Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 676–750

934 questions total · 13pages · All types, answers revealed

Page 9

Page 10 of 13

Page 11
676
MCQhard

An organization's business impact analysis shows that a payment processing system has a recovery time objective of two hours and a recovery point objective of fifteen minutes. The current disaster recovery strategy restores the system from nightly tape backups at an alternate site, with an observed restoration time of eight hours and up to twenty-four hours of data loss. Which action should the IS auditor recommend FIRST?

A.Schedule more frequent full interruption tests at the alternate site to validate the current strategy.
B.Increase the frequency of tape backups to every fifteen minutes.
C.Report the gap to management and recommend a recovery strategy capable of meeting the objectives, such as replication or continuous data protection.
D.Revise the recovery time objective and recovery point objective to match current capabilities.
AnswerC

The current strategy cannot meet either objective, so the auditor's first action is to communicate the gap and recommend a solution whose capabilities match the requirements. Technologies such as synchronous or asynchronous replication and continuous data protection can deliver a fifteen-minute recovery point and support a two-hour recovery time. Recommending a capability-aligned strategy addresses the root problem rather than adjusting targets or marginally improving an inadequate method.

Why this answer

The recovery strategy must be capable of meeting the stated objectives. Nightly tape restoration fails both the two-hour recovery time objective and the fifteen-minute recovery point objective, so the auditor should report the shortfall and recommend a design such as replication or continuous data protection that can achieve those targets. Changing the objectives or merely testing more often leaves the business exposure intact.

Exam trap

The trap here is proposing a tactical tweak, such as more frequent backups or more testing, when the architecture itself cannot satisfy the recovery objectives and requires a different recovery technology.

677
MCQhard

During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?

A.Recommend that a new BIA be conducted to validate and update the DRP.
B.Accept the IT manager's rationale and close the finding.
C.Recommend terminating the current DRP until the BIA is completed.
D.Recommend accepting the risk and documenting the decision.
AnswerA

A DRP derives its recovery priorities and timeframes from BIA output; a three-year-old BIA may no longer reflect current systems or dependencies. Recommending a fresh BIA validates assumptions and updates the DRP, satisfying the need for an accurate, current recovery baseline.

Why this answer

A business impact analysis (BIA) is the foundation of a valid disaster recovery plan (DRP). Without a current BIA, the DRP may not reflect the organization's current critical processes, recovery time objectives (RTOs), or recovery point objectives (RPOs). Even if no major changes are perceived, subtle shifts in dependencies, resource availability, or regulatory requirements can render the DRP ineffective.

Therefore, the auditor should recommend conducting a new BIA to validate and update the DRP.

Exam trap

The trap here is that candidates may assume the IT manager's claim of 'no major changes' is sufficient, but the CISA exam emphasizes that a BIA must be periodically reviewed (typically annually) regardless of perceived stability, because hidden dependencies or gradual changes can still affect recovery requirements.

How to eliminate wrong answers

Option B is wrong because accepting the IT manager's rationale without evidence ignores the risk that the DRP may be outdated; the auditor's role is to verify, not assume, that no changes have impacted recovery requirements. Option C is wrong because terminating the current DRP would leave the organization without any recovery plan until the BIA is completed, increasing operational risk unnecessarily. Option D is wrong because accepting the risk and documenting the decision without further action is premature; the auditor should first recommend a BIA to determine the actual risk level before deciding to accept it.

678
MCQmedium

An organization is implementing a new customer relationship management (CRM) system. The project manager proposes using a pilot conversion strategy, where the new system is implemented in one department first, then gradually rolled out to others. Which of the following is the PRIMARY benefit of this approach?

A.It ensures that all data is migrated at once.
B.It minimizes the overall project cost.
C.It allows for early detection of issues before full-scale rollout.
D.It eliminates the need for user training.
AnswerC

A pilot conversion limits the impact of potential problems by testing the system in a controlled environment before organization-wide deployment. This enables the project team to identify and resolve issues, refine procedures, and provide targeted training. It reduces the risk of a failed full-scale implementation. This is the primary benefit, as it directly addresses the risk of unforeseen problems affecting the entire organization.

Why this answer

The primary benefit of a pilot conversion is risk mitigation. By implementing the system in a limited area first, the organization can uncover and address problems before they affect the entire enterprise. This approach allows for learning and adjustment, reducing the chance of a costly failure.

It is particularly useful for complex systems where full-scale rollout carries high risk.

Exam trap

The trap here is assuming that pilot conversion saves money or eliminates training, when its main advantage is controlled risk exposure.

679
MCQhard

During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:

A.Systematic sampling
B.Judgmental sampling
C.Random sampling
D.Stratified sampling
AnswerD

Stratified sampling divides the population into distinct subgroups (strata) and draws samples from each, directly matching the stem's description. Unlike simple random or systematic sampling, it guarantees representation across every subgroup, which suits audit populations with heterogeneous characteristics where each stratum warrants coverage.

Why this answer

Stratified sampling divides the population into homogeneous subgroups (strata) — such as by department, transaction type, or risk level — and then draws samples from each stratum, often proportionally or with higher sampling in high-risk strata. This guarantees representation of every subgroup and reduces sampling risk compared to simple random sampling. It is the standard ISACA-recommended technique when the population is heterogeneous and the auditor needs coverage across distinct categories.

Exam trap

CISA often tests the distinction between stratified and systematic sampling — candidates confuse 'dividing into subgroups' with 'selecting every nth item', but only stratified sampling involves population subdivision.

How to eliminate wrong answers

Option A is wrong because systematic sampling selects every nth item from a sequentially ordered list after a random start — it does not divide the population into subgroups. Option B is wrong because judgmental sampling relies on the auditor's professional judgment and experience to select items (e.g., high-value or unusual transactions), not on statistical subdivision of the population. Option C is wrong because simple random sampling gives every item an equal chance of selection without any stratification or subgroup structure, which can under-represent small but risky subpopulations.

680
MCQmedium

A multinational corporation has adopted a decentralized IT governance model where business units have significant autonomy over IT decisions. The IS auditor is assessing the effectiveness of this model. Which of the following is the MOST critical factor for the auditor to evaluate?

A.Whether business units have the autonomy to select their own hardware and software vendors.
B.Whether the central IT function has been completely eliminated.
C.Whether a common framework and standards exist to ensure consistency and interoperability.
D.Whether each business unit has its own IT steering committee.
AnswerC

In a decentralized IT governance model, business units make independent decisions, which can lead to fragmentation, duplication, and integration challenges. The existence of a common framework and standards is critical to ensure that IT systems and processes remain consistent, secure, and interoperable across the organization. Without such a framework, the organization may face increased costs, data silos, and difficulty in achieving enterprise-wide objectives. Thus, this is the most critical factor for the auditor to evaluate.

Why this answer

The most critical factor in a decentralized IT governance model is the existence of a common framework and standards to ensure consistency, interoperability, and alignment with enterprise objectives. Without such a framework, business units may make disparate decisions that lead to fragmentation, duplication, and increased risk. The auditor should evaluate whether standards are in place and enforced, and whether they effectively balance autonomy with enterprise-wide needs.

Exam trap

The trap here is assuming that decentralization requires the elimination of central IT or that local steering committees are the key, when the real critical factor is the presence of common standards and frameworks.

681
MCQhard

During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?

A.Using automated data extraction tools
B.Performing a trial migration and reconciling the results
C.Assigning a data owner for each data field
D.Running parallel processing for one month
AnswerB

A trial migration replicates the full extract, transform and load process against a subset, then reconciles record counts and financial totals against source systems. This detects truncation, duplication and mapping errors before go-live, directly satisfying the accuracy and completeness objective.

Why this answer

A trial migration followed by reconciliation is the most effective control because it validates the accuracy and completeness of the migrated data by comparing source and target records before the final cutover. Reconciliation identifies discrepancies, missing records, and transformation errors, allowing correction before go-live. This directly addresses both accuracy and completeness.

Exam trap

CISA often tests the difference between preventive, detective, and corrective controls, and the trap is choosing a tool (automated extraction) or a responsibility assignment (data owner) instead of a detective control that actually verifies accuracy and completeness.

How to eliminate wrong answers

Option A is wrong because automated extraction tools improve efficiency but do not by themselves ensure accuracy or completeness; they can still extract incorrect or incomplete data. Option C is wrong because assigning data owners establishes accountability but does not verify that the migrated data is correct or complete. Option D is wrong because parallel processing tests the new system's outputs against the old system over time, which is more about operational readiness than validating the migration itself, and it is costly and time-consuming.

682
MCQhard

A project uses a waterfall model. After design, the team discovers that the requirements have changed significantly. What is the BEST action?

A.Cancel the project and start over
B.Update the requirements and proceed with the design revision
C.Continue with original requirements as planned
D.Switch to an agile methodology for the remainder of the project
AnswerB

Waterfall permits change only through formal revision of affected baselines. Updating the requirements and reworking the design keeps subsequent build and test phases aligned with what the business now needs, rather than continuing against obsolete specifications that would guarantee rework later.

Why this answer

In a waterfall model, each phase must be completed before the next begins, but when requirements change significantly after design, the best action is to update the requirements and revise the design. This preserves the structured, sequential nature of the waterfall while ensuring the final product meets the new needs. Canceling or ignoring changes would waste resources, and switching methodologies mid-project introduces integration risks and process discontinuity.

Exam trap

The trap here is that candidates may think switching to agile is a flexible solution, but the CISA exam tests understanding that changing development methodologies mid-project violates the waterfall's sequential phase completion and introduces significant process and documentation risks.

How to eliminate wrong answers

Option A is wrong because canceling the project and starting over is an extreme, wasteful response that ignores the possibility of revising the design to accommodate the changed requirements, which is a standard practice in waterfall when changes are identified early. Option C is wrong because continuing with the original requirements as planned would deliver a product that no longer meets the stakeholder needs, leading to rework or project failure. Option D is wrong because switching to an agile methodology mid-project disrupts the established waterfall lifecycle, introduces process mismatches (e.g., no iterative feedback loops in place), and typically requires retraining and tooling changes that delay delivery.

683
MCQmedium

An IS auditor is conducting a follow-up review of prior audit findings. Management has implemented a new automated control but has not yet updated the risk register to reflect the residual risk. Which of the following should the auditor do FIRST?

A.Verify that the new control is operating effectively through testing before concluding on residual risk.
B.Recommend that management update the risk register before any further audit work is performed.
C.Accept management's representation that the control is effective and close the finding.
D.Report to the audit committee that management has failed to maintain the risk register.
AnswerA

The auditor should first validate the design and operating effectiveness of the implemented control, since management's assertion alone is insufficient evidence. Only after testing can the auditor assess whether residual risk has actually been reduced to an acceptable level. Updating the risk register is a management responsibility, and reporting to the audit committee is premature without verification.

Why this answer

The auditor's core duty during follow-up is to independently verify that management's remediation actually works. Testing the new control provides the evidence needed to determine whether residual risk is acceptable. Only after that verification is it appropriate to consider reporting or recommending documentation updates.

Verification must precede conclusions about risk reduction.

Exam trap

The trap here is assuming that management's implementation of a control, or its representation, is itself sufficient evidence of remediation without independent testing.

684
MCQmedium

During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?

A.The organization may fail to detect an incident in a timely manner
B.The organization may not comply with regulatory reporting requirements
C.The incident response plan may be outdated
D.Employees may not know their roles during an incident
AnswerD

Without tabletop exercises, staff never rehearse incident roles, so during a real event they may duplicate effort, miss escalation steps or fail to contain the breach promptly. This directly addresses the stem's two-year gap in exercising, leaving role familiarity untested.

Why this answer

Tabletop exercises are primarily designed to validate and practice the incident response plan by walking participants through simulated scenarios, which reveals whether employees understand their roles, responsibilities, and decision-making authority during an incident. Without them, the most significant risk is that staff will be unprepared and confused when a real incident occurs, leading to delayed or ineffective response.

Exam trap

CISA often tests the distinction between detection capabilities and response readiness — candidates may incorrectly attribute detection failures to a lack of exercises when exercises actually test response roles and plan effectiveness.

How to eliminate wrong answers

Option A is wrong because incident detection depends on monitoring tools, SIEM, and alerting processes, not on tabletop exercises; exercises test response, not detection capability. Option B is wrong because regulatory reporting compliance is a documentation and process requirement that can be met without tabletop exercises; while exercises may help, the absence of exercises does not directly cause non-compliance. Option C is wrong because the plan becoming outdated is a documentation maintenance issue; tabletop exercises test the plan's effectiveness and staff readiness, but an outdated plan is a different risk than untested staff roles.

685
Multi-Selecthard

An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)

Select 2 answers
A.Implement exclusions for routine maintenance activities
B.Enable alerts for all database queries
C.Increase the sensitivity of all detection rules
D.Review alerts in real-time only
E.Define a baseline of normal user behavior
AnswersA, E

Routine maintenance generates predictable, legitimate database activity that otherwise triggers alerts. Excluding these known operations removes noise at the source, directly reducing false positives without weakening detection of genuinely anomalous behaviour, which is the tuning goal the stem specifies.

Why this answer

Option A is correct because routine maintenance activities such as backups, index rebuilds, and batch jobs generate large volumes of legitimate database traffic that would otherwise trigger alerts; creating exclusions or allowlists for these known-good operations directly reduces false positives without weakening detection of anomalous activity. Option E is correct because establishing a baseline of normal user behavior (typical query patterns, access times, source hosts, and data volumes) lets the DAM distinguish genuine deviations from benign activity, which is the foundational tuning technique for reducing false positives. Option B is incorrect because alerting on all database queries produces overwhelming noise rather than reducing false positives.

Option C is incorrect because increasing detection rule sensitivity makes rules fire more easily, which increases false positives. Option D is incorrect because real-time-only review is an operational workflow choice, not a tuning practice, and does not by itself reduce false positives.

Exam trap

The trap here is that candidates may think increasing sensitivity (Option C) improves detection, but it actually amplifies false positives, whereas the correct approach is to establish a baseline (Option E) and exclude known benign activities (Option A).

686
MCQeasy

Which of the following backup types copies only data that has changed since the last full backup?

A.Mirror backup
B.Differential backup
C.Full backup
D.Incremental backup
AnswerB

A differential backup copies all data modified since the last full backup, accumulating changes across successive runs. This directly satisfies the stem's constraint of capturing only post-full-backup changes, unlike incremental backups, which capture only changes since the previous backup of any type. Restoration therefore requires just the last full backup plus the latest differential.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of how many incremental backups have been performed. This means each differential backup contains all changes accumulated since the most recent full backup, making it larger than an incremental backup but faster to restore (requiring only the full backup plus the latest differential).

Exam trap

The trap here is that candidates often confuse 'differential' with 'incremental' because both copy changed data, but the key differentiator is the reference point: differential uses the last full backup, while incremental uses the last backup of any type.

How to eliminate wrong answers

Option A is wrong because a mirror backup creates an exact, real-time copy of the source data, often using block-level replication (e.g., RAID 1 or rsync), and does not rely on a 'last full backup' marker; it continuously synchronizes changes. Option C is wrong because a full backup copies all selected data regardless of change status, serving as the baseline for differential and incremental backups. Option D is wrong because an incremental backup copies only data that has changed since the last backup of any type (full or incremental), not specifically since the last full backup; this is the key distinction from differential backups.

687
MCQhard

An IS auditor is evaluating the use of continuous auditing techniques. Which of the following is the most significant benefit of implementing continuous monitoring over traditional periodic audits?

A.Reduced need for substantive testing
B.Elimination of control risk assessments
C.Automated generation of audit reports
D.Timely detection of control deficiencies
AnswerD

Continuous monitoring evaluates controls at frequent intervals against live data, so deviations are flagged as they emerge rather than at the next scheduled audit. This delivers timely detection of control deficiencies, directly satisfying the stem's demand for the most significant benefit over traditional periodic audits.

Why this answer

Continuous monitoring provides timely detection of control deficiencies, enabling faster remediation.

688
Multi-Selectmedium

An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)

Select 2 answers
A.The project was completed 10% over budget.
B.User acceptance testing did not include all payroll scenarios.
C.The vendor's implementation team was helpful.
D.The system's response time is slower than expected.
E.Some employees reported inaccurate pay calculations.
AnswersB, E

Incomplete user acceptance testing coverage means untested payroll scenarios, such as overtime, deductions or tax bands, may fail silently in production. This directly undermines the control evidence that the system meets requirements, so the auditor should be most concerned.

Why this answer

Option B is correct because incomplete user acceptance testing means key payroll scenarios (e.g., overtime, deductions, tax withholding, leave accrual) were never validated before go-live, so defects in those paths can reach production undetected and directly affect pay accuracy and compliance. Option E is correct because inaccurate pay calculations are a realized material failure of the system's core control objective, indicating that payroll processing, calculation logic, or data conversion is faulty and that employees, tax filings, and statutory deductions may all be wrong. These two findings are the most concerning because they strike at the integrity of payroll data and the testing that should have prevented such errors.

Option A does not belong because a 10% budget overrun is a cost-management issue, not a control or data-integrity failure. Option C does not belong because a helpful vendor team is a positive observation with no audit significance. Option D does not belong because slower-than-expected response time is a performance issue that, while worth noting, does not by itself threaten the accuracy or completeness of payroll processing.

Exam trap

CISA often tests the distinction between project management issues (budget, schedule, vendor relations) and control/risk issues (incomplete testing, data integrity failures), so candidates must prioritize findings that threaten accuracy, compliance, or control effectiveness.

689
MCQhard

A large enterprise is implementing a backup strategy for a critical database that requires an RTO of 2 hours and an RPO of 15 minutes. The database is 2 TB in size. Which backup method would BEST meet these requirements while minimizing storage costs?

A.Daily full backups
B.Continuous data protection (CDP) replicating to a remote site
C.Weekly full backups with transactional log backups every 15 minutes
D.A daily full backup and a differential backup every 4 hours
AnswerC

Transaction log backups every 15 minutes satisfy the 15-minute RPO, while weekly fulls plus log replay meet the 2-hour RTO. This combination minimises storage costs compared with frequent full or differential backups of a 2 TB database.

Why this answer

Weekly full backups with transactional log backups every 15 minutes meets the RPO of 15 minutes because logs capture all transactions since the last log backup, and meets the RTO of 2 hours because restoring the full backup plus applying log backups can be completed within that window. It minimizes storage costs compared to daily fulls or CDP because full backups are infrequent and logs are small and incremental.

Exam trap

CISA often tests the distinction between RPO and RTO and the cost implications of backup methods, so candidates who focus only on RPO pick CDP or frequent fulls without considering storage cost or RTO.

How to eliminate wrong answers

Option A is wrong because daily full backups leave up to 24 hours of data loss, violating the 15-minute RPO, and storing 2 TB daily is costly. Option B is wrong because CDP to a remote site provides near-zero RPO/RTO but is significantly more expensive in storage, bandwidth, and licensing, contradicting the requirement to minimize storage costs. Option D is wrong because differential backups every 4 hours still leave up to 4 hours of data loss, violating the 15-minute RPO, and daily fulls plus differentials consume more storage than weekly fulls plus logs.

690
Multi-Selecthard

Which THREE are indicators of a possible data exfiltration attempt via the network? (Choose three.)

Select 3 answers
A.Use of unauthorized encryption or tunneling protocols
B.Unusual outbound data transfer volumes during non-business hours
C.Increase in phishing emails targeting executives
D.Repeated access attempts to sensitive databases by unauthorized users
E.Large number of HTTPS connections to legitimate cloud services
AnswersA, B, D

Unauthorised encryption or tunnelling protocols conceal payload contents from inspection appliances, letting attackers move data past DLP and firewall controls. Legitimate services rarely introduce new tunnels, so their sudden appearance signals possible exfiltration rather than normal egress traffic.

Why this answer

Option A is correct because attackers commonly hide stolen data inside unauthorized encryption or tunneling protocols (e.g., DNS tunneling, SSH, or custom TLS on nonstandard ports) to evade content inspection and DLP controls, making it a strong network exfiltration indicator. Option B is correct because exfiltration frequently occurs during non-business hours to avoid detection, and abnormal outbound volume spikes at those times deviate from the baseline of normal traffic behavior. Option D is correct because repeated unauthorized access attempts to sensitive databases indicate an adversary probing or harvesting data, which often precedes or accompanies exfiltration over the network.

Option C is not a network exfiltration indicator; phishing emails targeting executives are an initial access or social-engineering tactic, not evidence of data leaving the network. Option E is not inherently suspicious because numerous HTTPS connections to legitimate cloud services are common in normal business operations and are only meaningful if correlated with other anomalies such as unusual volume, timing, or destination.

Exam trap

ISACA often tests the distinction between precursors to an attack (like phishing) and actual indicators of exfiltration (like unauthorized tunneling or unusual outbound volumes), so candidates mistakenly choose phishing because it is a common attack vector, but it is not a network-level exfiltration indicator.

691
Multi-Selectmedium

An IS auditor is reviewing an organization's problem management process. The auditor wants to verify that the process effectively identifies and resolves root causes of incidents. Which TWO of the following are the MOST important controls to ensure effective problem management? (Choose two.)

Select 2 answers
A.Incidents are logged with sufficient detail to allow trend analysis and identification of recurring issues.
B.Known errors are documented in a knowledge base and linked to the incidents they may cause.
C.Service level agreements (SLAs) specify penalties for missing incident resolution targets.
D.Problem tickets are automatically closed when the associated incident is resolved.
E.All changes are approved by the change advisory board (CAB) before implementation.
AnswersA, B

Detailed incident logging is essential for problem management because it enables the identification of patterns and recurring incidents. Without adequate data, root cause analysis cannot be performed effectively. This control ensures that problems are detected proactively rather than reactively, reducing downtime and improving service quality.

Why this answer

The two most important controls are detailed incident logging for trend analysis and documentation of known errors linked to incidents. These controls enable the problem management process to identify recurring issues and provide workarounds, ultimately reducing the frequency and impact of incidents. They are fundamental to effective root cause analysis and continuous improvement.

Exam trap

The trap here is confusing problem management with change management or service level management, and selecting controls that belong to those processes instead of focusing on root cause analysis.

692
MCQhard

An IS auditor is reviewing a project that replaced a legacy system. The project used a phased cutover, with each phase going live in a different region. After the final phase, the auditor finds that the legacy system was kept in read-only mode for six months, but no formal reconciliation was performed between legacy and new system balances during that period. Which of the following is the MOST significant concern?

A.Undetected data discrepancies may have persisted, and the organization may have lost the ability to correct them after the legacy system was retired.
B.The project team may have incurred unnecessary licensing and maintenance costs by keeping the legacy system available for six months.
C.The phased cutover may have caused inconsistent business processes across regions, leading to operational inefficiencies.
D.Users may have continued to access the legacy system for reporting and made decisions based on outdated information.
AnswerA

Keeping the legacy system read-only provides a reference for reconciliation, but without a formal reconciliation, differences between legacy and new balances may go unnoticed. Once the legacy system is retired, the source data needed to investigate and correct those discrepancies may no longer be available. This creates a lasting risk of inaccurate financial or operational reporting, making it the most significant concern.

Why this answer

When a legacy system remains available after cutover, it offers a baseline for verifying that the new system contains complete and accurate data. Without formal reconciliation, differences can go undetected. Retiring the legacy system then eliminates the source data needed to investigate and correct those differences.

The most significant concern is therefore the permanent loss of the ability to identify and remediate data discrepancies, which can affect financial reporting and operational decisions.

Exam trap

The trap here is focusing on cost or user access to the legacy system, when the real risk is the lost opportunity to reconcile and correct data before the source is retired.

693
MCQeasy

Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?

A.External auditors follow stricter standards.
B.External auditors have more technical expertise.
C.External auditors have access to more resources.
D.External auditors are not employees of the organization.
AnswerD

External auditors sit outside the organisation's reporting line, so they owe no employment allegiance to management and face no promotion or remuneration pressure from the audited entity. This structural separation from the chain of command directly satisfies the stem's independence constraint, unlike internal auditors who remain employees subject to management authority.

Why this answer

The primary reason external auditors are considered more independent is that they are not employees of the organization, so they have no reporting line, compensation, or career dependency on the entity being audited. This structural separation reduces the risk of bias and conflicts of interest. Internal auditors, while ideally independent in function, remain employees and therefore have an inherent organizational relationship that can impair perceived independence.

Exam trap

CISA often tests the misconception that independence derives from expertise, standards, or resources, when the fundamental driver is the absence of an employment relationship with the audited organization.

How to eliminate wrong answers

Option A is wrong because both internal and external auditors follow professional standards (IIA Standards for internal, ISACA/IFAC for external); stricter standards is not the defining factor for independence. Option B is wrong because technical expertise varies by individual and engagement, not by internal versus external status, and expertise is not the basis for independence. Option C is wrong because resource access is a practical capability, not the reason external auditors are considered more independent — an internal audit function can be well-resourced yet still lack structural independence.

694
MCQmedium

An IS auditor is evaluating the results of a penetration test performed by an external vendor on a web-facing application. The report identifies a critical SQL injection vulnerability. Which of the following is the MOST appropriate action for the IS auditor to recommend FIRST?

A.Include the finding in the audit report and schedule remediation during the next quarterly patch cycle
B.Escalate the finding to the audit committee and await their direction before recommending remediation
C.Immediately remediate or mitigate the vulnerability and validate the fix before the report is finalized
D.Repeat the penetration test with a different vendor to confirm the finding is not a false positive
AnswerC

A critical exploitable vulnerability in a web-facing application represents an immediate risk of data compromise. The auditor should recommend urgent remediation or mitigation, such as applying a patch, input validation, or a web application firewall rule, and then validate that the fix works. Addressing the exposure takes precedence over documentation and longer-term process improvements.

Why this answer

A critical SQL injection vulnerability in an internet-facing application can be exploited to access or modify data, so the priority is to remediate or mitigate it immediately and confirm the fix. Reporting, re-testing by another vendor, or waiting for governance direction are appropriate supporting activities but must not delay protection of the exposed system.

Exam trap

The trap here is allowing process steps such as report finalization, vendor confirmation, or committee escalation to take precedence over immediate containment of an actively exploitable critical vulnerability.

695
MCQmedium

Which policy hierarchy document provides detailed steps for performing a specific task, such as resetting a user password?

A.Guideline
B.Work instruction
C.Policy
D.Standard
AnswerB

A work instruction sits at the lowest level of the policy hierarchy, beneath policies, standards and procedures, and gives step-by-step operational detail for a single task. Resetting a user password is exactly that granular, task-specific level of guidance.

Why this answer

A work instruction is the most detailed document in the policy hierarchy, providing step-by-step guidance.

696
MCQmedium

During the acquisition of a new software package, the procurement team evaluates two vendors. Vendor A offers a lower upfront cost but higher annual maintenance fees. Vendor B has a higher upfront cost but includes three years of maintenance. What is the MOST important factor for the IS auditor to consider?

A.The upfront cost of each vendor.
B.The vendor's market reputation.
C.The total cost of ownership over the expected life of the system.
D.The organization's budget constraints.
AnswerC

Total cost of ownership captures acquisition plus recurring maintenance across the system's expected life, exposing Vendor A's higher annual fees against Vendor B's bundled three years. Comparing upfront price alone would mislead the auditor, since the stem deliberately trades initial cost against ongoing maintenance.

Why this answer

The IS auditor should focus on total cost of ownership (TCO) over the expected life of the system because it captures all direct and indirect costs—upfront licensing, annual maintenance, support, training, infrastructure, and eventual replacement—providing a true comparison between the two vendors. Vendor A's lower upfront cost may be misleading if higher annual maintenance fees accumulate over several years, while Vendor B's bundled three years of maintenance changes the long-term cost profile. TCO aligns with the auditor's role of evaluating the economic efficiency and value of the acquisition, not just the initial price.

Exam trap

CISA often tests the misconception that the lowest upfront cost or the vendor's reputation is the decisive factor, when the auditor's focus should be on lifecycle TCO and economic value.

How to eliminate wrong answers

Option A is wrong because upfront cost alone ignores recurring maintenance, support, and operational expenses that can dominate the lifecycle cost, leading to a misleading comparison. Option B is wrong because vendor market reputation, while relevant to risk assessment, is not the most important factor for comparing the financial and operational value of two acquisition options. Option D is wrong because budget constraints are a constraint, not the primary evaluation criterion; an auditor should first determine the true TCO and then assess affordability, rather than letting the current budget dictate the analysis.

697
MCQmedium

An organization outsources its help desk to a third-party vendor. The contract includes a service level agreement (SLA) with response times. The auditor wants to ensure that the organization can monitor vendor performance. Which clause is most important?

A.Exit strategy clause
B.Right-to-audit clause
C.Indemnification clause
D.Confidentiality clause
AnswerB

A right-to-audit clause contractually grants the organisation and its auditors access to the vendor's records, controls and facilities, enabling independent verification of SLA response times. Without it, performance monitoring relies solely on vendor self-reporting, which cannot substantiate compliance claims during audit.

Why this answer

A right-to-audit clause contractually grants the organization the authority to audit the vendor's processes, controls, and records. Without it, the organization cannot independently verify SLA compliance or vendor performance, making it the most critical clause for monitoring. It provides the legal basis for the auditor to examine vendor operations and evidence.

Exam trap

CISA often tests the misconception that SLAs alone ensure performance monitoring, when the right-to-audit clause is what legally enables verification of vendor compliance.

How to eliminate wrong answers

Option A is wrong because an exit strategy clause addresses termination and transition, not ongoing performance monitoring — it is important for continuity but does not enable audit. Option C is wrong because indemnification allocates liability for damages; it protects financially but does not provide monitoring capability. Option D is wrong because confidentiality protects data privacy but does not grant the organization the right to inspect vendor performance or verify SLA adherence.

698
MCQmedium

Which of the following types of audit evidence provides the highest level of assurance?

A.Re-performance of control procedures
B.Inquiry of process owners
C.Observation of processes
D.Inspection of documents
AnswerA

Re-performance involves the auditor independently executing the control procedure and comparing the result with the original, producing evidence generated directly by the auditor rather than the auditee. This self-generated evidence satisfies the stem's demand for the highest assurance, outranking inspection, observation and inquiry, which rely on entity personnel or documentation.

Why this answer

Re-performance provides direct evidence that a control is operating effectively.

699
MCQeasy

An organization's IT department has recently implemented a new project management methodology. The IS auditor is reviewing the project portfolio and finds that projects are prioritized based on the personal preferences of the IT director rather than strategic alignment. Which of the following is the MOST significant risk arising from this practice?

A.Projects may not align with business strategy, leading to wasted resources and missed opportunities.
B.The IT director may become overburdened with decision-making, causing project delays.
C.The organization may fail to comply with regulatory requirements for project documentation.
D.Project managers may lack clear direction, resulting in scope creep and budget overruns.
AnswerA

Prioritizing projects based on personal preferences rather than strategic alignment means IT investments may not support the organization's goals. This can result in resources being allocated to low-value projects while critical strategic initiatives are delayed or unfunded. The most significant risk is the misalignment of IT with business strategy, which undermines the value IT delivers and can lead to competitive disadvantage.

Why this answer

When IT projects are prioritized based on personal preferences instead of strategic alignment, the organization risks investing in initiatives that do not support its business goals. This can lead to wasted resources, missed market opportunities, and a failure to achieve expected benefits. The most significant risk is the misalignment between IT and business strategy, which directly impacts the organization's ability to create value and remain competitive.

Exam trap

The trap here is focusing on operational symptoms like delays or scope creep rather than the fundamental strategic misalignment that drives those symptoms.

700
MCQhard

An IS auditor is reviewing a biometric access control system used to protect a data center. The system uses fingerprint recognition and is configured so that any single enrolled user who fails three consecutive attempts is locked out and must be re-enrolled by security staff. Which of the following is the MOST significant security concern with this configuration?

A.The system does not combine biometrics with a second authentication factor.
B.The lockout and re-enrollment process creates a denial-of-service and administrative burden risk.
C.The false acceptance rate may be too high for a high-security environment.
D.Fingerprint biometrics can be affected by changes in the user's skin condition.
AnswerB

Locking out any user after three failed attempts and requiring security staff to re-enroll means an attacker or a clumsy user can repeatedly trigger lockouts, denying access to legitimate staff and consuming administrative effort. The re-enrollment requirement also depends on staff availability, so the process itself becomes an availability and operational risk that outweighs the tuning concerns in this scenario.

Why this answer

The configuration described makes repeated lockouts easy to trigger and requires security staff to re-enroll affected users, which can deny access to legitimate personnel and create an administrative bottleneck. That operational and availability exposure is more significant than general biometric tuning questions such as false acceptance rate, skin variability, or the absence of a second factor, none of which are uniquely highlighted by the configuration as described.

Exam trap

The trap here is focusing on biometric accuracy metrics like false acceptance rate when the described lockout and manual re-enrollment process is the concrete availability and administration weakness.

701
MCQmedium

During the implementation of a new ERP system, the project team discovers that the legacy system data cannot be directly migrated due to incompatible data formats. The project manager proposes building a custom script to extract, transform, and load (ETL) data. Which of the following is the BEST course of action?

A.Manually re-enter all legacy data into the new system.
B.Delay the implementation until a commercial migration tool is available.
C.Proceed with the custom ETL script after thorough testing and validation.
D.Abandon the legacy data and start fresh in the new system.
AnswerC

Custom ETL is the only viable route because the legacy formats are incompatible with direct migration. Proceeding after thorough testing and validation ensures transformed data is complete and accurate before loading, addressing the incompatibility while managing the risk inherent in bespoke extraction, transformation and load logic.

Why this answer

Building a custom ETL script is a common and acceptable approach when legacy data formats are incompatible with a new ERP system. The key is that the script must undergo thorough testing and validation to ensure data integrity, completeness, and accuracy before migration. This balances the need for timely implementation with the risk of data corruption, which can be mitigated through rigorous quality assurance processes.

Exam trap

The trap here is that candidates may assume custom scripts are inherently risky and choose to delay or abandon data, failing to recognize that with proper testing and validation, custom ETL is a standard and effective solution for incompatible data formats.

How to eliminate wrong answers

Option A is wrong because manual re-entry is error-prone, time-consuming, and impractical for large datasets, violating the principle of data integrity and efficiency in system implementation. Option B is wrong because delaying the implementation for a commercial migration tool is unnecessary when a custom ETL script can be developed and validated in a shorter timeframe, and commercial tools may still require customization for unique legacy formats. Option D is wrong because abandoning legacy data can lead to loss of critical historical records, operational continuity issues, and potential compliance violations, making it a high-risk and generally unacceptable approach.

702
MCQmedium

During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?

A.Report the increase as a finding
B.Ignore the increase if it is within budget
C.Investigate the reason for the increase
D.Expand the sample size for testing
AnswerC

A significant unexplained variance requires investigation before any conclusion is drawn, since analytical procedures identify anomalies rather than their causes. The auditor must obtain corroborating evidence, such as management explanations, supporting documentation or transaction testing, to determine whether the increase reflects error, fraud or legitimate business change.

Why this answer

Analytical procedures are used to identify unusual fluctuations that may indicate errors, fraud, or changes in the environment. A significant increase in IT expenses compared to the prior year is an unexpected variance that must be investigated to determine its cause before concluding whether it represents a finding. Only after understanding the reason can the auditor decide whether it is a reportable issue.

Exam trap

CISA often tests the misconception that any significant variance is automatically a finding, when in fact the auditor must first investigate the reason and only report it if the explanation is inadequate or indicates a control failure.

How to eliminate wrong answers

Option A is wrong because reporting the increase as a finding before investigating its cause would be premature and could result in a false positive. Option B is wrong because being within budget does not explain the variance or confirm that the expense is legitimate and properly authorized. Option D is wrong because expanding the sample size is a substantive testing response, not the appropriate next step when an analytical procedure reveals an unexplained fluctuation.

703
MCQeasy

Which physical security control is most effective for preventing unauthorized individuals from tailgating into a data center?

A.Mantrap (dual-door interlocking system).
B.Security guards at the entrance.
C.Closed-circuit television (CCTV) surveillance.
D.Biometric fingerprint readers.
AnswerA

A mantrap uses two interlocking doors so only one opens at a time, physically preventing a second person from following an authorised entrant through. This directly defeats tailgating, unlike badges, cameras or turnstiles, which detect or deter but do not physically stop it.

Why this answer

A mantrap, or dual-door interlocking system, is the most effective physical security control against tailgating because it physically isolates individuals in a small vestibule where both doors cannot be opened simultaneously. This forces authentication and verification for each person before the second door unlocks, preventing an unauthorized person from following an authorized individual through a single entry point.

Exam trap

The trap here is that candidates often choose biometric readers or CCTV because they associate them with high security, but fail to recognize that tailgating exploits the gap between authentication and physical passage, which only a mantrap's interlocking doors can mechanically enforce.

How to eliminate wrong answers

Option B is wrong because security guards, while useful for monitoring and deterrence, are prone to human error, distraction, or social engineering, and cannot guarantee prevention of tailgating in high-traffic scenarios. Option C is wrong because CCTV surveillance is a detective control that records events for after-the-fact review, not a preventive control that stops tailgating in real time. Option D is wrong because biometric fingerprint readers authenticate identity but do not prevent a second person from entering immediately after an authorized user without their own authentication.

704
MCQeasy

Refer to the exhibit. A CISA is reviewing this S3 bucket policy. What is the PRIMARY security concern?

A.The bucket is configured for public read access
B.Encryption is not enforced on the bucket
C.The policy allows unauthorized write access
D.Versioning is not enabled on the bucket
AnswerA

The bucket policy grants read permission to a wildcard principal, meaning any unauthenticated internet user can list and download objects. Public read access exposes the data regardless of other settings, making it the primary concern.

Why this answer

The bucket policy explicitly grants `s3:GetObject` to `Principal: "*"` with `Effect: "Allow"`, which means any unauthenticated user on the internet can read objects in the bucket. This is a classic misconfiguration that leads to public read access, exposing sensitive data. While encryption and versioning are important security controls, the immediate and most severe risk is unauthorized data disclosure via public read.

Exam trap

ISACA often tests the distinction between 'public read' and 'public write' — candidates may incorrectly assume the policy allows write access because it uses `"*"`, but the action is specifically `s3:GetObject`, so only read is permitted.

How to eliminate wrong answers

Option B is wrong because the policy does not mention encryption at all; while encryption enforcement is a best practice, the policy's explicit public read grant is a more direct and critical security concern. Option C is wrong because the policy only grants `s3:GetObject` (read) and does not include `s3:PutObject` or any write action, so unauthorized write access is not permitted by this policy. Option D is wrong because versioning is a data protection and recovery feature, not a security control that prevents unauthorized access; the lack of versioning does not create an immediate exposure risk like public read does.

705
MCQmedium

During a problem management meeting, the team identifies a recurring issue causing multiple incidents. The root cause is known, but a permanent fix is not yet available. Which of the following is the BEST approach to manage this situation until a permanent fix is implemented?

A.Escalate the problem to senior management
B.Reclassify the problem as an incident
C.Document the known error and implement a workaround
D.Close the problem record and wait for the fix
AnswerC

Recording the fault in the known error database with a documented workaround lets the service desk resolve recurrences quickly while the permanent fix is developed. This satisfies the stem's constraint that the root cause is known but no permanent fix yet exists.

Why this answer

In ITIL-based problem management, when a root cause is known but a permanent fix is unavailable, the known error should be documented in the Known Error Database (KEDB) and a workaround should be implemented to reduce incident impact and restore service. This aligns with the problem management process of controlling the error until a permanent solution (e.g., a patch or change) is deployed, ensuring operational continuity and minimizing recurrence of incidents.

Exam trap

The trap here is that candidates confuse 'problem' with 'incident' and think reclassifying (Option B) is acceptable, but the CISA exam tests the ITIL distinction that a problem is the root cause of multiple incidents and must be managed separately, not reclassified as an incident.

How to eliminate wrong answers

Option A is wrong because escalating to senior management is not the best operational step for a known error with a workaround; escalation is reserved for strategic decisions, resource approval, or when the problem exceeds the team's authority, not for routine workaround implementation. Option B is wrong because reclassifying a problem as an incident violates the ITIL distinction: a problem is the underlying cause of one or more incidents, and reclassifying it would incorrectly treat the root cause as a single event, bypassing proper problem management tracking. Option D is wrong because closing the problem record while waiting for a fix would remove visibility and control, preventing the team from applying the workaround and potentially allowing the same incidents to recur without a documented resolution path.

706
MCQhard

An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?

A.Systematic sampling
B.Judgmental sampling
C.Stratified sampling
D.Statistical attribute sampling
AnswerD

Statistical attribute sampling quantifies the exception rate against a defined confidence level and tolerable deviation rate, letting the auditor conclude on the 5,000-item population with measurable precision. Judgemental or block methods cannot support the stated 95% confidence and 2% tolerable error.

Why this answer

Statistical attribute sampling is the most appropriate method when the auditor wants to achieve a specified confidence level and tolerable error rate for a control that has a binary outcome (exception or no exception). It allows the auditor to project the exception rate to the population and conclude whether the control is operating effectively within the tolerable deviation rate.

Exam trap

CISA often tests the confusion between statistical and non-statistical sampling, and between attribute and variables sampling, causing candidates to choose stratified or systematic sampling when the question specifies confidence level and tolerable error rate for a control test.

How to eliminate wrong answers

Option A is wrong because systematic sampling selects every nth item and does not by itself provide a statistical basis for projecting error rates with a specified confidence level. Option B is wrong because judgmental sampling relies on auditor judgment rather than statistical probability, so it cannot support a quantified confidence level and tolerable error rate. Option C is wrong because stratified sampling divides the population into subpopulations and samples each, which is useful for reducing variability but is not the primary method for attribute testing with a specified confidence and tolerable error rate.

707
MCQeasy

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental backups, and is often used to reduce restore time?

A.Full backup
B.Differential backup
C.Incremental backup
D.Mirror backup
AnswerB

A differential backup copies every change since the last full backup, accumulating successive modifications regardless of intervening incremental runs. This cumulative approach means only the latest full plus one differential are needed for restore, reducing restore time compared with incremental chains.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any incremental backups taken in between. This approach reduces restore time because only the last full backup and the most recent differential backup are needed, unlike incremental backups which require the full backup plus every subsequent incremental in sequence.

Exam trap

The trap here is confusing differential backups with incremental backups, as both copy only changed data, but the key distinction is that differentials copy all changes since the last full backup, while incrementals copy changes since the last backup of any type, leading to longer restore chains for incrementals.

How to eliminate wrong answers

Option A is wrong because a full backup copies all data, not just changed data, and is typically the baseline for other backup types, not a method to reduce restore time by copying only changes. Option C is wrong because an incremental backup copies only data changed since the last backup of any type (full, differential, or incremental), requiring the full backup plus all subsequent incremental backups for restore, which increases restore time. Option D is wrong because a mirror backup creates an exact replica of the source data in real-time or near-real-time, often using disk mirroring (e.g., RAID 1), and does not focus on copying only changed data since the last full backup; it is designed for high availability, not backup efficiency or restore time reduction.

708
MCQeasy

An IT auditor is reviewing capacity management. The server team monitors CPU utilization and disk space. They receive alerts when thresholds are exceeded. Which practice is most effective for proactive capacity planning?

A.Performing weekly manual checks
B.Analyzing historical utilization trends
C.Increasing server resources quarterly
D.Setting threshold alerts at 90% utilization
AnswerB

Analysing historical utilisation trends reveals growth patterns and seasonal peaks, allowing capacity to be provisioned before thresholds are breached. Threshold alerts are reactive, firing only once consumption is already excessive, whereas trend analysis supports genuine proactive forecasting and planning.

Why this answer

Analyzing historical utilization trends allows the team to identify growth patterns, seasonal peaks, and long-term capacity exhaustion points before thresholds are breached. This is the essence of proactive capacity planning: using past data to predict future demand rather than reacting to alerts. Threshold alerts and manual checks are reactive or operational, not strategic planning practices.

Exam trap

CISA often tests the difference between proactive and reactive controls — candidates pick threshold alerts because they sound like monitoring best practice, but alerts are reactive detection, not proactive planning.

How to eliminate wrong answers

Option A is wrong because weekly manual checks are a reactive operational task that detects current state but does not forecast future capacity needs or identify trends. Option C is wrong because increasing server resources quarterly on a fixed schedule is arbitrary and not based on actual demand data, which can lead to over-provisioning or under-provisioning. Option D is wrong because setting threshold alerts at 90% utilization is a reactive monitoring control that only notifies after the system is already approaching exhaustion, not a proactive planning technique.

709
MCQhard

During a follow-up audit, an IS auditor finds that management implemented a compensating control rather than the recommended primary control to address a previously reported high-risk finding. The residual risk is now within the organization's risk appetite. How should the IS auditor respond?

A.Evaluate whether the compensating control adequately mitigates the risk and close the finding if it does.
B.Escalate the matter to the audit committee because a compensating control was used.
C.Document that management accepted the risk without implementing the recommended control.
D.Reopen the original finding because the recommended control was not implemented as specified.
AnswerA

The auditor's responsibility is to assess whether the implemented control reduces risk to an acceptable level, regardless of whether it matches the original recommendation. If the compensating control adequately mitigates the risk and residual risk falls within the risk appetite, the finding can be closed. This reflects the principle that management owns risk response while the auditor provides objective assurance on the outcome.

Why this answer

Audit recommendations describe a desired risk outcome, not a mandatory control design. When management implements a compensating control that reduces residual risk to within the organization's risk appetite, the auditor should evaluate whether that control adequately mitigates the risk and close the finding if it does. Reopening, escalating, or mislabeling the response as risk acceptance would misrepresent the outcome and ignore management's ownership of risk.

Exam trap

The trap here is treating the original recommendation as a binding requirement, when in fact management may satisfy the underlying risk reduction through an alternative compensating control.

710
Multi-Selectmedium

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Select 2 answers
A.Performing daily IT operations
B.Defining IT security policies
C.Approving IT project budgets and priorities
D.Conducting technical vulnerability assessments
E.Ensuring IT investments deliver value
AnswersC, E

Approving IT project budgets and priorities is a primary steering committee duty, since the committee allocates resources and sequences projects to match business objectives. This governance decision keeps investment aligned with strategy rather than departmental preference.

Why this answer

Option C is correct because an IT steering committee is a governance body that reviews and approves IT project budgets and sets project priorities, ensuring that funding and sequencing decisions align with business strategy rather than being left to operational teams. Option E is correct because a core governance responsibility is ensuring IT investments deliver value, which the committee accomplishes by monitoring benefits realization, tracking ROI, and holding IT accountable for outcomes tied to business objectives. Options A, B, and D do not belong: performing daily IT operations (A) is an operational/IT operations function, defining IT security policies (B) is typically delegated to a security governance or CISO function (the steering committee may endorse them but does not author them), and conducting technical vulnerability assessments (D) is a hands-on technical security task performed by security engineers or analysts, not a governance committee.

Exam trap

CISA often tests the distinction between governance (setting direction, approving budgets, ensuring value) and management (executing operations, writing policies, running scans) — candidates who pick operational-sounding options confuse the two layers.

711
MCQmedium

A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:

A.Increase the frequency of security reviews for all projects
B.Change the IT steering committee's meeting frequency to weekly with detailed reviews
C.Establish a project management office (PMO) to oversee project governance and reporting
D.Require all projects to use a specific project management software tool
AnswerC

A PMO establishes standardised project governance, oversight and reporting, directly addressing the unclear requirements, scope creep and high-level-only reviews causing overruns. It satisfies the need for project-level governance discipline that the existing framework lacks, rather than merely refining committee structure.

Why this answer

Establishing a project management office (PMO) provides standardized project management practices, oversight, and controls to prevent scope creep and improve delivery. Option A is tactical and focuses on security, not project delivery. Option B changes meeting frequency but does not establish a dedicated project governance function.

Option D mandates a tool but does not address underlying governance processes.

712
MCQmedium

An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?

A.Stratified sampling
B.Random sampling
C.Systematic sampling
D.Judgmental sampling
AnswerB

Random sampling gives every transaction in the 1,000-item population an equal, non-zero chance of selection, which the random number generator enforces. This satisfies the stem's requirement for a statistically valid, unbiased sample, unlike haphazard or judgmental methods, and supports extrapolating the 50-transaction results to the full population.

Why this answer

Using a random number generator to select 50 transactions from a population of 1,000 is the definition of random sampling, where every item in the population has an equal chance of being selected. This method is a form of statistical sampling that supports projection of results to the population.

Exam trap

CISA often tests the distinction between random sampling and systematic sampling, where candidates confuse the use of a random number generator with systematic selection, or incorrectly associate random sampling with stratified or judgmental methods.

How to eliminate wrong answers

Option A is wrong because stratified sampling involves dividing the population into homogeneous subgroups and sampling from each, which is not described here. Option C is wrong because systematic sampling selects every nth item after a random start, not via a random number generator applied to the entire population. Option D is wrong because judgmental sampling relies on the auditor's judgment to select items, not on random selection.

713
MCQeasy

Which COBIT 2019 governance objective describes the board's responsibility for overseeing IT?

A.Deliver, Service, and Support (DSS)
B.Align, Plan, and Organize (APO)
C.Evaluate, Direct, and Monitor (EDM)
D.Build, Acquire, and Implement (BAI)
AnswerC

The Evaluate, Direct and Monitor domain covers the governing body's own responsibilities, including evaluating options, directing the entity and monitoring performance. It is the governance objective describing board-level oversight of IT, distinct from the management objectives.

Why this answer

COBIT 2019 defines the governance objective as Evaluate, Direct, and Monitor (EDM), which is the board's responsibility.

714
MCQeasy

What is the primary purpose of the planning phase in an IS audit?

A.To execute audit tests
B.To issue the final report
C.To identify risks and define audit scope
D.To follow up on findings
AnswerC

The planning phase establishes the audit's foundation by assessing inherent and control risks, then using that risk assessment to define scope, objectives, criteria and resource allocation, ensuring fieldwork concentrates effort on the areas of greatest significance to the organisation.

Why this answer

The planning phase of an IS audit is where the auditor defines the audit objectives, identifies and assesses risks, determines the scope and criteria, and develops the audit program. This foundational phase ensures that the audit is focused on the areas of greatest risk and that resources are allocated effectively.

Exam trap

CISA often tests the sequence of audit phases, and candidates may confuse planning with fieldwork by selecting 'execute audit tests' or with reporting by selecting 'issue the final report' when asked about the primary purpose of planning.

How to eliminate wrong answers

Option A is wrong because executing audit tests occurs during the fieldwork phase, not planning. Option B is wrong because issuing the final report happens in the reporting phase, after fieldwork and review. Option D is wrong because following up on findings is part of the post-audit or follow-up phase, not planning.

715
Multi-Selecteasy

Which TWO of the following are primary objectives of information classification? (Choose two.)

Select 2 answers
A.Simplify network architecture by segmenting data.
B.Determine appropriate access controls and protection requirements.
C.Improve system performance by prioritizing critical data.
D.Ensure compliance with legal and regulatory requirements.
E.Reduce storage costs by identifying duplicate data.
AnswersB, D

Classification assigns sensitivity labels that directly drive which access controls and protection mechanisms apply, satisfying the stem's requirement to identify primary objectives. By mapping data sensitivity to handling rules, it ensures controls such as encryption and permissions match the data's value and risk, rather than being applied uniformly.

Why this answer

Information classification is the process of labeling data based on its sensitivity and value, and its primary objectives include determining the appropriate access controls and protection requirements (B) — once data is classified (e.g., public, internal, confidential, secret), the organization can apply matching controls such as encryption, RBAC permissions, and handling procedures. It also ensures compliance with legal and regulatory requirements (D), because frameworks like GDPR, HIPAA, PCI DSS, and ISO/IEC 27001 mandate that data be categorized so that mandated safeguards and retention rules can be applied to each class. The remaining options do not belong: network segmentation (A) is a security architecture technique that may follow from classification but is not a primary objective of it, performance prioritization (C) is a QoS/operations concern unrelated to classification's purpose, and deduplication for storage savings (E) is a data-management/storage optimization activity, not a classification objective.

Exam trap

The trap here is that candidates confuse the secondary benefits of classification (like improved storage management or network design) with its primary objectives, which are strictly about determining protection requirements and ensuring compliance.

716
MCQhard

An IS auditor is evaluating the disaster recovery plan (DRP) for a organization that relies on a cloud-based ERP system. The DRP states that the recovery time objective (RTO) is 4 hours and the recovery point objective (RPO) is 1 hour. The cloud provider's SLA guarantees 99.9% availability but does not specify RTO or RPO. Which of the following should the auditor recommend FIRST?

A.Develop an internal disaster recovery site to eliminate reliance on the cloud provider.
B.Obtain a contractual commitment from the cloud provider that includes specific RTO and RPO guarantees.
C.Increase the frequency of backup testing to ensure the RPO can be met.
D.Implement a secondary cloud region for real-time replication to achieve the RPO.
AnswerB

The organization's DRP depends on the cloud provider's recovery capabilities, but the SLA does not define RTO/RPO. Without contractual guarantees, the organization cannot ensure that its own RTO/RPO will be met. The auditor should first recommend renegotiating the contract to include these critical metrics, as they are foundational to the DRP.

Why this answer

The correct answer is to obtain a contractual commitment from the cloud provider that includes specific RTO and RPO guarantees. The organization's DRP is based on assumptions about the provider's recovery capabilities that are not backed by the SLA. Without contractual assurance, the organization cannot demonstrate that its RTO/RPO will be achieved.

This is the foundational step before considering technical or architectural changes.

Exam trap

The trap here is jumping to technical solutions like a secondary region or internal DR site without first addressing the missing contractual guarantees, which are the root cause of the risk.

717
MCQmedium

During an audit of an organization's backup and recovery process, the IS auditor finds that full backups are performed weekly and incremental backups are performed nightly. Restoration testing has not been performed in over two years. Which of the following should the auditor do FIRST?

A.Perform or observe a restoration test to evaluate the effectiveness of the backups
B.Review the backup logs to confirm that nightly jobs completed without error
C.Recommend that management immediately increase the frequency of full backups
D.Report the absence of restoration testing as a high-risk finding in the audit report
AnswerA

The most persuasive evidence about whether backups can actually be restored is a restoration test. Performing or observing a test allows the auditor to verify that the backup media are readable, that the recovery procedures work, and that recovery time objectives are realistic. This direct evidence supports a reliable conclusion about the control's operating effectiveness, which is exactly what the auditor needs before deciding whether a finding is warranted.

Why this answer

The key question is whether the backups can actually be restored, and the most persuasive evidence is a restoration test. Performing or observing a test verifies media readability, procedure effectiveness, and recovery objectives. Reporting a finding, changing backup frequency, or reviewing logs address related but different concerns and do not directly demonstrate restoration capability, so they are not the appropriate first action.

Exam trap

The trap here is treating successful backup job logs as proof that recovery will work, when only an actual restoration test demonstrates recoverability.

718
MCQhard

During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?

A.Non-compliance with software licensing
B.Increased likelihood of security breaches
C.Inability to calculate total cost of ownership
D.Uncertainty regarding recovery time objectives for critical systems
AnswerD

Without a BIA, the organisation cannot determine maximum tolerable downtime or derive recovery time objectives for critical systems. That gap leaves recovery priorities and continuity requirements undefined, making uncertainty over RTOs the most significant risk identified.

Why this answer

A business impact analysis (BIA) is essential for identifying critical business functions and determining recovery time objectives (RTOs) and recovery point objectives (RPOs). Without a BIA, the organization lacks a clear understanding of how long systems can be down and what data loss is acceptable, leading to uncertainty in recovery planning. This is the most significant risk because it directly affects the ability to recover from disruptions.

Exam trap

CISA often tests the misconception that a BIA is primarily about security or compliance, when its core purpose is to determine recovery objectives and business impact.

How to eliminate wrong answers

Option A is wrong because software licensing non-compliance is a legal and financial risk, but it is not directly related to the absence of a BIA. Option B is wrong because while security breaches are a risk, a BIA does not directly prevent them; it focuses on recovery. Option C is wrong because total cost of ownership is a financial metric, not a primary outcome of a BIA, which is more about recovery objectives.

719
Multi-Selectmedium

An IS auditor is reviewing the software asset management (SAM) process. The organization uses a mix of commercial off-the-shelf (COTS) and open-source software. The auditor finds that several servers are running end-of-life (EOL) operating systems that are no longer patched. Which TWO risks are most directly associated with this finding?

Select 2 answers
A.Increased risk of security breaches due to unpatched vulnerabilities.
B.Difficulty in integrating with newer systems.
C.Non-compliance with regulatory requirements for patching.
D.Reduced performance due to outdated software.
E.Higher software licensing costs.
AnswersA, C

End-of-life operating systems no longer receive vendor security patches, so known vulnerabilities remain exploitable indefinitely. This directly increases the likelihood of security breaches through unpatched flaws, satisfying the stem's request for the risk most directly associated with running unpatched EOL servers.

Why this answer

Option A is correct because EOL operating systems no longer receive vendor security patches, so known vulnerabilities (e.g., unpatched CVEs) remain exploitable, directly raising the likelihood of security breaches, malware infection, and unauthorized access. Option C is correct because many regulatory and compliance frameworks (e.g., PCI DSS, HIPAA, ISO 27001) mandate timely patching and vulnerability management; running unpatched EOL systems constitutes a direct compliance violation subject to audit findings, fines, or loss of certification. Option B is not the most direct risk, since integration difficulty is an operational/interoperability concern rather than the primary consequence of missing patches.

Option D is not directly tied to EOL status, as reduced performance stems from hardware or software age, not the absence of security patches. Option E is unrelated, because licensing costs depend on contract terms and usage, not on whether an OS is EOL or unpatched.

Exam trap

The trap here is that candidates may confuse operational issues (like integration difficulty or performance) with the primary security and compliance risks that directly stem from unpatched vulnerabilities on EOL systems.

720
MCQhard

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation, and success depends on individual heroics. Which of the following maturity levels BEST describes this situation?

A.Level 3 – Defined
B.Level 0 – Incomplete
C.Level 2 – Managed
D.Level 1 – Initial
AnswerD

Level 1 in COBIT 2019 is characterized by ad hoc processes, lack of documentation, and reliance on individual efforts. The scenario describes exactly this: no formal processes and success dependent on heroics. This is the lowest maturity level, indicating that governance is unstructured and unpredictable.

Why this answer

COBIT 2019 defines maturity levels from 0 to 5. Level 1 (Initial) is assigned when processes are ad hoc and undocumented, and success depends on individual competence. This matches the scenario precisely.

Higher levels require increasing degrees of planning, documentation, and standardization, which are not present here.

Exam trap

The trap here is confusing Level 1 with Level 0; Level 0 means processes are not performed at all, while Level 1 means they are performed but informally.

721
Multi-Selectmedium

An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)

Select 2 answers
A.Data ownership clause
B.Indemnification clause
C.Audit rights
D.Service level agreements (SLAs)
E.Non-disclosure agreement (NDA)
AnswersC, D

Audit rights grant the organisation contractual authority to inspect vendor controls, logs and processes, directly satisfying the stem's requirement to monitor vendor security. Without this clause, assurance relies on vendor self-reporting, which is insufficient for a critical cloud ERP system.

Why this answer

Option C (Audit rights) is correct because it contractually grants the organization the ability to inspect, assess, and verify the vendor's security controls, processes, and compliance — for example through on-site audits, penetration test reports, or SOC 2 evidence — which is essential for ongoing security monitoring of a critical ERP system. Option D (Service level agreements (SLAs)) is correct because SLAs define measurable performance and availability commitments (e.g., uptime percentages, response and resolution times, penalties for misses), giving the organization the metrics and remedies needed to monitor vendor performance. Option A (Data ownership clause) is not correct here because it establishes who owns the data rather than providing a monitoring mechanism.

Option B (Indemnification clause) is not correct because it allocates financial/legal liability after a loss rather than enabling performance or security oversight. Option E (Non-disclosure agreement (NDA)) is not correct because it protects confidentiality of shared information but does not by itself provide performance or security monitoring rights.

Exam trap

CISA often tests the distinction between contractual clauses that enable monitoring (audit rights, SLAs) and those that address other concerns (ownership, indemnification, confidentiality), so candidates must focus on the specific objective of monitoring performance and security.

722
MCQmedium

Based on the exhibit, what is the most likely control weakness that allowed this condition?

A.Weak password complexity requirements
B.Lack of individual accountability for privileged actions
C.Failure to disable the default administrator account
D.Inadequate segregation of duties between IT and security teams
AnswerB

Shared privileged accounts let multiple administrators act under one identity, so audit logs cannot attribute a specific change to a named person. This directly satisfies the stem's condition: the exhibit shows activity that cannot be traced to an individual, defeating non-repudiation and least-privilege monitoring over privileged actions.

Why this answer

The exhibit shows that multiple users are sharing a single privileged account (e.g., 'root' or 'admin') to perform administrative actions. Without unique user IDs for each administrator, it is impossible to map specific actions (e.g., a 'sudo' command or a configuration change) back to an individual. This lack of individual accountability is the core control weakness, as it violates the audit principle of non-repudiation and prevents effective forensic investigation.

Exam trap

The trap here is that candidates confuse 'shared accounts' with 'default accounts' (Option C) or 'weak passwords' (Option A), but the exhibit's key indicator is multiple users logging in with the same non-default privileged account, which directly points to a lack of individual accountability.

How to eliminate wrong answers

Option A is wrong because weak password complexity requirements would allow brute-force attacks, but the exhibit shows shared credentials, not a password cracking scenario. Option C is wrong because failure to disable the default administrator account is a specific vulnerability (e.g., leaving the 'sa' account enabled in SQL Server), but the exhibit indicates multiple users actively using a shared account, not a dormant default account. Option D is wrong because inadequate segregation of duties between IT and security teams would involve conflicting roles (e.g., a network admin also managing firewall rules), but the exhibit focuses on shared credentials, not role separation.

723
MCQhard

An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?

A.Missing dependency management in job scheduling.
B.Insufficient capacity management to handle job load.
C.Inadequate rerun procedures for the failed job.
D.Lack of a known error database entry for this issue.
AnswerA

Dependency management prevents a job from starting until its prerequisite completes successfully. Its absence let the batch job run against unmet dependencies and fail silently, which is the root weakness; alerting alone would only report the symptom after the scheduling logic had already misfired.

Why this answer

The job failed because it ran before its prerequisite job completed, which is a classic dependency management failure in job scheduling. The scheduler should have enforced the dependency so the downstream job waits for the upstream job's successful completion. The absence of an alert is a secondary symptom of the same missing control, but the root control weakness is the lack of dependency management.

Exam trap

CISA often tests root cause versus symptom — candidates pick the missing alert or rerun procedure because they are visible symptoms, but the question asks for the most significant control weakness, which is the missing dependency management.

How to eliminate wrong answers

Option B is wrong because insufficient capacity management would cause jobs to run slowly or time out due to resource contention, not fail because a predecessor job had not finished. Option C is wrong because inadequate rerun procedures address recovery after a failure, not the root cause of why the job ran prematurely in the first place. Option D is wrong because a known error database entry is a problem management artifact that documents known issues and workarounds; its absence does not cause the job to fail and is not the most significant control weakness in this scenario.

724
MCQeasy

Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?

A.The backup job was scheduled during peak hours causing timeout
B.The destination path '\\BackupServer01\Backup\Shares' is invalid
C.A file in the source volume was moved or deleted during the backup window
D.Insufficient disk space on the backup destination
AnswerC

A missing file error during backup typically means the source file was moved or deleted mid-window, so the backup agent could no longer read it. This differs from media failure, which reports write or read errors on the target, and from permission changes, which produce access-denied messages.

Why this answer

The error indicates a failed backup due to a missing file. The most likely cause is that a file in the source volume was moved or deleted during the backup window. Backup processes that use file-level snapshots or open-file managers (e.g., Volume Shadow Copy Service on Windows) capture a point-in-time view; if a file is moved or deleted after the snapshot is taken but before it is read by the backup agent, the backup will fail with a 'missing file' error.

This is a classic race condition in file-level backups without proper snapshot consistency.

Exam trap

The trap here is that candidates may confuse a 'missing file' error with a destination path issue or resource constraint, but the error message specifically points to a source-side file inconsistency, not a connectivity or capacity problem.

How to eliminate wrong answers

Option A is wrong because a timeout due to peak hours would typically produce a 'timeout' or 'operation aborted' error, not a 'missing file' error. Option B is wrong because an invalid destination path would cause a 'path not found' or 'access denied' error at the start of the backup, not a mid-backup missing file error. Option D is wrong because insufficient disk space on the destination would generate a 'disk full' or 'out of space' error, not a 'missing file' error.

725
MCQhard

During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?

A.The IR team may not have adequate forensic capabilities
B.The exercises are not conducted quarterly
C.The IR team is not following the defined procedures
D.The IR plan may not address all relevant incident types
AnswerD

Restricting tabletop scenarios to malware outbreaks leaves the IR plan untested against other plausible incidents, such as insider misuse, denial of service or data breach. The plan's coverage of relevant incident types therefore remains unverified.

Why this answer

If tabletop exercises only cover malware outbreaks, the incident response plan may not be validated against other relevant incident types such as ransomware, insider threats, DDoS, or data breaches. The greatest concern is that the IR plan has untested gaps for scenarios the organization is likely to face. This is a coverage and validation issue, not a frequency or capability issue.

Exam trap

CISA often tests the difference between frequency and coverage — candidates pick 'not quarterly' because it sounds like a control gap, but the real issue is that limited scenario coverage leaves the IR plan unvalidated for other incident types.

How to eliminate wrong answers

Option A is wrong because forensic capability is a specific technical skill set, and the scenario does not provide evidence that forensics are inadequate; the concern is scenario coverage, not forensic proficiency. Option B is wrong because quarterly exercises are a frequency preference, not a control requirement; annual exercises can be adequate if scenarios are comprehensive, so frequency alone is not the greatest concern. Option C is wrong because the scenario states the team conducts exercises, which implies they are following the exercise process; there is no evidence they are deviating from defined procedures.

726
MCQeasy

An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?

A.Perform reconciliation of total record counts and key field sums before and after conversion.
B.Implement encryption for data in transit during migration.
C.Conduct user acceptance testing on the new system.
D.Ensure data mapping documents are approved by business owners.
AnswerA

Reconciliation of record counts and key field sums verifies completeness and accuracy by comparing source and target totals. This detective control directly confirms that no records were lost, duplicated or corrupted during conversion, satisfying the data integrity objective.

Why this answer

Reconciliation of total record counts and key field sums before and after conversion is the most direct control to ensure data integrity during data conversion. It verifies that all records were transferred and that key values (e.g., totals, hashes) match, detecting any loss or alteration. While encryption, UAT, and data mapping are important, they do not provide the same level of assurance that the data itself is complete and accurate after conversion.

Exam trap

CISA often tests the difference between preventive controls (encryption, mapping) and detective controls (reconciliation); candidates may choose UAT or mapping because they sound thorough, but reconciliation is the most direct integrity check.

How to eliminate wrong answers

Option B is wrong because encryption for data in transit protects data from interception during migration but does not verify that the data was correctly converted or that no records were lost or altered. Option C is wrong because user acceptance testing validates functionality and business fit but may not catch subtle data integrity issues like missing records or incorrect values. Option D is wrong because approved data mapping documents ensure the mapping logic is correct in design, but they do not confirm that the actual conversion executed correctly; reconciliation provides that verification.

727
MCQhard

An IS auditor is evaluating the IT governance structure of a multinational corporation. The auditor finds that IT decisions are made independently by regional business units, with no central oversight. The corporate IT strategy exists but is not enforced. Which of the following is the MOST likely consequence of this governance approach?

A.Increased agility and faster response to local market needs.
B.Duplication of IT resources and inability to achieve economies of scale.
C.Enhanced innovation from diverse regional approaches.
D.Improved compliance with local regulations due to regional autonomy.
AnswerB

Without central oversight, regional units may independently procure and manage IT resources, leading to redundant systems, duplicated efforts, and lost opportunities for standardization and cost savings. This fragmentation is a classic risk of uncoordinated decentralization. The corporate IT strategy is not enforced, so there is no mechanism to align regional decisions with enterprise goals, making duplication and inefficiency the most likely outcome.

Why this answer

The most likely consequence is duplication of IT resources and inability to achieve economies of scale. When regional units make independent IT decisions without central oversight or enforcement of a corporate strategy, they often procure redundant systems and fail to leverage enterprise-wide contracts or shared services. This fragmentation increases costs, complicates integration, and undermines the ability to achieve strategic alignment, making it the most significant governance risk.

Exam trap

The trap here is focusing on potential benefits of decentralization, such as agility or innovation, while overlooking the governance risk of uncoordinated decision-making that leads to duplication and inefficiency.

728
MCQmedium

An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are only created after a major incident, and there is no proactive analysis of incident trends to identify underlying problems. Which of the following is the MOST likely consequence of this approach?

A.Recurring incidents will continue because their root causes are not identified and eliminated.
B.The incident management process will be unable to meet service level agreements for incident resolution.
C.Known errors will be documented and workarounds will be available for all incidents.
D.The change management process will be bypassed to implement fixes for recurring incidents.
AnswerA

Without proactive problem management, the organization reacts only to major incidents, leaving chronic issues unresolved. Recurring incidents will persist, consuming resources and potentially causing service disruptions. The auditor should highlight this as the primary consequence because problem management aims to prevent incidents by addressing root causes. The lack of trend analysis means minor incidents that collectively indicate a larger problem are ignored, leading to a cycle of repeated failures.

Why this answer

Proactive problem management analyzes incident trends to identify and resolve root causes before they cause major disruptions. Without it, recurring incidents persist because underlying problems are never addressed. The most likely consequence is therefore the continuation of recurring incidents, which can erode service quality and consume operational resources.

The other options either describe unrelated impacts or positive outcomes that would not result from this weakness.

Exam trap

The trap here is confusing problem management with incident management; problem management is proactive and aims to prevent incidents, while incident management is reactive and aims to restore service quickly.

729
MCQeasy

Which of the following is a principle of ISO/IEC 38500 for corporate governance of IT?

A.Start where you are
B.Optimise and automate
C.Strategy
D.Focus on value
AnswerC

ISO/IEC 38500 defines six principles for IT governance, one of which is "Strategy," requiring that IT plans align with and support the organisation’s current and future business objectives. This satisfies the stem’s constraint of identifying a governance principle, as distinct from frameworks like COBIT or ITIL that focus on management processes or service delivery.

Why this answer

ISO/IEC 38500 outlines six principles: responsibility, strategy, acquisition, performance, conformance, and human behavior.

730
MCQmedium

An IS auditor is reviewing a project to implement a new customer relationship management (CRM) system. The project manager has created a work breakdown structure (WBS) and a Gantt chart. Which of the following should the auditor verify to ensure the project schedule is realistic?

A.The project manager has used project management software to create the schedule.
B.The schedule includes contingency reserves for known risks.
C.The WBS includes all deliverables and the Gantt chart reflects dependencies and resource availability.
D.The project budget is aligned with the schedule and approved by the steering committee.
AnswerC

A realistic schedule depends on a complete WBS that captures all deliverables and a Gantt chart that accurately models task dependencies and resource constraints. Without this, the schedule may be optimistic. The auditor should verify that the WBS is comprehensive and that the Gantt chart reflects logical sequencing and resource calendars, ensuring the timeline is achievable.

Why this answer

A realistic project schedule requires a complete work breakdown structure that captures all deliverables and a Gantt chart that accurately reflects task dependencies and resource availability. Without these elements, the schedule may be unachievable. The auditor should focus on the schedule's underlying assumptions and structure rather than ancillary factors like budget approval or software usage.

Exam trap

The trap here is assuming that a detailed Gantt chart alone guarantees a realistic schedule, without verifying that the WBS is complete and dependencies are correctly modeled.

731
MCQmedium

An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?

A.Walkthrough
B.Re-performance
C.Inquiry
D.Observation
AnswerA

A walkthrough is itself the audit procedure being executed; the auditor traces transactions through the accounts payable process to confirm controls operate as described. This satisfies the stem directly, as the procedure's name matches the activity performed.

Why this answer

A walkthrough is an audit procedure where the auditor traces a transaction or process from start to finish, often by interviewing personnel and inspecting documents, to understand the flow of transactions and the design of controls. Performing a walkthrough of the accounts payable process is precisely executing a walkthrough procedure.

Exam trap

CISA often tests the distinction between walkthrough, inquiry, observation, and re-performance, and candidates may incorrectly select inquiry or observation when the scenario describes tracing a transaction through the entire process.

How to eliminate wrong answers

Option B is wrong because re-performance involves the auditor independently executing a control or procedure to verify its effectiveness, not tracing a process to understand it. Option C is wrong because inquiry alone involves asking questions, but a walkthrough typically combines inquiry with inspection and observation to follow the process. Option D is wrong because observation involves watching a process being performed, but a walkthrough is more comprehensive, involving tracing transactions through the system.

732
MCQhard

During data conversion from a legacy system to a new ERP, the project team decides to clean data during extraction but not during loading. What is the PRIMARY risk associated with this approach?

A.Data integrity issues may remain undetected in the target system.
B.The legacy system performance may degrade.
C.The project may exceed its budget due to rework.
D.The conversion process will be significantly slower.
AnswerA

Cleaning only at extraction leaves errors introduced or exposed during transformation and loading unchecked, so corrupt records reach the target ERP without a validation gate. The absence of load-stage cleansing removes the final detection point, letting integrity defects persist silently in production data.

Why this answer

Cleaning data only during extraction and not during loading means that any data quality issues introduced during the extraction process or that become apparent only after mapping to the target schema will not be caught. This creates a primary risk that data integrity issues—such as referential integrity violations, duplicate keys, or format mismatches—will remain undetected in the new ERP system, potentially corrupting business operations and reporting.

Exam trap

The trap here is that candidates focus on operational concerns like speed or cost, rather than the core IS audit principle that data integrity is the paramount risk when data is not validated at the final point of entry into the target system.

How to eliminate wrong answers

Option B is wrong because legacy system performance degradation is not a primary risk of the data cleaning approach; it is more related to the extraction method (e.g., full table scans) rather than the cleaning phase. Option C is wrong because while rework could occur, the primary risk is not budget overrun but undetected data integrity issues that could cause systemic failures. Option D is wrong because cleaning during extraction can actually slow the extraction process, but the question asks about the primary risk, and performance speed is secondary to data integrity.

733
MCQmedium

An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?

A.Implementing role-based access controls
B.Performing a data migration risk assessment
C.Reviewing vendor SOC 2 reports
D.Conducting user acceptance testing
AnswerA

Role-based access controls assign permissions by job function rather than individual, preventing any single user from holding conflicting duties such as creating a vendor and approving its payment. This directly addresses the segregation of duties conflicts the ERP implementation raises.

Why this answer

Role-based access controls (RBAC) are the most effective control to address segregation of duties conflicts during ERP implementation because they allow the organization to define roles with specific permissions and assign users to roles, preventing conflicting access. RBAC enforces SoD by design, ensuring that no single user has incompatible duties.

Exam trap

CISA often tests the difference between controls that directly enforce SoD (RBAC) and those that are supportive but not directly addressing SoD, and the trap is choosing a testing or assessment activity instead of a preventive control.

How to eliminate wrong answers

Option B is wrong because a data migration risk assessment addresses data integrity risks, not SoD conflicts. Option C is wrong because reviewing vendor SOC 2 reports assesses the vendor's controls, not the organization's internal SoD within the ERP. Option D is wrong because user acceptance testing validates functionality and usability, not access control design or SoD enforcement.

734
MCQhard

An IS auditor is evaluating a system development project that uses an outsourced team. The contract allows the vendor to reuse some of the developed code in other projects. What is the auditor's PRIMARY concern?

A.The vendor might not deliver on time.
B.The organization may lose control of intellectual property.
C.The vendor may not maintain the code after the project ends.
D.The vendor may use substandard development practices.
AnswerB

Contractual reuse rights let the vendor redeploy code built for this organisation into other clients' projects, eroding exclusive ownership and potentially exposing proprietary logic or data-handling design. The primary concern is therefore loss of control over intellectual property, not delivery timelines or code quality.

Why this answer

The contract clause allowing the vendor to reuse developed code in other projects directly transfers ownership or licensing rights of the intellectual property (IP) to the vendor. This means the organization may lose exclusive control over the code, potentially allowing competitors to access proprietary logic or algorithms. The IS auditor's primary concern is safeguarding the organization's IP assets, as this loss can have long-term strategic and competitive implications.

Exam trap

The trap here is that candidates focus on operational risks (delays, maintenance, quality) rather than the contractual and legal risk of losing intellectual property rights, which is the auditor's primary concern when the vendor is explicitly allowed to reuse code.

How to eliminate wrong answers

Option A is wrong because delivery timelines are a project management risk, not the primary audit concern when IP reuse rights are granted; the contract clause directly addresses IP, not schedule. Option C is wrong because post-project maintenance is a separate contractual issue (e.g., SLA for support) and is not inherently tied to the vendor's right to reuse code; the auditor's focus is on ownership, not ongoing maintenance. Option D is wrong because substandard development practices are a quality risk that can be mitigated through code reviews and testing, but the explicit permission to reuse code is a direct IP concern, not a quality concern.

735
MCQeasy

When implementing a commercial off-the-shelf (COTS) system, what is the MOST important factor?

A.Customization to fit all requirements
B.Lowest total cost
C.Vendor reputation
D.Alignment with business processes with minimal modification
AnswerD

COTS systems deliver value through standardised, vendor-supported functionality; heavy customisation breaks upgrade paths, voids support, and inflates cost. Aligning business processes to the product with minimal modification preserves those benefits, making it the most important factor during implementation.

Why this answer

When implementing a commercial off-the-shelf (COTS) system, the most important factor is alignment with business processes with minimal modification. COTS systems are designed to provide standardized functionality; extensive customization undermines the core benefits of reduced cost, faster deployment, and easier vendor support. Modifying the COTS codebase creates a 'forked' version that complicates patch management, increases testing overhead, and risks incompatibility with future vendor updates, directly contradicting the acquisition rationale.

Exam trap

The trap here is that candidates confuse 'customization' (modifying source code) with 'configuration' (using built-in parameters), and mistakenly believe that tailoring the software to every requirement is the goal, when in fact minimizing modification is the key to preserving the COTS benefits of low cost and easy maintenance.

How to eliminate wrong answers

Option A is wrong because extensive customization of a COTS system negates its primary advantages—lower total cost of ownership, faster time-to-market, and simplified maintenance—by creating a unique codebase that requires custom testing, documentation, and support, often leading to vendor lock-in and upgrade failures. Option B is wrong because while total cost is a consideration, prioritizing the lowest initial cost can lead to hidden expenses from necessary modifications, integration work, or poor vendor support; the most important factor is ensuring the COTS product fits business processes to avoid costly rework. Option C is wrong because vendor reputation is secondary to functional fit; a reputable vendor's product that requires heavy customization will still incur significant long-term costs and risks, whereas a less-known vendor with a product that aligns closely with business needs can deliver greater value.

736
MCQhard

An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?

A.Increase the sample size for substantive testing to compensate.
B.Test the compensating controls to determine if they adequately mitigate the risk.
C.Immediately report the missing control as a material weakness.
D.Ignore the missing control since compensating controls exist.
AnswerB

Testing the compensating controls establishes whether they actually reduce the risk arising from the missing control, which is the evidence needed before concluding on control adequacy. Walkthroughs alone only confirm design; substantive testing of the compensating control's operating effectiveness satisfies the auditor's obligation to assess residual risk.

Why this answer

When a control gap is identified but management asserts compensating controls exist, the auditor cannot simply accept the assertion — the auditor must obtain evidence that the compensating controls actually operate effectively and reduce the risk to an acceptable level. Testing the compensating controls is the only way to determine whether the residual risk is adequately mitigated before concluding on the control environment.

Exam trap

CISA often tests the misconception that the existence of compensating controls automatically eliminates the need for further auditor action, when in fact the auditor must test those controls to validate their effectiveness.

How to eliminate wrong answers

Option A is wrong because increasing substantive testing sample size addresses detection risk at the transaction level but does not evaluate whether the compensating controls mitigate the identified design deficiency. Option C is wrong because a missing control is not automatically a material weakness — materiality depends on the assessed risk and whether compensating controls reduce it to an acceptable level. Option D is wrong because the auditor cannot ignore a missing control based solely on management's assertion; compensating controls must be tested and validated before reliance can be placed on them.

737
MCQhard

A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?

A.The architecture board meets at least quarterly and maintains minutes of its deliberations.
B.Exception requests are documented, time-bound, and approved at a level commensurate with the risk of noncompliance.
C.The board's technology committee reviews the IT capital budget at each scheduled meeting.
D.Business units are surveyed annually on their satisfaction with the standards and the exception process.
AnswerB

The framework's credibility depends on whether the delegated authority is actually enforced. Exceptions are the primary leak path: if they are undocumented, open-ended, or approved at too low a level, the architecture board's decision rights become nominal. Verifying that exceptions are documented, time-bound, and approved commensurate with risk directly tests whether the governance design operates as intended in practice.

Why this answer

Governance frameworks allocate decision rights, but their effectiveness is determined by how deviations are handled. Because business units can request exceptions to architecture standards, the exception process is where delegated authority is either preserved or eroded. Documented, time-bound exceptions approved at a risk-commensurate level preserve the architecture board's authority while allowing justified flexibility.

Meeting cadence, satisfaction surveys, and budget review do not test whether standards are actually binding.

Exam trap

The trap here is focusing on the visible activity of the governance bodies rather than on the exception mechanism that determines whether their decision rights are real.

738
Multi-Selecteasy

Which TWO of the following are benefits of using a version control system in software development?

Select 2 answers
A.Generate test cases
B.Eliminate all bugs
C.Automate deployment
D.Rollback to previous versions
E.Track changes made by developers
AnswersD, E

Core feature.

Why this answer

Version control systems (e.g., Git, SVN) allow developers to revert code to a previous commit or tag, enabling recovery from bugs or regressions. This rollback capability is a core feature that preserves the history of the codebase and supports safe experimentation.

Exam trap

The trap here is that candidates confuse version control with CI/CD or testing tools, mistakenly thinking VCS can automate deployment or generate test cases, when its primary purpose is change tracking and history management.

739
MCQmedium

An IS auditor reviewing the backup strategy for a financial application finds that full backups run every Sunday, with daily incremental backups Monday through Saturday. The recovery point objective (RPO) for the application is 4 hours. Which of the following is the MOST significant finding?

A.The backup schedule cannot achieve the 4-hour RPO because incrementals capture changes only once per day.
B.Incremental backups are more prone to corruption than full backups and should be replaced with differential backups.
C.Backup tapes are stored in a cabinet in the data center rather than at an offsite location.
D.Full backups are performed weekly, which may be insufficient for recovering large data volumes quickly.
AnswerA

With daily incremental backups, the maximum data loss is up to 24 hours of transactions if a failure occurs just before the next backup. The RPO of 4 hours requires backups at least every 4 hours, such as transaction log shipping or more frequent incrementals. This is the most critical finding because it directly violates the recovery requirement.

Why this answer

The recovery point objective defines the maximum acceptable data loss, measured in time. Daily incremental backups leave up to 24 hours of data at risk, far exceeding the 4-hour RPO. The auditor should report that the backup frequency is inadequate.

Offsite storage, full backup frequency, and backup type are relevant but do not directly violate the stated RPO in this scenario.

Exam trap

The trap here is focusing on backup media handling or backup type instead of calculating the maximum data loss window against the stated RPO.

740
MCQhard

A company outsources its data center operations. Which IT governance practice is MOST critical to ensure the outsourcing arrangement meets business requirements?

A.Establishing a service level agreement (SLA) with key performance indicators
B.Performing a total cost of ownership analysis
C.Creating a RACI matrix for the outsourced processes
D.Conducting background checks on outsourcer employees
AnswerA

An SLA translates business requirements into measurable key performance indicators, giving the company an enforceable basis to monitor the outsourcer's delivery. Without defined metrics and remedies, governance over the arrangement lacks objective evidence of compliance.

Why this answer

Service level management ensures that the outsourcer's performance is monitored against agreed-upon metrics.

741
MCQeasy

An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?

A.Training hours per employee
B.System uptime percentage
C.User satisfaction survey results
D.Project completion rate
AnswerC

User satisfaction survey results directly capture how customers perceive IT service quality, matching the balanced scorecard's customer perspective. Other metrics, such as incident resolution or budget variance, reflect internal process or financial perspectives rather than customer outcomes.

Why this answer

The customer perspective focuses on user satisfaction and service responsiveness. Option A is incorrect as training hours relate to learning and growth perspective. Option B is incorrect as system uptime is an internal process metric.

Option D is incorrect as project completion rate is an internal efficiency metric.

742
MCQeasy

Which of the following is a key objective of a post-implementation review?

A.To conduct penetration testing
B.To approve the project budget
C.To determine if the system meets user requirements
D.To select the vendor
AnswerC

A post-implementation review compares delivered functionality against the original business case and user requirements, confirming the system actually delivers intended benefits. This satisfies the stem's objective of verifying that user requirements were met after go-live.

Why this answer

The key objective of a post-implementation review (PIR) is to determine whether the system meets user requirements and delivers the expected benefits. It evaluates the project's success against its original objectives, including functionality, performance, and user satisfaction. This helps the organization learn and improve future projects.

Exam trap

CISA often tests the timing and purpose of PIR, and the trap is confusing it with other project phases like testing, budgeting, or vendor selection.

How to eliminate wrong answers

Option A is wrong because penetration testing is a security assessment activity, not the objective of a PIR. Option B is wrong because budget approval occurs during project initiation or planning, not after implementation. Option D is wrong because vendor selection happens before implementation, not during a PIR.

743
Multi-Selecteasy

Which THREE of the following are typical phases in the system development life cycle (SDLC)?

Select 3 answers
A.Unit testing.
B.Implementation.
C.Patch management.
D.Requirements analysis.
E.Design.
AnswersB, D, E

Implementation is a recognised SDLC phase in which the designed system is coded, configured and deployed into the production environment. It follows design and precedes testing and maintenance, forming the build stage of the lifecycle.

Why this answer

The SDLC is commonly modeled as a sequence of phases such as requirements gathering/analysis, design, development, testing, implementation/deployment, and maintenance. Option D (Requirements analysis) is correct because it is the phase where business and functional needs are elicited, documented, and validated, forming the basis for all later work. Option E (Design) is correct because it translates the approved requirements into system architecture, components, interfaces, and detailed specifications before coding begins.

Option B (Implementation) is correct because it is the phase in which the designed system is built, coded, tested at the unit level, and deployed into production or a target environment. Option A (Unit testing) is a testing activity performed within the development/implementation phase rather than a distinct top-level SDLC phase, and Option C (Patch management) is an ongoing IT operations/maintenance process for applying vendor fixes, not a standard SDLC phase.

Exam trap

The trap here is confusing operational activities like patch management or specific testing techniques with the high-level phases of the SDLC, leading candidates to select activities that occur post-deployment or are sub-steps of a phase.

744
MCQhard

A multinational corporation's data center in the European Union (EU) stores personal data of EU citizens. The company must comply with the General Data Protection Regulation (GDPR), which requires that personal data be protected and that data subjects have the right to erasure ('right to be forgotten'). The company's IT team uses a centralized identity management system that stores user credentials and personal data in an active directory (AD) forest. The AD forest is replicated across multiple data centers worldwide, including a non-EU country. The data protection officer (DPO) is concerned that personal data might be inadvertently replicated to jurisdictions without adequate protection. Which of the following is the most effective way to address this concern?

A.Pseudonymize all personal data before storing it in AD
B.Encrypt all personal data at rest and in transit, with keys held solely within the EU
C.Implement data residency controls to ensure EU personal data is only stored and processed within the EU
D.Obtain explicit consent from all EU data subjects for international data transfer
AnswerC

Data residency controls restrict where EU personal data is stored and processed, preventing replication of the AD forest's personal data to non-EU data centres. This keeps processing within a jurisdiction offering GDPR-equivalent protection, directly addressing the DPO's concern about inadvertent transfer to inadequately protected countries.

Why this answer

GDPR mandates that personal data of EU citizens must not be transferred to countries without adequate protection unless specific safeguards are in place. Implementing data residency controls ensures that EU personal data is stored and processed only within the EU, preventing inadvertent replication to non-EU jurisdictions via AD replication. This directly addresses the DPO's concern by enforcing geographic boundaries on data storage and processing.

Exam trap

The trap here is that candidates often confuse encryption (Option B) with data residency, thinking encryption alone prevents data exposure, but encryption does not stop replication and may still allow data to be stored in non-EU jurisdictions where it could be subject to local access laws.

How to eliminate wrong answers

Option A is wrong because pseudonymization reduces identifiability but does not prevent data from being replicated to non-EU jurisdictions; the pseudonymized data remains personal data under GDPR and could still be subject to inadequate protection. Option B is wrong because encryption protects data confidentiality but does not prevent replication; if keys are held solely within the EU, the data can still be replicated to non-EU servers, and the encrypted data may be accessible if the key management is compromised or if the encryption is bypassed during replication. Option D is wrong because explicit consent for international data transfer is a possible lawful basis but is not the most effective technical control; it does not prevent inadvertent replication and can be withdrawn by data subjects, making it unreliable for ongoing compliance.

745
Multi-Selecthard

An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).

Select 3 answers
A.Reduced need for data backups
B.Regulatory non-compliance
C.Higher software licensing costs
D.Compatibility issues with newer systems
E.Increased vulnerability to security breaches
AnswersB, D, E

Unsupported software no longer receives security patches, so known vulnerabilities remain exploitable, undermining controls required by regulations such as GDPR, PCI DSS or HIPAA. This exposes the organisation to fines, sanctions and audit findings, satisfying the stem's regulatory non-compliance risk.

Why this answer

Option B (Regulatory non-compliance) is correct because running EOL software often violates frameworks and mandates such as PCI DSS, HIPAA, or ISO 27001, which require supported, patched components, exposing the organization to fines and audit findings. Option D (Compatibility issues with newer systems) is correct because unsupported software no longer receives vendor updates, drivers, or patches, so it can fail to interoperate with current operating systems, databases, APIs, and hardware, causing integration and availability problems. Option E (Increased vulnerability to security breaches) is correct because once a vendor ends support, no new security patches are issued, leaving known and newly discovered CVEs permanently exploitable by attackers.

Option A is not a risk of unsupported software; backups remain necessary regardless of support status, and EOL software does not reduce backup requirements. Option C is not inherently a risk of EOL software; licensing costs may actually drop or become irrelevant, and cost changes are not a standard risk associated with running unsupported software.

Exam trap

The trap is the distractor 'higher software licensing costs' — candidates assume old software is expensive, but EOL software is typically cheaper to license (or free) while being far riskier; the exam tests whether you focus on risk, not cost.

746
Multi-Selecteasy

During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)

Select 2 answers
A.User acceptance testing (UAT)
B.Code review
C.Threat modeling
D.Architecture review
E.Penetration testing
AnswersC, D

Threat modeling systematically identifies potential threats, attack vectors and required mitigations against the proposed design. Conducted during the design phase, it satisfies the requirement to integrate security before coding begins, when architectural changes remain inexpensive compared with remediation after implementation.

Why this answer

Threat modeling (C) is correct because it is a design-phase activity that systematically identifies potential threats, attack vectors, and mitigations against the proposed architecture and data flows before code is written. Architecture review (D) is correct because it evaluates the proposed system design against security requirements, standards, and best practices (e.g., segmentation, least privilege, trust boundaries) to catch structural weaknesses early. User acceptance testing (A) is wrong because UAT validates business functionality and user requirements during testing, not design.

Code review (B) is wrong because it examines implemented source code, which occurs after design. Penetration testing (E) is wrong because it is an active exploitation test performed on a built system, typically in later testing or deployment phases.

Exam trap

CISA often tests the phase-appropriateness of security activities; candidates incorrectly select testing-phase activities (UAT, code review, pen testing) for a design-phase question because they conflate 'security assurance' with 'security integration.'

747
MCQmedium

An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?

A.Yes, because 45 minutes is within 0.1% of the total time.
B.Yes, because the SLA is calculated per day, not per month.
C.No, because any downtime exceeding 30 minutes is a violation.
D.No, because the allowed downtime for 99.9% uptime is approximately 43 minutes.
AnswerD

99.9% uptime permits 0.1% downtime; in a 30-day month (43,200 minutes) that equals about 43.2 minutes. The 45-minute outage exceeds this allowance, so the SLA was breached, confirming the service did not meet its monthly commitment.

Why this answer

The SLA guarantees 99.9% uptime per month. For a 30-day month (43,200 minutes), 99.9% uptime allows only 0.1% downtime, which is 43.2 minutes. The actual outage of 45 minutes exceeds this threshold, so the SLA was not met.

Option D correctly identifies the allowed downtime as approximately 43 minutes.

Exam trap

The trap here is that candidates may incorrectly round 43.2 minutes to 43 minutes and then assume 45 minutes is close enough, or they may mistakenly think 0.1% of a month is 30 minutes, leading them to choose option C.

How to eliminate wrong answers

Option A is wrong because 45 minutes is not within 0.1% of the total time; 0.1% of 43,200 minutes is 43.2 minutes, so 45 minutes exceeds the allowed downtime. Option B is wrong because the SLA explicitly states 'per month,' not per day, and calculating per day would allow even less downtime (e.g., 0.1% of 1,440 minutes = 1.44 minutes per day). Option C is wrong because the SLA does not specify a 30-minute threshold; the allowed downtime is derived from the 99.9% uptime calculation, not an arbitrary 30-minute limit.

748
MCQhard

You are the IT audit manager for a multinational corporation. The company recently implemented a new enterprise resource planning (ERP) system using a phased rollout approach. The first phase (finance module) was deployed to three regional offices six months ago. During a post-implementation review, you discovered that the user acceptance testing (UAT) for the finance module was completed in only two days instead of the planned two weeks. The UAT was performed by a small group of power users selected by the project manager, and they reported no critical issues. However, after go-live, several finance staff in one region found that the system does not support a statutory reporting requirement specific to that country, which was not tested. The project manager argues that the requirement was never documented in the business requirements specification. The system has been live for six months, and the missing functionality requires a significant customization that will take three months and cost $200,000. Management is reluctant to fund the customization because the budget is exhausted. As the IT auditor, what is the BEST course of action?

A.Report the project manager to senior management for failing to include the requirement
B.Recommend that the organization accept the risk and proceed without the customization
C.Advise the project manager to retroactively document the requirement and request a change order for the customization
D.Recommend that management implement a formal UAT process with representatives from all regions and include a checklist of statutory requirements for future rollouts
AnswerD

The two-day UAT by hand-picked power users missed a country-specific statutory requirement, so the control weakness is the UAT design itself. Recommending a formal process covering all regions with a statutory-requirement checklist addresses the root cause and prevents recurrence in later phased rollouts.

Why this answer

The root cause is a deficient UAT process, not just a missing requirement. A formal UAT process with representatives from all regions and a statutory requirements checklist would have caught the country-specific reporting need before go-live. As an IT auditor, recommending process improvements for future rollouts addresses the systemic control weakness, which is more effective than blaming individuals or accepting risk without remediation.

Exam trap

The trap here is that candidates focus on the missing requirement or blame the project manager, rather than recognizing that the core issue is a weak UAT process that failed to include all regional stakeholders and statutory requirements, which is a systemic control weakness the auditor should address.

How to eliminate wrong answers

Option A is wrong because the project manager correctly notes the requirement was never documented in the business requirements specification; reporting him without addressing the process gap does not fix the underlying UAT deficiency. Option B is wrong because accepting the risk of non-compliance with a statutory reporting requirement could lead to regulatory penalties, which is not a prudent recommendation for an auditor. Option C is wrong because retroactively documenting a requirement and requesting a change order after six months of live operation is a project management action, not an audit recommendation; it does not prevent recurrence and may not be feasible given budget exhaustion.

749
MCQhard

An IS auditor is assessing the audit risk for an engagement covering a core banking application. The auditor determines that inherent risk is high because the application processes high-value transactions in real time. The auditor also concludes that control risk is low because strong automated controls and segregation of duties are in place and have been tested. Which of the following BEST describes the appropriate response to this assessment?

A.Rely on the tested controls and reduce the extent of substantive procedures accordingly
B.Increase the extent of substantive testing because inherent risk is high
C.Reduce reliance on controls and perform more detailed transaction testing
D.Set detection risk at a low level regardless of the control assessment
AnswerA

The assessed level of control risk is low because controls are strong and have been tested. Under the audit risk model, lower control risk allows the auditor to place greater reliance on controls and reduce the extent of substantive procedures. This keeps detection risk at a level that holds overall audit risk within acceptable bounds while avoiding unnecessary testing. High inherent risk is already reflected in the assessment and is managed through this combined approach.

Why this answer

The audit risk model links inherent risk, control risk, and detection risk to overall audit risk. With strong, tested controls, control risk is assessed as low, which permits the auditor to rely on those controls and reduce the extent of substantive procedures. High inherent risk is already factored into the assessment and does not by itself justify expanding substantive testing, nor should detection risk be fixed independently of the other components.

Exam trap

The trap here is reacting to high inherent risk by expanding substantive testing, while overlooking that low, tested control risk allows reduced substantive work.

750
MCQhard

An IS auditor is testing the effectiveness of a preventive control that rejects invalid transactions. The auditor uses a computer-assisted audit technique (CAAT) to create a set of test transactions. What is the primary risk associated with this approach?

A.The audit may disrupt system performance
B.Test transactions may be processed as real transactions
C.Test transactions may not be representative
D.The CAAT may corrupt production data
AnswerB

Test transactions submitted through live production systems can be indistinguishable from genuine entries, so the system may post, approve or settle them as real business. This contaminates financial data and could trigger actual payments or obligations, which is the primary risk of this technique.

Why this answer

The primary risk is that test transactions may be processed as real transactions if the CAAT does not properly isolate them from the production environment. This could result in unintended data corruption, financial misstatements, or operational disruptions. The auditor must ensure that test data is clearly flagged or run in a separate test environment to avoid integration with live processing.

Exam trap

The trap here is that candidates often confuse the risk of test transactions being processed as real (option B) with the risk of CAATs corrupting production data (option D), but corruption is a consequence of the processing error, not the direct risk of the CAAT tool itself.

How to eliminate wrong answers

Option A is wrong because system performance disruption is a secondary operational risk, not the primary risk specific to using test transactions; CAATs are designed to minimize performance impact. Option C is wrong because while representativeness is a concern for test data validity, it is not the primary risk of the approach—the core risk is that test transactions could be processed as real. Option D is wrong because CAATs themselves do not corrupt production data; the corruption occurs only if test transactions are mistakenly processed as real, which is already covered by option B.

Page 9

Page 10 of 13

Page 11