Courseiva

CISA · domain

Information System Auditing Process

This domain covers how IS audits are planned, executed, reported and followed up: audit charter and scope, risk-based planning, evidence gathering and classification, control testing, workpaper documentation, and reporting with follow-up. Questions are scenario-based, asking you to select the best auditor action, classify evidence, or judge whether a finding, opinion or follow-up conclusion is appropriate.

120 questions30 easy58 medium32 hard

Focused practice

Practice Information System Auditing Process questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information System Auditing Process

Be able to plan a risk-based IS audit, choose and evaluate sufficient appropriate evidence, test controls, document workpapers, and write findings with clear criteria, cause, effect and recommendation. The single most important thing: base every conclusion on corroborated evidence, not management assertion.

Audit evidence types and reliability: inspection, observation, inquiry, reperformance, recalculation, confirmation and analytical procedures

Risk-based audit planning, scoping, materiality, audit charter, engagement letters and resource scheduling

Control testing approaches: compliance versus substantive testing, sampling, walkthroughs and evidence sufficiency

Reporting, follow-up procedures, management responses, residual risk and tracking remediation of prior findings

Watch out for

Common Information System Auditing Process exam traps

  • ▸Treating inquiry alone as sufficient evidence; inquiry must be corroborated by inspection, observation or reperformance before concluding a control works.
  • ▸Confusing follow-up purpose: it verifies remediation and residual risk, not re-auditing the whole area or accepting management's claim without evidence.
  • ▸Assuming a control operated because procedures exist; the auditor must test whether reviews occurred and whether exceptions were escalated and resolved.

Question index

All Information System Auditing Process questions (120)

Click any question to see the full explanation, or start a practice session above.

1

An IS auditor is conducting a preliminary review of a newly acquired subsidiary and needs to understand the organizational structure, key business processes, and the technology environment before drafting the engagement plan. Which of the following techniques is MOST appropriate for gathering this broad understanding?

Easy
2

An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?

Hard
3

An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?

Hard
4

An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?

Easy
5

An IS auditor is designing test procedures for an audit of an organization's network perimeter. The auditor plans to use computer-assisted audit techniques (CAATs) to analyze firewall log data covering six months. Which TWO of the following are the MOST important considerations when using CAATs in this engagement? (Choose two.)

Hard
6

Which of the following is the BEST example of an analytical procedure used during an IS audit?

Medium
7

According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?

Easy
8

An IS auditor is reviewing a network access control list and finds that a rule permits traffic from any source to a database server on port 1521. Management states the rule is required for a legacy application. Which of the following is the MOST appropriate audit response?

Hard
9

An IS auditor is reviewing the audit committee's oversight of the IT audit function. Which of the following is the MOST important factor for the auditor to consider when assessing the committee's effectiveness?

Easy
10

An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?

Hard
11

Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?

Easy
12

During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?

Easy
13

According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?

Easy
14

Which TWO of the following are components of audit risk in IS auditing?

Medium
15

A compliance audit is primarily concerned with:

Easy
16

An IS auditor is conducting an audit of a payroll application and selects a statistical sample of 200 payment transactions from a population of 20,000. Testing reveals 12 transactions where the gross pay was calculated incorrectly due to a flawed overtime rule. Which of the following is the MOST appropriate interpretation of this result?

Medium
17

During an audit of a data center, an IS auditor discovers that a critical server's operating system has not been patched for eight months because the vendor's patch conflicted with a legacy application. Management accepts the risk and documents a compensating control of enhanced network monitoring. Which of the following should the IS auditor do NEXT?

Hard
18

An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?

Medium
19

An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?

Hard
20

During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:

Medium
21

Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?

Easy
22

According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?

Easy
23

According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?

Medium
24

An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)

Medium
25

An IS auditor is planning an audit of a cloud service provider's controls over data backup and recovery. The auditor needs to obtain evidence about the provider's backup procedures and restoration testing. Which of the following is the MOST appropriate source of evidence?

Medium
26

An IS auditor is preparing the audit report after completing fieldwork on an organization's backup and restoration process. Management disagrees with one of the findings and has provided additional evidence. Which of the following is the auditor's MOST appropriate course of action?

Medium
27

Which of the following is the PRIMARY purpose of audit working papers?

Medium
28

An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:

Hard
29

Which of the following is the best example of audit evidence obtained through re-performance?

Medium
30

Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)

Hard
31

An IS auditor is evaluating the reliability of audit evidence obtained from an IT system. Which TWO of the following factors most directly affect the reliability of the evidence? (Choose two.)

Hard
32

Which of the following is a permanent file item in an IS audit working paper?

Medium
33

An IS auditor is leading an audit engagement and discovers that a key member of the audit team lacks the technical expertise to evaluate a newly implemented cloud encryption control. The audit manager insists the team member proceed anyway to save time. According to ISACA IT Audit Standards, what is the MOST appropriate action for the IS auditor to take?

Medium
34

Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?

Easy
35

An IS auditor is planning an audit of a cloud-hosted application and needs to determine whether the cloud provider's controls are adequate. The provider offers a SOC 2 Type II report. Which of the following should the auditor do FIRST?

Medium
36

An IS auditor is reviewing the audit committee's oversight of the IT audit function. The auditor notes that the audit committee approves the annual IT audit plan but does not receive regular updates on the status of management's remediation of audit findings. Which of the following is the MOST significant risk arising from this situation?

Easy
37

An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?

Hard
38

An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)

Hard
39

An IS auditor is planning an engagement and needs to obtain an understanding of the organization's IT environment to develop the audit programme. Which of the following techniques is MOST appropriate for this purpose?

Medium
40

An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)

Medium
41

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Hard
42

An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?

Medium
43

Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)

Medium
44

An IS auditor is reviewing an organization's incident management process after a ransomware attack encrypted several file servers. Which TWO of the following should the auditor verify as part of assessing the effectiveness of the incident response? (Choose two.)

Hard
45

An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?

Hard
46

An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)

Medium
47

During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?

Medium
48

An IS auditor is assessing the risk of material misstatement in a highly automated transaction processing environment. The auditor notes that the system automatically calculates interest and posts it to customer accounts. Which of the following audit approaches would BEST address the risk of incorrect interest calculations?

Hard
49

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?

Medium
50

An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?

Easy
51

Which of the following audit types is MOST likely to be performed by an organization's own employees?

Easy
52

An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:

Medium
53

Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)

Medium
54

An IS auditor is assessing the effectiveness of the change management process for a critical financial application. The auditor wants to determine whether changes are adequately tested before being deployed to production. Which TWO of the following procedures would provide the MOST relevant evidence? (Choose two.)

Medium
55

An IS auditor is evaluating the reliability of audit evidence obtained during a review of an outsourced payroll provider. Which TWO of the following considerations most directly affect the reliability of that evidence? (Choose two.)

Medium
56

An IS auditor is designing substantive test procedures for a newly implemented automated accounts payable system and wants to rely less on the client's automated controls. The auditor decides to use computer-assisted audit techniques to test the completeness and accuracy of transaction processing. Which TWO of the following techniques would BEST provide direct evidence about the population of transactions? (Choose two.)

Hard
57

An IS auditor is planning an audit of a cloud service provider's security controls. The auditor has limited access to the provider's internal systems. Which of the following would be the MOST effective way to obtain assurance over the provider's security controls?

Medium
58

Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?

Hard
59

Which of the following is an example of a compliance audit?

Easy
60

An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?

Medium
61

Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?

Medium
62

An IS auditor is documenting the audit programme for an engagement and must decide how specific the procedures should be. Which of the following BEST describes the appropriate level of detail for procedures recorded in the audit programme?

Medium
63

An IS auditor is planning an audit of a financial application. The auditor wants to ensure that audit effort is focused on areas with the highest risk. Which approach should the auditor adopt?

Medium
64

Which TWO of the following are types of statistical sampling methods? (Select TWO.)

Medium
65

Which of the following is the most reliable form of audit evidence?

Medium
66

During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?

Easy
67

Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?

Medium
68

An IS auditor is planning a compliance audit of a payment gateway that processes credit card transactions. The auditor needs to determine whether the control environment meets the requirements of the applicable payment card industry standard. Which of the following should be the auditor's PRIMARY basis for defining the audit criteria?

Medium
69

An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed but no evidence of follow-up exists for two anomalies identified in one review. Which of the following conclusions is MOST appropriate?

Hard
70

An IS auditor is reviewing the audit documentation from a prior year and finds that a material weakness was reported but not remediated. According to ISACA standards, which audit phase should address this?

Hard
71

An IS auditor is conducting an audit of a payroll application and needs to verify that user access rights match each employee's current job responsibilities. Which of the following is the MOST appropriate source of evidence for this test?

Easy
72

During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?

Medium
73

An IS auditor is conducting an audit of a hospital's electronic health record system. During fieldwork, the auditor discovers that several database administrators have the ability to modify patient records directly in the production database without leaving an audit trail. The auditor wants to gather sufficient appropriate evidence to determine whether this is a widespread issue. Which of the following is the MOST appropriate action?

Medium
74

Which TWO of the following are phases of the audit process? (Select two.)

Easy
75

Which of the following is a key difference between internal and external auditors?

Medium
76

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. The audit team has limited experience with this ERP. Which of the following is the BEST course of action?

Medium
77

Which document is typically included in the permanent file of audit documentation?

Easy
78

An IS auditor is evaluating the design of controls over a new financial system. Which of the following is the BEST approach to assess control design?

Hard
79

Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)

Medium
80

Which of the following is a characteristic of non-statistical (judgmental) sampling?

Medium
81

An IS auditor is preparing working papers. Which of the following items should be included in the permanent file rather than the current file?

Hard
82

During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:

Hard
83

An IS auditor is conducting a follow-up review of prior audit findings. Management has implemented a new automated control but has not yet updated the risk register to reflect the residual risk. Which of the following should the auditor do FIRST?

Medium
84

Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?

Easy
85

An IS auditor is evaluating the results of a penetration test performed by an external vendor on a web-facing application. The report identifies a critical SQL injection vulnerability. Which of the following is the MOST appropriate action for the IS auditor to recommend FIRST?

Medium
86

Which of the following types of audit evidence provides the highest level of assurance?

Medium
87

During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?

Medium
88

An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?

Hard
89

During a follow-up audit, an IS auditor finds that management implemented a compensating control rather than the recommended primary control to address a previously reported high-risk finding. The residual risk is now within the organization's risk appetite. How should the IS auditor respond?

Hard
90

An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?

Medium
91

What is the primary purpose of the planning phase in an IS audit?

Easy
92

During an audit of an organization's backup and recovery process, the IS auditor finds that full backups are performed weekly and incremental backups are performed nightly. Restoration testing has not been performed in over two years. Which of the following should the auditor do FIRST?

Medium
93

An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?

Medium
94

An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?

Hard
95

An IS auditor is assessing the audit risk for an engagement covering a core banking application. The auditor determines that inherent risk is high because the application processes high-value transactions in real time. The auditor also concludes that control risk is low because strong automated controls and segregation of duties are in place and have been tested. Which of the following BEST describes the appropriate response to this assessment?

Hard
96

An IS auditor is planning an audit of a small organization with limited IT staff. Which approach is most appropriate?

Medium
97

During which phase of the IS audit process does the auditor perform walkthroughs and test controls?

Easy
98

During an operational audit, the auditor uses ratio analysis to compare current year expenses to prior years and industry benchmarks. This is an example of which type of audit evidence?

Medium
99

An IS auditor is performing a risk assessment to prioritize audit engagements for the annual audit plan. Which TWO of the following factors should the auditor consider when evaluating inherent risk? (Choose two.)

Medium
100

In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?

Hard
101

During an audit of a data center, the IS auditor observes that visitors are escorted at all times but the visitor log is not reconciled to the badge access system. Which of the following BEST describes the audit concern?

Easy
102

An IS auditor is planning an audit of a small organization with limited IT staff. Which of the following is a key consideration for the audit approach?

Hard
103

Which of the following is a key difference between an internal audit and an external audit?

Medium
104

Which TWO of the following are types of audit evidence recognized in IS audit practice?

Easy
105

Which THREE of the following are characteristics of SMART recommendations in an audit report? (Select three.)

Hard
106

Which type of audit is primarily concerned with evaluating the efficiency and effectiveness of operations?

Easy
107

In the audit follow-up phase, which TWO actions are essential? (Select two.)

Medium
108

During an audit of a bank's online transaction processing system, the IS auditor discovers that batch totals are reconciled only at the end of each business day, while individual transactions are posted to customer accounts in real time. Which of the following is the GREATEST risk arising from this control design?

Hard
109

An IS auditor is reviewing the audit charter of an organization's internal audit function. Which of the following should the auditor expect to find as the PRIMARY purpose of the audit charter?

Easy
110

An IS auditor is evaluating the reliability of evidence obtained from a system-generated exception report. The report is produced by a script written by a database administrator who has both the ability to modify the script and the production data. The auditor has obtained the report directly from the system. Which of the following is the MOST important factor affecting the auditor's reliance on this evidence?

Hard
111

Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?

Easy
112

During an audit, the IS auditor identifies that the audit team lacks the technical expertise to evaluate a specific system. According to ISACA standards, the auditor should:

Easy
113

An IS auditor has completed fieldwork for an audit of a data center's physical access controls and has documented several findings. Before drafting the final report, the auditor discusses the findings with the data center manager. Which of the following is the PRIMARY purpose of this discussion?

Easy
114

An IS auditor is conducting a follow-up review of a previously identified high-risk finding. Management has implemented a compensating control instead of the recommended control. Which of the following is the MOST appropriate action for the auditor to take?

Medium
115

An IS auditor is executing a compliance test of change management controls over a core banking application. The audit programme requires evidence that all production changes were approved before implementation. Which of the following techniques provides the MOST persuasive evidence for this test?

Medium
116

An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?

Medium
117

After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?

Medium
118

An IS auditor is assessing the sufficiency of audit evidence gathered for a conclusion about database access controls. Which TWO of the following characteristics must the evidence possess to be considered appropriate? (Choose two.)

Medium
119

An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?

Medium
120

An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?

Easy

Frequently asked questions

What does the Information System Auditing Process domain cover on the CISA exam?
Be able to plan a risk-based IS audit, choose and evaluate sufficient appropriate evidence, test controls, document workpapers, and write findings with clear criteria, cause, effect and recommendation. The single most important thing: base every conclusion on corroborated evidence, not management assertion.
How many questions are in this domain?
This page lists all 120 Information System Auditing Process questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information System Auditing Process questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cisa ISACA-CISA cisa audit process Practice Questions