Sample questions
Certified Information Systems Auditor CISA practice questions
A company is migrating from a legacy system to a cloud-based ERP. Which of the following is the MOST important control to ensure data integrity during data conversion?
An organization uses a chargeback model to allocate IT costs to business units. What is a PRIMARY benefit of this approach?
Which TWO of the following are types of audit evidence recognized in IS audit practice?
Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?
After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?
An organization uses a cloud-based ERP system to manage financial transactions. The system is accessed by employees in finance, procurement, and sales departments. The IS auditor i…
An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery…
Information Systems Operations and Business ResiliencemediumSee the answer and why each option is right or wrong →An IS auditor is reviewing an organization's data classification policy. Which of the following findings is MOST critical?
During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change wa…
Information Systems Operations and Business ResiliencemediumSee the answer and why each option is right or wrong →An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch nee…
Order the steps for conducting an audit engagement from start to finish.
Which THREE of the following are key considerations when selecting a software development methodology for a project?
Which of the following is a primary advantage of fixed-price contracts in systems acquisition?
Information Systems Acquisition, Development, and ImplementationeasySee the answer and why each option is right or wrong →Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?
Order the steps for performing a data backup in the correct sequence.
An IS auditor is conducting a follow-up review of prior audit findings. Management has implemented a new automated control but has not yet updated the risk register to reflect the…
An IS auditor is reviewing the backup strategy for a financial institution. The backup administrator states that full backups are taken every Sunday, and incremental backups are ta…
Information Systems Operations and Business ResiliencemediumSee the answer and why each option is right or wrong →Which of the following is the BEST indicator of IT performance from the customer perspective in an IT balanced scorecard?
An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is th…
An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and…
Information Systems Operations and Business ResiliencemediumSee the answer and why each option is right or wrong →An IS auditor is evaluating how an organization manages its backup and restoration process for a critical financial application. The backup job completes successfully each night an…
Information Systems Operations and Business ResiliencehardSee the answer and why each option is right or wrong →An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed…
An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evid…
Information Systems Acquisition, Development, and ImplementationmediumSee the answer and why each option is right or wrong →An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are…