Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 151–225

934 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
MCQhard

An organization is adopting agile development methodology. Which control is MOST critical to ensure security is integrated?

A.Penetration testing before release
B.Including security stories in the product backlog
C.Code reviews after each sprint
D.Security requirements defined at project initiation
AnswerB

Placing security stories in the product backlog makes security work a first-class, estimated and prioritised deliverable that the team addresses each sprint. This embeds controls into features as they are built, rather than retrofitting them after release, which is the critical mechanism for agile security integration.

Why this answer

In agile development, security must be continuously integrated into each iteration. Including security stories in the product backlog ensures that security tasks are prioritized, estimated, and addressed during each sprint, making security an inherent part of the development lifecycle rather than an afterthought. This aligns with the principle of 'shifting left' on security, where controls are applied as early as possible.

Exam trap

The trap here is that candidates often choose 'Security requirements defined at project initiation' (Option D) because it sounds like early planning, but in agile, requirements must be continuously refined and added to the backlog, not locked in at the start.

How to eliminate wrong answers

Option A is wrong because penetration testing before release is a point-in-time validation that occurs late in the cycle and does not ensure security is integrated throughout development; it can miss vulnerabilities introduced after the test. Option C is wrong because code reviews after each sprint, while valuable for quality, are reactive and may not cover all security aspects (e.g., architecture, threat modeling) that need to be planned as backlog items. Option D is wrong because security requirements defined only at project initiation are static and do not adapt to evolving threats or changes in agile iterations; they must be continuously refined and added as backlog items.

152
MCQeasy

A company is developing a custom application. During the requirements phase, the project manager documents that the system must encrypt all sensitive data at rest. Which of the following is the BEST control to ensure this requirement is met throughout the development lifecycle?

A.Perform static code analysis on the final code.
B.Create a requirements traceability matrix (RTM).
C.Conduct a post-implementation security review.
D.Deploy a database activity monitoring tool.
AnswerB

A requirements traceability matrix links the encryption-at-rest requirement to its design, code, and test artefacts, providing verifiable evidence throughout development. This directly satisfies the need to confirm the control is implemented and tested at each lifecycle stage.

Why this answer

A requirements traceability matrix (RTM) links each requirement to corresponding design, development, and testing artifacts. By mapping the encryption-at-rest requirement to specific code modules, configuration settings, and test cases, the RTM ensures that the control is implemented and verified at every stage of the lifecycle, not just at the end. This makes it the best proactive control for continuous compliance throughout development.

Exam trap

The trap here is that candidates often choose static code analysis (A) because it seems technical and security-focused, but they overlook that it only checks the final code and cannot enforce lifecycle-wide traceability of requirements.

How to eliminate wrong answers

Option A is wrong because static code analysis only checks the final source code for vulnerabilities, but it cannot verify that the encryption requirement was consistently addressed during design, implementation, and testing phases; it is a point-in-time check. Option C is wrong because a post-implementation security review occurs after deployment, which is too late to ensure the requirement was met throughout the development lifecycle; it is reactive, not preventive. Option D is wrong because a database activity monitoring tool monitors runtime access and queries, but it does not enforce or verify that encryption-at-rest is implemented correctly in the application code or database schema during development.

153
MCQeasy

An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?

A.Percentage of employees who completed the training
B.Average score on post-training quiz
C.Number of reported phishing emails
D.Reduction in the number of successful phishing attacks
AnswerD

Successful phishing attacks measure actual security outcomes rather than activity. Completion rates and quiz scores reflect attendance, not behaviour change; a sustained fall in employees falling for simulated or real phishing demonstrates the training altered real-world susceptibility, which is the program's purpose.

Why this answer

A reduced number of successful phishing attacks indicates that employees are applying the training to recognize and avoid threats. The other metrics are useful but less direct indicators of behavioral change.

154
MCQhard

An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?

A.Control risk and detection risk only
B.Inherent risk and detection risk only
C.Inherent risk, control risk, and detection risk
D.Inherent risk and control risk only
AnswerC

The audit risk model comprises inherent risk, control risk and detection risk, and fraud assessment turns on the same three components: susceptibility of the account to fraud, effectiveness of controls, and the auditor's procedures. Combining them directly satisfies the stem's request for the most relevant combination.

Why this answer

The audit risk model comprises inherent risk, control risk, and detection risk. All three are directly relevant when assessing fraud risk because fraud can arise from inherent susceptibility, control failures, or the auditor's failure to detect it. The combination of all three determines the overall audit risk.

Exam trap

CISA often tests the audit risk model; candidates may incorrectly exclude detection risk, thinking it is only the auditor's responsibility, but it is an integral part of the model.

How to eliminate wrong answers

Option A is wrong because it omits inherent risk, which is critical in fraud assessment as some accounts are more susceptible to fraud. Option B is wrong because it omits control risk, which is essential to evaluate the effectiveness of controls in preventing or detecting fraud. Option D is wrong because it omits detection risk, which is the risk that audit procedures fail to detect a material misstatement, a key consideration in planning substantive tests.

155
MCQeasy

Which of the following is the BEST control to ensure that system changes are authorized?

A.Change advisory board approval
B.Audit trail of all changes
C.Segregation of duties between developers and operators
D.Version control system
AnswerA

A change advisory board reviews each request against business, risk and technical criteria before approving it, creating documented authorisation independent of the person requesting the change. This segregation of duties satisfies the stem's requirement that changes be authorised, unlike testing or logging, which detect rather than approve.

Why this answer

The change advisory board (CAB) is the primary control for authorizing system changes because it provides a formal, documented approval process before any change is implemented. This ensures that changes are reviewed by stakeholders with appropriate authority, reducing the risk of unauthorized or poorly planned modifications. Without CAB approval, there is no definitive authorization step, making it the best control for ensuring authorization.

Exam trap

The trap here is that candidates often confuse detective controls (audit trails) or technical controls (version control) with the governance-based authorization control (CAB approval), leading them to select a control that records or manages changes rather than one that formally authorizes them.

How to eliminate wrong answers

Option B is wrong because an audit trail of all changes is a detective control that records changes after they occur, not a preventive control that ensures authorization beforehand. Option C is wrong because segregation of duties between developers and operators is a control to prevent unauthorized changes from being implemented without oversight, but it does not directly ensure that changes are authorized by a governing body. Option D is wrong because a version control system is a technical tool for managing code versions and tracking changes, but it does not enforce or verify that a change has been formally authorized by a decision-making group like the CAB.

156
MCQeasy

An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?

A.Conducting periodic access recertification
B.Implementing single sign-on (SSO)
C.Enforcing password complexity rules
D.Using role-based access control (RBAC)
AnswerA

Periodic access recertification requires managers to confirm each user's rights remain necessary, catching privilege creep, transfers and stale accounts that accumulate over time. It directly satisfies the requirement that access rights stay appropriate, which provisioning-time approvals alone cannot guarantee.

Why this answer

Periodic access recertification is the most important control to ensure user access rights remain appropriate over time because it forces business owners to review and confirm each user's entitlements on a scheduled basis. It detects and removes accumulated privileges from role changes, transfers, or terminations. Other controls like SSO, password rules, and RBAC support access management but do not verify ongoing appropriateness.

Exam trap

CISA often tests the difference between access provisioning controls (RBAC, SSO) and access governance controls (recertification); candidates pick RBAC because it sounds like it manages access over time, but only recertification validates that rights remain appropriate.

How to eliminate wrong answers

Option B is wrong because single sign-on improves user convenience and centralizes authentication but does not verify that each user's access rights are still appropriate. Option C is wrong because password complexity rules protect against credential compromise but have no bearing on whether entitlements match current job roles. Option D is wrong because role-based access control provides a structured way to assign rights, but without periodic recertification, users can retain stale or excessive roles over time.

157
MCQmedium

An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?

A.Certificate authorities may lose their root key
B.Compromised certificates could still be used to establish trust
C.Certificates may expire without renewal
D.Users may not be able to verify certificate signatures
AnswerB

CRLs are the mechanism relying parties use to learn that a certificate is revoked. If they are stale, a compromised certificate's serial number is absent, so systems continue trusting it and attackers can still authenticate or decrypt traffic until the CRL is refreshed.

Why this answer

If CRLs are not updated in a timely manner, a certificate that has been revoked due to compromise or misuse will still appear valid to relying parties, allowing it to be used to establish trust. This defeats the purpose of revocation and can enable man-in-the-middle or impersonation attacks. Timely CRL publication is essential for the integrity of the PKI trust model.

Exam trap

The trap is confusing revocation with expiration or signature verification; candidates may pick 'certificates may expire' or 'users may not verify signatures' when the real risk is that revoked certificates continue to be trusted.

How to eliminate wrong answers

Option A is wrong because CRL updates have no relationship to the security of the CA's root private key; root key compromise is a separate, catastrophic event managed by offline storage and HSMs. Option C is wrong because certificate expiration is governed by the certificate's validity period and renewal processes, not by CRL update frequency. Option D is wrong because signature verification uses the certificate's public key and the CA's certificate, not the CRL; CRLs are used for revocation status checking, not signature validation.

158
MCQmedium

An IT balanced scorecard for a retail company shows that the percentage of IT projects delivered on time has decreased from 85% to 70%. Which perspective of the balanced scorecard is MOST directly affected?

A.Learning and Growth
B.Financial
C.Customer
D.Internal Process
AnswerD

Internal Process covers operational efficiency and delivery capability, so a fall in on-time project delivery directly measures this perspective. The stem's constraint is the 85% to 70% decline in timely delivery, an execution metric, not a customer, financial or learning-and-growth outcome.

Why this answer

The internal process perspective focuses on operational efficiency and project delivery metrics.

159
MCQeasy

An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?

A.Separating key management duties
B.Storing keys in a hardware security module (HSM)
C.Regular key rotation
D.Encrypting keys with a master key
AnswerB

An HSM generates, stores and uses keys inside tamper-resistant hardware, so plaintext key material never enters general memory or storage. This satisfies the programme's core requirement to protect keys from extraction, unlike software storage or file-based encryption, where compromise of the host exposes the keys.

Why this answer

Storing keys in a hardware security module (HSM) is the most important control because HSMs provide tamper-resistant hardware that protects keys from extraction, ensures cryptographic operations occur inside a secure boundary, and enforces access controls. This directly addresses the core security objective of key protection. Other controls like separation of duties, rotation, and key wrapping are important but secondary to secure storage.

Exam trap

CISA often tests the hierarchy of key protection controls; candidates may choose key rotation or separation of duties because they sound like strong controls, but the question asks for the MOST important control to ensure key security, which is hardware-based protection (HSM).

How to eliminate wrong answers

Option A is wrong because separating key management duties reduces insider fraud risk but does not protect keys from technical compromise or extraction if they are stored in software. Option C is wrong because regular key rotation limits the impact of a compromised key but does not prevent the key from being stolen in the first place. Option D is wrong because encrypting keys with a master key (key wrapping) protects keys at rest but the master key itself must be protected, and software-based wrapping is weaker than hardware-based protection.

160
MCQmedium

Based on the exhibit, what is the MOST likely security risk?

A.The web server is fully protected
B.Traffic to port 80 is not encrypted
C.Unrestricted traffic is allowed after the specific deny
D.The host 192.168.1.100 is exposed to denial-of-service attacks
AnswerC

This option accurately highlights a common security misconfiguration in sequential rule processing, typical of firewalls or Access Control Lists. If an exhibit demonstrates a specific deny rule that is subsequently followed by a broader, less restrictive allow rule (e.g., an implicit or explicit 'allow any any'), any traffic not explicitly matched and denied by the preceding specific rule will be permitted. This circumvents the intended denial, creating a significant vulnerability by failing to enforce the principle of least privilege.

Why this answer

The 'permit ip any any' at the end allows all traffic, bypassing earlier specific denials. Option A is not correct because the deny line only blocks other traffic, but the permit any any overrides it. Option B is not directly indicated.

Option D is a risk but less direct than the rule order issue.

161
MCQmedium

An IS auditor is reviewing the logical access controls of a legacy payroll application that authenticates users directly against its own internal user table rather than the corporate directory. Management states that this was a deliberate design choice by the vendor. Which of the following is the MOST significant audit concern with this arrangement?

A.Password policy enforcement may be inconsistent with the corporate standard and orphaned accounts may persist.
B.The application's database may not be able to support concurrent user sessions at peak payroll processing times.
C.Users may need to remember an additional password, which could increase help desk call volume.
D.Vendor support for the authentication module may lapse if the application is not upgraded to the current release.
AnswerA

When an application maintains its own credential store, corporate password complexity, lockout, rotation, and expiry settings are not automatically inherited, and accounts are not disabled when the employee leaves or transfers. The directory's joiner-mover-leaver process no longer governs access, so orphaned and excessive rights accumulate silently. This is the most material concern because it breaks centralized identity governance for a financially sensitive system.

Why this answer

A locally maintained user table sits outside the corporate directory, so provisioning, modification, and timely revocation depend on manual processes that frequently fail. The result is inconsistent password standards and accounts that survive termination or role change. Auditors should focus on whether identity lifecycle controls still cover the application, since that determines whether access remains authorized, least-privileged, and auditable over time.

Exam trap

The trap here is treating a vendor design decision as automatically acceptable and focusing on support or usability rather than on the loss of centralized provisioning and de-provisioning.

162
MCQmedium

An IS auditor is reviewing an organization's IT governance framework and notices that the IT steering committee, chaired by the CIO, approves all IT investments and also monitors their benefits realization. The board has delegated full IT decision-making authority to this committee. The auditor is MOST likely to conclude that:

A.The arrangement is appropriate as long as the committee reports regularly to the board on its decisions and outcomes.
B.The committee structure provides adequate oversight because the CIO has the technical expertise to evaluate IT investments.
C.The board's delegation of full authority to the committee is acceptable because IT governance is an operational responsibility, not a board responsibility.
D.The committee's dual role of approving investments and monitoring benefits creates a self-review risk that weakens independent oversight.
AnswerD

The IT steering committee, chaired by the CIO, both approves investments and monitors their benefits realization. This self-review creates a conflict of interest because the same group evaluates the success of its own decisions. Effective governance requires independent oversight, typically by the board or a separate audit function, to ensure objective assessment. The auditor should flag this as a governance weakness.

Why this answer

The IT steering committee, led by the CIO, both approves IT investments and monitors their benefits, which is a self-review conflict. The board has delegated full authority, meaning it lacks independent oversight. Effective IT governance requires separation between those who make investment decisions and those who evaluate their outcomes.

The auditor should conclude that this structure weakens independent oversight and may lead to biased benefits assessments.

Exam trap

The trap here is assuming that regular reporting to the board or the CIO's technical expertise can compensate for the lack of independent oversight in a self-review situation.

163
Multi-Selecthard

During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?

Select 3 answers
A.Vendor concentration risk from subcontractor dependency
B.Exit strategy complications if subcontractor fails
C.Improved service level performance
D.Increased licensing costs
E.Fourth-party risk due to lack of contractual oversight
AnswersA, B, E

Subcontractors managing storage introduce vendor concentration risk: the provider's reliance on a single subcontractor means an outage, insolvency or service failure at that third party cascades directly to the organisation, yet the contract grants no visibility, audit rights or service-level guarantees over that dependency.

Why this answer

Option A is correct because undisclosed subcontracting creates vendor concentration risk: the organization becomes dependent not only on the primary provider but also on subcontractors it did not evaluate or approve, so a subcontractor failure or change can disrupt critical data storage services. Option B is correct because the absence of subcontracting clauses complicates the exit strategy — the organization may lack contractual rights to require transition assistance, data return, or cooperation from subcontractors during termination or migration. Option E is correct because unmanaged subcontractors are fourth parties, and without contractual flow-down requirements (e.g., security, privacy, audit rights, SLAs), the provider's oversight of them is unverified, exposing the organization to compliance and data protection failures.

Option C is not a risk but a potential benefit, and it is not guaranteed by subcontracting. Option D is not a relevant risk here, since the scenario concerns undisclosed data storage subcontracting, not licensing cost increases.

Exam trap

CISA often tests third-party and fourth-party risk concepts, and candidates may overlook the lack of contractual oversight as a distinct risk, focusing only on concentration and exit strategy, but the question asks for THREE risks, and fourth-party risk is a key one.

164
Multi-Selecthard

An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)

Select 2 answers
A.Ensuring the hypervisor is kept up to date with the latest security patches.
B.Using a host-based intrusion detection system (HIDS) on each VM.
C.Regularly backing up VM images to a separate storage system.
D.Enabling promiscuous mode on the virtual switch to monitor all traffic.
E.Implementing strict isolation between VMs by disabling unnecessary virtual hardware and shared folders.
AnswersA, E

Keeping the hypervisor patched is critical because VM escape vulnerabilities are often due to bugs in the hypervisor code. Patches address known exploits that could allow an attacker to break out of a VM and compromise the host. This is a fundamental security practice for any software, and especially for the hypervisor, which is the foundation of the virtualized environment. Regular patching reduces the attack surface and mitigates known escape techniques.

Why this answer

The most effective controls to mitigate VM escape are patching the hypervisor and hardening VM configurations by disabling unnecessary virtual hardware and shared folders. Patching addresses known vulnerabilities that could be exploited for escape, while reducing the attack surface limits the vectors an attacker can use. Together, these preventive measures significantly reduce the risk of a VM compromising the hypervisor.

Exam trap

The trap here is selecting controls that detect or recover from an attack, such as HIDS or backups, instead of preventive controls that directly reduce the likelihood of VM escape.

165
MCQmedium

During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:

A.An observation
B.A deficiency
C.A finding
D.A material weakness
AnswerD

A deficiency whose possible effect is a material misstatement represents a material weakness, because the severity threshold is met by the potential material impact on the financial statements or related assertions. ISACA standards require this classification, distinguishing it from lesser significant deficiencies that do not reach materiality.

Why this answer

A material weakness is a deficiency or combination of deficiencies that results in a reasonable possibility that a material misstatement will not be prevented or detected.

166
MCQhard

Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?

A.Implement automatic firmware updates to eliminate human error.
B.Increase the frequency of CAB meetings to weekly to expedite change approvals.
C.Enforce the change management policy by implementing stricter controls and disciplinary measures for non-compliance.
D.Remove the network engineer's administrative access to all network devices.
AnswerC

The outage stemmed from an engineer bypassing the documented CAB and emergency-change routes. Enforcing the existing policy with stricter preventive controls and consequences directly addresses that non-compliance, closing the gap that allowed the unapproved firmware update.

Why this answer

The root cause was a deliberate bypass of the existing change management policy, not a flaw in the policy itself. Enforcing stricter controls and disciplinary measures directly addresses the human factor by reinforcing accountability and deterring unauthorized changes, which is the most effective way to prevent recurrence when a well-documented process is already in place but ignored.

Exam trap

The trap here is that candidates often choose technical controls (like automatic updates or removing access) instead of recognizing that the fundamental issue is a governance failure—the policy exists but was not enforced, so the best action is to strengthen enforcement and accountability, not to add or remove technical capabilities.

How to eliminate wrong answers

Option A is wrong because implementing automatic firmware updates would remove human oversight entirely, potentially causing widespread outages if a faulty update is pushed without testing or CAB review, and it does not address the policy violation. Option B is wrong because increasing CAB meeting frequency does not solve the core issue of an engineer bypassing the process; the emergency change process already exists for urgent patches, so the problem is non-compliance, not approval speed. Option D is wrong because removing the network engineer's administrative access is an overly punitive and impractical measure that could hinder legitimate emergency responses; it does not enforce the existing change management process and may violate the principle of least privilege by eliminating necessary access for a qualified engineer.

167
MCQmedium

You are an IS auditor for a financial institution that processes credit card payments. The organization uses a key management system (KMS) to store encryption keys for point-of-sale (POS) data. The KMS is a hardware security module (HSM) located in a secured data center. The audit reveals that the HSM is administered by two individuals who both have full access to the HSM, including the ability to export keys. The organization has a policy requiring split knowledge and dual control for key management, but in practice, the two administrators often perform key ceremonies alone due to scheduling conflicts. The logs show that one administrator exported a key last month without the other present, and the export was approved via email by the other administrator after the fact. Which of the following is the BEST corrective action?

A.Reduce the number of administrators to one to simplify accountability
B.Configure the HSM to require two administrators to be physically present for key exports
C.Provide training to administrators on the importance of dual control
D.Implement automated key rotation every 90 days
AnswerB

Enforcing dual physical presence at the HSM directly satisfies the split knowledge and dual control policy, preventing any single administrator from exporting keys alone. Email approval after the fact does not provide the required real-time, two-person authorisation during the key ceremony.

Why this answer

The HSM must enforce split knowledge and dual control at the technical level, not rely on procedural compliance. By configuring the HSM to require two administrators to be physically present for key exports, the organization ensures that no single individual can export keys, directly addressing the policy violation and the log evidence of a solo export. This technical control is the most effective corrective action because it prevents the bypass of dual control even if administrators attempt to circumvent procedures.

Exam trap

The trap here is that candidates may choose training (Option C) as a quick fix, overlooking that the root cause is a lack of technical enforcement, not a lack of awareness.

How to eliminate wrong answers

Option A is wrong because reducing to one administrator eliminates split knowledge entirely, violating the core security principle and increasing the risk of key compromise. Option C is wrong because training alone does not enforce compliance; the administrators already know the policy but bypass it due to scheduling conflicts, so a technical control is needed. Option D is wrong because automated key rotation does not address the lack of dual control during key exports; it only changes keys periodically, leaving the export vulnerability unmitigated.

168
MCQmedium

During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?

A.The MTD should be reduced to match the RTO
B.The RPO is too high because it exceeds the MTD
C.The RTO is acceptable as it is less than the MTD
D.The RTO should be equal to the MTD
AnswerC

The proposed Recovery Time Objective (RTO) of 2 hours is acceptable because it directly satisfies the critical business continuity constraint established by the Maximum Tolerable Downtime (MTD) of 4 hours. For any recovery strategy to be effective, the RTO, representing the target time to restore operations, must always be less than or equal to the MTD. This ensures that the process can resume before the organisation incurs unacceptable losses, which is met in this scenario.

Why this answer

The RTO must be less than or equal to the MTD. Here, RTO (2 hours) is less than MTD (4 hours), so the recovery target is acceptable.

169
MCQhard

During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?

A.Certificate authorities may become unavailable
B.Revoked certificates may be accepted as valid
C.Increased network traffic due to large CRLs
D.Users may experience delays in certificate validation
AnswerB

Weekly CRL publication creates a window in which a revoked certificate remains absent from the list, so relying parties continue to treat it as valid. Until the next update, compromised or misissued certificates can still authenticate, undermining the PKI's revocation assurance.

Why this answer

If CRLs are only updated weekly, revoked certificates may still be accepted as valid during the interval between revocation and CRL publication, allowing compromised or misused certificates to be trusted. This is the most significant risk because it undermines the revocation mechanism and can enable impersonation or man-in-the-middle attacks. Timely revocation is critical to PKI trust.

Exam trap

CISA often tests the difference between availability/performance impacts and security impacts; candidates may pick network traffic or validation delays because they sound like consequences of large CRLs, but the most significant risk is that revoked certificates remain trusted.

How to eliminate wrong answers

Option A is wrong because CRL update frequency does not affect CA availability; CA availability depends on infrastructure and redundancy. Option C is wrong because increased network traffic from large CRLs is an operational concern, not a security risk, and can be mitigated with delta CRLs or OCSP. Option D is wrong because delays in certificate validation are a performance issue, not a security risk; the security risk is accepting revoked certificates.

170
Multi-Selectmedium

Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)

Select 2 answers
A.Early and frequent feedback from stakeholders
B.Simpler documentation requirements
C.Predictable project timeline
D.Ability to incorporate changing requirements
E.Reduced need for user involvement
AnswersA, D

Iterative delivery produces working increments each cycle, so stakeholders review functioning software rather than documents, surfacing requirement defects while change remains cheap. This directly satisfies the stem's comparison against waterfall, whose single late validation phase defers feedback until rework is costly.

Why this answer

Option A is correct because iterative SDLC delivers working increments at the end of each short iteration, letting stakeholders review and provide feedback early and frequently rather than waiting until the end of the project as in waterfall. Option D is correct because iterative development welcomes and accommodates changing requirements between iterations, whereas waterfall typically freezes requirements after the initial phase and makes late changes costly. Option B is not inherently true, since iterative methods still require documentation and may even produce more artifacts across iterations.

Option C is wrong because iterative projects are generally less predictable in overall timeline due to evolving scope, unlike waterfall's fixed sequential plan. Option E is incorrect because iterative approaches actually increase, not reduce, the need for ongoing user involvement through regular reviews and feedback.

Exam trap

The trap is picking 'predictable timeline' or 'reduced user involvement' as iterative benefits — those are waterfall strengths or Agile misconceptions, and the exam expects you to distinguish feedback/change-adaptability from schedule predictability.

171
MCQhard

A company is migrating its customer database to a public cloud provider. Which of the following encryption strategies best protects data while minimizing performance impact on queries?

A.Encrypt the entire database at rest using AES-256, and decrypt for each query.
B.Encrypt the database at the application layer before storage.
C.Use column-level encryption and tokenization for sensitive fields.
D.Rely on the cloud provider's default encryption for the storage.
AnswerC

Column-level encryption and tokenisation protect only sensitive fields, leaving non-sensitive columns in plaintext so indexes and query operations remain fast. This satisfies the stem's constraint of minimising query performance impact, unlike full-disk or whole-database encryption, which decrypts broadly.

Why this answer

Column-level encryption and tokenization allow sensitive fields (e.g., SSNs, credit card numbers) to be protected while leaving non-sensitive columns unencrypted, preserving query performance on indexed and frequently queried data. Tokenization replaces sensitive values with non-sensitive placeholders, enabling joins and lookups without decryption overhead, and column-level encryption limits decryption to only the required fields per query.

Exam trap

The trap here is that candidates assume full-database encryption (Option A) is the most secure and thus the best choice, overlooking the critical requirement to minimize performance impact on queries, which column-level encryption and tokenization directly address by avoiding unnecessary decryption of non-sensitive data.

How to eliminate wrong answers

Option A is wrong because encrypting the entire database at rest and decrypting for each query would impose massive decryption overhead on every read operation, severely degrading query performance and defeating the purpose of a production database. Option B is wrong because application-layer encryption before storage means the database cannot index or query the encrypted data efficiently; any search or filter on encrypted fields would require full table scans and client-side decryption, making queries impractical. Option D is wrong because relying solely on the cloud provider's default encryption (typically server-side encryption at rest) protects data on disk but does not protect data in use or in transit, and it does not address the need to minimize performance impact on queries—default encryption adds no query-time overhead but also provides no granular control over sensitive fields.

172
MCQhard

A multinational corporation has implemented a hot site disaster recovery solution for its critical financial applications. Which of the following is the MOST important consideration to ensure the effectiveness of the hot site?

A.Data replication latency is less than 15 minutes
B.The hot site is located in a different seismic zone
C.The hot site complies with regional data privacy regulations
D.Regular, documented testing of the failover process is performed
AnswerD

A hot site only delivers recovery if failover actually works when invoked. Regular, documented testing validates replication currency, configuration parity and recovery-time objectives, exposing gaps before a real disaster and satisfying the requirement that the solution remain effective.

Why this answer

Regular, documented testing of the failover process is the most important consideration because a hot site's effectiveness depends on whether it can actually be activated and operate as intended during a real disaster. Without periodic testing, configuration drift, outdated replication, or untested procedures can cause the failover to fail. Testing validates not only the technology but also the people and processes involved in recovery.

This aligns with CISA's emphasis on business continuity and disaster recovery validation.

Exam trap

CISA often tests the distinction between technical metrics (like replication latency) and the overarching need for validation through testing; candidates may choose a specific technical parameter as most important, overlooking that without testing, even the best-designed hot site may fail.

How to eliminate wrong answers

Option A is wrong because data replication latency, while important, is a technical metric that can be optimized but does not guarantee the hot site will function when needed; a low latency does not address procedural or human errors. Option B is wrong because geographic separation reduces the risk of a single disaster affecting both sites, but it is a design consideration, not the most critical factor for ensuring effectiveness; a site in a different seismic zone can still fail due to untested processes. Option C is wrong because regulatory compliance is a legal and operational requirement, but it does not ensure the hot site will work during a disaster; compliance alone does not validate failover capabilities.

173
MCQeasy

Which of the following is the PRIMARY objective of a post-implementation review of an information system?

A.To assess the performance of the project team
B.To evaluate whether the system achieved its planned objectives and benefits
C.To document the technical architecture for future reference
D.To identify new requirements for future enhancements
AnswerB

A post-implementation review compares actual outcomes against the business case and stated benefits, determining whether the system delivered its planned objectives. This addresses the primary governance objective rather than technical performance or user satisfaction alone.

Why this answer

The primary objective of a post-implementation review (PIR) is to evaluate whether the system achieved its planned objectives and delivered the expected benefits. It assesses the system against the original business case, requirements, and success criteria to determine if the investment realized its intended value. This evaluation informs future investment decisions and identifies lessons learned.

Exam trap

CISA often tests the difference between primary and secondary objectives, tempting candidates to select project management concerns like team performance or technical documentation instead of the core benefit realization focus.

How to eliminate wrong answers

Option A is wrong because assessing project team performance is a secondary or incidental outcome, not the primary objective; PIR focuses on system outcomes, not individual performance. Option C is wrong because documenting technical architecture is a design or documentation activity, not the purpose of a PIR; architecture should already be documented. Option D is wrong because identifying new requirements is a forward-looking enhancement activity, not the primary objective of a PIR, which is retrospective evaluation of achieved benefits.

174
MCQmedium

An IS auditor is reviewing a project that is developing a new customer relationship management (CRM) system using the Agile Scrum framework. The project team has completed several sprints, and the product owner has accepted the increments. The auditor wants to ensure that the system will meet the organization's security requirements before go-live. Which of the following is the MOST effective way for the auditor to achieve this?

A.Verify that the product owner has signed off on all functional requirements, as this ensures security is also covered.
B.Examine the project charter to confirm that security testing is listed as a deliverable in the overall project plan.
C.Review the user stories and acceptance criteria to verify that security requirements are included and tested in each sprint.
D.Recommend that a comprehensive security assessment be conducted only after the final sprint, just before deployment.
AnswerC

In Agile development, security requirements must be integrated into the product backlog as user stories or acceptance criteria to be addressed during sprints. By reviewing these, the auditor can confirm that security is continuously validated, not deferred to the end. This approach aligns with the principle of building security in from the start, ensuring that each increment meets security expectations. The other options either postpone security testing or focus on documentation rather than actual implementation.

Why this answer

In Agile Scrum, security requirements should be treated as backlog items and tested within sprints to ensure continuous validation. The most effective audit approach is to examine user stories and acceptance criteria for security content and evidence of testing. This provides real-time assurance that security is being addressed, rather than relying on post-hoc assessments or high-level plans.

Thus, reviewing user stories and acceptance criteria is the correct approach.

Exam trap

The trap here is assuming that security is automatically covered by functional acceptance or that a final security assessment is sufficient, when in Agile it must be integrated into each sprint.

175
MCQeasy

Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?

A.External auditors follow stricter standards
B.External auditors are not employees of the organization
C.External auditors have more industry knowledge
D.External auditors have more resources
AnswerB

External auditors have no employment relationship with the organisation, so they are not subject to management direction, internal promotion pressures or reporting lines that can compromise objectivity. This structural separation from the entity provides the primary basis for greater independence than internal audit.

Why this answer

External auditors are not employees, reducing organizational pressures and biases.

176
Multi-Selectmedium

An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?

Select 2 answers
A.The encryption algorithm used to protect the data
B.The location (systems and physical) where PII is stored
C.The cost of storing the data
D.The retention period for each type of PII
E.The names of all employees who process the data
AnswersB, D

Recording where PII resides, both in systems and physical premises, is essential because privacy obligations attach to every storage location. Without this, the institution cannot scope subject access requests, cross-border transfer restrictions or breach notification, leaving copies of personal data unaccounted for during compliance assessments.

Why this answer

Option B is correct because a data inventory must record where PII resides—both the systems (applications, databases, cloud services) and physical locations—so the organization can apply appropriate safeguards and respond to access, breach, or deletion requests under privacy regulations. Option D is correct because documenting the retention period for each type of PII ensures data is kept only as long as legally or operationally necessary and is securely disposed of when that period ends, which is a core privacy compliance requirement. Option A is not essential to the inventory itself; encryption algorithms are security controls recorded in system documentation, not identifying attributes of a data inventory.

Option C is irrelevant to privacy compliance, as storage cost is a financial metric rather than a data-governance attribute. Option E is unnecessary and impractical, since the inventory should identify processing activities and roles, not list every individual employee who handles the data.

Exam trap

CISA often tests the distinction between privacy-compliance metadata (location, retention) and security or financial metadata (encryption algorithm, cost), tempting candidates to pick controls that sound important but are not inventory essentials.

177
Drag & Dropmedium

Arrange the steps to set up a virtual private network (VPN) for remote access in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VPN setup: server configuration, user provisioning, client installation, connection testing, and monitoring.

178
MCQeasy

According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?

A.Documentation must support the audit findings and conclusions.
B.Documentation must be retained for at least 10 years.
C.Documentation must be reviewed by the audit committee.
D.Documentation must be prepared in the local language of the auditee.
AnswerA

ISACA standards require audit documentation to substantiate the auditor's findings and conclusions, so working papers must evidence the procedures performed, the evidence obtained and the judgements made. This supports the stem's requirement by enabling an independent reviewer to reperform the work and reach the same conclusions.

Why this answer

According to ISACA IT Audit Standards, audit documentation must support the audit findings and conclusions. This is a fundamental requirement to ensure that the work performed is verifiable and that conclusions are based on sufficient evidence. It allows for review and re-performance.

Exam trap

CISA often tests specific ISACA standards; candidates may assume a fixed retention period like 10 years, but ISACA does not specify a number, leaving it to other requirements.

How to eliminate wrong answers

Option B is wrong because ISACA does not mandate a specific retention period of 10 years; retention is determined by legal, regulatory, and organizational requirements. Option C is wrong because review by the audit committee is not a standard requirement for all documentation; it may be reviewed by audit management. Option D is wrong because documentation language is not prescribed; it should be understandable to the intended users, typically in the language of the audit report.

179
MCQmedium

During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?

A.Recovery Point Objective (RPO)
B.Work Recovery Time (WRT)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Time Objective (RTO)
AnswerC

MTD defines the longest a process can be unavailable before unacceptable business impact occurs, directly setting the recovery time objective and driving continuity strategy. During a BIA, it is the primary metric quantifying tolerable outage per critical process, making it the most important figure to establish.

Why this answer

Maximum Tolerable Downtime (MTD) is the most important metric because it defines the maximum time a business process can be unavailable before causing unacceptable consequences. It sets the upper bound for recovery objectives like RTO and WRT. Without knowing MTD, other metrics lack context.

Exam trap

The trap is selecting RTO or RPO as the most important, but MTD is the business-driven metric that sets the stage for all others.

How to eliminate wrong answers

Option A is wrong because RPO defines acceptable data loss, which is important but secondary to MTD; MTD determines how long the business can survive without the process. Option B is wrong because WRT is the time to verify and resume operations after recovery, a component of MTD but not the overarching metric. Option D is wrong because RTO is the target time to restore, which must be less than MTD; it is derived from MTD, not the most important metric itself.

180
MCQmedium

An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?

A.Timeframe for delivery
B.Fixed price
C.Audit rights
D.Warranty period
AnswerC

Audit rights contractually permit the buyer to examine the vendor's controls, records and compliance evidence, providing ongoing assurance over the outsourced system. This is the most important factor because it preserves the organisation's ability to verify security and regulatory compliance, satisfying the stem's vendor selection requirement.

Why this answer

Audit rights are critical for the organization to verify the vendor's controls and compliance, especially for outsourced systems.

181
MCQhard

An IS auditor is reviewing the requirements definition phase of a new system development project. The business analyst has documented functional requirements but has not yet defined non-functional requirements. Which of the following is the MOST significant risk of proceeding to the design phase without non-functional requirements?

A.The system may not meet performance, security, and availability expectations.
B.The development team may not understand the business processes.
C.The project timeline may be extended due to rework.
D.The project budget may be exceeded.
AnswerA

Non-functional requirements define quality attributes such as performance, security, and availability. Without them, designers may make assumptions that lead to a system that fails to meet stakeholder expectations. These attributes are often costly to retrofit later. The auditor should ensure non-functional requirements are defined and approved before design begins to mitigate this risk.

Why this answer

Non-functional requirements specify criteria such as performance, security, and availability that are essential for system acceptance. Proceeding without them increases the likelihood that the system will fail to meet stakeholder expectations and may require costly rework. The auditor should verify that both functional and non-functional requirements are defined and approved before design begins.

Exam trap

The trap here is focusing on project management symptoms like timeline or budget overruns, rather than the core risk of delivering a system that does not meet quality attributes.

182
MCQeasy

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?

A.Classify data based on sensitivity
B.Encrypt all data at rest
C.Establish an incident response team
D.Create user awareness training
AnswerA

DLP rules match on data classification labels; without first classifying data by sensitivity, rules cannot reliably identify what to protect. Classification is the prerequisite that makes policy enforcement accurate, so it must precede rule creation.

Why this answer

Data classification is the foundational step for effective DLP rules because it defines which data is sensitive and how it should be handled. Without classification, DLP policies cannot accurately identify or enforce rules on sensitive content, leading to false positives or missed detections. Classification enables the DLP system to apply context-aware rules (e.g., regex patterns for PII, keywords for confidential documents) that align with the organization's data governance requirements.

Exam trap

The trap here is that candidates often choose user awareness training (Option D) as the most important step, confusing human behavior controls with the technical prerequisite of data classification for DLP rule accuracy.

How to eliminate wrong answers

Option B is wrong because encrypting all data at rest protects confidentiality but does not control data in use or in motion, and DLP rules require visibility into content to detect policy violations; encryption can actually blind DLP inspection if not implemented with decryption capabilities. Option C is wrong because an incident response team handles post-event remediation, not the proactive enforcement of DLP rules; it is a supporting function, not the most important step for rule effectiveness. Option D is wrong because user awareness training reduces accidental data leaks but does not define the technical criteria (e.g., data patterns, tags) that DLP rules need to operate; training complements but cannot replace data classification.

183
MCQmedium

According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?

A.The availability of audit staff
B.The budget approved for the audit
C.The risk assessment of the area under review
D.The results of prior audit findings
AnswerC

The risk assessment of the area under review determines where audit effort is directed, so scope is set by the identified risk exposure rather than by convenience, prior-year scope or management preference. This satisfies the stem by making risk the governing consideration when defining what the audit covers.

Why this answer

The most important consideration when determining the scope of an IS audit is the risk assessment of the area under review. ISACA standards emphasize a risk-based approach, where audit resources are directed to areas with the highest risk. This ensures that the audit addresses the most significant threats to the organization.

Exam trap

CISA often tests the risk-based approach; candidates may choose prior audit findings or budget because they seem practical, but risk assessment is the cornerstone of audit scoping.

How to eliminate wrong answers

Option A is wrong because staff availability is a logistical constraint, not a primary driver of scope. Option B is wrong because budget is a constraint, not a determinant of what should be audited. Option D is wrong because prior audit findings are inputs to risk assessment but not the most important consideration; they inform but do not replace a current risk assessment.

184
Multi-Selectmedium

An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)

Select 2 answers
A.Performing a walkthrough of the control process.
B.Performing a penetration test on the application.
C.Sending a confirmation letter to the vendor.
D.Calculating the return on investment for the application.
E.Inspecting the control documentation and procedure manuals.
AnswersA, E

A walkthrough traces a transaction through the control process, confirming the control exists and is implemented as described. This directly tests design and implementation, satisfying the stem's requirement, by revealing whether the control operates as intended rather than merely being documented.

Why this answer

Option A (Performing a walkthrough of the control process) is correct because a walkthrough traces a transaction or process from start to finish, allowing the auditor to confirm that the control has been designed as described and is actually implemented in practice. Option E (Inspecting the control documentation and procedure manuals) is correct because examining documented policies, procedures, and control descriptions provides direct evidence of the control's design and whether it has been formally established and communicated. Together, walkthroughs and documentation inspection are standard procedures for testing design and implementation of controls.

Option B (penetration test) is a technical security assessment that tests exploitability of vulnerabilities, not the design and implementation of financial application controls. Option C (confirmation letter to the vendor) is a substantive test of balances or transactions, not a control design/implementation test. Option D (ROI calculation) is a business case or performance metric, not an audit procedure for evaluating control design and implementation.

185
MCQmedium

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

A.Conduct an IT risk assessment to identify critical areas.
B.Develop a dashboard that presents key IT metrics to the board.
C.Implement an IT balanced scorecard that aligns with corporate strategy.
D.Assign a chief information officer (CIO) to report directly to the board.
AnswerB

A dashboard directly addresses the missing reporting channel by giving the board recurring visibility of key IT metrics, satisfying the governance requirement for ongoing performance oversight. Unlike one-off reports, it establishes a repeatable mechanism aligned to the framework's monitoring and communication controls, closing the gap between implementation and board-level accountability.

Why this answer

The gap identified is that the board is not receiving regular IT performance reports — a communication and reporting deficiency, not a risk identification or organizational design problem. Developing a dashboard that presents key IT metrics to the board (B) directly closes that gap by establishing a repeatable, structured reporting mechanism that gives the board visibility into IT performance. It is the most targeted, proportionate response to the stated deficiency.

Exam trap

The trap is choosing a broader or more prestigious-sounding governance initiative (balanced scorecard, CIO reporting line) when the question describes a specific, narrow deficiency — CISA rewards the most direct, proportionate fix to the stated problem.

How to eliminate wrong answers

Option A is wrong because conducting an IT risk assessment addresses risk identification, not the reporting gap — it does not create a mechanism for the board to receive ongoing performance information. Option C is wrong because implementing an IT balanced scorecard is a broader strategic alignment initiative; while valuable, it is heavier than needed and does not directly solve the immediate reporting deficiency (and a scorecard still needs a delivery mechanism to the board). Option D is wrong because assigning a CIO to report directly to the board changes reporting lines but does not guarantee regular IT performance reporting — it addresses structure, not the missing reporting content and cadence.

186
MCQhard

An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?

A.Perform a vulnerability assessment on the fourth party.
B.Include a right-to-audit clause for all subcontractors in the contract.
C.Terminate the contract with the vendor.
D.Require the vendor to provide evidence of fourth-party compliance.
AnswerB

A right-to-audit clause extending to subcontractors gives the organisation contractual authority to examine fourth-party controls directly, closing the oversight gap created by reliance on vendor-managed compliance. Without it, assurance depends entirely on vendor reporting. This satisfies the stem's constraint: no direct oversight of the fourth party exists, so enforceable audit access must be established contractually.

Why this answer

The primary recommendation is to include a right-to-audit clause for all subcontractors in the contract. This ensures the organization retains direct oversight and contractual leverage over fourth-party risks, as relying solely on the vendor's assurance without audit rights creates a blind spot in the supply chain. Without such a clause, the organization cannot independently verify the fourth party's compliance with security controls, which is critical for maintaining business resilience.

Exam trap

The trap here is that candidates confuse operational verification (Option D) with contractual governance, failing to recognize that without a right-to-audit clause, the organization has no enforceable mechanism to independently validate fourth-party compliance.

How to eliminate wrong answers

Option A is wrong because performing a vulnerability assessment on the fourth party without contractual authority or direct access is impractical and may violate legal boundaries; it also addresses technical vulnerabilities but not the root governance gap. Option C is wrong because terminating the contract is a drastic, business-disruptive step that should only be considered after less severe remediation options (like renegotiating contract terms) have failed. Option D is wrong because requiring evidence from the vendor is insufficient without a contractual right to audit; the vendor could provide incomplete or falsified evidence, and the organization has no means to verify its accuracy or scope.

187
MCQmedium

An IT steering committee is reviewing a proposed project to implement a new customer relationship management (CRM) system. The project has strong support from the sales department but is opposed by the finance department due to cost concerns. What is the primary role of the IT steering committee in this situation?

A.Approve the project because sales is a revenue-generating department
B.Evaluate the project's alignment with strategic goals and make a decision
C.Delegate the decision to the IT manager
D.Reject the project due to finance department opposition
AnswerB

The steering committee weighs the CRM proposal against organisational strategy, balancing sales benefits against finance's cost concerns, then decides whether to proceed. This satisfies its governance role of prioritising and approving projects aligned with strategic goals rather than departmental interests.

Why this answer

The IT steering committee ensures that IT investments align with business strategy and provide value, balancing stakeholder needs.

188
MCQeasy

A hospital's IT department has implemented a new electronic health record (EHR) system. The IS auditor is reviewing the IT governance over the project and finds that the project sponsor is the CIO, who also chairs the IT steering committee that approved the project. Which of the following is the MOST significant governance risk?

A.Lack of segregation of duties between project sponsorship and project approval.
B.The project sponsor should be a clinical leader rather than the CIO.
C.The IT steering committee may not have the authority to approve large projects.
D.The CIO may not have sufficient technical knowledge to sponsor an EHR project.
AnswerA

Having the CIO serve as both project sponsor and chair of the committee that approves the project creates a conflict of interest and a lack of segregation of duties. The sponsor is responsible for advocating for the project, while the approval body should provide independent oversight. This combination can lead to biased decisions, insufficient challenge, and inadequate risk assessment. It undermines the governance principle of independent review and can result in projects proceeding without proper scrutiny.

Why this answer

The most significant governance risk is the lack of segregation of duties between project sponsorship and project approval. When the CIO sponsors the project and also chairs the committee that approves it, independent oversight is compromised. This can lead to inadequate challenge, biased decision-making, and insufficient risk assessment.

Proper governance requires that project approval be made by a body that can objectively evaluate the project's merits and risks, separate from those advocating for it.

Exam trap

The trap here is focusing on the CIO's technical knowledge or the sponsor's role, rather than recognizing the conflict of interest created by combining sponsorship and approval responsibilities.

189
Multi-Selecthard

A company is developing a new financial application. Which THREE of the following are valid reasons to involve internal audit during the development phase?

Select 3 answers
A.To ensure compliance with regulatory requirements
B.To design the application architecture
C.To validate that security controls are built in
D.To approve all user requirements
E.To provide guidance on internal controls
AnswersA, C, E

Internal audit's independence and regulatory knowledge let it assess whether the application's design and data handling will satisfy financial-sector mandates before build costs escalate. Involvement during development satisfies the stem's compliance constraint, since remediation after go-live is far costlier and may breach reporting deadlines.

Why this answer

Option A is correct because internal audit involvement during development helps verify that the financial application meets applicable regulatory requirements (e.g., SOX, PCI DSS, GDPR, or financial-industry regulations), since audit's independence lets it assess compliance obligations before the system goes live. Option C is correct because internal audit can validate that security controls are designed and built into the application from the start, rather than retrofitted later, which is far more effective and less costly. Option E is correct because internal audit provides guidance on internal controls, advising on control design and risk mitigation without taking ownership of the controls themselves.

Option B is not correct because designing the application architecture is the responsibility of the development and architecture teams, not internal audit, whose role must remain independent of design decisions. Option D is not correct because approving all user requirements is a business/user responsibility, and audit should not approve requirements it may later have to independently review.

190
Multi-Selecteasy

During the system development life cycle (SDLC), which THREE of the following are recognized benefits of involving internal audit early in the process?

Select 3 answers
A.Reduced need for future independent audits.
B.Lower cost of implementing controls due to early design changes.
C.Reduction in the number of system tests required.
D.Identification of potential control weaknesses before they are ingrained.
E.Enhanced assurance that controls are embedded in the system design.
AnswersB, D, E

Audit involvement during requirements and design lets control requirements be built into the system rather than retrofitted, avoiding costly rework and remediation after implementation. Catching design gaps early directly reduces the expense of implementing controls.

Why this answer

Option B is correct because involving internal audit during the design phase allows control requirements to be identified and incorporated while changes are still inexpensive, avoiding costly rework later in the SDLC when modifications become far more expensive. Option D is correct because early audit involvement surfaces potential control weaknesses during design and development, before they become embedded in the system and are much harder and costlier to remediate. Option E is correct because audit participation in the design phase provides assurance that necessary controls are built directly into the system architecture rather than bolted on afterward.

Option A is not correct because early internal audit involvement does not eliminate or reduce the need for future independent audits, which remain necessary for objective assurance. Option C is not correct because early audit involvement does not reduce the number of system tests required; testing scope is driven by system complexity, risk, and requirements, not by audit's early participation.

Exam trap

The trap here is that candidates may confuse 'reduced need for future audits' (a false benefit) with 'enhanced assurance' (a real benefit), or assume that early audit involvement reduces testing effort, when in fact it may increase the scope of validation to ensure controls are properly designed and implemented.

191
MCQeasy

A company is designing its backup strategy for a critical database that must be available 24/7. The database experiences high transaction volumes. Which backup method minimizes data loss while allowing continuous operations?

A.Offline full backup performed weekly
B.Differential backup performed daily
C.Online backup with transaction log backups
D.Full backup performed during low-usage periods
AnswerC

Online backups capture the database while it remains accessible, and transaction log backups capture every committed change between full backups, enabling point-in-time recovery. This combination minimises data loss to the last log backup while the database continues serving transactions around the clock.

Why this answer

Online backup with transaction log backups (Option C) is correct because it allows the database to remain fully operational (24/7 availability) while capturing every committed transaction in the transaction log. In the event of a failure, you can restore the most recent full backup and then apply all subsequent transaction log backups to recover to the exact point of failure, minimizing data loss to only uncommitted transactions.

Exam trap

The trap here is that candidates often confuse 'differential backup' with 'transaction log backup,' assuming differential backups provide the same granularity of recovery, when in fact differentials only capture cumulative changes since the last full backup and cannot restore to an arbitrary point in time.

How to eliminate wrong answers

Option A is wrong because an offline full backup performed weekly requires taking the database offline, which violates the 24/7 availability requirement, and a weekly full backup alone would result in up to a week of potential data loss. Option B is wrong because a differential backup captures all changes since the last full backup but does not capture every individual transaction; it still requires a full backup and can lose all changes made since the last differential backup, which could be up to 24 hours of data. Option D is wrong because a full backup performed during low-usage periods still requires taking the database offline (or at least putting it in a consistent state), which disrupts continuous operations, and it does not provide point-in-time recovery granularity.

192
MCQmedium

An IS auditor is planning an audit of a cloud service provider's controls over data backup and recovery. The auditor needs to obtain evidence about the provider's backup procedures and restoration testing. Which of the following is the MOST appropriate source of evidence?

A.The provider's marketing brochure describing its backup and recovery capabilities.
B.The provider's service level agreement (SLA) specifying recovery time objectives.
C.A verbal confirmation from the provider's account manager that backups are performed daily.
D.A service organization control (SOC) 2 Type II report obtained from the provider.
AnswerD

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls over a period, including backup and recovery controls. It is a reliable source of evidence because it is based on testing by a qualified third party. This report can give the auditor confidence in the provider's controls without direct access to the provider's environment.

Why this answer

When auditing a cloud service provider, the auditor often relies on independent third-party attestation reports. A SOC 2 Type II report provides an independent assessment of the design and operating effectiveness of controls, including backup and recovery, over a specified period. It is more reliable than marketing materials, contractual SLAs, or verbal assurances, which do not provide evidence of actual control performance.

Exam trap

The trap here is accepting an SLA or verbal assurance as evidence of control effectiveness, when these only represent commitments or claims rather than tested results.

193
Multi-Selectmedium

During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)

Select 2 answers
A.The system is running 5% slower than expected
B.The system's tax calculation module produced incorrect results for a subset of employees
C.Some employees have not completed training
D.Unauthorized overtime payments were processed due to a configuration error
E.The user manual is not yet finalized
AnswersB, D

Incorrect tax calculations breach statutory withholding and reporting obligations, producing wrong net pay and filing errors for affected employees. This is a data integrity failure in a legally mandated function, so it demands immediate correction ahead of cosmetic or efficiency issues.

Why this answer

Option B is critical because incorrect tax calculations in a payroll system directly violate legal and regulatory compliance requirements, can result in penalties from tax authorities, and harm employee trust through inaccurate pay and withholding. Option D is critical because unauthorized overtime payments from a configuration error represent a direct financial loss and indicate a control failure in the payroll processing logic that could recur and compound if not remediated immediately. In contrast, option A (5% performance degradation) is a performance/efficiency concern that does not affect data integrity or compliance and can be tuned later.

Option C (incomplete training) is a people/process issue that, while important, does not by itself cause incorrect or unauthorized transactions. Option E (unfinalized user manual) is a documentation gap with no immediate financial, legal, or control impact.

Exam trap

CISA often tests the ability to prioritize issues based on risk, tempting candidates to select operational inefficiencies like performance slowdowns or training gaps over critical financial and compliance failures.

194
MCQhard

During an incident, the IT team identifies that a critical patch was not applied due to an expired software maintenance contract. Which of the following is the BEST long-term remediation?

A.Renew the maintenance contract
B.Apply the patch immediately
C.Isolate the affected system
D.Implement a vulnerability management program
AnswerD

The expired maintenance contract is a symptom; the absent control is ongoing identification and remediation of vulnerabilities. A vulnerability management programme continuously scans, prioritises and tracks patching, ensuring contract lapses or missed patches are detected before exploitation rather than after an incident.

Why this answer

The root cause is not the expired contract itself but the absence of a systematic process to identify, prioritize, and remediate vulnerabilities before they are exploited. A vulnerability management program provides ongoing identification, classification, remediation, and verification of vulnerabilities across all assets, ensuring patches are applied regardless of contract status. Renewing the contract or applying the patch addresses only the immediate symptom, while isolation is a containment tactic.

Thus, implementing a vulnerability management program is the best long-term remediation.

Exam trap

CISA often tests the distinction between tactical fixes and strategic root-cause remediation, so candidates may choose 'Apply the patch immediately' because it seems urgent, but the question asks for the BEST long-term remediation.

How to eliminate wrong answers

Option A is wrong because renewing the maintenance contract only restores access to vendor support and patches but does not prevent future lapses or ensure timely patching; it addresses a symptom, not the root cause. Option B is wrong because applying the patch immediately is a tactical fix that resolves the current incident but does not prevent recurrence; it is not a long-term remediation. Option C is wrong because isolating the affected system is a containment measure to limit damage during an incident, not a permanent solution to prevent similar issues.

195
Multi-Selectmedium

Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)

Select 2 answers
A.Mandatory vacation policies
B.Separation of duties
C.Background checks on new hires
D.Password complexity requirements
E.Single sign-on (SSO) systems
AnswersA, B

Mandatory vacation policies force employees to step away from their duties, enabling colleagues to review transactions and uncover irregularities that continuous access would conceal. This directly satisfies the fraud-prevention constraint by removing the perpetrator's ability to sustain concealment, since most IT fraud schemes require ongoing manipulation of records to avoid detection.

Why this answer

Mandatory vacation policies (A) are an effective anti-fraud control because they force another employee to perform the fraudster's duties, exposing schemes such as lapping, ghost vendors, or concealed transactions that depend on continuous, unmonitored access. Separation of duties (B) is effective because it splits critical functions (e.g., authorization, custody of assets, and record-keeping) among different people, so no single individual can both perpetrate and conceal a fraudulent act. Background checks (C) are a preventive screening measure for hiring, not an ongoing control that detects or blocks fraud once an employee is in place.

Password complexity requirements (D) are an authentication control that reduces the risk of credential compromise, but they do not address the internal trust and collusion risks that enable fraud. Single sign-on (E) is a convenience and access-management mechanism that can even concentrate risk, and it does not by itself prevent fraudulent activity.

Exam trap

CISA often tests the distinction between fraud-specific controls (SoD, mandatory vacation, job rotation) and general security controls (passwords, SSO, background checks), tempting candidates to select broad security measures that do not directly address fraud concealment.

196
MCQmedium

An IS auditor is preparing the audit report after completing fieldwork on an organization's backup and restoration process. Management disagrees with one of the findings and has provided additional evidence. Which of the following is the auditor's MOST appropriate course of action?

A.Include management's disagreement in the report but keep the finding unchanged
B.Evaluate the additional evidence and revise or retain the finding based on the results
C.Delete the finding to maintain a cooperative relationship with management
D.Escalate the dispute to the audit committee before evaluating the evidence
AnswerB

Auditors must remain objective and evidence-driven. When management provides new evidence, the auditor should assess its relevance and sufficiency, and if it demonstrates the finding is inaccurate or the risk is mitigated, revise the finding accordingly. If it does not, the finding stands, with management's position documented. This preserves both accuracy and auditor independence.

Why this answer

When management supplies additional evidence during report preparation, the auditor's duty is to evaluate it objectively and adjust the finding if warranted. The conclusion must follow the evidence, not the desire to avoid conflict or the assumption that the original finding is always right. Retaining a finding without evaluation or escalating prematurely both fail to demonstrate the objectivity expected of the auditor.

Exam trap

The trap here is believing the auditor must either defend the original finding or drop it to avoid conflict, when the correct behavior is to objectively evaluate management's new evidence and let it determine the outcome.

197
MCQeasy

An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?

A.It simplifies the IT budgeting process.
B.It ensures IT metrics are aligned with business strategy.
C.It automates data collection for IT metrics.
D.It provides a single financial metric for IT performance.
AnswerB

A balanced scorecard links IT measures across financial, customer, internal process and learning perspectives to organisational objectives, so IT performance is judged by strategic contribution rather than isolated technical metrics. That strategic alignment is its primary benefit.

Why this answer

A balanced scorecard (BSC) translates an organization's mission and strategy into a comprehensive set of performance measures across four perspectives: financial, customer, internal business processes, and learning and growth. Its primary benefit in an IT context is ensuring that IT metrics and activities are directly linked to and driven by business strategy, rather than being measured in isolation. This strategic alignment is the defining purpose of the BSC framework as developed by Kaplan and Norton.

Exam trap

CISA often tests whether candidates confuse the BSC's strategic alignment purpose with operational tooling benefits like budgeting, automation, or single-metric reporting — the trap is picking a tactically appealing but strategically incorrect benefit.

How to eliminate wrong answers

Option A is wrong because the BSC is a strategic performance measurement and management framework, not a budgeting tool; it does not simplify or automate the budgeting process. Option C is wrong because the BSC does not automate data collection — it defines what should be measured, while data collection automation is handled by separate BI or monitoring tools. Option D is wrong because the BSC deliberately uses multiple perspectives (financial, customer, internal process, learning and growth), not a single financial metric, which would defeat its purpose.

198
Multi-Selectmedium

Which TWO of the following are key activities in the system design phase of the SDLC?

Select 2 answers
A.Defining system architecture
B.Writing unit tests
C.Performing user acceptance testing
D.Developing data flow diagrams
E.Gathering business requirements
AnswersA, D

A design activity.

Why this answer

Defining system architecture is a key activity in the system design phase because it establishes the high-level structure of the system, including hardware, software, network components, and their interactions. This blueprint guides subsequent detailed design and implementation, ensuring alignment with functional and non-functional requirements. Without a defined architecture, the system risks integration failures and scalability issues.

Exam trap

The trap here is that candidates often confuse the system design phase with later phases like testing or earlier phases like requirements gathering, leading them to select activities such as writing unit tests or gathering business requirements as design-phase tasks.

199
MCQhard

An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?

A.Several segregation of duties conflicts were identified and not resolved.
B.The implementation took three months longer than planned.
C.The project exceeded the budget by 15%.
D.User acceptance testing (UAT) was completed with only 80% test coverage.
AnswerA

Unresolved segregation of duties conflicts leave incompatible functions, such as creating a vendor and approving its payment, with one person. Unlike tuning or training issues, this is a live control failure that enables fraud or error, so it is the finding of greatest concern in a post-implementation review.

Why this answer

Unresolved segregation of duties (SoD) conflicts in an ERP system pose a significant risk of fraud, unauthorized transactions, and financial misstatement. SoD is a fundamental internal control that prevents any single individual from having control over all aspects of a transaction. Unresolved conflicts indicate a control deficiency that could lead to material misstatement and is of greatest concern to an IS auditor.

Exam trap

CISA often tests the auditor's ability to distinguish between control deficiencies and project management variances, tempting candidates to select budget or schedule overruns over unresolved SoD conflicts that directly impact control effectiveness.

How to eliminate wrong answers

Option B is wrong because a three-month delay is a schedule variance that, while notable, does not directly compromise control integrity or financial accuracy. Option C is wrong because a 15% budget overrun is a financial performance issue but does not inherently indicate a control weakness or risk of fraud. Option D is wrong because 80% UAT coverage, although not ideal, is a testing completeness issue that may be acceptable if risks are mitigated; it is less critical than unresolved SoD conflicts that directly threaten control objectives.

200
MCQeasy

An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are often closed without identifying the root cause, and incidents continue to recur. Which of the following is the MOST likely consequence of this practice?

A.Higher change management costs due to emergency changes.
B.Decreased effectiveness of the service desk due to increased workload.
C.Noncompliance with regulatory requirements for incident reporting.
D.Increased number of incidents and reduced service availability.
AnswerD

If problems are not resolved by addressing root causes, the underlying issues persist and generate recurring incidents. This leads to increased incident volume and reduced service availability, as the same problems disrupt services repeatedly. The auditor should recognize that effective problem management is essential to prevent incident recurrence and improve overall stability. This is the most direct consequence.

Why this answer

Problem management aims to identify and resolve root causes to prevent incident recurrence. When problems are closed without root cause analysis, the underlying issues remain, causing the same incidents to happen again. This directly increases the number of incidents and reduces service availability.

Other consequences, such as higher change costs or service desk workload, are secondary effects. The auditor should recognize that ineffective problem management leads to chronic operational instability.

Exam trap

The trap here is selecting a secondary effect like increased service desk workload or change costs, instead of recognizing that the fundamental consequence of unresolved problems is the persistent recurrence of incidents and degraded availability.

201
Multi-Selectmedium

Which TWO of the following are key controls for ensuring data privacy during system development?

Select 2 answers
A.Using real customer data for testing
B.Encrypting stored data
C.Disabling audit logs during development
D.Allowing developers unlimited access to production data
E.Data masking in test environments
AnswersB, E

Encrypting stored data directly satisfies the privacy requirement by rendering data unreadable without decryption keys, protecting confidentiality if storage media or backups are compromised. This control addresses data-at-rest exposure, a core privacy safeguard during development, ensuring sensitive personal information remains protected against unauthorised access throughout the system's lifecycle.

Why this answer

Option B (Encrypting stored data) is correct because encryption at rest (e.g., AES-256) protects sensitive data from unauthorized disclosure even if storage media or backups are compromised, directly supporting data privacy during development. Option E (Data masking in test environments) is correct because masking, tokenization, or pseudonymization replaces real PII with realistic but fictitious values, allowing developers and testers to work without exposing actual customer data. Option A is wrong because using real customer data for testing violates privacy principles and regulations like GDPR or HIPAA; test data should be synthetic or masked.

Option C is wrong because disabling audit logs removes accountability and traceability, which are essential privacy and security controls. Option D is wrong because unlimited developer access to production data violates least privilege and dramatically increases the risk of privacy breaches.

Exam trap

The trap here is that candidates may confuse 'data masking' with 'anonymization' and overlook its role as a key privacy control, or mistakenly think that using real data in test environments is acceptable if it is 'just for testing,' ignoring regulatory and ethical requirements.

202
MCQmedium

An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?

A.Secure key storage (e.g., HSM)
B.Key rotation policy
C.Key generation in a secure environment
D.Key destruction procedures
AnswerA

Secure key storage in a hardware security module protects keys at rest within tamper-resistant hardware, preventing extraction or disclosure. Since compromise of the key itself defeats every cryptographic protection built upon it, this control is the most critical safeguard.

Why this answer

Secure key storage, typically in a hardware security module (HSM), is the most critical control because it protects keys at rest from extraction, tampering, and unauthorized access throughout their lifecycle. If keys can be stolen from storage, every other control — generation, rotation, destruction — is undermined, since the attacker gains the key material itself. HSMs provide tamper resistance, cryptographic isolation, and access controls that software storage cannot match.

Exam trap

CISA often tests the hierarchy of key management controls — candidates pick rotation or generation because they sound proactive, but the exam expects recognition that secure storage is foundational because compromised keys nullify all other controls.

How to eliminate wrong answers

Option B is wrong because key rotation limits the window of exposure if a key is compromised, but it is a mitigating control, not the foundational one — a stolen key is still usable until rotation occurs. Option C is wrong because secure key generation ensures keys have sufficient entropy and are not predictable, which is important, but a well-generated key is worthless if it can be extracted from weak storage. Option D is wrong because key destruction procedures prevent residual key material from being recovered after retirement, which addresses end-of-life risk, not the ongoing protection of active keys.

203
MCQhard

An organization is implementing a data retention policy for personally identifiable information (PII) to comply with GDPR. Which of the following is the MOST appropriate approach?

A.Delete PII as soon as it is collected
B.Anonymize PII after a fixed period and retain indefinitely
C.Retain PII indefinitely for historical analysis
D.Define retention periods based on legal and business requirements and securely delete after
AnswerD

GDPR requires storage limitation, so retention periods must derive from specific legal and business justifications rather than blanket indefinite storage. Securely deleting PII once those periods expire enforces the principle, satisfying the regulation's requirement that personal data be kept no longer than necessary.

Why this answer

GDPR mandates that PII must not be kept longer than necessary for the purpose for which it was collected. Defining retention periods based on legal and business requirements ensures compliance with the storage limitation principle (Article 5(1)(e)), and secure deletion (e.g., using cryptographic erasure or overwriting with tools like shred on Linux) prevents unauthorized recovery. This approach balances regulatory compliance with operational needs.

Exam trap

The trap here is that candidates may confuse 'anonymization' (Option B) as a safe harbor for indefinite retention, but GDPR requires that anonymization be irreversible and that the retained data serve a legitimate purpose, not just be kept indefinitely without justification.

How to eliminate wrong answers

Option A is wrong because deleting PII immediately upon collection would violate legitimate business and legal requirements (e.g., tax records or contractual obligations) that necessitate retention for a defined period. Option B is wrong because anonymization after a fixed period may comply with GDPR if irreversible, but retaining anonymized data indefinitely still poses re-identification risks (e.g., via linkage attacks) and violates the principle of data minimization if no business need exists. Option C is wrong because retaining PII indefinitely for historical analysis violates GDPR's storage limitation principle unless the data is anonymized and the purpose is compatible with the original collection; indefinite retention of PII without a legal basis exposes the organization to fines and breach risks.

204
Multi-Selecteasy

An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?

Select 2 answers
A.Use of biometric authentication
B.Single sign-on for all applications
C.Quarterly recertification of access by managers
D.Automatic provisioning upon employee hire
E.Access requests approved by the data owner
AnswersC, E

Quarterly recertification forces managers to confirm each user's continued business need for financial application access, catching privilege creep and stale entitlements between joiner-mover-leaver events. This directly satisfies the stem's requirement for controls ensuring access remains appropriate over time.

Why this answer

Option C is correct because quarterly recertification of access by managers ensures that users' privileges are periodically reviewed and revoked when no longer needed, directly supporting the principle of least privilege and preventing privilege creep in a sensitive financial application. Option E is correct because access requests approved by the data owner enforce proper authorization by the individual accountable for the data, ensuring that only legitimate business needs grant access to sensitive financial information. Biometric authentication (A) strengthens identity verification but does not by itself ensure that access rights are appropriate or authorized.

Single sign-on (B) improves convenience and can centralize authentication, but it can also broaden exposure if not tightly controlled and does not validate the appropriateness of access. Automatic provisioning upon hire (D) speeds onboarding but risks granting excessive or unauthorized access without proper approval, making it a weaker control for ensuring appropriate access.

Exam trap

CISA often tests the distinction between authentication controls (biometrics, SSO) and authorization/governance controls (recertification, data-owner approval), luring candidates toward technically impressive but governance-irrelevant options.

205
MCQhard

An IS auditor is reviewing a batch job scheduling environment. A critical nightly job that feeds the general ledger depends on a file transfer from a subsidiary. The scheduler is configured so that if the transfer does not complete by 02:00, the job is cancelled and the ledger is not updated. Operations staff report that they manually rerun the job each morning when this occurs. Which of the following is the MOST important issue for the auditor to raise?

A.The manual morning reruns are not documented, approved, or monitored as operational procedures.
B.The scheduler cancels the job instead of retrying the file transfer automatically.
C.The subsidiary file transfer uses a protocol that is not encrypted.
D.The 02:00 cutoff time is too early for the subsidiary to complete its transfer.
AnswerA

Undocumented manual reruns mean the ledger update depends on informal operator knowledge rather than a controlled procedure. If the operator is absent or the rerun is performed incorrectly, financial data may be incomplete or posted late without detection. The auditor's key concern is that a recurring failure has been normalized into an uncontrolled workaround, bypassing scheduling, approval, and monitoring controls over a financially significant batch process.

Why this answer

A recurring batch failure that is silently corrected by manual reruns represents an uncontrolled operational workaround. Because the ledger update depends on informal operator action, there is no assurance that the rerun is performed consistently, authorized, or evidenced. The auditor should require that the dependency failure be detected and alerted, that the recovery procedure be documented and approved, and that reruns be logged and reviewed so completeness of financial processing is demonstrable.

Exam trap

The trap here is focusing on the technical scheduling configuration instead of recognizing that the real weakness is an undocumented manual workaround supporting a financially significant process.

206
MCQmedium

Which of the following is the PRIMARY purpose of audit working papers?

A.To facilitate peer review of the audit
B.To serve as a legal record of the audit
C.To store historical data for future audits
D.To provide a basis for the audit report
AnswerD

Working papers document the evidence gathered, procedures performed and conclusions reached, forming the evidential foundation on which the auditor's opinion rests. This satisfies the primary purpose by supporting the audit report, rather than serving as a management record or operational tool.

Why this answer

Working papers document audit procedures, evidence, and conclusions to support the audit opinion.

207
MCQhard

An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:

A.Finding
B.Deficiency
C.Observation
D.Material weakness
AnswerD

A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement will not be prevented or detected timely. This classification matches the stem's identified risk of material misstatement.

Why this answer

A control deficiency that could result in a material misstatement in the financial statements should be classified as a material weakness. This is a significant deficiency, or combination of deficiencies, that results in a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.

Exam trap

CISA often tests the definitions of deficiency classifications; candidates may confuse 'deficiency' with 'material weakness', but the latter specifically implies a reasonable possibility of material misstatement.

How to eliminate wrong answers

Option A is wrong because 'finding' is a general term for any audit result, not a specific classification of deficiency severity. Option B is wrong because 'deficiency' is a broader term that includes less severe issues; a material weakness is a specific type of deficiency. Option C is wrong because 'observation' is a neutral term for something noted, not a classification of control deficiency severity.

208
MCQmedium

Which of the following is the best example of audit evidence obtained through re-performance?

A.Reviewing log files for unauthorized access attempts
B.Interviewing the system administrator about backup procedures
C.Observing employees as they process transactions
D.Recalculating the total of a control report to verify accuracy
AnswerD

Re-performance requires the auditor to independently execute the control or calculation and compare the result with the original. Recalculating a control report's total reproduces the entity's own procedure, yielding direct evidence of accuracy rather than relying on inspection or inquiry.

Why this answer

Re-performance involves the auditor independently executing the same procedure or control that was originally performed by the auditee. Recalculating the total of a control report to verify accuracy is a classic example of re-performance, as the auditor independently computes the total to confirm it matches the report.

Exam trap

CISA often tests evidence-gathering techniques; candidates may confuse re-performance with inspection or observation, but re-performance requires the auditor to actually execute the procedure.

How to eliminate wrong answers

Option A is wrong because reviewing log files is inspection of documents, not re-performance. Option B is wrong because interviewing is inquiry, a verbal evidence-gathering technique. Option C is wrong because observing employees is observation, which involves watching a process without executing it.

209
MCQeasy

An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?

A.To identify inactive user accounts
B.To verify that users' access rights remain appropriate for their roles
C.To ensure compliance with password policies
D.To enforce segregation of duties
AnswerB

Recertification forces managers to periodically revalidate each user's entitlements against current job duties, catching privilege creep and stale accounts created by transfers or role changes. This directly satisfies the control objective of confirming access remains appropriate for users' roles.

Why this answer

The primary purpose of user access recertification is to verify that each user's access rights remain appropriate for their current role and responsibilities (B). It is a detective governance control that catches privilege creep, role changes, and orphaned entitlements that accumulate over time. While recertification can surface inactive accounts, that is a byproduct rather than the primary objective; the core intent is validating the ongoing business need for access.

Exam trap

The trap here is confusing recertification's primary purpose (validating appropriateness of access) with its incidental benefits (finding inactive accounts), causing candidates to select the tempting but secondary answer.

How to eliminate wrong answers

Option A is wrong because identifying inactive accounts is a secondary benefit of recertification, not its primary purpose; dedicated dormancy reports or last-login analysis handle that more directly. Option C is wrong because password policy compliance is enforced through technical controls such as complexity rules, expiration, and lockout thresholds, not through access reviews. Option D is wrong because segregation of duties is enforced through role design, conflict-of-interest rules, and preventive controls at provisioning time; recertification may detect SoD conflicts but does not enforce them.

210
MCQmedium

An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?

A.Right-to-audit clause
B.Service level agreement (SLA) with penalties
C.Exit strategy clause
D.Confidentiality clause
AnswerA

A right-to-audit clause contractually grants the organisation and its IS auditors the authority to examine the provider's controls, evidence and processes. Without it, the provider can lawfully refuse access, so this clause directly satisfies the requirement to assess third-party controls.

Why this answer

A right-to-audit clause (A) is the most important contractual provision because it grants the organization (and its auditors or regulators) the legal right to examine the service provider's controls, records, and facilities. Without it, the auditor has no contractual basis to assess the provider's control environment, making third-party risk assurance impossible. SLAs, exit strategies, and confidentiality clauses address performance, transition, and data protection respectively, but none of them enable control assessment.

Exam trap

The trap is selecting a clause that sounds protective (SLA penalties, confidentiality) when the question specifically asks about enabling the auditor to assess controls, which only a right-to-audit clause provides.

How to eliminate wrong answers

Option B is wrong because an SLA with penalties governs service performance and remedies for failure; it does not grant the auditor access to evaluate the provider's internal controls. Option C is wrong because an exit strategy clause addresses how the relationship terminates and how data/assets are returned or destroyed; it is a continuity control, not an audit-enablement control. Option D is wrong because a confidentiality clause protects the provider's and the organization's sensitive information; it actually can restrict information sharing and does not by itself authorize audit access.

211
MCQhard

A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?

A.The IT infrastructure complexity.
B.The size of the organization.
C.The number of IT staff.
D.The industry and regulatory environment.
AnswerD

Industry and regulatory environment design factors shape mandatory compliance obligations and risk appetite, so they most strongly determine governance system design. They drive which COBIT components and focus areas are tailored, outweighing enterprise-specific factors such as size or threat landscape.

Why this answer

According to COBIT 2019, the industry and regulatory environment is a key design factor that significantly influences the governance system design, as it dictates compliance and risk management requirements. Options A, B, and C are factors but have a lesser impact compared to industry and regulatory considerations.

212
MCQhard

An organization is developing a critical application using an agile methodology. The project sponsor demands frequent deliveries but the development team is concerned about insufficient testing. Which of the following BEST mitigates this risk?

A.Deploy with known defects and fix them in the next sprint
B.Increase manual testing effort at the end of each sprint
C.Extend the release cycle to allow more time for testing
D.Implement continuous integration and automated testing
AnswerD

Automated testing within a continuous integration pipeline runs on every commit, so defects surface immediately rather than accumulating. This directly satisfies the sponsor's demand for frequent deliveries while removing the team's testing-capacity constraint, since regression checks execute without manual effort.

Why this answer

Continuous integration (CI) and automated testing enable frequent, reliable code integration and immediate feedback on defects, directly addressing the tension between rapid delivery and insufficient testing. Automated tests run on every commit, catching regressions early without manual overhead, which is essential for agile sprints where manual testing alone cannot scale to match delivery velocity.

Exam trap

The trap here is that candidates may choose Option B (increase manual testing) because they equate 'more testing' with 'better quality,' failing to recognize that manual testing cannot keep pace with agile's rapid delivery cycles and that automation is the only scalable solution to integrate testing into every iteration.

How to eliminate wrong answers

Option A is wrong because deploying known defects increases technical debt and risk in production, violating the principle of maintaining a shippable increment in agile and potentially causing cascading failures. Option B is wrong because increasing manual testing at the end of each sprint creates a bottleneck, contradicts the agile goal of continuous testing, and does not scale with frequent deliveries, leading to delayed feedback and incomplete coverage. Option C is wrong because extending the release cycle undermines the project sponsor's demand for frequent deliveries and does not solve the root cause of insufficient testing; it merely postpones risk rather than mitigating it through automation.

213
MCQmedium

An IT auditor is evaluating the change management process for a financial trading system. Which of the following is the BEST indicator of a mature change management process?

A.Changes are documented after deployment
B.All changes are logged and require automated approval workflows
C.Developers can deploy changes directly to production if urgent
D.Changes are approved verbally by the IT manager
AnswerB

Provides control and traceability.

Why this answer

A mature change management process requires that all changes be formally logged and subjected to automated approval workflows. This ensures traceability, segregation of duties, and auditability, which are critical for a financial trading system where unauthorized or untracked changes could lead to financial loss or regulatory non-compliance.

Exam trap

The trap here is that candidates may confuse 'efficiency' (e.g., allowing direct deployment for urgent changes) with 'maturity,' but mature processes prioritize control and auditability over speed, especially in high-risk systems like financial trading platforms.

How to eliminate wrong answers

Option A is wrong because documenting changes after deployment violates the principle of proactive control; changes should be approved and documented before deployment to prevent unauthorized or untested modifications. Option C is wrong because allowing developers to deploy changes directly to production bypasses all change control gates, increasing the risk of introducing errors or security vulnerabilities without review. Option D is wrong because verbal approvals lack an audit trail and are not verifiable, making them unsuitable for a regulated financial environment where every change must be recorded and traceable.

214
Multi-Selecthard

An IS auditor is assessing the IT governance framework of a retail company. The auditor finds that the company has a formal IT strategy, an IT steering committee, and a defined IT organizational structure. However, the auditor notes that there is no process to ensure that IT investments are justified and prioritized. Which of the following are the MOST appropriate recommendations to address this deficiency? (Choose two.)

Select 2 answers
A.Conduct a post-implementation review of all IT projects.
B.Increase the frequency of IT steering committee meetings to monthly.
C.Implement a formal IT investment approval process with defined criteria.
D.Establish an IT portfolio management function to oversee investment prioritization.
E.Delegate investment decisions to individual business units to speed up approvals.
AnswersC, D

A formal IT investment approval process with defined criteria (e.g., ROI, strategic alignment, risk) ensures that investments are justified and prioritized consistently. This directly addresses the deficiency of no process to justify and prioritize IT investments. It provides a structured mechanism for decision-making and accountability, which is essential for effective IT governance.

Why this answer

The most appropriate recommendations are to implement a formal IT investment approval process with defined criteria and to establish an IT portfolio management function. These two measures directly address the absence of a process to justify and prioritize IT investments. The approval process ensures that each investment is evaluated against consistent criteria, while portfolio management provides ongoing oversight and prioritization across all investments, aligning them with strategic objectives.

Exam trap

The trap here is selecting actions that improve oversight frequency or delegate decisions, which do not establish a structured process for justifying and prioritizing investments.

215
MCQhard

During an IT audit, the auditor observes that mandatory vacation policies are not enforced for IT staff with access to financial systems. What is the PRIMARY risk associated with this finding?

A.Increased likelihood of system downtime
B.Increased risk of undetected fraud
C.Inadequate segregation of duties
D.Non-compliance with licensing agreements
AnswerB

Unenforced mandatory vacation lets staff with financial-system access retain continuous control of transactions, so fraudulent entries and concealment schemes can persist without a forced handover period. That continuity removes the detection window a rotated absence would create, directly increasing the risk of undetected fraud.

Why this answer

Mandatory vacation policies force the periodic removal of an employee's access, which allows detection of irregularities or fraudulent activities that require the employee's continued presence to conceal. Without enforcement, a malicious insider could perpetrate fraud (e.g., creating ghost vendors, altering payment records) and cover it up by maintaining daily control over transactions. This directly increases the risk that fraudulent actions will go undetected over extended periods.

Exam trap

The trap here is that candidates confuse mandatory vacation policies with segregation of duties, assuming both address the same control objective, when in fact vacation enforcement is a detective control for fraud detection, not a preventive control for duty separation.

How to eliminate wrong answers

Option A is wrong because system downtime is primarily caused by technical failures, misconfigurations, or denial-of-service attacks, not by the absence of mandatory vacation enforcement. Option C is wrong because segregation of duties is a separate control that divides critical functions among multiple people; mandatory vacation policies address detection of fraud, not the structural separation of duties. Option D is wrong because non-compliance with licensing agreements relates to software license management and unauthorized use, which is unrelated to employee vacation policies.

216
MCQhard

An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?

A.Insufficient training of end users
B.Lack of executive sponsorship
C.Inadequate segregation of duties in the new system
D.Inaccurate data mapping between legacy and new systems
AnswerD

Mapping errors propagate corrupted or misaligned values into the new ERP, so migrated records may be incomplete or wrongly attributed. Because mapping defects are systemic, they affect entire data sets rather than isolated rows, undermining financial reporting and downstream processing long after go-live.

Why this answer

Data migration often involves mapping old data to new structures. Inaccurate mapping can lead to data corruption or loss, which is a critical risk.

217
MCQeasy

An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?

A.CCTV cameras
B.Visitor log
C.Mantrap
D.Biometric readers
AnswerC

A mantrap admits one person at a time through interlocking doors, so a second individual cannot follow on the first person's valid credential. This physically enforces single-person entry, directly preventing the unauthorised tailgating the stem asks about.

Why this answer

A mantrap (C) is the most effective control for preventing tailgating because it physically admits only one person at a time through an interlocking door system, using weight sensors, biometrics, or access cards to verify each individual before the second door opens. It enforces one-person-per-entry at the physical layer, which no camera or log can do. CCTV and visitor logs are detective controls, and biometric readers authenticate individuals but do not by themselves prevent a second person from slipping through behind an authorized user.

Exam trap

The trap is confusing authentication controls (biometric readers) with anti-tailgating controls, leading candidates to pick a device that verifies identity but does not physically prevent multiple people from entering.

How to eliminate wrong answers

Option A is wrong because CCTV cameras are detective controls that record activity for later review; they do not physically prevent a person from following an authorized user through a door. Option B is wrong because a visitor log is an administrative, detective control that documents entry after the fact and does nothing to stop unauthorized physical entry. Option D is wrong because biometric readers authenticate the person presenting the credential but, without an interlocking physical barrier, an unauthorized person can still tailgate behind the authenticated individual.

218
Multi-Selecthard

Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)

Select 2 answers
A.Ensuring appropriate access to resources.
B.Enforcing least privilege principle.
C.Encrypting data at rest and in transit.
D.Patching software vulnerabilities.
E.Monitoring network traffic for anomalies.
AnswersA, B

IAM's core purpose is granting the right users access to the right resources at the right times, supporting business operations securely. This provisioning objective is distinct from authentication, which merely verifies identity before access decisions are enforced.

Why this answer

Option A, ensuring appropriate access to resources, is a core IAM objective because IAM governs who (identity) can access which resources (applications, data, systems) and under what conditions, typically through authentication, authorization, and provisioning/deprovisioning processes. Option B, enforcing the least privilege principle, is also a primary IAM objective since IAM implements least privilege by granting users only the minimum rights needed for their roles, often via role-based access control (RBAC), access reviews, and just-in-time elevation. The other options do not belong: C (encrypting data at rest and in transit) is a data protection/cryptography control, D (patching software vulnerabilities) is vulnerability and patch management, and E (monitoring network traffic for anomalies) is network security monitoring/IDS/IPS, none of which are primary IAM objectives.

Exam trap

The trap here is that candidates often confuse IAM with general security controls like encryption or network monitoring, but IAM strictly deals with identity lifecycle, authentication, authorization, and access governance, not data protection or network-level defenses.

219
MCQmedium

An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?

A.Approval from the Change Advisory Board (CAB)
B.Extensive user acceptance testing (UAT) results
C.A completed impact analysis
D.A documented rollback plan
AnswerD

A documented rollback plan directly satisfies the emergency change constraint by enabling rapid restoration of the financial application if the change fails, minimising disruption to critical processing. Verifying it confirms the organisation can reverse unplanned modifications without extended downtime, which matters more than retrospective approvals when emergency changes bypass normal change management controls.

Why this answer

In an emergency change, the most critical element to verify is a documented rollback plan. Emergency changes are implemented with minimal testing and often bypass normal approval processes; a rollback plan ensures that if the change fails or causes unintended consequences, the system can be restored to its previous state quickly, minimizing disruption to critical financial operations.

Exam trap

CISA often tests the prioritization of controls in emergency changes, tempting candidates to select standard controls like CAB approval or UAT that are often bypassed in emergencies, instead of the rollback plan that is the key risk mitigation.

How to eliminate wrong answers

Option A is wrong because while CAB approval is important, in an emergency, approval may be retrospective; the immediate priority is having a rollback plan to mitigate failure. Option B is wrong because extensive UAT is typically not feasible in an emergency; the focus is on minimizing risk through rollback rather than comprehensive testing. Option C is wrong because an impact analysis, though valuable, may be abbreviated in an emergency; the rollback plan is the key safeguard against unforeseen negative impacts.

220
MCQhard

An IS auditor is evaluating a wireless network deployed in a corporate headquarters. The auditor discovers that the network uses WPA2-Enterprise with 802.1X authentication, but the RADIUS server accepts any client presenting a valid domain user account, including accounts belonging to recently terminated employees that have not yet been disabled. Which of the following is the GREATEST risk arising from this configuration?

A.Rogue access points could be introduced without detection by the wireless intrusion prevention system.
B.Former employees with still-valid accounts could authenticate to the internal network and access resources.
C.Wireless traffic could be decrypted by anyone monitoring the radio frequency spectrum.
D.Attackers could capture and crack the pre-shared key used for wireless encryption.
AnswerB

The core weakness is that terminated users retain working credentials that the RADIUS server accepts. An ex-employee who remembers those credentials can pass 802.1X authentication and reach internal network resources as an authorized user. This is a logical access failure, and it directly enables unauthorized entry into the protected environment through the wireless infrastructure.

Why this answer

The finding is that authentication succeeds for accounts belonging to terminated employees, meaning the RADIUS server does not enforce timely deprovisioning. Because 802.1X grants network access on successful authentication, a former employee can re-enter the internal network using valid credentials. The primary risk is unauthorized internal access through a logical access control failure, not encryption weakness or rogue devices.

Exam trap

The trap here is focusing on wireless encryption strength when the actual exposure is a logical access control gap caused by stale, still-valid credentials.

221
Multi-Selecthard

Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)

Select 3 answers
A.Fieldwork
B.Remediation
C.Reporting
D.Planning
E.Execution
AnswersA, C, D

Fieldwork is the ISACA audit phase where evidence is gathered, tests are performed and working papers are produced. It sits between planning and reporting, satisfying the requirement to name an actual phase of the audit process.

Why this answer

ISACA's audit process is commonly structured around three core phases: Planning (option D), Fieldwork (option A), and Reporting (option C). Planning (D) is correct because it is the initial phase where the audit scope, objectives, risk assessment, criteria, and resource requirements are defined before any testing begins. Fieldwork (A) is correct because it is the phase in which auditors gather evidence, perform tests of controls and substantive procedures, and document findings to support conclusions.

Reporting (C) is correct because it is the phase where the auditor communicates results, including findings, conclusions, and recommendations, to management and the audit committee. Remediation (B) is not a phase of the audit process itself but rather a post-audit management activity of correcting identified issues, and Execution (E) is not an ISACA-defined phase name — it is essentially synonymous with fieldwork and is not used as a distinct phase in ISACA's model.

Exam trap

CISA often tests the distinction between audit phases and post-audit activities — candidates mistakenly include remediation or execution as audit phases, confusing management follow-up with the audit process itself.

222
MCQmedium

A company is implementing a cloud-based identity and access management (IAM) system. Which of the following best describes the principle of least privilege in this context?

A.Users should have administrative rights for troubleshooting.
B.Permissions should be revoked only when an employee leaves the company.
C.All users should have the same level of access for consistency.
D.Permissions should be granted based on the user's role and need-to-know.
AnswerD

Least privilege restricts each identity to the minimum permissions its job function requires, granted through role assignments rather than broad standing access. This limits blast radius if credentials are compromised, directly satisfying the need-to-know constraint for cloud IAM.

Why this answer

The principle of least privilege dictates that users should be granted only the permissions necessary to perform their job functions, based on their role and need-to-know. In a cloud-based IAM system, this is typically implemented through role-based access control (RBAC) or attribute-based access control (ABAC), ensuring minimal exposure to sensitive resources and reducing the attack surface.

Exam trap

The trap here is that candidates often confuse 'least privilege' with 'administrative convenience' or 'consistency,' mistakenly thinking that granting admin rights for troubleshooting (Option A) or uniform access (Option C) simplifies management, when in fact these practices directly violate the core security principle.

How to eliminate wrong answers

Option A is wrong because granting administrative rights for troubleshooting violates least privilege by providing excessive, often permanent, elevated privileges that can be exploited or misused; instead, temporary just-in-time (JIT) access or privileged access management (PAM) should be used. Option B is wrong because permissions should be reviewed and revoked promptly when no longer needed, not only upon employee departure; failure to do so leads to privilege creep and increased risk of unauthorized access. Option C is wrong because uniform access for all users contradicts least privilege, as it ignores the varying job functions and data sensitivity levels, leading to over-privileged users and potential data breaches.

223
Multi-Selecthard

A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)

Select 3 answers
A.IT decisions are made in silos
B.IT budget is allocated based on historical spending
C.There is a formal IT governance committee
D.IT performance metrics are linked to business outcomes
E.IT strategy is reviewed quarterly by the board
AnswersC, D, E

A formal IT governance committee provides the standing oversight structure through which decisions, accountability and resource direction are exercised. Its existence demonstrates that governance is institutionalised rather than ad hoc, which is a recognised indicator of a mature governance process.

Why this answer

Option C is correct because a formal IT governance committee establishes clear accountability, decision rights, and oversight structures, which are hallmarks of a mature governance process rather than ad hoc or siloed decision-making. Option D is correct because linking IT performance metrics to business outcomes demonstrates that governance is aligned with enterprise strategy and value delivery, a key maturity indicator in frameworks such as COBIT. Option E is correct because regular board-level review of IT strategy, such as quarterly, shows sustained executive engagement, strategic alignment, and proactive oversight rather than reactive or infrequent attention.

Options A and B do not belong because siloed IT decision-making and budget allocation based solely on historical spending reflect immature, reactive governance practices that lack integration, strategic alignment, and value-based prioritization.

Exam trap

CISA often tests whether candidates can distinguish mature governance indicators (formal committees, business-linked metrics, board review) from immature practices (silos, historical budgeting) that are sometimes mistaken for stability.

224
MCQmedium

An organization is transitioning from a waterfall to an agile development methodology. Which of the following is a key risk that the IS auditor should highlight?

A.User requirements may be incomplete at the start.
B.Testing is deferred until the end of the project.
C.Stakeholder involvement may decrease.
D.Scope creep may increase without proper controls.
AnswerD

Agile's short, iterative cycles and evolving backlogs let requirements expand continuously without formal change gates, so uncontrolled scope creep inflates effort and delays delivery. Waterfall's sequential baselined phases constrained this, making scope creep the key risk an IS auditor should highlight.

Why this answer

In agile development, iterative cycles and continuous feedback can lead to scope creep if changes are not managed through a disciplined backlog prioritization process. Unlike waterfall, where scope is fixed early, agile's flexibility requires robust controls (e.g., sprint boundaries, product owner authority) to prevent uncontrolled expansion. An IS auditor should highlight this risk because without proper governance, the project may exceed budget and timeline despite agile's adaptive nature.

Exam trap

The trap here is that candidates mistakenly think agile eliminates scope creep entirely, when in fact its flexibility requires even stronger controls to prevent uncontrolled expansion, especially during the transition from waterfall.

How to eliminate wrong answers

Option A is wrong because incomplete user requirements at the start are an accepted characteristic of agile, not a key risk; agile embraces evolving requirements through iterative refinement. Option B is wrong because agile integrates testing continuously throughout each sprint (e.g., test-driven development), not deferred to the end. Option C is wrong because agile explicitly requires high stakeholder involvement (e.g., daily stand-ups, sprint reviews, product owner role), so decreased involvement would violate core agile principles.

225
MCQhard

An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?

A.Accept the decision as business risk acceptance
B.Escalate to senior management as a critical finding
C.Recommend immediate decommissioning of the application
D.Verify that the risk has been formally accepted and compensating controls are implemented
AnswerD

Verifying formal risk acceptance and compensating controls confirms the residual risk is documented, authorised by accountable management and mitigated, satisfying the auditor's duty to ensure the unfixed vulnerability is consciously owned rather than silently ignored before decommissioning.

Why this answer

The auditor's proper action is to verify that the risk has been formally accepted by the appropriate authority and that compensating controls are implemented (D). Risk acceptance is a legitimate management decision, but it must be documented, approved at the right level, and supported by mitigating controls given the criticality of the vulnerability. The auditor's role is to validate that this governance process occurred, not to unilaterally accept, escalate, or demand decommissioning.

Exam trap

The trap is the auditor's role confusion — candidates either overstep by escalating or recommending decommissioning, or understep by accepting the risk themselves, instead of verifying formal acceptance and compensating controls.

How to eliminate wrong answers

Option A is wrong because the auditor cannot simply accept the decision; acceptance is management's prerogative, and the auditor must verify that it was formally documented and approved by the appropriate authority. Option B is wrong because escalation to senior management is premature if the risk has been properly accepted and compensating controls exist; escalation is warranted only when acceptance is undocumented or outside the approver's authority. Option C is wrong because recommending immediate decommissioning is a business decision beyond the auditor's mandate and ignores the possibility of compensating controls and the planned six-month decommissioning timeline.

Page 2

Page 3 of 13

Page 4