but secondary to comprehensive event aggregation.
Q36
When utilizing attribute sampling, which of the following would cause the sample size to increase?
  1. Tolerable error rate decrease
  2. Expected error rate decrease
  3. Population size decrease
  4. Acceptable risk level increase
✓ Correct Answer: A
When utilizing attribute sampling, a tolerable error rate decrease (A) would cause the sample size to increase. In attribute sampling, sample size is determined by: expected error rate, tolerable error rate, acceptable risk level, and population size. A lower tolerable error rate means the auditor requires higher precision, which requires a larger sample size. Expected error rate decrease (B) would decrease sample size. Population size decrease (C) has minimal impact on sample size for large populations. Acceptable risk level increase (D) would decrease sample size.
Q37
An IS auditor is reviewing a client’s outsourced payroll system to assess whether the financial audit team can rely on the application. Which of the following findings would be the auditor's GREATEST concern?
  1. Payroll processing costs have not been included in the IT budget.
  2. User access rights have not been periodically reviewed by the client.
  3. The third-party contract does not comply with the vendor management policy.
  4. The third-party contract has not been reviewed by the legal department.
✓ Correct Answer: D
The GREATEST concern when reviewing an outsourced payroll system is that the third-party contract has not been reviewed by the legal department (D). Legal review ensures the contract adequately protects the organization's interests, including data privacy, security, SLAs, and liability. Without legal review, the organization may have inadequate legal protection. Payroll processing costs (A) are a budgetary concern. User access reviews (B) and vendor management policy compliance (C) are important but secondary to having a legally sound contract.
Q38
An IS auditor is planning an audit of an organization's risk management practices. Which of the following would provide the MOST useful information about risk appetite?
  1. Prior audit reports
  2. Risk policies
  3. Management assertion
  4. Risk assessments
✓ Correct Answer: B
Risk policies (B) would provide the MOST useful information about risk appetite. Risk appetite is typically documented in risk policies, which define the amount and type of risk the organization is willing to accept. Prior audit reports (A) may indicate risk issues but don't define appetite. Management assertion (C) is subjective and may not be documented. Risk assessments (D) identify specific risks but don't define overall risk appetite.
Q39
An IS auditor should be MOST concerned with the placement of environmental detectors for heat, water, and smoke in which of the following locations?
  1. Inside ventilation ducts
  2. Around cooling units
  3. Above the ceiling
  4. Under the floor
✓ Correct Answer: A
The GREATEST concern is the placement of environmental detectors inside ventilation ducts (A). Detectors in ventilation ducts can detect heat, smoke, or water early as these elements travel through the ducts, providing early warning. Around cooling units (B), above ceiling (C), and under floor (D) are also important locations but not as critical as inside ventilation ducts for early detection.
Q40
An IS auditor finds a computer that is suspected to have been involved in a cyber crime. Which of the following activities is MOST critical to ensure data collected is admissible in a court of law?
  1. Notify law enforcement upon detection.
  2. Track possession of the computer.
  3. Collect audit logs from the affected computer.
  4. Power off the computer to ensure data is not changed.
✓ Correct Answer: B
To ensure data collected from a computer involved in cyber crime is admissible in court, tracking possession of the computer (B) is MOST critical. This establishes chain of custody, which proves the evidence hasn't been tampered with. Notifying law enforcement (A) is important but not for admissibility. Collecting audit logs (C) is important evidence but doesn't ensure admissibility. Powering off (D) may destroy volatile data and doesn't establish chain of custody.

You've viewed 3 of 400 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 160 verified reviews

5.0 ★★★★★ Based on 160 reviews
★★★★★★
The CISA certification opened up a promotion for me at work. These practice questions were a big part of that success.
— Ryan J.
★★★★★★
I work full time and study at night. The CISA question bank allowed me to learn efficiently without wasting precious time.
— Harper S.
★★★★★
Ended up buying three different CISA prep resources and this was by far the most helpful one. Don’t waste money on others.
— Penelope W.
★★★★★★
I’ve purchased a few ISACA exam dumps over the years and this CISA one is easily the best quality.
— Samuel T.
★★★★★★
Best CISA prep I’ve found online. The question pool is deep and the randomized practice mode keeps you on your toes.
— Mason T.
★★★★★★
Straightforward and effective. No fluff in the CISA practice set, just relevant questions with solid answer keys.
— Owen P.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

Answering as an IT manager rather than an IS auditor. Auditors observe, document, report, and recommend. They do not fix vulnerabilities, implement controls, or make management decisions. When a question asks "What should the auditor do FIRST?", the answer almost always involves reporting to management or documenting findings. Our practice tests explicitly flag this distinction in every relevant explanation.

ISACA requires 5 years of professional IS audit experience (waivers available for up to 3 years with relevant degrees/certifications). For exam preparation, most candidates invest 8-12 weeks (150-200 total hours). Domain 5 (27%) and Domain 4 (23%) together account for 50% of the exam—allocate most study time here.

The exam tests your knowledge of audit evidence characteristics: sufficient (adequate quantity), reliable (from credible sources), relevant (pertains to audit objective), and useful (aids in forming audit opinion). System-generated evidence with automated controls is more reliable than manually created records. Know the hierarchy of evidence quality.

ISACA uses a psychometric scaled score from 200-800. 450 is the passing threshold. The scaling adjusts for question difficulty across exam forms—harder exams require fewer correct answers. You receive a preliminary pass/fail immediately after the exam; official scores appear in your ISACA account within 10 business days.

Free Study Resources

Community-verified analysis of 372 topics from real test-taker discussions — 36 deep analyses and 0 FAQs.