Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 451–525

934 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
Multi-Selectmedium

An IS auditor is evaluating the reliability of audit evidence obtained during a review of an outsourced payroll provider. Which TWO of the following considerations most directly affect the reliability of that evidence? (Choose two.)

Select 2 answers
A.Whether the vendor's management has verbally confirmed the accuracy of the evidence.
B.Whether the evidence is stored in the auditor's working paper repository.
C.Whether the evidence was collected within the current audit period.
D.Whether the evidence is supported by an independent third-party assurance report, such as a SOC 2 report.
E.Whether the evidence was obtained directly by the auditor rather than provided by the vendor.
AnswersD, E

An independent assurance report provides corroboration from a qualified party and increases the reliability of the evidence about the vendor's controls. It reduces reliance on management representations alone. The auditor should still evaluate the report's scope, period, and the service auditor's competence, but the independent attestation materially strengthens the evidence's credibility.

Why this answer

Reliability of evidence is driven primarily by the independence of the source and the auditor's direct involvement in obtaining it. Evidence obtained directly by the auditor and evidence corroborated by an independent assurance report are the strongest here. Verbal representations and storage location do not enhance reliability, and timeliness speaks to relevance more than reliability.

Exam trap

The trap here is conflating relevance attributes such as timeliness with reliability, and treating management representations as if they were independent evidence.

452
Multi-Selecteasy

Which THREE of the following are commonly used data encryption standards? (Choose three.)

Select 3 answers
A.3DES
B.SHA-256
C.RSA
D.AES
E.MD5
AnswersA, C, D

3DES applies the DES cipher three times with two or three distinct keys, giving an effective strength of 112 or 168 bits. Although deprecated in favour of AES, it remains a widely recognised symmetric encryption standard and is therefore a valid selection here.

Why this answer

3DES (A) is a symmetric block cipher that applies the DES algorithm three times to each data block, making it a widely recognized data encryption standard. RSA (C) is an asymmetric encryption standard based on public/private key pairs, commonly used for encrypting data and exchanging keys. AES (D) is the modern symmetric block cipher standard adopted by NIST, widely used for data-at-rest and data-in-transit encryption.

SHA-256 (B) and MD5 (E) are cryptographic hash functions used for integrity and message digests, not for encrypting data, so they do not belong among encryption standards.

Exam trap

The trap here is confusing cryptographic hash functions (SHA-256, MD5) with encryption standards, leading candidates to select them as methods for protecting data confidentiality rather than integrity.

453
MCQmedium

An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?

A.Strong password policy
B.Audit logging of access attempts
C.Monthly access recertification
D.Role-based access control (RBAC)
AnswerB

Audit logging records every authentication and authorisation event, including failed attempts, giving the auditor an independent trail to detect unauthorised access after the fact. This directly satisfies the stem's requirement for a detective control, unlike preventive measures such as passwords or Microsoft Entra ID conditional access, which block access but cannot reveal that an intrusion occurred.

Why this answer

Audit logging of access attempts is the most important control to detect unauthorized access because it creates a chronological record of who attempted to access what, when, and whether the attempt succeeded or failed. Detection requires evidence of events, and only logging provides that evidence after the fact. Strong passwords, recertification, and RBAC are preventive or administrative controls that reduce the likelihood of unauthorized access but do not detect it when it occurs.

Exam trap

CISA often tests the distinction between preventive, detective, and corrective controls; candidates frequently choose a strong preventive control like RBAC or password policy when the question specifically asks for detection of unauthorized access.

How to eliminate wrong answers

Option A is wrong because a strong password policy is a preventive control that makes credential guessing harder, but it does not record or alert on unauthorized access attempts. Option C is wrong because monthly access recertification is a detective control for excessive or inappropriate entitlements, not for actual unauthorized access events; it reviews who should have access, not who actually accessed. Option D is wrong because RBAC is a preventive access control model that limits permissions based on roles, but it does not detect when someone bypasses or abuses those permissions.

454
Multi-Selecthard

An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?

Select 2 answers
A.Regression testing is not performed for minor changes.
B.Emergency changes are authorized by the change manager only.
C.Normal changes are tested in a development environment before production.
D.The change advisory board meets weekly to review all changes.
E.All changes are documented in a change log.
AnswersA, B

Regression testing verifies that existing functionality still works after a change. Skipping it for minor changes allows unintended side effects to reach production undetected, directly weakening change control in a financial application where data integrity and transaction accuracy are critical.

Why this answer

Option A is a control weakness because regression testing verifies that a change has not broken existing functionality; skipping it even for minor changes to a financial application risks undetected defects or integrity failures in production. Option B is a control weakness because emergency changes should be authorized by an appropriate business or IT authority (and later reviewed by the change advisory board), not by the change manager alone, which creates an improper segregation-of-duties conflict since the same person manages and approves the change. Option C is not a weakness because testing normal changes in a development environment before production is a sound change management control.

Option D is not a weakness because a weekly change advisory board reviewing all changes provides proper oversight and authorization. Option E is not a weakness because documenting all changes in a change log supports traceability and auditability.

Exam trap

The trap here is that candidates may incorrectly consider emergency changes authorized only by the change manager as acceptable, but it is a control weakness because it bypasses proper segregation of duties and approval hierarchy. Even emergency changes should require authorization from a higher authority or be subject to post-implementation review.

455
MCQmedium

An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?

A.The chief information security officer (CISO)
B.The system administrator of the database
C.The head of the business unit that creates and uses the data
D.The legal counsel responsible for compliance
AnswerC

The data owner is a business role accountable for a data domain's classification, protection requirements and access decisions. The head of the business unit that creates and uses the data holds the requisite business context and authority, unlike IT custodians or security staff who implement controls on the owner's behalf.

Why this answer

The data owner is the person or entity with ultimate accountability for a specific dataset, typically a senior business manager who understands the data's value, legal requirements, and usage context. In this scenario, the head of the business unit that creates and uses the data is best positioned to classify the data, authorize access, and ensure compliance with the data classification policy, as they have direct business responsibility for the data's lifecycle.

Exam trap

The trap here is confusing the data owner (business accountability) with the data custodian (technical implementation) or the data steward (compliance oversight), leading candidates to incorrectly select the CISO or system administrator.

How to eliminate wrong answers

Option A is wrong because the CISO is a security advisor and enforcer, not the business owner; they lack the business context to determine data classification and usage rules. Option B is wrong because the system administrator is a custodian who implements technical controls (e.g., access control lists, encryption) but does not have ownership authority or business accountability for the data. Option D is wrong because legal counsel provides compliance guidance but does not own the data operationally; ownership must reside with the business unit that creates and uses the data.

456
Multi-Selecthard

An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are logged, but there is no formal problem management process. Which TWO of the following are the MOST likely consequences of this deficiency? (Choose two.)

Select 2 answers
A.Major incidents will automatically be escalated to the problem manager for resolution.
B.Incident resolution times will increase because support staff lack a knowledge base of known errors.
C.Recurring incidents will not be analyzed to identify and eliminate their root causes.
D.The service desk will be unable to log incidents due to the absence of problem records.
E.Change management will be unable to assess the impact of changes without problem tickets.
AnswersB, C

Problem management maintains a known error database and workarounds. Without it, support staff cannot quickly reference previously identified issues and solutions, so they may spend more time diagnosing the same problems. This leads to longer resolution times and reduced service quality, making it a correct consequence.

Why this answer

Problem management focuses on identifying the root causes of incidents and preventing recurrence. Without it, organizations suffer from repeated incidents and lack a known error database, which slows resolution. Incident logging and change management are separate processes that do not depend on problem management.

Escalation of major incidents is an incident management activity, not a consequence of missing problem management.

Exam trap

The trap here is assuming that incident management depends on problem management for basic functions like logging or escalation, when in fact problem management is an improvement layer that addresses root causes.

457
MCQhard

A multinational corporation is replacing its legacy on-premises customer relationship management (CRM) system with a new cloud-based CRM solution. The project involves migrating data from the old system, customizing the new system to match business processes, and integrating with an existing enterprise resource planning (ERP) system. The project has a tight deadline of six months. During the planning phase, the project team decides to use a waterfall methodology because the requirements are well-defined. However, three months into the project, the business users request significant changes to the customer data fields, which were not originally specified. The project manager is concerned that accommodating these changes will delay the project. The integration with the ERP system is also proving more complex than anticipated, with data mapping errors causing delays. The go-live date is fixed due to the end-of-support for the legacy system. What is the BEST course of action for the project manager?

A.Conduct a formal change impact assessment and prioritize the changes; implement only critical ones for go-live
B.Inform the business users that no changes can be made due to the fixed deadline
C.Delay the go-live date to accommodate all changes and integration issues
D.Switch to an agile methodology for the remaining three months
AnswerA

A formal change impact assessment evaluates the requested customer data field changes against the fixed go-live date, letting the project manager accept only critical ones. This controls scope creep while preserving the waterfall baseline and the ERP integration work already underway.

Why this answer

It follows the structured change management process required in a waterfall project with a fixed deadline. By conducting a formal change impact assessment, the project manager can objectively evaluate the cost, schedule, and resource implications of the requested changes. Prioritizing only critical changes for go-live ensures that the core CRM functionality is delivered on time, while non-critical enhancements can be deferred to a post-implementation phase.

This approach balances the need to meet the legacy system's end-of-support deadline with accommodating essential business requirements.

Exam trap

The trap here is that candidates may assume that switching to agile (Option D) is a flexible solution, but they overlook the fact that mid-project methodology changes are disruptive and rarely feasible within a fixed deadline, especially when the project has already invested heavily in waterfall artifacts and integration work.

How to eliminate wrong answers

Option B is wrong because it is an inflexible response that ignores the business value of the requested changes; outright rejection can lead to user dissatisfaction and a system that fails to meet critical business needs. Option C is wrong because delaying the go-live date is not feasible given the fixed deadline imposed by the legacy system's end-of-support, and it would likely cause significant operational risk. Option D is wrong because switching to an agile methodology mid-project is impractical; the project is already three months into a waterfall lifecycle with well-defined requirements, and a methodology shift would require retraining, rework, and disrupt the current integration and data migration work, likely causing further delays.

458
Multi-Selecthard

An IS auditor is designing substantive test procedures for a newly implemented automated accounts payable system and wants to rely less on the client's automated controls. The auditor decides to use computer-assisted audit techniques to test the completeness and accuracy of transaction processing. Which TWO of the following techniques would BEST provide direct evidence about the population of transactions? (Choose two.)

Select 2 answers
A.Reviewing the change management log for modifications to the accounts payable application
B.Integrated test facility that posts simulated transactions alongside live processing
C.Generalized audit software to extract and analyze the full accounts payable transaction file
D.Parallel simulation that reprocesses live transactions using auditor-controlled logic
E.Test data submitted through the production system to observe how the application processes it
AnswersC, D

Generalized audit software can read the client's data files directly and perform calculations, comparisons, and summarizations across the entire transaction population. This gives the auditor direct, independent evidence about completeness and accuracy without relying on the client's own reports or manual sampling. Because it works on the full population, it also supports identifying unusual items and re-performing control logic, which is exactly the kind of direct evidence this engagement requires.

Why this answer

Direct evidence about a transaction population requires the auditor to examine or reprocess the actual data. Generalized audit software extracts and analyzes the full accounts payable file, while parallel simulation reprocesses live transactions through auditor-controlled logic and compares results. Both operate on real transactions.

Test data, integrated test facilities, and change log reviews address control design or change activity, not the completeness and accuracy of the recorded population.

Exam trap

The trap here is assuming that any computer-assisted audit technique provides population-level evidence, when test data and integrated test facilities only examine how the system handles injected entries.

459
MCQeasy

A company is in the process of acquiring a new customer relationship management (CRM) system. During which phase of the systems development life cycle (SDLC) should the business requirements be formally documented?

A.Implementation phase
B.Requirements phase (Planning)
C.Design phase
D.Maintenance phase
AnswerB

Business requirements must be captured during the requirements phase, where stakeholder needs are elicited, analysed and formally documented as the baseline for design. Planning precedes this and only scopes feasibility and resources, so documenting requirements there would leave the CRM's functional and non-functional needs undefined before build.

Why this answer

The business requirements for a new CRM system must be formally documented during the Requirements phase (Planning) of the SDLC. This phase establishes the functional and non-functional needs that the system must satisfy, serving as the foundation for all subsequent design, development, and testing activities. Without a formal requirements document, the project risks scope creep, misalignment with business objectives, and costly rework during later phases.

Exam trap

The trap here is that candidates often confuse the Requirements phase with the Design phase, mistakenly thinking that requirements are documented during design, but in reality, design assumes requirements are already formally approved and focuses on how to implement them, not what to implement.

How to eliminate wrong answers

Option A is wrong because the Implementation phase focuses on deploying the system into production, including installation, configuration, and user training; documenting business requirements at this stage would be too late, as the system has already been built based on earlier decisions. Option C is wrong because the Design phase translates documented requirements into technical specifications (e.g., data models, interface designs); it assumes requirements are already finalized and formalized. Option D is wrong because the Maintenance phase involves post-deployment support, patches, and enhancements; formal business requirements for the initial system must be captured long before this phase to avoid reactive changes that increase cost and risk.

460
MCQmedium

An IS auditor is reviewing the acquisition of a new software package. The vendor provides a Service Organization Control (SOC) 2 Type II report. Which of the following is the MOST important factor for the auditor to consider when relying on this report?

A.The report is issued by a reputable audit firm.
B.The report's scope covers the specific services and systems that the organization will use.
C.The report covers the period that includes the current fiscal year.
D.The report includes a description of the vendor's system and the suitability of the design of controls.
AnswerB

The most critical factor is whether the SOC 2 report's scope aligns with the services the organization will consume. If the report excludes relevant systems or processes, it cannot be relied upon to provide assurance over those areas. The auditor must verify that the controls tested are relevant to the organization's use of the vendor's services.

Why this answer

When relying on a SOC 2 Type II report, the auditor must ensure that the report's scope covers the specific services and systems the organization uses. A report that excludes relevant components provides no assurance for those areas. Other factors like period, description, and auditor reputation are secondary to scope alignment.

Exam trap

The trap here is focusing on the auditor's reputation or the report period while overlooking that the report must cover the exact services the organization consumes.

461
MCQmedium

An organization uses risk-based authentication (RBA) for user access. Which of the following factors would MOST likely trigger a step-up authentication?

A.User logging in from a known device.
B.User accessing sensitive data from an unusual location.
C.User entering correct password.
D.User logging in during business hours.
AnswerB

Risk-based authentication evaluates contextual signals; an unusual location deviates from the user's normal behavioural baseline, raising risk and triggering step-up authentication. This satisfies the scenario's requirement for a contextual anomaly rather than a static credential factor.

Why this answer

Risk-based authentication (RBA) evaluates the risk level of each access attempt based on contextual factors. An unusual location is a high-risk indicator because it deviates from the user's established behavioral baseline, often triggering step-up authentication (e.g., requiring a one-time passcode or biometric verification) to verify the user's identity before granting access to sensitive data.

Exam trap

The trap here is that candidates may confuse 'step-up authentication' with 'multi-factor authentication' and assume any deviation from normal triggers it, but only high-risk anomalies (like unusual location or impossible travel) typically do, while low-risk factors like known devices or business hours do not.

How to eliminate wrong answers

Option A is wrong because logging in from a known device is a low-risk factor that typically reduces the authentication burden, not triggers step-up. Option C is wrong because entering a correct password is the baseline authentication requirement and does not itself indicate elevated risk; step-up is triggered by anomalous context, not by successful password entry. Option D is wrong because logging in during business hours is a normal, expected behavior that aligns with low-risk profiles and would not prompt additional verification.

462
MCQmedium

An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?

A.Scores on post-training quizzes
B.Reduction in the number of successful phishing attacks
C.Percentage of employees who completed the annual training
D.Number of security incidents reported by employees
AnswerB

Awareness programmes aim to change behaviour, so fewer successful phishing attacks demonstrates that staff actually recognise and resist real threats. This outcome metric reflects genuine risk reduction, unlike completion rates or quiz scores, which measure attendance rather than effectiveness.

Why this answer

The primary objective of a security awareness program is to change employee behavior to reduce security risks. A reduction in successful phishing attacks directly measures whether employees are applying what they learned to avoid real-world threats, making it the best outcome-based metric. Post-training quiz scores, completion rates, and incident reporting numbers are activity or output metrics that do not necessarily reflect actual behavioral change or risk reduction.

Exam trap

CISA often tests the difference between output metrics (e.g., completion rates, quiz scores) and outcome metrics (e.g., reduction in successful attacks). Candidates may mistakenly select completion rates or quiz scores as they are easy to measure, but the exam expects the metric that best indicates achievement of objectives, which is behavioral change.

How to eliminate wrong answers

Option A is wrong because quiz scores measure knowledge retention in a test environment, not actual behavior or application in real scenarios. Option C is wrong because completion rates only show participation, not whether the training was effective in changing behavior. Option D is wrong because the number of reported incidents can be influenced by many factors (e.g., reporting culture, actual incident increase) and does not directly measure the program's effectiveness in preventing successful attacks.

463
MCQmedium

An organization's IT policy review cycle is set to every two years. However, a new regulation requires immediate changes to data retention policies. What is the best course of action?

A.Reduce the review cycle to annually
B.Update the policy immediately through an exception process
C.Wait until the next scheduled review to make changes
D.Ignore the regulation until the review
AnswerB

When a new regulation demands immediate data retention changes, the policy must be updated now rather than waiting for the two-year cycle. Using the exception process allows the change to be made, reviewed and documented outside the standard schedule while maintaining governance.

Why this answer

When a new regulation mandates immediate changes to data retention policies, the policy must be updated right away rather than waiting for the scheduled two-year review. Using an exception process allows the organization to deviate from the standard review cycle, make the required changes promptly, and remain compliant while still preserving the formal change-control discipline. This balances regulatory urgency with governance integrity.

Exam trap

CISA often tests whether candidates understand that policy review cycles are administrative schedules, not legal shields — the trap is choosing 'wait for the review' or 'change the cycle' instead of recognizing that urgent regulatory drivers require an immediate, documented exception.

How to eliminate wrong answers

Option A is wrong because reducing the review cycle to annually does not address the immediate need — the regulation requires changes now, not at the next annual review. Option C is wrong because waiting until the next scheduled review would leave the organization non-compliant with the new regulation in the interim, exposing it to legal and regulatory risk. Option D is wrong because ignoring a regulation is never acceptable and would result in compliance violations, fines, and potential loss of certification or license to operate.

464
MCQmedium

An IS auditor is auditing the user access management process for a large healthcare organization that uses an electronic health records (EHR) system. The organization has 5,000 users including doctors, nurses, and administrative staff. The auditor reviews a sample of access requests and finds that 20% of the requests were approved by the user's manager but the approval was not documented in the system. The auditor also finds that there is no periodic review of user access rights. The IT security manager states that users are automatically provisioned based on their role in the HR system, and that access reviews are performed manually by managers but not documented. What is the auditor's BEST recommendation to address the most significant risk?

A.Implement an automated access recertification process with quarterly reviews.
B.Disable automatic provisioning and require manual approval for all access.
C.Require that all access approvals be documented and stored in the system.
D.Perform a risk assessment to determine appropriate access controls.
AnswerA

Automated recertification directly addresses the missing periodic review, forcing documented, scheduled attestation of every user's entitlements. Quarterly cycles satisfy the stem's control gap by generating auditable evidence that managers validated access, replacing the undocumented manual practise. This closes the segregation-of-duties and least-privilege risk inherent to 5,000 EHR users.

Why this answer

The most significant risk is the lack of periodic review of user access rights, which can lead to excessive or inappropriate access (e.g., a former nurse retaining EHR access). Automating access recertification with quarterly reviews directly addresses this by enforcing a regular, documented validation of user entitlements against their current roles, reducing the risk of unauthorized access to protected health information (PHI) under HIPAA. While the undocumented approvals are a control weakness, the absence of any review cycle is a systemic failure that automated recertification resolves.

Exam trap

The trap here is that candidates focus on the documented approval finding (20% undocumented) and choose Option C, missing that the lack of any periodic review is a far more systemic risk that automated recertification directly mitigates.

How to eliminate wrong answers

Option B is wrong because disabling automatic provisioning and requiring manual approval for all access would introduce operational inefficiency and delay for 5,000 users, and it does not address the root cause—the lack of periodic review of existing access rights. Option C is wrong because requiring documentation of approvals only fixes the symptom (undocumented approvals) but ignores the more critical risk that no one is periodically verifying whether current access is still appropriate. Option D is wrong because performing a risk assessment is a preliminary step, not a direct remediation; the auditor already identified the risk (no periodic reviews), so the best recommendation is to implement a control (automated recertification) rather than re-assess.

465
MCQhard

An IS auditor is reviewing an organization's disaster recovery plan (DRP) for its primary data center. The DRP specifies a reciprocal arrangement with a partner organization for backup processing. Which of the following is the MOST significant risk associated with this arrangement that the auditor should highlight?

A.The partner may not have adequate security controls to protect the organization's data.
B.The partner may not have sufficient capacity to handle the organization's workload during a simultaneous disaster.
C.The partner may not have compatible hardware and software configurations.
D.The arrangement may not be legally enforceable without a formal contract.
AnswerB

Reciprocal agreements rely on the assumption that the partner's facility will be available and have spare capacity. However, if both organizations are affected by the same disaster (e.g., regional event), the partner may be unable to accommodate the additional load. This is a critical risk because it can render the DRP ineffective precisely when needed. The auditor should emphasize this as the most significant concern.

Why this answer

A reciprocal disaster recovery arrangement depends on the partner's ability to provide processing capacity when needed. The most significant risk is that the partner may also be affected by the same disaster or may not have enough spare capacity to handle both organizations' workloads simultaneously. This can lead to failure of the DRP.

Compatibility, legal enforceability, and security are important but secondary to the fundamental availability risk. The auditor should prioritize highlighting the capacity risk.

Exam trap

The trap here is focusing on technical compatibility or legal issues as the primary risk, when the most critical weakness of reciprocal agreements is the unguaranteed availability of the partner's resources during a widespread disaster.

466
MCQmedium

A project team is using a prototyping approach for a new system. Which of the following is the BEST control to ensure the prototype accurately reflects user needs?

A.Conduct a post-implementation review.
B.Involve users in each iteration and obtain formal sign-off.
C.Require the project sponsor to approve the final design.
D.Perform regression testing after each prototype iteration.
AnswerB

Prototyping succeeds only when users review each iteration and formally accept the evolving design, because requirements emerge through that feedback loop. Continuous user involvement with sign-off keeps the prototype aligned to actual business needs rather than developer assumptions, satisfying the accuracy constraint.

Why this answer

In prototyping, iterative user involvement with formal sign-off at each iteration ensures that evolving requirements are captured and validated continuously. This control directly verifies that each prototype increment aligns with user needs before proceeding, reducing the risk of building a system that fails to meet expectations.

Exam trap

The trap here is that candidates may confuse regression testing (option D) with validation of user needs, but regression testing only ensures existing features still work, not that the prototype matches user expectations.

How to eliminate wrong answers

Option A is wrong because a post-implementation review occurs after the system is deployed, which is too late to influence the prototype's accuracy during development. Option C is wrong because project sponsor approval of the final design does not provide iterative validation; it bypasses user feedback loops and may overlook detailed user requirements. Option D is wrong because regression testing focuses on detecting defects in existing functionality after changes, not on verifying that the prototype reflects user needs.

467
MCQmedium

An IS auditor is planning an audit of a cloud service provider's security controls. The auditor has limited access to the provider's internal systems. Which of the following would be the MOST effective way to obtain assurance over the provider's security controls?

A.Perform penetration testing of the cloud environment.
B.Interview the provider's IT security manager.
C.Review the provider's independent audit reports (e.g., SOC 2 Type II).
D.Rely on the provider's self-assessment questionnaire.
AnswerC

Independent audit reports, such as SOC 2 Type II, provide an objective assessment of the provider's controls over a period. They are prepared by an independent auditor and cover the design and operating effectiveness of controls. This is a highly effective way to obtain assurance when direct access is limited. The IS auditor can review the report, assess the scope, and determine if it meets the audit objectives.

Why this answer

When an IS auditor has limited access to a cloud service provider's internal systems, reviewing the provider's independent audit reports (such as SOC 2 Type II) is the most effective way to obtain assurance over security controls. These reports are prepared by independent auditors and cover the design and operating effectiveness of controls over a period. They provide reliable, third-party evidence.

Self-assessments, penetration testing, and interviews are less reliable or comprehensive for this purpose.

Exam trap

The trap here is relying on the provider's self-assessment or interviews when independent third-party audit reports are available and provide stronger, more objective evidence.

468
MCQhard

An IS auditor is reviewing the implementation of a new payroll system that was developed in-house. The project team followed a traditional waterfall SDLC. During the post-implementation review, the auditor found that the system was delivered on time and within budget, but several critical payroll calculations were incorrect, leading to employee underpayments. The root cause was traced to a misunderstanding of tax law changes that occurred during the requirements phase. Which of the following is the MOST likely control weakness that contributed to this issue?

A.Inadequate segregation of duties between developers and testers, allowing developers to test their own code.
B.Insufficient involvement of tax experts and business stakeholders in requirements definition and validation.
C.Inadequate user acceptance testing (UAT) that did not include valid tax scenarios.
D.Lack of a formal change management process to handle tax law updates during development.
AnswerB

The root cause was a misunderstanding of tax law changes, which indicates that the requirements were not accurately captured or validated. Involving tax experts and business stakeholders would have ensured that the requirements reflected current tax laws. This is a critical control in the requirements phase. Without their input, the system was built on incorrect assumptions, leading to payroll errors. Thus, this is the most likely control weakness.

Why this answer

The payroll errors stemmed from a misunderstanding of tax law changes during requirements. The most likely control weakness is insufficient involvement of tax experts and business stakeholders in defining and validating requirements. Their participation ensures that requirements are accurate and complete.

While UAT, change management, and segregation of duties are important, they do not directly prevent requirements misunderstandings. Thus, the correct answer is the lack of expert involvement in requirements.

Exam trap

The trap here is focusing on testing or change management as the primary control, when the root cause is flawed requirements due to missing stakeholder input.

469
MCQhard

Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?

A.It is more effective for detecting fraud than non-statistical sampling.
B.It ensures that all items in the population are tested.
C.It provides a basis for quantifying sampling risk and projecting results to the population.
D.It requires less auditor judgment and is easier to apply.
AnswerC

Statistical sampling applies probability theory, allowing the auditor to quantify sampling risk and extrapolate sample results to the full population within defined confidence limits. Non-statistical sampling relies on judgement, providing no mathematically defensible basis for such projection.

Why this answer

Statistical sampling uses probability theory to select samples, which allows the auditor to quantify sampling risk and mathematically project sample results to the full population. This is its defining advantage over non-statistical (judgmental) sampling, which relies on auditor judgment and cannot support statistically valid projections. The other options describe goals that neither method guarantees.

Exam trap

The trap is equating 'statistical' with 'better at finding fraud' or 'more thorough' — the exam wants you to recognize that the unique benefit is quantifiable sampling risk and projection, not detection capability or coverage.

How to eliminate wrong answers

Option A is wrong because neither statistical nor non-statistical sampling is inherently more effective at detecting fraud; fraud detection depends on the nature of procedures and the auditor's skepticism, not the sampling method. Option B is wrong because sampling by definition tests a subset, not all items — testing 100% of a population is a census, not sampling. Option D is wrong because statistical sampling actually requires more auditor expertise and judgment in selecting appropriate parameters (confidence level, tolerable error, expected error), not less.

470
MCQhard

During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?

A.It is a mobile recovery unit
B.It has infrastructure but no processing equipment
C.It has equipment but requires data restoration
D.It is a fully operational duplicate of the primary site
AnswerC

A warm site is partially equipped: hardware, peripherals and network connectivity are installed, but current production data is absent and must be restored from backups before operations resume. This distinguishes it from a hot site, which holds mirrored live data, and a cold site, which lacks installed equipment.

Why this answer

A warm site is a partially equipped recovery facility that contains the hardware, network infrastructure, and peripherals needed to run operations, but it does not have current production data pre-loaded. After a disaster is declared, the organization must restore data from backups and apply recent transaction logs before the site can process live workloads. This makes warm sites a middle-ground option between a cold site (empty facility) and a hot site (fully mirrored, near-instant failover).

Exam trap

CISA often tests the distinction between cold, warm, and hot sites by swapping their defining characteristics — candidates frequently confuse 'has equipment but needs data' (warm) with 'has infrastructure but no equipment' (cold) or 'fully operational duplicate' (hot).

How to eliminate wrong answers

Option A is wrong because a mobile recovery unit is a self-contained trailer or portable facility that can be transported to a location — that is a distinct recovery strategy, not the definition of a warm site. Option B is wrong because a facility with infrastructure but no processing equipment describes a cold site, which lacks the servers and hardware needed to run applications. Option D is wrong because a fully operational duplicate of the primary site describes a hot site, which maintains synchronized data and can take over almost immediately.

471
MCQeasy

When implementing a data classification policy, which of the following roles is PRIMARILY responsible for assigning classification labels to data?

A.Data custodian.
B.Data owner.
C.Data user.
D.Data steward.
AnswerB

The data owner holds accountability for the data asset and understands its sensitivity and business context, so they assign classification labels. This satisfies the policy requirement that labelling decisions rest with the accountable business role rather than custodians or users.

Why this answer

The data owner is the senior manager or business process owner who has the authority to determine the sensitivity and criticality of the data. They are primarily responsible for assigning classification labels because they understand the business impact if the data is compromised. This role defines the classification level (e.g., Public, Internal, Confidential, Restricted) based on the data's value and legal or regulatory requirements.

Exam trap

ISACA often tests the distinction between data owner (who assigns classification) and data custodian (who implements controls), leading candidates to mistakenly choose the custodian because they confuse technical implementation with business ownership.

How to eliminate wrong answers

Option A is wrong because the data custodian (e.g., database administrator or system administrator) is responsible for implementing technical controls (access controls, encryption, backups) based on the classification assigned by the owner, not for assigning the labels themselves. Option C is wrong because the data user is an end-user who accesses data according to the policies and permissions set by the owner; they have no authority to assign classification labels. Option D is wrong because the data steward focuses on data quality, metadata management, and governance processes (e.g., data dictionary maintenance, data lineage) but does not have the business authority to determine the sensitivity or assign the classification label.

472
MCQmedium

During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?

A.Exposure to security vulnerabilities without patches.
B.Inability to recover data from backups.
C.Increased licensing costs due to non-compliance.
D.Difficulty in migrating to new versions.
AnswerA

Unsupported software no longer receives vendor security patches, so known vulnerabilities remain permanently exploitable. This directly satisfies the stem's primary risk: unmitigated exposure, since no remediation path exists until the version is upgraded or replaced.

Why this answer

The primary risk of using unsupported software versions is the absence of vendor-provided security patches. Without these patches, known vulnerabilities remain unaddressed, exposing the organization to exploitation, data breaches, and system compromise. This directly impacts the confidentiality, integrity, and availability of information assets.

Exam trap

The trap here is that candidates may focus on operational inconveniences like migration difficulty or licensing costs, overlooking the fact that the most critical and immediate risk from unsupported software is the lack of security patches, which directly enables exploitation.

How to eliminate wrong answers

Option B is wrong because data recovery from backups depends on backup integrity and restoration procedures, not on vendor support status; unsupported software can still be backed up and restored. Option C is wrong because unsupported software typically has no licensing costs (support contracts end), and non-compliance usually involves over-licensing or unlicensed use, not the use of unsupported versions. Option D is wrong while migration difficulty is a potential operational challenge, it is not the primary risk; the immediate and most severe risk is the security exposure from unpatched vulnerabilities.

473
MCQmedium

During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?

A.Code reviews may be less effective because developers are reluctant to critique tested code
B.Defects may be discovered later in the development lifecycle, increasing rework costs
C.Unit tests may mask code quality issues
D.The code review process may overlook security vulnerabilities
AnswerB

Reviewing code only after unit testing delays defect detection until later lifecycle stages, when remediation requires reworking tested components and dependent code. Defects found earlier during review are cheaper to fix, so this sequencing inflates rework cost and schedule risk.

Why this answer

Performing code reviews only after unit testing delays defect detection to a later stage in the development lifecycle, when rework costs are significantly higher. Code reviews are most effective when conducted early, before testing, because they catch design flaws, logic errors, and security issues at the source. The later a defect is found, the more expensive and time-consuming it is to fix, especially if it has propagated to other modules.

Exam trap

CISA often tests the principle that early detection reduces cost — candidates who focus on cultural or security-specific concerns miss the broader lifecycle cost risk that is the primary audit concern.

How to eliminate wrong answers

Option A is wrong because while developer reluctance may be a cultural concern, it is not the most significant risk — the primary risk is the increased cost and effort of late defect detection. Option C is wrong because unit tests are designed to validate specific functionality and do not inherently mask code quality issues; the risk is that code reviews after testing miss the opportunity for early defect prevention. Option D is wrong because while security vulnerabilities could be overlooked, this is a subset of the broader risk of late defect discovery, and the question asks for the MOST significant risk, which is lifecycle cost escalation.

474
MCQeasy

During an incident response, the IT team isolates a compromised system from the network. Which of the following is the primary purpose of this action?

A.To preserve evidence for forensic analysis.
B.To allow the system to be patched offline.
C.To comply with regulatory requirements.
D.To prevent further damage and contain the incident.
AnswerD

Isolation severs the compromised host's network connectivity, halting lateral movement and data exfiltration to other systems. This directly satisfies the containment objective of incident response: limiting the incident's scope and blast radius before eradication and recovery begin, preserving evidence while preventing the attacker from causing additional harm.

Why this answer

Isolating a compromised system from the network (e.g., by disconnecting the Ethernet cable, disabling the switch port, or applying a host-based firewall rule to drop all traffic) immediately stops the system from communicating with other hosts. This containment action prevents the attacker from moving laterally, exfiltrating data, or deploying additional malware, thereby limiting the blast radius and stopping ongoing damage.

Exam trap

The trap here is that candidates confuse 'preserving evidence' (a forensic goal) with 'containing the incident' (the immediate operational goal), leading them to choose Option A even though isolation is primarily about stopping the attack, not about evidence handling.

How to eliminate wrong answers

Option A is wrong because isolation is a containment step, not a preservation step; while it can help preserve volatile evidence by preventing remote tampering, the primary purpose is containment, and forensic preservation requires specific steps like creating a bit-for-bit image before any changes. Option B is wrong because patching offline is a remediation activity that occurs after containment; the immediate goal is to stop the attack, not to prepare the system for patching. Option C is wrong because compliance requirements may mandate containment, but the primary operational purpose is to prevent further damage, not to satisfy a regulation.

475
MCQeasy

A nonprofit organization develops a small online donation platform using a third-party payment gateway. The project team skips formal security testing because of budget constraints. After launch, a security researcher discovers that the application fails to validate input on the donation amount field, allowing manipulation. The nonprofit loses several thousand dollars before the issue is patched. The IS auditor is asked to review the system development process. Which of the following is the PRIMARY finding?

A.The donation amount field was not validated.
B.The organization lost money due to the exploit.
C.Security testing was not performed during development.
D.The payment gateway was not properly integrated.
AnswerC

The input validation flaw reached production because no security testing occurred during development, so the root cause is the omission of that control from the system development life cycle. Budget constraints explain the decision but do not change the primary finding.

Why this answer

The primary finding for an IS auditor reviewing the system development process is the absence of security testing during development. Skipping formal security testing (e.g., static application security testing, dynamic application security testing, or penetration testing) violates the secure development lifecycle (SDLC) best practices and directly led to the input validation vulnerability. The IS auditor's focus is on process deficiencies, not the specific exploit or financial loss.

Exam trap

The trap here is that candidates focus on the immediate technical flaw (unvalidated input) or the financial loss, rather than recognizing that the IS auditor's role is to identify the systemic process failure (lack of security testing) that allowed the vulnerability to be introduced.

How to eliminate wrong answers

Option A is wrong because the unvalidated donation amount field is a symptom (a technical vulnerability), not the root cause in the development process; the IS auditor's primary finding should address the process gap that allowed the vulnerability to exist. Option B is wrong because the financial loss is an impact or consequence, not a process finding; the IS auditor evaluates controls and processes, not the monetary outcome. Option D is wrong because the payment gateway integration may be functional; the issue is the lack of input validation on the application side, not a misconfiguration or improper integration of the third-party gateway (e.g., incorrect API endpoint or missing signature verification).

476
MCQeasy

An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?

A.Misconfigured VPN tunnel
B.Intrusion prevention system blocking
C.Missing firewall rule allowing RDP traffic
D.Incorrect NAT configuration
AnswerC

The exhibit shows the connection reaching the firewall but no matching permit entry, so the implicit deny rule drops the session. RDP requires an explicit inbound rule on port 3389; without it, traffic is denied. The missing firewall rule allowing RDP traffic is therefore the cause.

Why this answer

The exhibit shows RDP traffic (TCP/3389) being denied at the firewall. Since the traffic reaches the firewall but is blocked, the most likely cause is a missing firewall rule that explicitly permits RDP traffic. A misconfigured VPN tunnel would typically prevent traffic from reaching the firewall at all, while an IPS block would generate an alert and often target specific signatures, not a blanket deny.

Incorrect NAT would affect address translation but not cause a deny action at the firewall.

Exam trap

The trap here is that candidates may confuse a firewall deny with an IPS block or NAT failure, but the log entry's explicit 'denied' action and lack of IPS signature ID or NAT translation error point directly to a missing firewall rule.

How to eliminate wrong answers

Option A is wrong because a misconfigured VPN tunnel would prevent the traffic from reaching the firewall interface (e.g., tunnel not established, mismatched phase 2 parameters), resulting in no log entry at the firewall, not a deny action. Option B is wrong because an intrusion prevention system (IPS) block would be triggered by a specific attack signature (e.g., MS12-020 exploit) and would log an IPS alert, not a simple firewall deny rule; the exhibit shows a firewall deny, not an IPS block. Option D is wrong because an incorrect NAT configuration (e.g., missing or misapplied NAT rule) would cause traffic to be dropped or misrouted due to translation failure, but the firewall log shows a deny action, which is a policy-based block, not a NAT failure.

477
MCQeasy

Which of the following is an example of a compliance audit?

A.Evaluating whether IT controls meet SOX requirements
B.Assessing the performance of a new system
C.Reviewing the efficiency of a production line
D.Analyzing financial statement ratios
AnswerA

SOX requirements are externally mandated legal obligations, so evaluating whether IT controls satisfy them tests adherence to prescribed criteria, which is the defining characteristic of a compliance audit rather than an operational or financial statement audit.

Why this answer

A compliance audit specifically evaluates whether an organization adheres to external laws, regulations, or standards. Option A is correct because SOX (Sarbanes-Oxley Act) is a mandatory regulatory requirement, and auditing IT controls for SOX compliance directly assesses conformity with those legal obligations. This is the essence of a compliance audit—verifying adherence to prescribed rules rather than evaluating performance or efficiency.

Exam trap

CISA often tests the distinction between compliance audits (adherence to laws/regulations) and performance/operational audits (efficiency/effectiveness), so candidates must recognize that SOX requirements represent a mandatory compliance driver, not a performance metric.

How to eliminate wrong answers

Option B is wrong because assessing the performance of a new system is a performance or operational audit, which focuses on effectiveness, efficiency, and goal achievement, not regulatory adherence. Option C is wrong because reviewing the efficiency of a production line is an operational audit concerned with process optimization and productivity, not compliance with laws or standards. Option D is wrong because analyzing financial statement ratios is a financial audit technique used to assess financial health and performance, not to verify compliance with specific regulatory requirements.

478
Multi-Selecteasy

Which TWO of the following are HR controls that help mitigate the risk of insider fraud in IT? (Select TWO.)

Select 2 answers
A.Flexible work hours
B.Employee recognition programs
C.Annual performance reviews
D.Job rotation
E.Mandatory vacation
AnswersD, E

Job rotation moves staff through different roles, so no single employee retains long-term control over one process, limiting opportunity for concealed insider fraud. This satisfies the stem's requirement for an HR control mitigating insider fraud risk in IT.

Why this answer

Job rotation (D) is a recognized HR control that mitigates insider fraud because moving employees among different duties prevents any single person from maintaining long-term, unchallenged control over a sensitive process, and it increases the chance that irregularities or fraudulent activity are detected by a fresh set of eyes. Mandatory vacation (E) is also a standard fraud-deterrence control: requiring employees to take continuous time away forces their duties to be performed by someone else, exposing schemes such as lapping, ghost vendors, or unauthorized transactions that depend on the perpetrator being continuously present to conceal them. By contrast, flexible work hours (A) can actually reduce oversight and segregation of duties, employee recognition programs (B) address morale and motivation rather than fraud detection or prevention, and annual performance reviews (C) evaluate job performance but do not inherently remove or rotate an employee's access and opportunity to commit and conceal fraud.

Exam trap

CISA often tests the difference between general HR practices (recognition, reviews, flexible hours) and specific fraud-deterrent controls (job rotation, mandatory vacation), so candidates who pick feel-good HR activities miss the control objective.

479
MCQmedium

An IS auditor is reviewing the change management process for a financial application. Which of the following findings would be of MOST concern?

A.Change requests are logged in a spreadsheet
B.Standard changes are pre-approved
C.Change windows are defined in the policy
D.Emergency changes are not reviewed within 30 days
AnswerD

Emergency changes bypass normal approval and testing controls, so they carry the highest risk of introducing unauthorised or faulty code into a financial application. Failing to review them within 30 days means these untested changes remain unvalidated, leaving the control gap open indefinitely.

Why this answer

Emergency changes bypass normal controls; failure to review them within a reasonable time (e.g., 30 days) increases risk of undocumented changes. Logging in spreadsheet, pre-approved standard changes, and defined change windows are acceptable or even good practices.

480
MCQhard

A company stores sensitive customer data in a database. To comply with privacy regulations, the data must be anonymized for analytics. Which technique provides the strongest anonymization while preserving data utility?

A.Differential privacy with calibrated noise.
B.Tokenization with a reversible mapping.
C.Removing direct identifiers like names and SSNs.
D.Data masking with static substitution.
AnswerA

Differential privacy adds calibrated statistical noise, giving each individual plausible deniability while aggregate query results remain accurate. This provides mathematically provable anonymisation that k-anonymity and masking lack, satisfying the requirement for strong anonymisation with preserved analytical utility.

Why this answer

Differential privacy with calibrated noise is the strongest anonymization technique because it provides a formal mathematical guarantee that the output of a query does not reveal whether any specific individual's data was included. By adding carefully calibrated noise to query results, it preserves statistical utility for analytics while ensuring that re-identification is provably infeasible, meeting strict privacy regulations like GDPR or CCPA.

Exam trap

The trap here is that candidates often confuse pseudonymization (e.g., tokenization) with anonymization, or assume that simply removing direct identifiers is sufficient, failing to recognize that re-identification via quasi-identifiers is a well-known attack vector in privacy regulations.

How to eliminate wrong answers

Option B is wrong because tokenization with a reversible mapping is not anonymization; it is pseudonymization, as the original data can be recovered via the mapping table, which does not meet the irreversible anonymization required by privacy regulations. Option C is wrong because removing direct identifiers like names and SSNs alone leaves quasi-identifiers (e.g., ZIP code, age, gender) that can be combined with external data to re-identify individuals through linkage attacks, providing weak anonymization. Option D is wrong because data masking with static substitution (e.g., replacing values with fixed characters) is a form of obfuscation that does not preserve data utility for analytics (e.g., masked values lose statistical properties) and can often be reversed if the masking pattern is known or inferred.

481
MCQmedium

An IS auditor is evaluating the IT service continuity plan for a hospital's electronic health record (EHR) system. The auditor finds that the plan includes a recovery time objective (RTO) of 4 hours, but the hospital's clinical staff state that they can tolerate only 1 hour of downtime before patient safety is compromised. Which of the following should the auditor recommend FIRST?

A.Conduct a full interruption test to validate the current recovery capabilities.
B.Revise the RTO to align with the clinical requirement and reassess the recovery strategy.
C.Implement a redundant server cluster at the primary site to improve availability.
D.Increase the frequency of data backups to reduce potential data loss.
AnswerB

The RTO in the plan does not match the business requirement identified by clinical staff. The auditor should first recommend that the RTO be corrected to reflect the actual tolerable downtime, and then the recovery strategy must be reassessed to ensure it can meet the new RTO. Aligning the RTO with business needs is the foundation for an effective continuity plan.

Why this answer

The RTO in the plan is 4 hours, but clinical staff require no more than 1 hour of downtime. The auditor should first recommend revising the RTO to reflect the true business requirement, then reassess whether the recovery strategy can meet that RTO. Without this alignment, any subsequent technical improvements may be misdirected.

The RTO is a business-driven metric and must be accurate before designing recovery solutions.

Exam trap

The trap here is jumping to technical solutions like backups or clustering without first correcting the misaligned RTO, which is the root cause of the mismatch between the plan and business needs.

482
MCQhard

Refer to the exhibit. This log entry MOST likely indicates:

A.An attempt to escalate privileges or lateral movement
B.A scheduled backup using the service account
C.A brute-force attack
D.Normal administrative activity
AnswerA

The log records authentication followed by privileged command execution against remote hosts, the signature pattern of privilege escalation and lateral movement. This satisfies the stem's constraint by matching the observed credential use and cross-host access rather than routine administrative activity.

Why this answer

The log entry shows a service account (svc_backup) executing commands that create a new local user and add it to the Administrators group, which is a classic privilege escalation technique. The use of net user and net localgroup commands from a service account indicates an attempt to gain unauthorized administrative access, often as a precursor to lateral movement. This is not normal administrative activity because service accounts are typically restricted to specific tasks and should not be creating interactive user accounts.

Exam trap

The trap here is that candidates see a service account and assume it is legitimate backup activity, but the specific commands (net user /add, net localgroup Administrators) are clear indicators of privilege escalation, not routine maintenance.

How to eliminate wrong answers

Option B is wrong because a scheduled backup using a service account would involve backup-specific commands (e.g., wbadmin, robocopy, or backup software APIs) and would not include net user or net localgroup commands to create a new user. Option C is wrong because a brute-force attack would manifest as multiple failed login attempts (Event ID 4625) or repeated authentication failures, not a single successful command execution from an already-authenticated session. Option D is wrong because normal administrative activity would typically use a dedicated admin account, not a service account, and would follow change management procedures; creating a new user and adding it to the Administrators group is a high-risk action that is not routine.

483
MCQhard

An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?

A.Regular background checks on provider employees
B.Access to provider's incident management system
C.Monthly meetings with provider management
D.Service level agreement (SLA) with key performance indicators
AnswerD

An SLA with key performance indicators defines measurable service targets, such as response and resolution times, against which the outsourced provider's performance is monitored. This satisfies the stem's requirement to ensure service quality, since without measurable KPIs the organisation cannot objectively verify or enforce the provider's obligations.

Why this answer

A Service Level Agreement (SLA) with key performance indicators (KPIs) is the most critical control because it defines measurable targets (e.g., average speed to answer, first-call resolution rate, ticket closure time) and establishes contractual remedies for non-compliance. Without an SLA, the organization has no enforceable mechanism to hold the provider accountable for service quality, making it the foundational control for outsourced IT help desk governance.

Exam trap

The trap here is that candidates confuse operational or security controls (background checks, system access, meetings) with the contractual governance control (SLA) that directly enforces and measures service quality, leading them to pick a plausible but less critical option.

How to eliminate wrong answers

Option A is wrong because regular background checks on provider employees address security and trust, not service quality; they are a personnel security control, not a service performance control. Option B is wrong because access to the provider's incident management system enables visibility but does not enforce or measure service quality; it is an operational monitoring tool, not a contractual or performance control. Option C is wrong because monthly meetings with provider management facilitate communication and escalation but lack the binding, measurable commitments and remedies that an SLA provides; meetings alone cannot guarantee consistent service levels.

484
MCQmedium

An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?

A.Understand the process and identify controls
B.Gather evidence for audit findings
C.Test the effectiveness of controls
D.Verify the accuracy of transaction data
AnswerA

A walkthrough traces a single transaction through the purchase-to-pay process from initiation to payment, letting the auditor confirm their understanding of the actual flow and pinpoint the controls embedded at each step before designing detailed testing procedures.

Why this answer

A walkthrough is a preliminary audit technique used to trace a transaction through the entire process from initiation to recording. Its primary purpose is to gain an understanding of the process flow, identify key controls, and assess the design of those controls. Unlike testing, walkthroughs do not involve sampling or verification of accuracy; they are about understanding and documenting the system.

Therefore, option A is correct.

Exam trap

CISA often tests the distinction between understanding a process (walkthrough) and testing controls (compliance testing), so candidates may confuse the purpose of a walkthrough with that of a control test.

How to eliminate wrong answers

Option B is wrong because gathering evidence for audit findings typically occurs during substantive testing or detailed control testing, not during a walkthrough, which is more about understanding. Option C is wrong because testing the effectiveness of controls involves sampling and reperformance, which is beyond the scope of a walkthrough; a walkthrough only confirms that controls exist and are designed properly. Option D is wrong because verifying the accuracy of transaction data requires vouching, reconciliation, and other substantive procedures, not a walkthrough.

485
Multi-Selecthard

An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)

Select 2 answers
A.Verify that the ERP system's database backups complete successfully each night.
B.Confirm that the ERP system's password policy enforces complexity and expiration requirements.
C.Examine a sample of users provisioned in the last quarter to confirm that conflicting access was not granted.
D.Interview the ERP administrator to confirm that SoD conflicts are taken seriously.
E.Review the ruleset used by the access management tool to identify conflicting role combinations.
AnswersC, E

Provisioning-time detection can fail if the tool is bypassed, if roles change later, or if emergency access is granted outside the workflow. Testing a sample of recently provisioned users verifies whether the control actually prevented conflicting combinations in practice. This substantive test provides evidence that the designed control operated on real transactions, complementing a review of the ruleset and revealing gaps between policy and execution.

Why this answer

Effective SoD assurance requires both design and operating evidence. Reviewing the conflict ruleset confirms that the detection logic covers the right combinations of duties, while testing recently provisioned users confirms the control actually prevented conflicts in practice. Together they address whether the control is correctly defined and whether it operates as intended.

Password policy, backups, and interviews do not provide direct evidence about conflicting access assignments in the ERP system.

Exam trap

The trap here is accepting management's statement that conflicts are caught at provisioning, when the auditor must test both the ruleset that defines conflicts and the actual users provisioned under it.

486
MCQeasy

An IS auditor is reviewing the antivirus and endpoint protection deployment across a hospital's clinical workstations. The auditor finds that signature updates are delivered daily, real-time scanning is enabled on all workstations, but the endpoint protection console shows that 40 of 600 workstations have not checked in for more than 30 days. Which of the following should the auditor do FIRST?

A.Report a critical finding that 40 workstations are unprotected and could spread malware throughout the hospital network.
B.Recommend that the organization purchase additional endpoint protection licenses to cover the 40 unmanaged devices.
C.Verify that the antivirus signature update frequency meets the organization's policy of daily updates.
D.Determine whether the 40 unmanaged workstations are still in service and whether they have compensating controls.
AnswerD

Before concluding that a control failure exists, the auditor must establish whether those endpoints are still active and what protection they actually have. The 40 devices may be decommissioned, in storage, or covered by an alternate solution, in which case the finding changes significantly. Confirming asset status and compensating controls is the appropriate first step to validate the observation and avoid reporting an inaccurate finding.

Why this answer

The missing check-ins could indicate unprotected endpoints, but they could equally reflect decommissioned hardware or devices covered by other controls. An auditor must validate the condition before reporting it, since the characterization of risk depends entirely on whether those 40 workstations are active and what protection they have. Confirming asset status and compensating controls is the logical first step.

Exam trap

The trap here is treating a management console gap as conclusive proof that endpoints are unprotected without first validating whether the devices are still in service.

487
MCQmedium

A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?

A.Reject the project and require the system to remain on-premises.
B.Request a revised risk assessment that includes contingency plans for provider outages.
C.Approve the project based on the provider's strong SLA.
D.Approve a pilot migration for non-critical systems first.
AnswerB

The SLA covers provider uptime, not the bank's regulatory obligation to plan for outage impact on critical transactions. Requesting contingency planning in the risk assessment satisfies the incomplete-assessment constraint before approval, rather than accepting the SLA as sufficient mitigation.

Why this answer

The governance committee's role is to ensure that risks are identified, assessed, and mitigated before approving a high-risk project. An incomplete risk assessment that ignores the impact of a cloud provider outage on critical banking transactions is a material gap. Requesting a revised risk assessment with contingency plans directly addresses this gap while allowing the project to proceed responsibly.

This aligns with CISA's emphasis on risk-based decision-making and IT governance.

Exam trap

CISA often tests the misconception that a strong SLA eliminates the need for contingency planning, but governance requires assessing residual risk and ensuring business continuity even with contractual guarantees.

How to eliminate wrong answers

Option A is wrong because rejecting the project outright is an overreaction; the committee should first ensure risks are properly assessed and mitigated, not abandon the cloud strategy. Option C is wrong because an SLA is a contractual commitment, not a guarantee of uninterrupted service; it does not eliminate the need for contingency planning, and 99.99% uptime still allows for downtime that could impact critical transactions. Option D is wrong because a pilot for non-critical systems does not address the core deficiency—the lack of a risk assessment for critical transactions—and could delay necessary risk mitigation for the full migration.

488
MCQhard

An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?

A.Incompatibility with existing infrastructure
B.Inadequate vendor security controls
C.Vendor lock-in due to proprietary data formats
D.Cost overruns from customization
AnswerB

Audit rights clauses let the organisation inspect the vendor's control environment, obtain evidence and enforce remediation, directly addressing the risk that the vendor's security controls are inadequate. Without this contractual leverage, assurance over a COTS ERP's hosted processing depends solely on the vendor's own reporting.

Why this answer

A contractual clause for audit rights allows the organization to assess the vendor's security controls, ensuring they meet the organization's requirements and mitigating the risk of inadequate vendor security. This is critical because the organization relies on the vendor to protect its data, and without audit rights, it cannot verify the effectiveness of the vendor's controls. The other risks are not directly addressed by audit rights: incompatibility is a technical integration issue, vendor lock-in relates to data portability, and cost overruns stem from project management.

Exam trap

CISA often tests the misconception that audit rights mitigate all vendor-related risks, but they specifically address security and compliance verification, not technical compatibility, data portability, or cost control.

How to eliminate wrong answers

Option A is wrong because incompatibility with existing infrastructure is a technical risk mitigated through thorough requirements analysis and compatibility testing, not audit rights. Option C is wrong because vendor lock-in due to proprietary data formats is mitigated by contractual clauses requiring data export in standard formats and exit provisions, not audit rights. Option D is wrong because cost overruns from customization are mitigated by fixed-price contracts, change control procedures, and detailed scoping, not audit rights.

489
MCQeasy

An organization wants to protect its intellectual property from unauthorized disclosure via email. Which control should be implemented?

A.Encrypt all outgoing emails.
B.Implement a data loss prevention (DLP) system.
C.Disable email altogether.
D.Require employees to sign non-disclosure agreements.
AnswerB

A data loss prevention system inspects email content and attachments, then blocks or quarantines messages matching sensitive-data policies, such as intellectual property fingerprints. This directly enforces the confidentiality objective by preventing unauthorised disclosure at the point of egress, satisfying the requirement to stop proprietary information leaving the organisation via email.

Why this answer

A DLP system is the correct control because it can inspect email content and attachments in real time, applying policies to block or quarantine unauthorized disclosures of intellectual property. Unlike encryption, which only protects data in transit but does not prevent an authorized user from sending sensitive information, DLP provides content-aware enforcement at the point of transmission.

Exam trap

The trap here is confusing encryption (which protects data in transit) with data loss prevention (which controls what data can leave the organization), leading candidates to choose encryption as a catch-all security measure.

How to eliminate wrong answers

Option A is wrong because encrypting all outgoing emails protects the confidentiality of the message in transit but does not prevent an authorized user from sending intellectual property to an unauthorized recipient; encryption alone lacks content inspection and policy enforcement. Option C is wrong because disabling email altogether is an extreme operational disruption that eliminates a critical business communication channel, and it does not address other vectors like file uploads or messaging apps. Option D is wrong because requiring employees to sign non-disclosure agreements is a administrative control that relies on user compliance and provides no technical enforcement to stop unauthorized email disclosures.

490
MCQhard

Based on the exhibit, which control is most likely missing to prevent this type of event?

A.Applying the latest security patches to the SSH service
B.Implementing account lockout after three failed attempts
C.Disabling direct root login via SSH
D.Enforcing strong password complexity
AnswerB

Account lockout after three failed attempts blocks continued password guessing against the same account, directly preventing the brute-force authentication event shown. This satisfies the control gap by throttling repeated failures rather than merely logging or alerting on them.

Why this answer

The exhibit describes a brute-force attack against an SSH service, where an attacker repeatedly attempts to guess credentials. Implementing account lockout after three failed attempts is the most direct control to prevent this type of event, as it halts further login attempts after a threshold, stopping the attack in its tracks regardless of password strength or patching.

Exam trap

The trap here is that candidates often choose 'Disabling direct root login via SSH' (Option C) because it is a well-known security best practice, but it does not prevent brute-force attacks against other user accounts, whereas account lockout directly stops the attack mechanism.

How to eliminate wrong answers

Option A is wrong because applying the latest security patches to the SSH service addresses vulnerabilities in the SSH protocol or implementation, but does not prevent brute-force attacks that exploit weak or guessed credentials. Option C is wrong because disabling direct root login via SSH reduces the attack surface by requiring a non-root account first, but it does not prevent brute-force attacks against any user account; the attacker can still target other usernames. Option D is wrong because enforcing strong password complexity makes passwords harder to guess, but it does not stop an attacker from making unlimited attempts; a brute-force attack can still succeed over time if no lockout mechanism is in place.

491
MCQmedium

During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?

A.Recommend immediate performance tuning to resolve the issue
B.Report the issue to senior management immediately
C.Conduct a load test to identify bottlenecks
D.Compare actual performance to the performance criteria in the business case
AnswerD

Performance criteria were defined in the business case, so the auditor must first compare measured transaction throughput against those agreed benchmarks. This establishes whether the shortfall is a genuine deviation before investigating root cause or recommending remediation.

Why this answer

The auditor's best initial action is to compare actual system performance against the performance criteria defined in the business case. This establishes whether the slowdown represents a genuine deviation from expected outcomes and provides an objective basis for further investigation. Without this comparison, any recommendation or escalation would lack context and could be premature.

Exam trap

CISA often tests the audit principle of evidence before action — candidates who jump to technical remediation or escalation without first validating against business criteria fall for the 'solution-first' trap.

How to eliminate wrong answers

Option A is wrong because recommending performance tuning before confirming the performance gap against business case criteria is premature and may address a non-issue or the wrong root cause. Option B is wrong because reporting to senior management immediately without first validating the deviation against expected performance criteria bypasses the auditor's due diligence and may cause unnecessary alarm. Option C is wrong because conducting a load test is a technical diagnostic step that should follow, not precede, the determination that a performance gap actually exists relative to business requirements.

492
MCQmedium

An IT manager is reviewing the access control model for a financial application. The policy requires that no single person can approve a transaction. Which access control principle does this policy enforce?

A.Least privilege
B.Separation of duties
C.Mandatory access control
D.Need to know
AnswerB

Separation of duties splits a critical transaction across multiple people so no single individual controls the whole process. Requiring that one person cannot approve a transaction directly enforces this principle, preventing fraud and unilateral action.

Why this answer

The policy that no single person can approve a transaction enforces the separation of duties (SoD) principle. In financial applications, SoD requires that critical tasks, such as initiating and approving a transaction, be divided among multiple individuals to prevent fraud or error. This control ensures that no single user has the authority to complete a high-risk action alone, directly aligning with the requirement stated.

Exam trap

The trap here is that candidates confuse separation of duties with least privilege, but least privilege focuses on limiting permissions to the minimum needed, whereas separation of duties specifically requires dividing critical tasks among multiple users to prevent fraud or error.

How to eliminate wrong answers

Option A is wrong because least privilege restricts user permissions to the minimum necessary for their job function, but it does not inherently prevent a single user from approving a transaction if that approval is within their role. Option C is wrong because mandatory access control (MAC) enforces system-wide policies based on labels and clearances, not the division of task responsibilities among multiple users. Option D is wrong because need to know limits access to information required for a specific task, but it does not address the requirement that no single person can approve a transaction, which is a process control, not an information access restriction.

493
MCQeasy

An organization is acquiring a new software package. The IS auditor is asked to review the contract with the vendor. Which of the following clauses is MOST important to ensure the organization can continue to use the software even if the vendor goes out of business?

A.Software escrow agreement.
B.Acceptance testing criteria.
C.Service level agreement (SLA) with performance metrics.
D.Indemnification clause.
AnswerA

A software escrow agreement ensures that source code and related materials are held by a third party and released to the customer if the vendor fails to meet obligations, such as going bankrupt. This allows the organization to maintain and modify the software independently, ensuring business continuity. It directly addresses the risk of vendor failure, making it the most important clause in this scenario.

Why this answer

A software escrow agreement is designed to protect the customer by providing access to source code and documentation if the vendor cannot fulfill its obligations, such as bankruptcy or acquisition. This enables the organization to maintain, modify, and continue using the software, ensuring business continuity. It is the key contractual safeguard against vendor failure.

Exam trap

The trap here is confusing legal protections like indemnification with continuity mechanisms, when escrow specifically addresses vendor failure.

494
MCQeasy

Based on the exhibit, what is the MOST appropriate action for IT management?

A.Investigate the reasons for the shortfall and implement corrective actions.
B.Ignore the variance as it is within acceptable range.
C.Adjust the target to 80% to match actual performance.
D.Replace the survey with a different measurement tool.
AnswerA

A shortfall against the exhibit's planned targets signals a control or performance gap, so management must first establish root cause before committing resources. Investigating the reasons and implementing corrective actions satisfies the stem's demand for the most appropriate management response, closing the gap rather than merely reporting it.

Why this answer

When a performance metric shows a significant shortfall against its target, IT management's most appropriate action is to investigate the root cause and implement corrective actions. This aligns with continuous improvement and governance principles rather than adjusting targets or ignoring the gap.

Exam trap

CISA often tests whether candidates choose the 'investigate and correct' answer over 'adjust the target' — the latter sounds pragmatic but is a classic governance anti-pattern that auditors flag as metric manipulation.

How to eliminate wrong answers

Option B is wrong because ignoring the variance assumes it is acceptable without evidence; a shortfall against target should be investigated, not dismissed. Option C is wrong because lowering the target to match actual performance is 'gaming the metric' and undermines the purpose of the measurement — it hides the problem instead of fixing it. Option D is wrong because replacing the measurement tool is premature and does not address the underlying performance gap; the tool may be perfectly valid.

495
MCQeasy

An organization's IT department has grown rapidly, and the CIO wants to ensure that employees understand expected behaviors when handling sensitive data and operating critical systems. Which of the following is the MOST appropriate governance mechanism to establish?

A.A service level agreement with the infrastructure hosting provider.
B.A documented IT code of conduct, acknowledged by staff, supported by periodic awareness training.
C.An annual penetration test of systems that store sensitive data.
D.A technical control that blocks access to sensitive data outside business hours.
AnswerB

A code of conduct translates governance expectations into explicit behavioral requirements, and acknowledgment plus recurring training makes those expectations enforceable and current. This combination addresses both awareness and accountability for sensitive data handling and critical system operations. It is a foundational governance mechanism that scales as the department grows and new staff join, unlike one-off or purely technical measures.

Why this answer

The CIO's objective is behavioral: staff must understand and follow expected practices for sensitive data and critical systems. A code of conduct with acknowledgment and recurring awareness training establishes those expectations, makes them explicit, and refreshes them as the organization grows. Technical restrictions, penetration tests, and vendor agreements address other risk areas and do not create or reinforce employee accountability for conduct.

Exam trap

The trap here is selecting a technical or assurance control when the objective is to establish and reinforce expected workforce behavior.

496
Multi-Selectmedium

An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)

Select 2 answers
A.A known error database that records diagnosed root causes and workarounds for reuse.
B.Weekly reporting of incident volumes by category to the service desk manager.
C.Escalation of every incident to senior management within one hour of detection.
D.Automatic closure of incidents once the affected service is restored to users.
E.Root cause analysis performed for recurring incidents, with corrective actions tracked to closure.
AnswersA, E

A known error database captures diagnosed root causes and documented workarounds so that support staff can resolve recurrences faster and avoid duplicating diagnostic effort. It converts problem investigations into organizational knowledge. For an environment where the same faults reappear, this repository directly supports consistent handling and provides evidence that problems are being analyzed rather than merely closed, making it a core problem management activity.

Why this answer

Effective problem management identifies the underlying cause of recurring incidents and prevents recurrence. Root cause analysis with corrective actions tracked to closure delivers the permanent fix, while a known error database preserves diagnosed causes and workarounds so recurrences are handled consistently and diagnostic effort is not repeated. Incident escalation, automatic closure, and volume reporting support operations but do not eliminate the root causes.

Exam trap

The trap here is confusing incident management activities, such as rapid escalation and automatic closure, with problem management, which exists specifically to find and eliminate the underlying cause of recurring incidents.

497
MCQeasy

An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?

A.Reduced scope of the PCI DSS assessment
B.Improved network performance
C.Elimination of the need for firewalls
D.Simplified patch management
AnswerA

Segmenting the cardholder data environment from corporate systems isolates it behind controlled conduits, so only that zone falls within PCI DSS assessment boundaries. This directly satisfies the stem's requirement by shrinking the systems, networks and business processes requiring validation, lowering audit effort and residual risk exposure.

Why this answer

Network segmentation reduces the scope of the PCI DSS assessment by isolating the cardholder data environment from other networks, so only systems that handle card data need to comply with PCI DSS.

498
Multi-Selecteasy

Which TWO of the following are characteristics of the iterative SDLC model?

Select 2 answers
A.The final product is delivered only at the end of the project
B.User feedback is incorporated after each iteration
C.Requirements are defined in detail at the start of the project
D.The system is developed and refined through multiple cycles
E.Risk analysis is performed only at the beginning
AnswersB, D

Each iteration ends with a working increment that users evaluate, and their feedback shapes the next cycle's requirements and design. This continuous user involvement is a defining trait of iterative development, satisfying the stem's requirement for a characteristic of that model.

Why this answer

Option B is correct because the iterative SDLC model builds the product in repeated cycles, and after each iteration the working increment is reviewed with users so their feedback can be incorporated into the next iteration. Option D is correct because the defining trait of the iterative model is that the system is developed and refined through multiple cycles, with each cycle producing a progressively more complete version of the product. Options A, C, and E describe characteristics of plan-driven or waterfall-style approaches rather than iterative development: delivering the final product only at the end (A) and freezing detailed requirements at the start (C) reflect a single-pass sequential model, and performing risk analysis only at the beginning (E) contradicts the iterative practice of reassessing risks in each cycle.

Exam trap

CISA often tests whether candidates can distinguish iterative SDLC characteristics (feedback per iteration, multiple cycles) from waterfall characteristics (upfront requirements, single delivery, initial risk analysis).

499
MCQmedium

A hospital is implementing a new electronic health record (EHR) system. The project team includes clinicians and IT staff. During integration testing, the system fails to exchange lab results with the existing legacy system due to format mismatches. The IT team suggests developing a custom interface. The clinical team is concerned that any custom solution may not comply with health data privacy regulations. The project sponsor pressures the team to quickly fix the issue to avoid delays. The IS auditor is reviewing this situation. What is the MOST appropriate action for the auditor to recommend?

A.Conduct a privacy impact assessment on the custom interface and ensure controls are in place before deployment.
B.Proceed with the custom interface to meet the project deadline.
C.Reject the custom interface and delay the project until a standard solution is found.
D.Replace the legacy system with a new one that is compatible.
AnswerA

A privacy impact assessment evaluates the custom interface against health data privacy regulations before deployment, satisfying the clinical team's compliance concern. It identifies required controls and documentation, letting the sponsor proceed without exposing protected health information to regulatory breach.

Why this answer

The custom interface introduces a new data exchange path between the EHR and legacy system. Without a privacy impact assessment (PIA), the auditor cannot verify that the interface will enforce encryption, access controls, and audit logging required by HIPAA or similar regulations. A PIA identifies risks like unauthorized disclosure of protected health information (PHI) during format translation, ensuring controls are implemented before deployment.

This aligns with the IS auditor's role to safeguard data privacy, not just meet deadlines.

Exam trap

The trap here is that candidates may prioritize speed (Option B) or absolute standardization (Option C) over the auditor's core responsibility to assess and mitigate privacy risks before any new data processing component goes live.

How to eliminate wrong answers

Option B is wrong because proceeding without assessing privacy risks violates the auditor's duty to ensure compliance with health data privacy regulations (e.g., HIPAA), and a rushed custom interface may introduce vulnerabilities like unencrypted PHI in transit. Option C is wrong because rejecting the custom interface outright is overly rigid; a properly assessed and controlled custom interface can be compliant, and delaying the project unnecessarily ignores a viable solution. Option D is wrong because replacing the entire legacy system is disproportionate, costly, and introduces far greater project risk and disruption than addressing the format mismatch with a controlled interface.

500
MCQmedium

An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?

A.The technical details of the vulnerability
B.The patch deployment schedule for the next quarter
C.Whether a formal risk acceptance and compensating controls are in place
D.The vendor's patch release notes
AnswerC

Unpatched critical vulnerabilities accepted for six months require documented risk acceptance and compensating controls. Examining these satisfies the stem's constraint by verifying that the business impact assessment was formally approved and that residual risk is mitigated, rather than merely deferred.

Why this answer

When a critical vulnerability remains unpatched due to a business impact assessment, the auditor's next step is to verify whether a formal risk acceptance and compensating controls are in place, because unpatched critical vulnerabilities require documented management approval and mitigating measures. This ensures the organization has consciously accepted the risk with proper governance rather than leaving it unaddressed. The auditor must confirm that the decision was authorized, documented, and supported by controls that reduce the residual risk to an acceptable level.

Exam trap

CISA often tests the principle that unpatched vulnerabilities are acceptable only with formal risk acceptance and compensating controls, so the trap is focusing on technical remediation or patch scheduling instead of verifying governance documentation.

How to eliminate wrong answers

Option A is wrong because the technical details of the vulnerability are already known and are not the auditor's focus; the issue is governance and risk treatment, not technical characterization. Option B is wrong because reviewing the next quarter's patch schedule does not address the six-month delay or the absence of risk acceptance — it only looks forward without resolving the current governance gap. Option D is wrong because vendor patch release notes provide technical information about the patch, not evidence of the organization's risk management decision or compensating controls.

501
Drag & Dropmedium

Order the steps for responding to a security incident in the correct sequence.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Incident response follows: detection, containment, eradication/recovery, review, and improvement.

502
Multi-Selecteasy

Which TWO of the following are essential components of a business case for a new system?

Select 2 answers
A.Implementation schedule.
B.Detailed system architecture.
C.Alignment with business strategy.
D.Risk assessment for all identified risks.
E.Cost-benefit analysis.
AnswersC, E

A business case must demonstrate that the proposed system supports the organisation's strategic objectives, otherwise the investment cannot be justified to sponsors. Strategic alignment provides the rationale linking expected capability to business goals, and it is a mandatory component alongside financial justification.

Why this answer

Option C (Alignment with business strategy) is correct because a business case must demonstrate that the proposed system directly supports the organization's strategic goals and objectives, justifying why the investment is worthwhile from a business perspective. Option E (Cost-benefit analysis) is correct because a business case must quantify and compare the expected costs against the anticipated benefits (financial and non-financial) to show the investment delivers value and to support go/no-go decision-making. Option A (Implementation schedule) is not essential to the business case itself; scheduling belongs to the project plan and is derived after approval.

Option B (Detailed system architecture) is a technical design artifact, not a business justification component. Option D (Risk assessment for all identified risks) is too absolute and belongs to risk management planning; while some risk consideration may appear in a business case, assessing every identified risk is not an essential component.

Exam trap

The trap here is that candidates confuse project management deliverables (like schedules and detailed architectures) with the strategic and financial justification required in a business case, leading them to select implementation schedule or detailed system architecture instead of the correct options.

503
MCQeasy

An organization is developing a new customer portal. The development team wants to use an agile methodology. Which of the following is a key benefit of using agile for this project?

A.Continuous stakeholder feedback is incorporated
B.Detailed requirements are defined upfront
C.Documentation is minimized to save time
D.The entire system is delivered at once
AnswerA

Agile's iterative sprints deliver working increments that stakeholders review regularly, so feedback shapes subsequent development rather than arriving after final delivery. This satisfies the portal project's need to accommodate evolving customer requirements throughout the build, reducing the risk of delivering a product misaligned with user expectations.

Why this answer

Agile methodologies emphasize iterative development with continuous stakeholder feedback, which is critical for a customer portal where user needs evolve. This ensures the final product aligns with actual requirements, reducing rework and increasing satisfaction. Option A directly captures this core benefit.

Exam trap

The trap here is that candidates often confuse agile's reduced documentation overhead (Option C) as a primary benefit, but the key advantage is continuous stakeholder feedback, not just saving time on documentation.

How to eliminate wrong answers

Option B is wrong because agile deliberately avoids defining detailed requirements upfront; instead, it embraces changing requirements through the project lifecycle. Option C is wrong because while agile values working software over comprehensive documentation, it does not minimize documentation to save time—it produces just enough documentation for the team and stakeholders. Option D is wrong because agile delivers the system incrementally in small, functional releases, not all at once, enabling early value delivery and feedback.

504
MCQmedium

In a RACI matrix for an IT process, which role should be assigned to the person who ultimately approves the outcome and is held accountable for its success?

A.Consulted (C)
B.Responsible (R)
C.Accountable (A)
D.Informed (I)
AnswerC

Accountable (A) designates the single person who owns the outcome and holds final approval authority, satisfying the stem's requirement for ultimate accountability. Unlike Responsible, which covers those performing the work, only one Accountable role should exist per activity, ensuring unambiguous ownership and preventing diffused decision-making.

Why this answer

In a RACI matrix, the Accountable (A) role is assigned to the person who ultimately approves the outcome and is held answerable for its success or failure. This is the single individual who owns the process or decision and has the authority to sign off. The Accountable person must be unique per activity to avoid ambiguity in ownership and decision-making.

Exam trap

CISA often tests the confusion between Responsible (does the work) and Accountable (owns the outcome), so candidates who equate the two pick R instead of A.

How to eliminate wrong answers

Option A is wrong because Consulted (C) refers to subject matter experts or stakeholders whose input is sought before a decision or action, but they do not approve or own the outcome. Option B is wrong because Responsible (R) is the person who performs the work or executes the task, not the one ultimately accountable for its success. Option D is wrong because Informed (I) is kept up to date on progress or decisions but has no approval authority or accountability.

505
MCQeasy

An organization uses a chargeback model to allocate IT costs to business units. What is a PRIMARY benefit of this approach?

A.Reduces total IT costs
B.Eliminates the need for an IT steering committee
C.Simplifies IT budgeting process
D.Encourages responsible consumption of IT resources
AnswerD

Under chargeback, each business unit's budget is directly debited for the IT resources it consumes, so units see the marginal cost of over-provisioning and self-limit demand. This cost visibility satisfies the stem's allocation model by tying consumption decisions to financial accountability.

Why this answer

Chargeback increases transparency and encourages business units to use IT resources efficiently.

506
MCQhard

An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?

A.Report the issue to senior management as a critical finding
B.Recommend immediate removal of the rule
C.Accept the risk as a compensating control
D.Determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs
AnswerD

The rule permits unrestricted access to Microsoft SQL on TCP port 1433, a severe exposure. Validating business justification before recommending removal or IP restriction is proportionate: the auditor confirms whether the documented temporary need still exists, then addresses the actual risk rather than assuming misuse.

Why this answer

The auditor's best course of action is to determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs, because audit findings must be based on evidence and business context rather than assumptions. A rule permitting any source IP to access TCP port 1433 is a significant security risk, but the auditor must first understand why it exists before recommending action. This approach ensures the recommendation is appropriate, justified, and aligned with business needs.

Exam trap

CISA often tests the auditor's role as an independent assessor who gathers evidence before recommending action, so the trap is selecting immediate escalation or removal instead of first determining business justification.

How to eliminate wrong answers

Option A is wrong because reporting to senior management as a critical finding before investigating the business justification skips the evidence-gathering step and may result in an inaccurate or premature escalation. Option B is wrong because recommending immediate removal without understanding the business need could disrupt legitimate operations and is not the auditor's role — auditors recommend, they do not implement. Option C is wrong because accepting the risk as a compensating control is not the auditor's decision; risk acceptance is a management prerogative, and the auditor should not assume the rule is a valid compensating control without evidence.

507
Multi-Selecthard

Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?

Select 2 answers
A.Encrypt all data in transit
B.Identify and classify sensitive data
C.Replace all existing security controls
D.Monitor and control data movement across endpoints
E.Ensure compliance with all regulations
AnswersB, D

A DLP strategy must first discover where sensitive data resides and label it by classification, since policy enforcement, blocking and reporting all depend on knowing which content is regulated or confidential before any protective control can be applied.

Why this answer

Option B is correct because a core objective of any DLP strategy is to discover, identify, and classify sensitive data (e.g., PII, PHI, PCI, intellectual property) so that policies can be applied based on data sensitivity and regulatory category. Option D is correct because DLP's defining function is to monitor and control data movement across endpoints, networks, and cloud channels — inspecting content in use, in motion, and at rest and enforcing actions such as block, quarantine, encrypt, or alert when policy violations occur. Option A is not a primary DLP objective; encryption in transit is typically handled by TLS/IPsec and is a separate control, though DLP may trigger encryption as an enforcement action.

Option C is incorrect because DLP augments, rather than replaces, existing security controls like firewalls, IAM, and endpoint protection. Option E is too broad — DLP supports compliance with specific data-handling regulations but does not by itself ensure compliance with all regulations.

Exam trap

The trap here is that candidates confuse DLP's primary objectives (identify, monitor, control) with supporting or adjacent activities like encryption or compliance, leading them to select options A or E instead of the core DLP functions.

508
Multi-Selecthard

An IS auditor is reviewing the requirements definition phase of a new system development project. The auditor finds that business users have provided functional requirements, but non-functional requirements are largely missing. Which TWO of the following are the MOST significant risks of proceeding without well-defined non-functional requirements? (Choose two.)

Select 2 answers
A.The development team may not understand the business processes.
B.The project may exceed its budget due to scope creep.
C.The system may lack necessary security controls.
D.The system may be difficult to maintain due to lack of documentation.
E.The system may not meet performance and scalability expectations.
AnswersC, E

Security requirements, including authentication, authorization, encryption, and auditing, are often classified as non-functional. If they are not specified, developers may not implement them, leaving the system vulnerable to breaches. This is a critical risk because security is essential for protecting data and complying with regulations. Thus, this is a major consequence of missing non-functional requirements.

Why this answer

Non-functional requirements cover critical aspects such as performance, scalability, security, and availability. Omitting them increases the risk that the system will fail to meet operational expectations and security needs. These failures can lead to system outages, data breaches, and user rejection, making them the most significant risks.

Exam trap

The trap here is focusing on functional gaps or project management issues, while overlooking that non-functional requirements encompass security and performance.

509
MCQhard

An IS auditor is reviewing how a retail company protects stored payment card data. The company states it encrypts card numbers using AES-256, but the auditor finds that the database encryption keys are stored in a plaintext configuration file on the same application server as the encrypted data. Which of the following is the auditor's PRIMARY concern?

A.Cardholder data should be tokenized instead of encrypted.
B.AES-256 is insufficient for protecting cardholder data at rest.
C.Storing the key with the encrypted data on the same server defeats the protection the encryption is meant to provide.
D.The encryption keys are not rotated frequently enough.
AnswerC

When the decryption key sits in plaintext on the same host as the ciphertext, a single server compromise yields both, so encryption provides little protection against that threat. The control objective for stored card data is to keep keys separate from data and from the application, typically in a key management system or hardware security module (HSM), which this configuration fails to do.

Why this answer

Encryption only reduces risk if the key is protected independently of the ciphertext and the host that processes it. A plaintext key file on the same application server means a single compromise exposes both data and key, nullifying the protection. Proper key management places keys in a dedicated key management system or hardware security module with strict access controls, separation from data, and documented lifecycle procedures.

Exam trap

The trap here is focusing on the strength of the encryption algorithm or on rotation schedules while overlooking that the key is stored in cleartext beside the data, which collapses the entire control.

510
MCQmedium

Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?

A.To test the operating effectiveness of controls
B.To collect evidence of control failures
C.To identify process owners and key personnel
D.To gain an understanding of the process and identify control points
AnswerD

A walkthrough traces a transaction through the entire process, letting the auditor observe actual procedures and pinpoint where controls are applied. This satisfies the planning objective of understanding the process and identifying control points before designing detailed tests.

Why this answer

A walkthrough is performed during audit planning to trace a transaction or process from start to finish, allowing the auditor to understand how the process actually operates and to pinpoint where controls exist. This understanding is the foundation for scoping the audit, designing test procedures, and identifying risks. It is not a test of control effectiveness — that comes later during fieldwork.

Exam trap

CISA often tests the distinction between planning-phase understanding activities (walkthroughs, inquiry, observation) and fieldwork-phase testing activities (reperformance, inspection, data analysis), so candidates who conflate 'walkthrough' with 'test of control' pick option A.

How to eliminate wrong answers

Option A is wrong because testing operating effectiveness is a fieldwork activity performed after the auditor already understands the process and has selected controls to test. Option B is wrong because collecting evidence of control failures presupposes that testing has occurred; walkthroughs are exploratory and understanding-oriented, not evidence-gathering for conclusions. Option C is wrong because although identifying process owners is a useful byproduct, it is not the primary purpose — the primary purpose is understanding the process and its control points.

511
Multi-Selecthard

During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?

Select 3 answers
A.Extent of integration testing performed
B.Whether all predefined user requirements were met
C.Accuracy and completeness of data migration
D.Compliance with the original project budget
E.Adequacy of user training provided
AnswersB, C, E

Low satisfaction despite budget compliance suggests functional shortfalls, so the auditor should test whether the system delivered the predefined user requirements. Unmet requirements directly explain user dissatisfaction and indicate the project missed its stated objectives.

Why this answer

Option B is correct because low user satisfaction often stems from unmet functional requirements, so the auditor should verify whether the delivered ERP actually satisfies the predefined user requirements captured during the requirements-gathering phase. Option C is correct because inaccurate or incomplete data migration directly degrades usability and trust in the new ERP, making data accuracy and completeness a key area to examine. Option E is correct because inadequate user training is a leading cause of poor satisfaction and low adoption, so the adequacy of the training provided must be reviewed.

Option A is not marked correct because integration testing is more relevant to technical defects and interface failures than to the stated symptom of low user satisfaction. Option D is not marked correct because budget compliance was already confirmed (delivered within budget) and does not explain low user satisfaction.

Exam trap

CISA often tests the distinction between project management success (on time, on budget) and product success (meets user needs) — candidates who equate budget compliance with project success pick the wrong options.

512
MCQhard

An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?

A.Report the finding as a non-compliance with the patch management policy
B.Discuss with management the absence of a risk acceptance
C.Escalate the issue to senior management immediately
D.Determine if compensating controls exist to mitigate the vulnerability
AnswerD

Before escalating or reporting, the auditor must establish whether existing compensating controls already reduce the vulnerability's exploitability, since unpatched systems are often mitigated by segmentation, virtual patching or monitoring, which determines the actual residual risk.

Why this answer

The auditor should first determine if compensating controls exist to mitigate the vulnerability, because the presence of effective compensating controls may reduce the residual risk to an acceptable level even without patching. This step gathers evidence before concluding on the adequacy of risk treatment. Only after understanding the control environment can the auditor assess whether the lack of patching and risk acceptance constitutes a significant finding.

Exam trap

CISA often tests the auditor's sequence of evidence gathering before drawing conclusions, so the trap is jumping to reporting or escalation without first assessing whether compensating controls mitigate the risk.

How to eliminate wrong answers

Option A is wrong because reporting non-compliance with the patch management policy before assessing compensating controls may be premature — the policy may allow exceptions with compensating controls. Option B is wrong because discussing the absence of risk acceptance with management is a valid step but should come after determining whether compensating controls exist, as that information shapes the conversation. Option C is wrong because escalating to senior management immediately skips the investigative steps and may be disproportionate if compensating controls effectively mitigate the risk.

513
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?

A.To determine the criticality of business processes and their recovery requirements
B.To create a list of emergency contacts
C.To identify the resources required for recovery
D.To document the technical recovery procedures
AnswerA

A BIA identifies which business processes are most critical and quantifies their recovery time and recovery point objectives, prioritising continuity investment. This determines criticality and recovery requirements, distinguishing it from risk assessment, which evaluates threat likelihood and impact.

Why this answer

The primary purpose of a BIA is to identify and prioritize business processes based on their criticality to the organization and to determine the recovery time objectives (RTOs) and recovery point objectives (RPOs) for each. This analysis forms the foundation for the business continuity plan by establishing what must be recovered and how quickly, before any recovery strategies or resource requirements are defined.

Exam trap

CISA often tests the distinction between the BIA (which determines criticality and recovery requirements) and the subsequent recovery strategy development (which identifies resources and procedures), so candidates must not confuse outputs of the BIA with activities that follow it.

How to eliminate wrong answers

Option B is wrong because creating a list of emergency contacts is an operational detail of incident response, not the analytical purpose of a BIA. Option C is wrong because identifying recovery resources is a downstream output of the BIA (part of the recovery strategy), not its primary purpose. Option D is wrong because documenting technical recovery procedures is a function of disaster recovery planning and execution, not the BIA itself.

514
MCQhard

In an agile development environment, an IS auditor reviews the backlog and finds that security requirements are not explicitly included. What is the best recommendation?

A.Engage external security auditors to define requirements
B.Allocate a separate sprint dedicated solely to security
C.Perform comprehensive security testing during the final sprint
D.Include security stories in the product backlog
AnswerD

Embedding security stories in the product backlog makes security requirements visible, estimable and prioritised alongside functional work, satisfying the stem's constraint that they are currently absent. This integrates security into agile planning rather than bolting it on, so each sprint delivers verifiable security outcomes.

Why this answer

In agile development, security should be integrated continuously rather than treated as an afterthought. Including security stories in the product backlog ensures that security requirements are prioritized, estimated, and implemented incrementally within each sprint, aligning with the agile principle of delivering value early and often. This approach embeds security into the development lifecycle from the start, reducing technical debt and vulnerabilities.

Exam trap

The trap here is that candidates often choose a dedicated security sprint (Option B) or final testing (Option C) because they resemble traditional security review phases, but the CISA exam emphasizes integrating security into every sprint to align with agile's continuous delivery and risk management principles.

How to eliminate wrong answers

Option A is wrong because engaging external security auditors to define requirements creates a dependency on outside parties and delays security integration, contradicting agile's self-organizing team model and continuous feedback loops. Option B is wrong because allocating a separate sprint dedicated solely to security violates agile's iterative delivery principle and can lead to security being treated as a separate phase, increasing risk of integration issues and rework. Option C is wrong because performing comprehensive security testing only during the final sprint is a waterfall-like approach that misses the opportunity to detect and fix vulnerabilities early, often resulting in costly late-stage remediation and potential release delays.

515
MCQmedium

An IS auditor is documenting the audit programme for an engagement and must decide how specific the procedures should be. Which of the following BEST describes the appropriate level of detail for procedures recorded in the audit programme?

A.Specific steps identifying what is to be tested, how, and by whom
B.Broad control objectives that allow the auditor to choose procedures during fieldwork
C.The final audit opinion and the criteria against which it will be measured
D.A list of prior audit findings to be re-verified in the current engagement
AnswerA

An audit programme should specify the procedures to be performed, the population or sample, the evidence to be obtained, and the responsibility for each step. This level of detail enables supervision, supports consistent execution, and provides a basis for confirming that the planned work was actually carried out before conclusions are drawn.

Why this answer

An audit programme converts engagement objectives into executable procedures. Each step should state the procedure, the items or population to which it applies, the evidence expected, and who performs it, so that work can be supervised, reviewed, and evidenced. Objectives, prior findings, and criteria inform the programme but do not replace the specific procedural detail that makes the engagement repeatable and defensible.

Exam trap

The trap here is equating a well-written control objective with an audit programme step, when objectives describe what must be achieved while programme steps describe exactly what the auditor will do to test it.

516
MCQhard

A security review of the above Apache configuration identifies a critical vulnerability. Which of the following is the MOST significant issue?

A.Default DocumentRoot path is used
B.Directory listing is enabled (Indexes option)
C.AllowOverride All allows .htaccess overrides
D.Require all granted permits all access
AnswerB

With Indexes enabled, Apache returns an auto-generated listing of every file in a directory lacking an index file, exposing backups, configuration files and source code to unauthenticated visitors. This directly enables reconnaissance and data disclosure, making it the most significant issue in the configuration review.

Why this answer

The Indexes option in Apache enables directory listing, which exposes the entire contents of a directory when no index file (e.g., index.html) is present. This can reveal sensitive files, configuration backups, or source code, making it a critical information disclosure vulnerability. Unlike other options, Indexes directly leads to unauthorized data exposure without requiring any additional conditions.

Exam trap

The trap here is that candidates often focus on access control (Require all granted) or override permissions (AllowOverride All) as the most critical issue, but the immediate and direct information disclosure from directory listing (Indexes) is typically the most severe in a standard web server configuration.

How to eliminate wrong answers

Option A is wrong because using the default DocumentRoot path (e.g., /var/www/html) is a common configuration and not inherently a vulnerability; it only becomes a risk if combined with other misconfigurations. Option C is wrong because AllowOverride All allows .htaccess overrides, which can be a security concern if not properly managed, but it is not as immediately exploitable as directory listing and can be mitigated with proper .htaccess controls. Option D is wrong because 'Require all granted' permits all access, but this is often the intended default for public web content; the vulnerability arises only when combined with other issues like Indexes or weak authentication, and by itself it does not directly expose directory contents.

517
MCQeasy

During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?

A.Sprint planning meeting
B.Sprint review
C.Daily standup meeting
D.Sprint retrospective
AnswerB

The sprint review demonstrates the completed increment to stakeholders, exposing working functionality and the controls embedded in it. This gives the auditor direct evidence of control effectiveness for the current sprint, unlike planning or retrospective sessions.

Why this answer

The sprint review is where the team demonstrates the completed increment to stakeholders, making it the best venue for the auditor to observe working software and evaluate whether controls built into the sprint were actually implemented and effective. It provides tangible evidence of the increment, unlike planning or standup meetings which discuss future or in-progress work.

Exam trap

CISA often tests the confusion between the sprint review (product demonstration) and the sprint retrospective (process improvement) — candidates who conflate the two pick the retrospective as the control-assessment venue.

How to eliminate wrong answers

Option A is wrong because sprint planning focuses on selecting and estimating work for the upcoming sprint, not on demonstrating completed controls. Option C is wrong because the daily standup is a brief coordination ceremony covering progress and blockers, with no demonstration or verification of control effectiveness. Option D is wrong because the sprint retrospective examines process improvement and team dynamics, not the functional effectiveness of implemented controls.

518
MCQmedium

An organization is migrating sensitive customer data to a public cloud. Which of the following encryption strategies provides the STRONGEST protection against data exposure to the cloud provider?

A.Use transport layer security (TLS) for data in transit
B.Implement client-side encryption with keys managed on-premises
C.Encrypt data at rest using server-side encryption with AES-256
D.Enable the cloud provider's key management service
AnswerB

Client-side encryption with on-premises key management ensures plaintext and keys never reach the provider, so the cloud only stores ciphertext. This directly satisfies the stem's constraint of strongest protection against exposure to the cloud provider itself, unlike provider-managed keys where Microsoft Entra ID or the vendor could technically access data.

Why this answer

Client-side encryption with keys managed on-premises ensures that the cloud provider never has access to the encryption keys or the plaintext data. Even if the cloud provider's infrastructure is compromised or they have administrative access, the data remains encrypted and unreadable. This provides the strongest protection because the cloud provider is excluded from the cryptographic trust boundary.

Exam trap

The trap here is that candidates often confuse 'encryption at rest' or 'TLS' with full data protection, failing to realize that these methods still allow the cloud provider to access plaintext data either during processing or through key management access.

How to eliminate wrong answers

Option A is wrong because TLS only protects data in transit between the client and the cloud provider; once the data reaches the cloud provider's servers, it is decrypted and stored in plaintext, leaving it exposed to the provider. Option C is wrong because server-side encryption with AES-256 means the cloud provider manages the encryption process and typically has access to the keys (or can access them via their key management service), so the provider can decrypt the data at rest. Option D is wrong because enabling the cloud provider's key management service gives the provider control over the encryption keys, allowing them to decrypt the data if they choose or if compelled by legal request.

519
MCQhard

An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?

A.Business-IT strategy mapping workshops
B.Weekly IT status reports
C.Outsourcing non-core IT functions
D.IT budget increase
AnswerA

Misalignment stems from business and IT holding different assumptions, so structured mapping workshops force both groups to articulate objectives, capabilities and dependencies in one forum. That shared translation of business goals into IT services directly repairs the communication gap the stem identifies.

Why this answer

Business-IT strategy mapping workshops bring business and IT stakeholders together to explicitly map IT initiatives to business goals, which directly addresses the lack of communication and misalignment. This collaborative exercise creates shared understanding and a documented linkage between IT investments and business outcomes, which is the most effective way to improve alignment. It is a governance and communication mechanism, not just a reporting or budgeting action.

Exam trap

CISA often tests the difference between communication (reports) and alignment (joint strategy mapping) — candidates who pick 'weekly status reports' mistake information flow for strategic alignment.

How to eliminate wrong answers

Option B is wrong because weekly IT status reports are one-way communication that informs but does not create alignment — they do not involve business stakeholders in strategy mapping. Option C is wrong because outsourcing non-core IT functions may reduce cost or focus but does not improve strategic alignment between IT and business. Option D is wrong because increasing the IT budget without addressing communication and governance does not align IT with business strategy — it may even increase misalignment if spent on the wrong priorities.

520
MCQhard

During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?

A.PCI DSS
B.SOX
C.HIPAA
D.GDPR
AnswerD

GDPR mandates a DPO for public authorities and for processing requiring large-scale, regular and systematic monitoring or special-category data. Processing EU residents' personal data without an appointed DPO breaches that obligation, whereas other privacy regulations impose no equivalent universal DPO requirement.

Why this answer

The GDPR (EU Regulation 2016/679) governs the processing of personal data of EU residents and mandates the appointment of a Data Protection Officer (DPO) in specific circumstances—such as large-scale systematic monitoring or large-scale processing of special categories of data by public authorities or core-activity organizations. Processing EU residents' personal data without a required DPO is a direct GDPR Article 37 violation. The other regulations listed address payment card data, financial reporting integrity, and US healthcare information, none of which impose a DPO requirement for EU personal data.

Exam trap

CISA often tests regulation-to-requirement mapping, and the trap is confusing HIPAA's 'Privacy Officer' or PCI DSS's security controls with GDPR's specific DPO mandate—candidates who see 'privacy' and jump to HIPAA or PCI DSS miss the EU-resident trigger.

How to eliminate wrong answers

Option A is wrong because PCI DSS is a payment card industry standard governing cardholder data (PAN, CVV, etc.) and has no DPO appointment requirement—it focuses on protecting card data through controls like encryption and access management. Option B is wrong because SOX (Sarbanes-Oxley) governs financial reporting controls and corporate governance for publicly traded US companies; it does not address personal data privacy or DPOs. Option C is wrong because HIPAA governs protected health information (PHI) in the US healthcare context and requires a Privacy Officer, not a GDPR-style DPO, and does not apply to general EU resident data processing.

521
MCQmedium

During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?

A.Negotiate a lower price to offset the risk
B.Evaluate compensating controls or seek an alternative vendor
C.Accept the risk because the vendor is well-known
D.Request a customized SOC 2 report
AnswerB

An adverse SOC 2 opinion means the vendor's controls failed to meet trust services criteria, so the auditor should recommend evaluating compensating controls or selecting an alternative vendor. This directly addresses the assurance gap the adverse opinion creates for a critical system.

Why this answer

An adverse SOC 2 opinion means the service auditor found that controls were not suitably designed or operating effectively, so the vendor cannot be relied upon to protect the organization's data. The auditor's primary recommendation must therefore be to evaluate compensating controls the organization can apply or to seek an alternative vendor, since accepting the vendor as-is would transfer unacceptable risk.

Exam trap

CISA often tests the misconception that a well-known vendor's reputation or a price concession can offset an adverse SOC 2 opinion — candidates who pick A or C fail to recognize that control failures are not mitigated by commercial or reputational factors.

How to eliminate wrong answers

Option A is wrong because a price reduction does not mitigate the underlying control failure — risk transfer through discounting is not a valid audit recommendation. Option C is wrong because vendor reputation is irrelevant when an independent service auditor has issued an adverse opinion; accepting the risk on brand recognition alone violates due professional care. Option D is wrong because a SOC 2 report is issued by the service auditor based on the vendor's system description — the client cannot 'request a customized' report to change the opinion, only request a different report type or period.

522
MCQeasy

An organization is implementing a new human resources system. The IS auditor wants to determine whether the system will enforce segregation of duties (SoD) for sensitive transactions such as payroll changes and employee master data updates. Which of the following is the MOST appropriate source of evidence?

A.Interviews with HR managers to confirm that they monitor user activity and would detect any conflicting transactions.
B.Review of the role design and access control configuration within the application, including conflicting role analysis.
C.Review of the user access request forms to confirm that each user's manager approved the requested access.
D.Inspection of the organization's written security policy that prohibits employees from performing conflicting duties.
AnswerB

Segregation of duties is enforced through the application's role design and access control configuration. Reviewing role definitions, permission assignments, and conflicting role analysis provides direct evidence that incompatible duties cannot be performed by one user. This is the most appropriate source because it shows how the system actually restricts access, rather than relying on policy statements or user interviews that may not reflect the implemented controls.

Why this answer

Segregation of duties in an application is enforced through role design and access control settings. The auditor obtains the strongest evidence by examining how roles are defined, which permissions are assigned, and whether conflicting combinations are identified and blocked. Policy documents, interviews, and access request forms are all indirect and do not prove that the system itself prevents a single user from performing incompatible payroll and master data functions.

Exam trap

The trap here is accepting a policy or approval form as evidence of SoD enforcement, when only the application's role and access configuration shows whether conflicts are actually prevented.

523
MCQmedium

An IS auditor is reviewing a data center's environmental controls and observes that the fire suppression system uses water sprinklers in the main server room. The auditor learns that the sprinkler system was installed when the facility was a general office space. Management states that the sprinklers have never activated. Which of the following should the IS auditor recommend as the MOST appropriate control improvement?

A.Document a formal exception accepting the water sprinkler system based on its clean activation history.
B.Replace the water sprinkler system with a clean agent or pre-action suppression system appropriate for IT equipment.
C.Increase the frequency of sprinkler head inspections to ensure they remain operational.
D.Install additional smoke detectors to provide earlier warning of a fire event.
AnswerB

Water-based sprinklers can cause catastrophic damage to energized IT equipment, and the historical absence of activation does not reduce that risk. A clean agent or pre-action system suppresses fire while limiting collateral damage to servers and storage. Recommending replacement addresses the actual environmental risk identified during the review and aligns with accepted data center protection practices.

Why this answer

Water sprinklers are inappropriate for rooms housing energized IT equipment because discharge can destroy hardware and interrupt operations far beyond the fire itself. A clean agent or pre-action system provides suppression while minimizing collateral damage. Because management's justification rests only on the absence of prior activations, the auditor should recommend replacing the suppression method rather than merely inspecting or accepting it.

Exam trap

The trap here is treating a long incident-free history as evidence that the water sprinkler system is an acceptable control, when the risk is the damage it would cause upon activation.

524
MCQmedium

An organization has decided to adopt a formal IT governance framework to improve alignment between IT and business objectives. Management asks the IS auditor to advise on the FIRST step in the adoption process. Which of the following should the IS auditor recommend?

A.Perform a gap assessment comparing current IT governance practices with the framework's control objectives.
B.Purchase and deploy a governance, risk, and compliance tool to automate control monitoring.
C.Benchmark the organization's IT spending ratio against industry peers.
D.Appoint a chief information security officer to own the governance initiative.
AnswerA

Adopting a framework begins with understanding the current state so that implementation effort is directed where it is needed. A gap assessment maps existing practices against the framework's control objectives and identifies what is missing, redundant, or misaligned. This evidence-based starting point prevents the organization from implementing controls it already has or overlooking critical deficiencies, and it produces the baseline needed for prioritization and later progress measurement.

Why this answer

Framework adoption follows a logical sequence: understand the current state, identify gaps against the target control objectives, prioritize remediation, then implement and monitor. A gap assessment produces the baseline that makes every later decision informed, from tool selection to ownership to investment prioritization. Tooling, role appointments, and peer benchmarking are either premature or too narrow to serve as the starting point.

Exam trap

The trap here is equating the start of governance adoption with acquiring a tool or naming an owner, rather than establishing an evidence-based current-state baseline.

525
Multi-Selectmedium

Which TWO of the following are guiding principles of ITIL 4? (Select TWO)

Select 2 answers
A.Progress iteratively with feedback
B.Automate everything
C.Focus on value
D.Standardize services
E.Centralize decision making
AnswersA, C

Progress iteratively with feedback is an ITIL 4 guiding principle advocating small, incremental improvements cycled with stakeholder feedback. It replaces big-bang change with continuous adjustment, reducing risk and enabling services to evolve as requirements and evidence emerge.

Why this answer

ITIL 4 has seven guiding principles. 'Focus on value' and 'Progress iteratively with feedback' are two of them. 'Centralize decision making' and 'Standardize services' are not ITIL 4 principles, and 'Automate everything' is not a principle.

Page 6

Page 7 of 13

Page 8