Courseiva

CCNA Information System Auditing Process Questions

75 of 120 questions · Page 1/2 · Information System Auditing Process · Answers revealed

1
MCQeasy

An IS auditor is conducting a preliminary review of a newly acquired subsidiary and needs to understand the organizational structure, key business processes, and the technology environment before drafting the engagement plan. Which of the following techniques is MOST appropriate for gathering this broad understanding?

A.Testing the operating effectiveness of general IT controls
B.Conducting interviews with key personnel
C.Reviewing prior audit working papers
D.Performing a walk-through of selected transactions
AnswerB

Interviews with management and process owners efficiently capture organizational structure, business objectives, key processes, and the technology environment. ISACA guidance identifies interviews and discussions with auditees as a primary information-gathering technique during the preliminary phase, allowing the auditor to scope the engagement before committing to detailed testing.

Why this answer

During preliminary review the auditor's objective is broad understanding, not verification. Interviewing management and process owners quickly reveals structure, processes, and technology, and lets the auditor follow up with documentation review or observation where answers are unclear. Detailed techniques such as walk-throughs, control testing, or reliance on prior papers presuppose knowledge the auditor does not yet possess for a newly acquired subsidiary.

Exam trap

The trap here is assuming that reviewing prior audit working papers is always the most efficient planning technique, when for a new subsidiary no relevant history exists and interviews are the practical way to build initial understanding.

2
MCQhard

An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?

A.Ensuring the CAAT scripts are documented in the permanent audit file
B.Verifying the completeness and accuracy of the data extracted from the source system
C.Obtaining management's written approval to run queries against production data
D.Confirming that the CAAT software is licensed to the audit organization
AnswerB

CAAT results are only as reliable as the data analysed. The auditor must establish that the extract is complete and accurate, for example by reconciling record counts and control totals to the source system. Without this validation, duplicates or omissions in the extract could produce false conclusions about the transaction population.

Why this answer

Before relying on CAAT output, the auditor must be satisfied that the data analysed is complete and accurate, typically by reconciling extract record counts and control totals to the source system. Only then can duplicate-payment exceptions be attributed to the population rather than to extraction errors. Licensing, approvals, and documentation support the work but do not validate the data itself.

Exam trap

The trap here is focusing on the tool and its permissions while overlooking that the reliability of the analysis depends first on the integrity of the extracted data.

3
MCQhard

An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?

A.Ignore the issue because the policy is only a minor deviation.
B.Report the finding as a non-compliance issue and recommend updates to the policy.
C.Draft a new privacy policy for the organization.
D.Conclude that the organization is compliant because the policy exists.
AnswerB

Because the policy fails to meet regulatory requirements, the auditor must document this as a non-compliance finding and recommend remediation. Reporting and recommending updates satisfies the compliance audit objective, giving management a basis to align the policy with the applicable privacy regulations.

Why this answer

The auditor should report the non-compliance finding and recommend corrective actions, as the primary goal of a compliance audit is to identify gaps.

4
MCQeasy

An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?

A.It ensures that all controls are tested equally.
B.It reduces the overall cost of the audit.
C.It focuses audit efforts on areas with the highest risk.
D.It guarantees the detection of material misstatements.
AnswerC

Risk-based auditing directs scarce audit resources toward the areas of greatest exposure, so coverage and testing concentrate where the likelihood and impact of failure are highest. This satisfies the stem's demand for the primary benefit by aligning audit effort with the organisation's most significant risks rather than treating all infrastructure equally.

Why this answer

A risk-based approach allows the auditor to focus on areas with higher risk, thereby optimizing the use of audit resources and ensuring that significant risks are addressed.

5
Multi-Selecthard

An IS auditor is designing test procedures for an audit of an organization's network perimeter. The auditor plans to use computer-assisted audit techniques (CAATs) to analyze firewall log data covering six months. Which TWO of the following are the MOST important considerations when using CAATs in this engagement? (Choose two.)

Select 2 answers
A.The brand and model of the firewall appliance generating the logs
B.Security and confidentiality controls over the extracted log data and the CAAT environment
C.Whether the audit team has prior experience auditing firewall rules
D.Completeness and integrity of the firewall log data extracted for analysis
E.The cost of the CAAT software license compared to manual testing
AnswersB, D

Extracted firewall logs can reveal network topology, internal addressing, and traffic patterns, so the data and the environment where CAATs run must be protected. If analysis occurs on an unsecured workstation or copies of logs are left on shared drives, the audit itself creates a confidentiality and security exposure. Safeguarding the data throughout analysis and retention is therefore a key consideration.

Why this answer

When CAATs are used, the auditor must first establish that the data being analyzed is complete and accurate, because flawed input guarantees flawed conclusions about firewall activity over six months. Equally important, extracted logs and the analysis environment must be secured so the audit does not introduce confidentiality or integrity risks. Appliance brand, team experience, and license cost affect logistics but not the fundamental reliability or safety of the CAAT results.

Exam trap

The trap here is focusing on tool-related logistics such as appliance brand or license cost, while overlooking that CAAT results are only valid when the extracted data is complete, unaltered, and protected throughout the analysis.

6
MCQmedium

Which of the following is the BEST example of an analytical procedure used during an IS audit?

A.Observing the data center's physical security controls.
B.Reviewing a sample of change requests for proper authorization.
C.Comparing current period IT expenses to prior periods and investigating significant variances.
D.Interviewing the IT manager about change management procedures.
AnswerC

Comparing current IT expenses against prior periods and investigating variances is a substantive analytical procedure: it identifies anomalous fluctuations requiring explanation, providing audit evidence about account balances without detailed transaction testing. This satisfies the stem's requirement for an analytical procedure, unlike compliance testing or control walkthroughs, which examine process design rather than financial reasonableness.

Why this answer

Analytical procedures involve evaluating financial information by studying plausible relationships among data. Comparing current period expenses to prior periods is a typical example.

7
MCQeasy

According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?

A.To facilitate the planning of the next audit
B.To serve as a legal record for potential litigation
C.To provide a basis for the audit report and support the auditor's conclusions
D.To demonstrate compliance with audit standards
AnswerC

Working papers record the procedures performed, evidence obtained and conclusions reached, giving reviewers and regulators a basis to support the audit report. This evidentiary foundation is the primary purpose, not administrative convenience or staff appraisal.

Why this answer

Audit documentation supports the auditor's conclusions and provides evidence of the work performed. It is not primarily for future audit planning or legal protection.

8
MCQhard

An IS auditor is reviewing a network access control list and finds that a rule permits traffic from any source to a database server on port 1521. Management states the rule is required for a legacy application. Which of the following is the MOST appropriate audit response?

A.Remove the rule immediately to eliminate the exposure.
B.Accept the rule because management has provided a documented business justification.
C.Escalate the matter directly to the board of directors without further analysis.
D.Document the rule as a finding with a recommendation to restrict source addresses to the application servers.
AnswerD

The rule permits unrestricted access to a database listener, which is a significant exposure regardless of the legacy justification. The auditor should document the risk and recommend tightening the source range to only the application servers that require access. This preserves functionality while reducing the attack surface, and it is the response most aligned with the auditor's role of identifying and communicating risk.

Why this answer

The auditor should identify the exposure created by an unrestricted database access rule and communicate it with a practical recommendation. Restricting the source addresses maintains the legacy application's function while reducing risk. Auditors report and recommend; they do not implement changes or accept risks on management's behalf.

Escalation should follow the normal reporting process.

Exam trap

The trap here is treating a documented business justification as equivalent to an acceptable level of residual risk, when the auditor must still evaluate the exposure.

9
MCQeasy

An IS auditor is reviewing the audit committee's oversight of the IT audit function. Which of the following is the MOST important factor for the auditor to consider when assessing the committee's effectiveness?

A.The number of IT audit findings reported to the committee.
B.The committee's technical expertise in IT systems.
C.The frequency of audit committee meetings.
D.The committee's independence from management and its ability to challenge IT risk decisions.
AnswerD

The effectiveness of an audit committee in overseeing IT audit is fundamentally dependent on its independence from management and its willingness to challenge IT risk decisions. Independence ensures objective oversight, and the ability to challenge ensures that management's assertions are scrutinized. Without these, the committee cannot provide effective governance over IT risks and the audit function. This is a core principle in ISACA's governance guidance.

Why this answer

The most important factor in assessing the audit committee's effectiveness in overseeing IT audit is its independence from management and its ability to challenge IT risk decisions. Independence ensures that the committee can objectively evaluate management's actions and the auditor's findings. The ability to challenge ensures that management is held accountable and that risks are adequately addressed.

Other factors like meeting frequency, number of findings, or technical expertise are secondary to this core governance principle.

Exam trap

The trap here is equating effectiveness with activity metrics like meeting frequency or number of findings, rather than focusing on independence and the ability to challenge management.

10
MCQhard

An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?

A.Inquiry and inspection
B.Inspection and observation
C.Analytical procedures and inquiry
D.Observation and re-performance
AnswerD

Observation supplies evidence that the control operates as described, while re-performance independently reproduces the same result, testing operating effectiveness rather than design alone. Together they satisfy the stem's requirement to confirm the control's effectiveness through direct auditor execution, not merely inquiry or inspection of documentation.

Why this answer

The auditor observed the control being performed (observation) and then independently performed the same control to confirm the result (re-performance). This combination of observation and re-performance provides strong evidence of control effectiveness because the auditor both witnesses and independently verifies the control. Inquiry and inspection are not the primary techniques used here.

Exam trap

CISA often tests whether candidates can distinguish observation from inspection and re-performance from inquiry, causing them to pick a combination that does not match the described auditor actions.

How to eliminate wrong answers

Option A is wrong because inquiry (asking questions) and inspection (examining records) were not the techniques described — the auditor watched and then re-executed the control. Option B is wrong because inspection involves examining documents or records, not independently re-performing the control. Option C is wrong because analytical procedures involve comparing data patterns and inquiry involves asking questions, neither of which matches the described activities.

11
MCQeasy

Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?

A.External audit
B.Operational audit
C.IS audit
D.Internal audit
AnswerA

External audits are conducted by auditors independent of the organisation, satisfying the regulatory-compliance constraint in the stem. This independence from management gives the resulting opinion the objectivity that internal or self-assessment reviews cannot provide, which regulators require when mandating assurance over controls and financial reporting.

Why this answer

External audits are conducted by third-party auditors to provide independent assurance, often required by regulations or standards.

12
MCQeasy

During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?

A.To determine the audit budget
B.To obtain management approval
C.To select the audit team members
D.To identify high-risk areas for audit focus
AnswerD

Risk assessment during planning directs audit resources toward areas of greatest exposure, ensuring effort concentrates where misstatement or control failure is most likely. It satisfies the stem by establishing which areas warrant audit focus, thereby shaping objectives, scope and subsequent testing priorities before fieldwork begins.

Why this answer

A risk assessment identifies high-risk areas to prioritize audit efforts and allocate resources effectively.

13
MCQeasy

According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?

A.Planning
B.Reporting
C.Fieldwork
D.Follow-up
AnswerA

Planning is the phase in which the audit programme is developed, setting scope, objectives, timing and the procedures to be performed. This satisfies the stem's requirement because ISACA standards place programme design before fieldwork begins, ensuring evidence gathering is structured and aligned to the engagement objectives.

Why this answer

According to ISACA IT Audit Standards, the audit programme — the detailed plan of audit procedures to be performed — is developed during the Planning phase. Planning encompasses scoping, risk assessment, resource allocation, and designing the procedures that will be executed during fieldwork. Reporting, fieldwork, and follow-up occur after the programme has been established.

Exam trap

CISA often tests whether candidates place audit programme development in Fieldwork rather than Planning, confusing the design of procedures with their execution.

How to eliminate wrong answers

Option B is wrong because Reporting is the phase where findings and conclusions are communicated, which occurs after the audit work is performed. Option C is wrong because Fieldwork is the execution phase where the audit programme is carried out, not where it is developed. Option D is wrong because Follow-up verifies that management remediated findings, which happens after reporting.

14
Multi-Selectmedium

Which TWO of the following are components of audit risk in IS auditing?

Select 2 answers
A.Detection risk
B.Financial risk
C.Business risk
D.Inherent risk
E.Operational risk
AnswersA, D

Detection risk is a component of audit risk, representing the risk that audit procedures fail to detect a material misstatement. It combines with inherent and control risk, satisfying the stem's requirement to identify audit risk components in IS auditing.

Why this answer

In IS auditing, audit risk is modeled as the risk that the auditor gives an inappropriate opinion on financial statements that are materially misstated, and its standard components are inherent risk, control risk, and detection risk. Detection risk (A) is correct because it is the risk that the auditor's procedures fail to detect a material misstatement that exists, and it is the component the auditor can directly manage by adjusting the nature, timing, and extent of audit procedures. Inherent risk (D) is correct because it is the susceptibility of an assertion to a material misstatement before considering any related internal controls, arising from factors such as complex IT environments, high transaction volumes, or estimation uncertainty.

The other options do not belong: financial risk (B), business risk (C), and operational risk (E) are broader enterprise or management risk categories, not the defined components of the audit risk model used in IS auditing.

15
MCQeasy

A compliance audit is primarily concerned with:

A.Evaluating the effectiveness of internal controls
B.Assessing the efficiency of IT operations
C.Ensuring the organization is meeting its strategic objectives
D.Determining whether the organization is following applicable laws and regulations
AnswerD

Compliance audits measure adherence to externally imposed criteria such as laws, regulations and contractual obligations, testing whether the organisation's controls and practises conform to those mandatory requirements rather than assessing efficiency or financial statement fairness.

Why this answer

A compliance audit is primarily concerned with determining whether the organization is adhering to applicable laws, regulations, standards, and contractual obligations. It tests conformity against defined criteria rather than evaluating control effectiveness, operational efficiency, or strategic alignment. The other options describe operational, performance, or strategic audits.

Exam trap

CISA often tests whether candidates confuse compliance audits (adherence to laws/regulations) with operational audits (control effectiveness) or performance audits (efficiency), leading them to select a control-focused answer.

How to eliminate wrong answers

Option A is wrong because evaluating the effectiveness of internal controls is the focus of an operational or internal control audit, not a compliance audit. Option B is wrong because assessing the efficiency of IT operations is a performance/operational audit objective. Option C is wrong because ensuring the organization meets strategic objectives is the domain of strategic or management audits, not compliance audits.

16
MCQmedium

An IS auditor is conducting an audit of a payroll application and selects a statistical sample of 200 payment transactions from a population of 20,000. Testing reveals 12 transactions where the gross pay was calculated incorrectly due to a flawed overtime rule. Which of the following is the MOST appropriate interpretation of this result?

A.The sample size should be increased until the number of exceptions falls within acceptable limits
B.The error rate in the sample should be projected to the population and evaluated against the tolerable deviation rate
C.The audit conclusion should be unqualified because 188 of 200 transactions were processed correctly
D.The 12 identified transactions should be corrected and the sample re-tested to confirm the control is now effective
AnswerB

For a compliance or attribute sample, the auditor projects the observed deviation rate to the population and compares it with the tolerable deviation rate set during planning. Twelve deviations in 200 items is a 6 percent rate, which must be evaluated against the tolerable rate before concluding whether the control or processing rule operated effectively across the population.

Why this answer

When testing attributes or compliance, the auditor projects the sample deviation rate to the population and compares it with the tolerable deviation rate established during planning. The finding of 12 deviations in 200 items yields a 6 percent rate that must be evaluated against that threshold, along with sampling risk, before determining whether the control can be relied upon.

Exam trap

The trap here is treating the raw percentage of correctly processed transactions as the audit conclusion instead of comparing the projected deviation rate with the pre-established tolerable deviation rate.

17
MCQhard

During an audit of a data center, an IS auditor discovers that a critical server's operating system has not been patched for eight months because the vendor's patch conflicted with a legacy application. Management accepts the risk and documents a compensating control of enhanced network monitoring. Which of the following should the IS auditor do NEXT?

A.Remove the finding from the report because management formally accepted the risk
B.Recommend replacing the legacy application to eliminate the patching conflict
C.Evaluate the design and operating effectiveness of the compensating control before concluding
D.Report the finding as a high-risk issue and demand immediate patching
AnswerC

When management accepts a risk and relies on a compensating control, the auditor must assess whether that control actually reduces the risk to an acceptable level. Enhanced network monitoring may or may not detect exploitation of the unpatched server. Testing the compensating control's design and operation allows the auditor to form a supportable conclusion about residual risk rather than accepting the documentation at face value.

Why this answer

Because management chose to accept the risk and rely on a compensating control, the auditor's next step is to test whether that control genuinely mitigates the risk. Only after evaluating its design and operating effectiveness can the auditor judge residual risk and decide how to report the matter. Simply accepting the documentation, dictating remediation, or jumping to application replacement all bypass the required evaluation.

Exam trap

The trap here is assuming that documented management risk acceptance ends the auditor's work, when the auditor must still assess whether the compensating control actually reduces risk to an acceptable level.

18
MCQmedium

An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?

A.Inspection of training completion records
B.Observation of a training session
C.Inquiry with the HR manager
D.Analytical procedures comparing training completion rates
AnswerA

Training completion records are documentary evidence generated by the learning system, directly showing whether each employee finished the mandatory privacy training. Inspection lets the auditor verify completion against the requirement, rather than relying on interviews or observation, which only confirm awareness or intent.

Why this answer

Inspection of training completion records provides documentary evidence that employees have actually completed the mandatory privacy training. This is a direct, tangible form of evidence that can be verified and tested. It is the most reliable and appropriate evidence for compliance verification because it shows a record of completion, not just intent or hearsay.

Exam trap

CISA often tests the reliability hierarchy of audit evidence; candidates may incorrectly choose inquiry or observation because they seem quicker, but inspection of records is the most reliable for compliance verification.

How to eliminate wrong answers

Option B is wrong because observing a training session only confirms that training is being delivered, not that all employees have completed it. Option C is wrong because inquiry with the HR manager yields verbal evidence, which is the least reliable and should be corroborated. Option D is wrong because analytical procedures compare rates but do not verify individual completion; they may highlight anomalies but are not direct evidence of completion.

19
MCQhard

An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?

A.Control risk and detection risk only
B.Inherent risk and detection risk only
C.Inherent risk, control risk, and detection risk
D.Inherent risk and control risk only
AnswerC

The audit risk model comprises inherent risk, control risk and detection risk, and fraud assessment turns on the same three components: susceptibility of the account to fraud, effectiveness of controls, and the auditor's procedures. Combining them directly satisfies the stem's request for the most relevant combination.

Why this answer

The audit risk model comprises inherent risk, control risk, and detection risk. All three are directly relevant when assessing fraud risk because fraud can arise from inherent susceptibility, control failures, or the auditor's failure to detect it. The combination of all three determines the overall audit risk.

Exam trap

CISA often tests the audit risk model; candidates may incorrectly exclude detection risk, thinking it is only the auditor's responsibility, but it is an integral part of the model.

How to eliminate wrong answers

Option A is wrong because it omits inherent risk, which is critical in fraud assessment as some accounts are more susceptible to fraud. Option B is wrong because it omits control risk, which is essential to evaluate the effectiveness of controls in preventing or detecting fraud. Option D is wrong because it omits detection risk, which is the risk that audit procedures fail to detect a material misstatement, a key consideration in planning substantive tests.

20
MCQmedium

During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:

A.An observation
B.A deficiency
C.A finding
D.A material weakness
AnswerD

A deficiency whose possible effect is a material misstatement represents a material weakness, because the severity threshold is met by the potential material impact on the financial statements or related assertions. ISACA standards require this classification, distinguishing it from lesser significant deficiencies that do not reach materiality.

Why this answer

A material weakness is a deficiency or combination of deficiencies that results in a reasonable possibility that a material misstatement will not be prevented or detected.

21
MCQeasy

Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?

A.External auditors follow stricter standards
B.External auditors are not employees of the organization
C.External auditors have more industry knowledge
D.External auditors have more resources
AnswerB

External auditors have no employment relationship with the organisation, so they are not subject to management direction, internal promotion pressures or reporting lines that can compromise objectivity. This structural separation from the entity provides the primary basis for greater independence than internal audit.

Why this answer

External auditors are not employees, reducing organizational pressures and biases.

22
MCQeasy

According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?

A.Documentation must support the audit findings and conclusions.
B.Documentation must be retained for at least 10 years.
C.Documentation must be reviewed by the audit committee.
D.Documentation must be prepared in the local language of the auditee.
AnswerA

ISACA standards require audit documentation to substantiate the auditor's findings and conclusions, so working papers must evidence the procedures performed, the evidence obtained and the judgements made. This supports the stem's requirement by enabling an independent reviewer to reperform the work and reach the same conclusions.

Why this answer

According to ISACA IT Audit Standards, audit documentation must support the audit findings and conclusions. This is a fundamental requirement to ensure that the work performed is verifiable and that conclusions are based on sufficient evidence. It allows for review and re-performance.

Exam trap

CISA often tests specific ISACA standards; candidates may assume a fixed retention period like 10 years, but ISACA does not specify a number, leaving it to other requirements.

How to eliminate wrong answers

Option B is wrong because ISACA does not mandate a specific retention period of 10 years; retention is determined by legal, regulatory, and organizational requirements. Option C is wrong because review by the audit committee is not a standard requirement for all documentation; it may be reviewed by audit management. Option D is wrong because documentation language is not prescribed; it should be understandable to the intended users, typically in the language of the audit report.

23
MCQmedium

According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?

A.The availability of audit staff
B.The budget approved for the audit
C.The risk assessment of the area under review
D.The results of prior audit findings
AnswerC

The risk assessment of the area under review determines where audit effort is directed, so scope is set by the identified risk exposure rather than by convenience, prior-year scope or management preference. This satisfies the stem by making risk the governing consideration when defining what the audit covers.

Why this answer

The most important consideration when determining the scope of an IS audit is the risk assessment of the area under review. ISACA standards emphasize a risk-based approach, where audit resources are directed to areas with the highest risk. This ensures that the audit addresses the most significant threats to the organization.

Exam trap

CISA often tests the risk-based approach; candidates may choose prior audit findings or budget because they seem practical, but risk assessment is the cornerstone of audit scoping.

How to eliminate wrong answers

Option A is wrong because staff availability is a logistical constraint, not a primary driver of scope. Option B is wrong because budget is a constraint, not a determinant of what should be audited. Option D is wrong because prior audit findings are inputs to risk assessment but not the most important consideration; they inform but do not replace a current risk assessment.

24
Multi-Selectmedium

An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)

Select 2 answers
A.Performing a walkthrough of the control process.
B.Performing a penetration test on the application.
C.Sending a confirmation letter to the vendor.
D.Calculating the return on investment for the application.
E.Inspecting the control documentation and procedure manuals.
AnswersA, E

A walkthrough traces a transaction through the control process, confirming the control exists and is implemented as described. This directly tests design and implementation, satisfying the stem's requirement, by revealing whether the control operates as intended rather than merely being documented.

Why this answer

Option A (Performing a walkthrough of the control process) is correct because a walkthrough traces a transaction or process from start to finish, allowing the auditor to confirm that the control has been designed as described and is actually implemented in practice. Option E (Inspecting the control documentation and procedure manuals) is correct because examining documented policies, procedures, and control descriptions provides direct evidence of the control's design and whether it has been formally established and communicated. Together, walkthroughs and documentation inspection are standard procedures for testing design and implementation of controls.

Option B (penetration test) is a technical security assessment that tests exploitability of vulnerabilities, not the design and implementation of financial application controls. Option C (confirmation letter to the vendor) is a substantive test of balances or transactions, not a control design/implementation test. Option D (ROI calculation) is a business case or performance metric, not an audit procedure for evaluating control design and implementation.

25
MCQmedium

An IS auditor is planning an audit of a cloud service provider's controls over data backup and recovery. The auditor needs to obtain evidence about the provider's backup procedures and restoration testing. Which of the following is the MOST appropriate source of evidence?

A.The provider's marketing brochure describing its backup and recovery capabilities.
B.The provider's service level agreement (SLA) specifying recovery time objectives.
C.A verbal confirmation from the provider's account manager that backups are performed daily.
D.A service organization control (SOC) 2 Type II report obtained from the provider.
AnswerD

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls over a period, including backup and recovery controls. It is a reliable source of evidence because it is based on testing by a qualified third party. This report can give the auditor confidence in the provider's controls without direct access to the provider's environment.

Why this answer

When auditing a cloud service provider, the auditor often relies on independent third-party attestation reports. A SOC 2 Type II report provides an independent assessment of the design and operating effectiveness of controls, including backup and recovery, over a specified period. It is more reliable than marketing materials, contractual SLAs, or verbal assurances, which do not provide evidence of actual control performance.

Exam trap

The trap here is accepting an SLA or verbal assurance as evidence of control effectiveness, when these only represent commitments or claims rather than tested results.

26
MCQmedium

An IS auditor is preparing the audit report after completing fieldwork on an organization's backup and restoration process. Management disagrees with one of the findings and has provided additional evidence. Which of the following is the auditor's MOST appropriate course of action?

A.Include management's disagreement in the report but keep the finding unchanged
B.Evaluate the additional evidence and revise or retain the finding based on the results
C.Delete the finding to maintain a cooperative relationship with management
D.Escalate the dispute to the audit committee before evaluating the evidence
AnswerB

Auditors must remain objective and evidence-driven. When management provides new evidence, the auditor should assess its relevance and sufficiency, and if it demonstrates the finding is inaccurate or the risk is mitigated, revise the finding accordingly. If it does not, the finding stands, with management's position documented. This preserves both accuracy and auditor independence.

Why this answer

When management supplies additional evidence during report preparation, the auditor's duty is to evaluate it objectively and adjust the finding if warranted. The conclusion must follow the evidence, not the desire to avoid conflict or the assumption that the original finding is always right. Retaining a finding without evaluation or escalating prematurely both fail to demonstrate the objectivity expected of the auditor.

Exam trap

The trap here is believing the auditor must either defend the original finding or drop it to avoid conflict, when the correct behavior is to objectively evaluate management's new evidence and let it determine the outcome.

27
MCQmedium

Which of the following is the PRIMARY purpose of audit working papers?

A.To facilitate peer review of the audit
B.To serve as a legal record of the audit
C.To store historical data for future audits
D.To provide a basis for the audit report
AnswerD

Working papers document the evidence gathered, procedures performed and conclusions reached, forming the evidential foundation on which the auditor's opinion rests. This satisfies the primary purpose by supporting the audit report, rather than serving as a management record or operational tool.

Why this answer

Working papers document audit procedures, evidence, and conclusions to support the audit opinion.

28
MCQhard

An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:

A.Finding
B.Deficiency
C.Observation
D.Material weakness
AnswerD

A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement will not be prevented or detected timely. This classification matches the stem's identified risk of material misstatement.

Why this answer

A control deficiency that could result in a material misstatement in the financial statements should be classified as a material weakness. This is a significant deficiency, or combination of deficiencies, that results in a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.

Exam trap

CISA often tests the definitions of deficiency classifications; candidates may confuse 'deficiency' with 'material weakness', but the latter specifically implies a reasonable possibility of material misstatement.

How to eliminate wrong answers

Option A is wrong because 'finding' is a general term for any audit result, not a specific classification of deficiency severity. Option B is wrong because 'deficiency' is a broader term that includes less severe issues; a material weakness is a specific type of deficiency. Option C is wrong because 'observation' is a neutral term for something noted, not a classification of control deficiency severity.

29
MCQmedium

Which of the following is the best example of audit evidence obtained through re-performance?

A.Reviewing log files for unauthorized access attempts
B.Interviewing the system administrator about backup procedures
C.Observing employees as they process transactions
D.Recalculating the total of a control report to verify accuracy
AnswerD

Re-performance requires the auditor to independently execute the control or calculation and compare the result with the original. Recalculating a control report's total reproduces the entity's own procedure, yielding direct evidence of accuracy rather than relying on inspection or inquiry.

Why this answer

Re-performance involves the auditor independently executing the same procedure or control that was originally performed by the auditee. Recalculating the total of a control report to verify accuracy is a classic example of re-performance, as the auditor independently computes the total to confirm it matches the report.

Exam trap

CISA often tests evidence-gathering techniques; candidates may confuse re-performance with inspection or observation, but re-performance requires the auditor to actually execute the procedure.

How to eliminate wrong answers

Option A is wrong because reviewing log files is inspection of documents, not re-performance. Option B is wrong because interviewing is inquiry, a verbal evidence-gathering technique. Option C is wrong because observing employees is observation, which involves watching a process without executing it.

30
Multi-Selecthard

Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)

Select 3 answers
A.Fieldwork
B.Remediation
C.Reporting
D.Planning
E.Execution
AnswersA, C, D

Fieldwork is the ISACA audit phase where evidence is gathered, tests are performed and working papers are produced. It sits between planning and reporting, satisfying the requirement to name an actual phase of the audit process.

Why this answer

ISACA's audit process is commonly structured around three core phases: Planning (option D), Fieldwork (option A), and Reporting (option C). Planning (D) is correct because it is the initial phase where the audit scope, objectives, risk assessment, criteria, and resource requirements are defined before any testing begins. Fieldwork (A) is correct because it is the phase in which auditors gather evidence, perform tests of controls and substantive procedures, and document findings to support conclusions.

Reporting (C) is correct because it is the phase where the auditor communicates results, including findings, conclusions, and recommendations, to management and the audit committee. Remediation (B) is not a phase of the audit process itself but rather a post-audit management activity of correcting identified issues, and Execution (E) is not an ISACA-defined phase name — it is essentially synonymous with fieldwork and is not used as a distinct phase in ISACA's model.

Exam trap

CISA often tests the distinction between audit phases and post-audit activities — candidates mistakenly include remediation or execution as audit phases, confusing management follow-up with the audit process itself.

31
Multi-Selecthard

An IS auditor is evaluating the reliability of audit evidence obtained from an IT system. Which TWO of the following factors most directly affect the reliability of the evidence? (Choose two.)

Select 2 answers
A.The format in which the evidence is presented (e.g., paper vs. electronic).
B.The cost of obtaining the evidence.
C.The effectiveness of the controls over the evidence's completeness and accuracy.
D.The qualifications of the IS auditor performing the review.
E.The independence of the provider of the evidence.
AnswersC, E

The effectiveness of controls over the completeness and accuracy of the evidence directly impacts its reliability. If the system that generates the evidence lacks proper controls, the evidence may be incomplete or inaccurate. The auditor must assess whether the controls ensure the data is reliable. This is a core consideration in IS auditing, as evidence from systems with strong controls is more trustworthy.

Why this answer

The reliability of audit evidence is directly influenced by the independence of the evidence provider and the effectiveness of controls over its completeness and accuracy. Independent sources are less likely to be biased, and strong controls ensure the evidence is accurate and complete. Auditor qualifications, cost, and format do not directly affect the inherent reliability of the evidence, although they may influence the auditor's evaluation or selection of evidence.

Exam trap

The trap here is confusing factors that affect the audit process (like auditor qualifications or cost) with factors that directly affect the reliability of the evidence itself.

32
MCQmedium

Which of the following is a permanent file item in an IS audit working paper?

A.Confirmation letters from vendors
B.Current year's audit program
C.Organizational chart of the IT department
D.List of audit findings for the current year
AnswerC

Permanent files hold enduring reference material relevant across multiple audits, such as organisational charts, policies and system inventories. An IT department organisational chart retains ongoing relevance to governance and segregation-of-duties assessments, unlike current-year working papers that are superseded each engagement.

Why this answer

The organizational chart of the IT department is a permanent file item because it documents the entity's structure and is retained across multiple audit engagements. Permanent files contain information of continuing relevance, such as organizational charts, accounting manuals, and long-term contracts. Current year's audit program and findings are current file items, and confirmation letters are also current file evidence.

Exam trap

CISA often tests the distinction between permanent and current audit files, and candidates frequently misclassify engagement-specific evidence like audit programs or findings as permanent.

How to eliminate wrong answers

Option A is wrong because vendor confirmation letters are audit evidence gathered for the current engagement and belong in the current file. Option B is wrong because the current year's audit program is specific to the engagement and is a current file item. Option D is wrong because the list of audit findings for the current year is engagement-specific and belongs in the current file.

33
MCQmedium

An IS auditor is leading an audit engagement and discovers that a key member of the audit team lacks the technical expertise to evaluate a newly implemented cloud encryption control. The audit manager insists the team member proceed anyway to save time. According to ISACA IT Audit Standards, what is the MOST appropriate action for the IS auditor to take?

A.Proceed with the audit as planned and note the limitation in the audit report.
B.Delegate the entire engagement to the audit manager who has more experience.
C.Expand the audit scope to include additional systems to compensate for the knowledge gap.
D.Obtain the necessary expertise through additional training or by engaging a qualified specialist.
AnswerD

ISACA IT Audit Standards require that auditors possess or obtain the competencies necessary to perform the engagement. When a team member lacks the technical skill to evaluate a control, the auditor should either ensure appropriate training or bring in a qualified specialist. This preserves the integrity of the audit opinion and complies with the standards' competence requirement, rather than accepting an inherent limitation.

Why this answer

ISACA IT Audit Standards require that the audit team collectively possess the competencies needed for the engagement. When a specific technical skill is missing, the auditor should acquire it through training or engage a qualified specialist. This preserves the validity of the audit opinion and satisfies professional standards.

Proceeding with known incompetence, reassigning the entire engagement, or expanding scope does not remedy the underlying proficiency deficiency.

Exam trap

The trap here is assuming that documenting a competence limitation in the report excuses the auditor from the standard's requirement to obtain the necessary expertise.

34
MCQeasy

Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?

A.Inspection
B.Observation
C.Inquiry
D.Re-performance
AnswerD

Re-performance involves the auditor independently executing the control procedure or calculation and comparing the result with the organisation's own performance. This directly satisfies the stem's constraint of independently verifying effectiveness, unlike inspection or observation, which only confirm that a control exists or was performed.

Why this answer

Re-performance involves the auditor independently executing a control procedure or recalculation to verify its effectiveness. This provides direct evidence of the control's operation. Inspection, observation, and inquiry are less direct forms of evidence.

Exam trap

CISA often tests the reliability of different evidence-gathering techniques, and candidates may confuse re-performance with observation or inspection, overlooking that re-performance provides the strongest evidence of control operation.

How to eliminate wrong answers

Option A is wrong because inspection involves examining records or documents, which provides indirect evidence of control effectiveness. Option B is wrong because observation involves watching a process being performed, but it only provides evidence at the time of observation and may be affected by the observer effect. Option C is wrong because inquiry involves asking questions, which yields verbal evidence that is generally less reliable and must be corroborated.

35
MCQmedium

An IS auditor is planning an audit of a cloud-hosted application and needs to determine whether the cloud provider's controls are adequate. The provider offers a SOC 2 Type II report. Which of the following should the auditor do FIRST?

A.Request a bridge letter to cover the gap between the report period and the current date.
B.Accept the SOC 2 Type II report as sufficient evidence without further review.
C.Review the report's scope, period, and the service auditor's opinion to determine its relevance to the audit objectives.
D.Perform independent penetration testing of the cloud provider's environment.
AnswerC

Before relying on a SOC 2 report, the auditor must confirm that its scope covers the relevant trust services criteria and systems, that the period aligns with the audit period, and that the opinion is unqualified or appropriately qualified. Only then can the auditor assess whether the report provides sufficient evidence. Using the report without this evaluation could lead to inappropriate reliance.

Why this answer

The auditor should first evaluate whether the SOC 2 Type II report is relevant and reliable by examining its scope, period, and opinion. This determines whether the report can be used as evidence or whether additional procedures are needed. Bridge letters and independent testing are secondary considerations.

Uncritical acceptance is not acceptable under audit standards.

Exam trap

The trap here is treating the mere existence of a SOC 2 report as sufficient evidence without evaluating its scope, period, and opinion.

36
MCQeasy

An IS auditor is reviewing the audit committee's oversight of the IT audit function. The auditor notes that the audit committee approves the annual IT audit plan but does not receive regular updates on the status of management's remediation of audit findings. Which of the following is the MOST significant risk arising from this situation?

A.Management may fail to address significant control weaknesses in a timely manner.
B.The auditor may not be able to perform follow-up activities on previous audit findings.
C.The IT audit function may not have sufficient resources to complete the audit plan.
D.The IT audit plan may not align with the organization's strategic objectives.
AnswerA

Without regular updates on remediation status, the audit committee cannot hold management accountable for resolving audit findings. This increases the likelihood that significant control weaknesses remain unaddressed, exposing the organization to unresolved risks. The audit committee's oversight role is critical to ensuring that management takes corrective action, so this is the most direct and significant risk.

Why this answer

The audit committee's oversight role includes monitoring management's progress in addressing audit findings. Without regular remediation updates, the committee cannot ensure that significant control weaknesses are corrected promptly. This creates a governance gap where unresolved risks persist, making the failure to remediate timely the most significant consequence of the described situation.

Exam trap

The trap here is assuming that the audit committee's approval of the audit plan is sufficient oversight, overlooking the need for ongoing monitoring of remediation activities.

37
MCQhard

An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?

A.The geographical location of each business unit.
B.The results of a risk assessment evaluating inherent risk and control effectiveness.
C.The budget allocated to each business unit for IT.
D.The number of employees in each business unit.
AnswerB

In a decentralised organisation, coverage should be prioritised by a risk assessment weighing inherent risk against control effectiveness across business units. This directs limited audit resources to the units with the greatest residual exposure, satisfying the stem's requirement for the most appropriate prioritisation factor.

Why this answer

A risk-based audit approach prioritizes coverage based on the likelihood and impact of risk, which is precisely what a risk assessment evaluating inherent risk and control effectiveness produces. Inherent risk reflects the susceptibility of a process or unit to error or fraud before controls, while control effectiveness indicates how much of that risk is mitigated. Combining these two factors lets the auditor direct limited audit resources to the areas of greatest residual risk, which is the defining principle of risk-based auditing.

Exam trap

CISA often tests the distinction between risk-based prioritization and convenience-based prioritization (location, budget, headcount), tempting candidates to pick a tangible, easily measured factor over the correct risk assessment output.

How to eliminate wrong answers

Option A is wrong because geographical location is at best a secondary scoping consideration and does not by itself indicate the level of risk to the organization. Option C is wrong because IT budget size reflects spending, not risk exposure — a well-funded unit can still carry high inherent risk. Option D is wrong because headcount is a size metric, not a risk metric, and larger units are not automatically riskier than smaller ones.

38
Multi-Selecthard

An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)

Select 3 answers
A.Complexity of the cloud architecture
B.Effectiveness of monitoring controls
C.Strength of access controls
D.Sensitivity of data stored in the cloud
E.Recent changes to the cloud environment
AnswersA, D, E

Complexity of the cloud architecture directly elevates inherent risk, since intricate multi-tenant, hybrid or interconnected designs enlarge the attack surface and obscure control gaps before any mitigation exists. It satisfies the stem's inherent-risk constraint by capturing design-driven uncertainty the auditor must weigh independently of implemented controls.

Why this answer

Inherent risk is assessed before considering controls, so the auditor should focus on factors that increase risk exposure independent of mitigation. Option A (Complexity of the cloud architecture) is correct because multi-tenant, virtualized, and distributed architectures increase the likelihood of misconfigurations, service dependencies, and attack surface, raising inherent risk. Option D (Sensitivity of data stored in the cloud) is correct because the classification and regulatory obligations of the data (e.g., PII, PCI DSS, PHI) directly determine the impact if confidentiality, integrity, or availability is compromised.

Option E (Recent changes to the cloud environment) is correct because changes such as new deployments, migrations, or configuration updates introduce instability and unverified states that elevate inherent risk. Options B (Effectiveness of monitoring controls) and C (Strength of access controls) are not inherent risk factors; they are control effectiveness considerations evaluated during the control risk assessment, after inherent risk has been determined.

Exam trap

CISA often tests the inherent-versus-control risk boundary, tempting candidates to select control-related options (monitoring, access controls) as inherent-risk factors because they sound risk-relevant.

39
MCQmedium

An IS auditor is planning an engagement and needs to obtain an understanding of the organization's IT environment to develop the audit programme. Which of the following techniques is MOST appropriate for this purpose?

A.Interviews with key IT personnel and review of system documentation.
B.Penetration testing of the organization's external network perimeter.
C.Substantive testing of transaction details in the general ledger.
D.Statistical sampling of user access records to project error rates.
AnswerA

Interviews and documentation review are core planning techniques used to understand the IT environment, including infrastructure, applications, and control processes. They help the auditor identify risks and design an appropriate audit programme. ISACA standards emphasize obtaining sufficient knowledge of the area under review during planning, and these techniques efficiently provide that understanding before fieldwork begins.

Why this answer

During planning, the auditor must obtain sufficient knowledge of the area under review to identify risks and design the audit programme. Interviews with IT personnel and review of system documentation are efficient, appropriate techniques for building that understanding. Substantive testing, statistical sampling, and penetration testing are fieldwork or specialized procedures that occur after planning has established the scope and objectives.

Exam trap

The trap here is selecting a technical testing technique such as penetration testing or sampling when the planning phase requires broad understanding rather than detailed testing.

40
Multi-Selectmedium

An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)

Select 2 answers
A.Complexity of transactions
B.Volume of transactions
C.Auditor's experience with similar systems
D.Results of prior audits
E.Effectiveness of internal controls
AnswersA, B

Complexity of transactions is a direct indicator of inherent risk because intricate processes and calculations are inherently more susceptible to errors or misstatements, even before considering internal controls. For a financial system, highly complex transactions, such as those involving derivatives or multi-currency conversions, present a greater predisposition to material misstatement. An IS auditor must recognise this increased susceptibility when assessing the risk profile of the system.

Why this answer

Inherent risk is the risk that exists before considering internal controls, so the auditor should focus on factors intrinsic to the system and its transactions. Option A, complexity of transactions, is correct because highly complex transactions increase the likelihood of errors, misstatements, or fraud going undetected, raising inherent risk. Option B, volume of transactions, is correct because a high volume of transactions increases the chance of errors and makes manual verification harder, which elevates inherent risk.

Option C, auditor's experience with similar systems, is not an inherent risk factor; it affects the auditor's competence and detection risk, not the risk inherent in the system. Option D, results of prior audits, is not an inherent risk factor; it is evidence used to assess control risk and plan the audit, but it does not define inherent risk. Option E, effectiveness of internal controls, is not an inherent risk factor because inherent risk is assessed before considering controls; control effectiveness relates to control risk.

Exam trap

CISA often tests the inherent-versus-control risk distinction, tempting candidates to select control effectiveness or prior audit results as inherent-risk factors because they are commonly used in audit planning.

41
Multi-Selecthard

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Select 3 answers
A.Measurable
B.General
C.Time-bound
D.Specific
E.Subjective
AnswersA, C, D

Measurable makes the recommendation verifiable: it specifies a quantifiable metric or threshold so the auditee and auditor can objectively confirm whether the action was implemented and effective, satisfying the SMART criterion that otherwise leaves recommendations unverifiable.

Why this answer

A SMART recommendation must be Measurable (A), meaning it includes quantifiable criteria or metrics (e.g., a percentage, count, or threshold) so progress and success can be objectively verified. It must also be Time-bound (C), specifying a deadline or timeframe (e.g., "within 90 days") so the recommendation has a defined completion point. Finally, it must be Specific (D), clearly stating the exact action, system, or process to be changed rather than a vague aspiration.

The unmarked options do not belong: General (B) contradicts the specificity requirement of SMART, and Subjective (E) is wrong because SMART criteria rely on objective, verifiable evidence rather than personal opinion.

42
MCQmedium

An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?

A.Prior audit findings
B.Industry best practices
C.The specific requirements of the regulation
D.The organization's internal policies
AnswerC

The regulation's own text supplies the authoritative criteria against which compliance is measured, since the audit tests conformity with those mandated requirements rather than internal policy or generic frameworks. It directly satisfies the stem's demand for the primary source of audit criteria in a regulatory compliance audit.

Why this answer

In a compliance audit, the audit criteria are the standards, laws, regulations, or contractual requirements against which the auditor measures the organization's controls and practices. When auditing against a data privacy regulation, the specific requirements of that regulation are the authoritative source of criteria — they define what compliance actually means. Internal policies and best practices may be relevant context, but they cannot override or substitute for the regulatory requirements themselves.

Exam trap

CISA often tests the distinction between audit criteria and audit evidence — candidates incorrectly select internal policies or best practices because they sound authoritative, but the regulation itself is always the primary criteria for a regulatory compliance audit.

How to eliminate wrong answers

Option A is wrong because prior audit findings are historical observations about past gaps; they inform follow-up but do not establish the criteria for the current compliance audit. Option B is wrong because industry best practices are advisory and not legally binding — they may exceed or fall short of regulatory requirements and cannot serve as the primary benchmark for regulatory compliance. Option D is wrong because the organization's internal policies are what is being audited, not the criteria — if internal policies are weaker than the regulation, the regulation still governs.

43
Multi-Selectmedium

Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)

Select 2 answers
A.Defining audit scope
B.Testing controls
C.Developing the audit program
D.Issuing the draft report
E.Performing walkthroughs
AnswersB, E

Testing controls occurs during fieldwork, where the auditor executes procedures such as inspection, inquiry, observation and re-performance to gather evidence supporting the preliminary control effectiveness conclusions formed during planning, directly satisfying the stem's fieldwork requirement.

Why this answer

Option B (Testing controls) is correct because the fieldwork phase is where the auditor executes the audit program by gathering evidence and evaluating whether controls are designed and operating effectively, which is the core of substantive and compliance testing. Option E (Performing walkthroughs) is correct because walkthroughs are an evidence-gathering technique performed during fieldwork to trace transactions or processes through the system and confirm the auditor's understanding of controls in operation. Option A (Defining audit scope) is incorrect because scope definition occurs during the planning phase, before fieldwork begins.

Option C (Developing the audit program) is incorrect because the audit program is designed in the planning phase to guide the subsequent fieldwork. Option D (Issuing the draft report) is incorrect because reporting occurs after fieldwork is completed, during the reporting phase.

44
Multi-Selecthard

An IS auditor is reviewing an organization's incident management process after a ransomware attack encrypted several file servers. Which TWO of the following should the auditor verify as part of assessing the effectiveness of the incident response? (Choose two.)

Select 2 answers
A.Whether the organization's antivirus signatures were updated on the same day as the attack
B.Whether the ransom demand was paid and whether the payment was properly authorized
C.Whether the organization's cyber insurance policy premium was paid before the incident occurred
D.Whether backups were isolated from the production network and restoration was successfully tested
E.Whether the incident was detected, contained, and communicated in accordance with the response plan
AnswersD, E

Ransomware commonly spreads to connected backup systems, so isolating backups from production and verifying that restoration actually works are essential controls. An untested or network-accessible backup may be encrypted along with production data. Confirming both isolation and successful restoration directly demonstrates whether the organization can recover without paying a ransom.

Why this answer

Assessing incident response effectiveness requires evidence that the organization could detect and contain the attack, communicate appropriately, and recover its data. Backup isolation and tested restoration, along with adherence to the response plan for detection, containment, and communication, directly demonstrate those capabilities. The other items address preventive metrics or financial matters that do not measure response performance.

Exam trap

The trap here is selecting financial or single-point preventive indicators, such as ransom payment or antivirus signature dates, instead of the operational capabilities that determine whether the incident was actually contained and recovered.

45
MCQhard

An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?

A.The population error rate is exactly 2.5%
B.The population has a material weakness
C.The population error rate is 5%
D.The population error rate is likely between 1% and 4% at a given confidence level
AnswerD

Five errors in 200 gives a 2.5% sample rate, and statistical projection applies a confidence interval around it. The range 1% to 4% reflects that sampling uncertainty, whereas a single point estimate would overstate precision.

Why this answer

Statistical sampling produces an estimate with a confidence interval, not a point value, so the correct conclusion is that the true population error rate likely falls within a range around the observed 2.5% (5/200). The option stating a range of 1% to 4% at a given confidence level correctly reflects that sampling results are probabilistic. The other options assert exact rates or draw conclusions about materiality that the sample alone cannot support.

Exam trap

CISA often tests the misconception that a sample error rate equals the population error rate, tempting candidates to pick the exact 2.5% figure instead of a confidence interval.

How to eliminate wrong answers

Option A is wrong because it treats the sample rate of 2.5% as the exact population rate, ignoring sampling risk and the confidence interval. Option B is wrong because materiality is a judgment based on the auditor's threshold and the nature of the errors, not something a sample of 200 can declare on its own. Option C is wrong because 5% is not the observed rate — 5 errors in 200 is 2.5%, so this option misstates the arithmetic and the concept.

46
Multi-Selectmedium

An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)

Select 2 answers
A.Re-performance of access provisioning using a test account
B.Inspection of access violation audit logs
C.Inquiry of the security administrator
D.Inspection of user access review documentation
E.Observation of access request processing
AnswersA, B

Re-performance of access provisioning using a test account lets the auditor independently execute the control and observe actual system behaviour, producing direct evidence. This satisfies the stem's requirement for the strongest evidence of access control effectiveness.

Why this answer

Re-performance of access provisioning using a test account (A) is correct because the auditor independently executes the provisioning process and directly verifies whether the system enforces the intended access rules, yielding first-hand evidence that is stronger than documentation or interviews. Inspection of access violation audit logs (B) is correct because these logs are system-generated records that reveal actual attempts to exceed authorized access and whether the controls detected and responded to them, providing objective evidence of control operation. Inquiry of the security administrator (C) is not sufficient because it relies on management's assertions rather than independent verification.

Inspection of user access review documentation (D) shows that reviews were documented but does not confirm the underlying access rights are actually correct or enforced. Observation of access request processing (E) only reflects the process at the moment observed and may not represent normal or complete control operation.

Exam trap

CISA often tests the evidence reliability hierarchy, tempting candidates to select inquiry or observation because they are easy to perform, when the exam expects the strongest (re-performance and system-generated logs).

47
MCQmedium

During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?

A.The department has a material weakness in controls
B.The department is efficient but may not be effective
C.The department is operating effectively based on uptime
D.The department should be outsourced
AnswerB

Uptime measures how well resources were used to keep systems running, indicating efficiency, while missed deadlines show the department failed to achieve its objectives, indicating ineffectiveness. Efficiency and effectiveness are distinct axes, so the department can be efficient yet ineffective.

Why this answer

Efficiency is about doing things right (resource utilization, uptime, throughput), while effectiveness is about doing the right things (achieving objectives such as project deadlines). The department kept systems running (efficient) but missed critical deadlines (not effective), so the correct conclusion is that it is efficient but may not be effective. This distinction is central to ISACA's performance management concepts.

Exam trap

CISA often tests the efficiency-versus-effectiveness distinction, tempting candidates to equate high uptime with overall effectiveness when the question deliberately includes missed objectives.

How to eliminate wrong answers

Option A is wrong because missing deadlines does not by itself establish a material weakness in controls — it is a performance outcome, not a control deficiency finding. Option C is wrong because uptime alone is an efficiency metric and does not demonstrate effectiveness against the department's objectives. Option D is wrong because outsourcing is a remediation decision that cannot be justified by the facts presented and is not an audit conclusion.

48
MCQhard

An IS auditor is assessing the risk of material misstatement in a highly automated transaction processing environment. The auditor notes that the system automatically calculates interest and posts it to customer accounts. Which of the following audit approaches would BEST address the risk of incorrect interest calculations?

A.Increase the sample size for substantive testing to achieve a higher confidence level.
B.Rely on the IT department's quality assurance testing of the interest calculation module.
C.Review and test the application's interest calculation logic and related change controls.
D.Perform substantive testing of a sample of interest calculations using an independent tool.
AnswerC

In a highly automated environment, the primary risk is that the programmed logic is incorrect or has been improperly changed. Testing the calculation logic and the change management controls provides assurance that the automated calculations are correct and remain so. This approach addresses the root cause and is more efficient than substantive testing of individual transactions, as it evaluates the system's inherent processing controls.

Why this answer

In a highly automated transaction processing environment, the most effective audit approach to address the risk of incorrect interest calculations is to review and test the application's calculation logic and the related change controls. This provides assurance that the automated calculations are correct and that any changes are properly authorized, tested, and implemented. Substantive testing alone may not detect systematic errors and is less efficient.

Relying on IT's QA lacks independence. Increasing sample size does not address root cause.

Exam trap

The trap here is defaulting to substantive testing of transactions when the risk is embedded in automated logic, where testing the program logic and change controls is more effective.

49
MCQmedium

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?

A.Exclude the ERP system from the audit scope because it is new and not yet stable
B.Include a review of the ERP system in the audit scope due to the high inherent risk
C.Delay the audit until the ERP system has been fully stabilized for six months
D.Focus only on financial reporting controls related to the ERP system
AnswerB

A newly implemented ERP system carries high inherent risk because of untested configuration, data migration and access provisioning. Including it in the audit scope ensures the auditor evaluates these risks during planning, directing resources toward the area most likely to contain material weaknesses.

Why this answer

A newly implemented ERP system represents high inherent risk due to its complexity, cost, and impact on financial reporting and operations, so the auditor should include it in the audit scope. Prioritizing the ERP review ensures that risks introduced by the new system — such as data migration errors, access control gaps, and process changes — are assessed early. Excluding or delaying the audit would leave significant risk unaddressed.

Exam trap

CISA often tests the misconception that new systems should be excluded or delayed from audit until 'stable' — candidates forget that high inherent risk demands earlier, not later, audit attention.

How to eliminate wrong answers

Option A is wrong because excluding a new ERP system from the audit scope ignores the elevated risk it introduces; new systems are precisely when controls are most likely to be misconfigured. Option C is wrong because delaying the audit for six months allows risks to persist unchecked and may violate audit timelines or regulatory requirements; audits should be timely. Option D is wrong because focusing only on financial reporting controls is too narrow — a new ERP affects operational, compliance, and IT general controls, all of which warrant review.

50
MCQeasy

An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?

A.Obtaining a representation letter from the internal audit director confirming all findings were reported
B.Evaluating the competence, objectivity, and quality of the internal auditors' work
C.Confirming that the internal audit function uses the same audit software tools as the IS auditor
D.Verifying that the internal audit function reports administratively to the audit committee of the board
AnswerB

ISACA standards require the external auditor to assess the internal audit function's competence and objectivity and to evaluate the quality of its work before relying on it. A favorable assessment allows the auditor to reduce direct testing, but the reliance decision must be documented and supported by evidence gathered about the internal function itself.

Why this answer

Before relying on the work of internal audit, the IS auditor must determine that the function is competent and objective and that its work is of adequate quality. This evaluation supports a decision to reduce, but not eliminate, the auditor's own procedures. The other listed activities do not establish the professional reliability of the internal audit work being considered.

Exam trap

The trap here is assuming that a favorable structural fact, such as a direct reporting line or a shared audit tool, is by itself sufficient to justify reliance on internal audit work.

51
MCQeasy

Which of the following audit types is MOST likely to be performed by an organization's own employees?

A.External audit
B.IS audit
C.Internal audit
D.Compliance audit
AnswerC

Internal audit is performed by the organisation's own employees, who report to management or the audit committee. This contrasts with external audit, delivered by independent third parties, directly satisfying the stem's requirement for work conducted by staff within the organisation.

Why this answer

An internal audit is performed by an organization's own employees, typically as part of an internal audit department, to evaluate the effectiveness of internal controls, risk management, and governance processes. This is distinct from external audits, which are conducted by independent third parties.

Exam trap

CISA often tests the distinction between internal and external audits; candidates may confuse 'IS audit' with 'internal audit' because IS audits are frequently performed internally, but the key is who performs the audit, not the subject matter.

How to eliminate wrong answers

Option A is wrong because an external audit is performed by an independent external auditor, not by the organization's own employees. Option B is wrong because an IS audit (information systems audit) can be internal or external; the term itself does not specify who performs it, and it is not necessarily limited to employees. Option D is wrong because a compliance audit can be internal or external, and it focuses on adherence to regulations or standards, not on the performer.

52
MCQmedium

An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:

A.Judgmental sampling
B.Random sampling
C.Systematic sampling
D.Stratified sampling
AnswerC

Systematic sampling selects items at fixed intervals from a population list, here every 50th purchase order. This satisfies the auditor's need for an efficient, unbiased selection method that spreads the sample evenly across the entire sequence, provided the list has no cyclical pattern aligning with the interval.

Why this answer

Systematic sampling involves selecting every nth item from a sequentially ordered population, such as every 50th purchase order. This method is a statistical sampling technique that provides a random-like selection if the starting point is random and the population is not patterned. The scenario explicitly describes selecting every 50th item, which is the definition of systematic sampling.

Exam trap

CISA often tests the distinction between systematic and random sampling — candidates see 'every 50th' and think it's random, but the fixed interval is the defining characteristic of systematic sampling.

How to eliminate wrong answers

Option A is wrong because judgmental sampling relies on the auditor's discretion to pick items, not a fixed interval. Option B is wrong because random sampling uses random number generators or tables to select items, with no fixed interval. Option D is wrong because stratified sampling divides the population into subgroups (strata) and samples from each, which is not described here.

53
Multi-Selectmedium

Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)

Select 2 answers
A.Ratio analysis
B.Observation
C.Re-performance
D.Trend analysis
E.Inquiry
AnswersA, D

Ratio analysis is an analytical procedure that compares financial or operational relationships, such as current assets to current liabilities, to identify unusual variances or trends. It is one of the recognised techniques IS auditors apply when performing substantive and preliminary analytical review.

Why this answer

Ratio analysis (A) is a correct type of analytical procedure because it compares financial or operational relationships—such as the current ratio or inventory turnover—to identify unusual variances or anomalies that may signal control weaknesses or misstatements during an IS audit. Trend analysis (D) is also correct because it examines data across multiple periods to detect patterns, directional changes, or outliers, such as a rising rate of failed login attempts or increasing transaction error rates, which helps auditors assess risk and system performance. Observation (B), re-performance (C), and inquiry (E) are not analytical procedures; they are substantive audit techniques or evidence-gathering methods—observation involves watching processes, re-performance involves independently executing controls or calculations, and inquiry involves asking personnel questions—none of which rely on the analytical comparison of financial or operational data relationships.

Exam trap

CISA often tests whether candidates can distinguish evidence-gathering techniques (inquiry, observation, re-performance) from analytical procedures (ratio, trend, regression, reasonableness).

54
Multi-Selectmedium

An IS auditor is assessing the effectiveness of the change management process for a critical financial application. The auditor wants to determine whether changes are adequately tested before being deployed to production. Which TWO of the following procedures would provide the MOST relevant evidence? (Choose two.)

Select 2 answers
A.Review the change management policy to verify that it requires user acceptance testing prior to production deployment.
B.Observe a developer performing unit testing in the development environment.
C.Re-perform the testing for a sample of changes by executing the test scripts in a test environment and comparing results.
D.Select a sample of recent production changes and inspect the associated test plans, test results, and approvals.
E.Interview the change manager to understand the testing process and any recent challenges.
AnswersC, D

Re-performing testing for a sample of changes allows the auditor to independently verify whether the tests produce the expected results and whether the changes function as intended. This provides strong, direct evidence of the effectiveness of testing. It is especially useful when documentation alone is insufficient or when the auditor needs to confirm the accuracy of reported test results.

Why this answer

To determine whether changes are adequately tested before production deployment, the auditor needs evidence of actual testing activities. Inspecting test documentation for a sample of changes confirms that testing occurred and was approved. Re-performing tests independently verifies the reliability of those tests.

Together, these procedures provide direct evidence of operating effectiveness, whereas policy review, interviews, and observation of development testing are less conclusive.

Exam trap

The trap here is selecting policy review or interviews, which test the design of the process rather than its operating effectiveness for specific changes.

55
Multi-Selectmedium

An IS auditor is evaluating the reliability of audit evidence obtained during a review of an outsourced payroll provider. Which TWO of the following considerations most directly affect the reliability of that evidence? (Choose two.)

Select 2 answers
A.Whether the vendor's management has verbally confirmed the accuracy of the evidence.
B.Whether the evidence is stored in the auditor's working paper repository.
C.Whether the evidence was collected within the current audit period.
D.Whether the evidence is supported by an independent third-party assurance report, such as a SOC 2 report.
E.Whether the evidence was obtained directly by the auditor rather than provided by the vendor.
AnswersD, E

An independent assurance report provides corroboration from a qualified party and increases the reliability of the evidence about the vendor's controls. It reduces reliance on management representations alone. The auditor should still evaluate the report's scope, period, and the service auditor's competence, but the independent attestation materially strengthens the evidence's credibility.

Why this answer

Reliability of evidence is driven primarily by the independence of the source and the auditor's direct involvement in obtaining it. Evidence obtained directly by the auditor and evidence corroborated by an independent assurance report are the strongest here. Verbal representations and storage location do not enhance reliability, and timeliness speaks to relevance more than reliability.

Exam trap

The trap here is conflating relevance attributes such as timeliness with reliability, and treating management representations as if they were independent evidence.

56
Multi-Selecthard

An IS auditor is designing substantive test procedures for a newly implemented automated accounts payable system and wants to rely less on the client's automated controls. The auditor decides to use computer-assisted audit techniques to test the completeness and accuracy of transaction processing. Which TWO of the following techniques would BEST provide direct evidence about the population of transactions? (Choose two.)

Select 2 answers
A.Reviewing the change management log for modifications to the accounts payable application
B.Integrated test facility that posts simulated transactions alongside live processing
C.Generalized audit software to extract and analyze the full accounts payable transaction file
D.Parallel simulation that reprocesses live transactions using auditor-controlled logic
E.Test data submitted through the production system to observe how the application processes it
AnswersC, D

Generalized audit software can read the client's data files directly and perform calculations, comparisons, and summarizations across the entire transaction population. This gives the auditor direct, independent evidence about completeness and accuracy without relying on the client's own reports or manual sampling. Because it works on the full population, it also supports identifying unusual items and re-performing control logic, which is exactly the kind of direct evidence this engagement requires.

Why this answer

Direct evidence about a transaction population requires the auditor to examine or reprocess the actual data. Generalized audit software extracts and analyzes the full accounts payable file, while parallel simulation reprocesses live transactions through auditor-controlled logic and compares results. Both operate on real transactions.

Test data, integrated test facilities, and change log reviews address control design or change activity, not the completeness and accuracy of the recorded population.

Exam trap

The trap here is assuming that any computer-assisted audit technique provides population-level evidence, when test data and integrated test facilities only examine how the system handles injected entries.

57
MCQmedium

An IS auditor is planning an audit of a cloud service provider's security controls. The auditor has limited access to the provider's internal systems. Which of the following would be the MOST effective way to obtain assurance over the provider's security controls?

A.Perform penetration testing of the cloud environment.
B.Interview the provider's IT security manager.
C.Review the provider's independent audit reports (e.g., SOC 2 Type II).
D.Rely on the provider's self-assessment questionnaire.
AnswerC

Independent audit reports, such as SOC 2 Type II, provide an objective assessment of the provider's controls over a period. They are prepared by an independent auditor and cover the design and operating effectiveness of controls. This is a highly effective way to obtain assurance when direct access is limited. The IS auditor can review the report, assess the scope, and determine if it meets the audit objectives.

Why this answer

When an IS auditor has limited access to a cloud service provider's internal systems, reviewing the provider's independent audit reports (such as SOC 2 Type II) is the most effective way to obtain assurance over security controls. These reports are prepared by independent auditors and cover the design and operating effectiveness of controls over a period. They provide reliable, third-party evidence.

Self-assessments, penetration testing, and interviews are less reliable or comprehensive for this purpose.

Exam trap

The trap here is relying on the provider's self-assessment or interviews when independent third-party audit reports are available and provide stronger, more objective evidence.

58
MCQhard

Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?

A.It is more effective for detecting fraud than non-statistical sampling.
B.It ensures that all items in the population are tested.
C.It provides a basis for quantifying sampling risk and projecting results to the population.
D.It requires less auditor judgment and is easier to apply.
AnswerC

Statistical sampling applies probability theory, allowing the auditor to quantify sampling risk and extrapolate sample results to the full population within defined confidence limits. Non-statistical sampling relies on judgement, providing no mathematically defensible basis for such projection.

Why this answer

Statistical sampling uses probability theory to select samples, which allows the auditor to quantify sampling risk and mathematically project sample results to the full population. This is its defining advantage over non-statistical (judgmental) sampling, which relies on auditor judgment and cannot support statistically valid projections. The other options describe goals that neither method guarantees.

Exam trap

The trap is equating 'statistical' with 'better at finding fraud' or 'more thorough' — the exam wants you to recognize that the unique benefit is quantifiable sampling risk and projection, not detection capability or coverage.

How to eliminate wrong answers

Option A is wrong because neither statistical nor non-statistical sampling is inherently more effective at detecting fraud; fraud detection depends on the nature of procedures and the auditor's skepticism, not the sampling method. Option B is wrong because sampling by definition tests a subset, not all items — testing 100% of a population is a census, not sampling. Option D is wrong because statistical sampling actually requires more auditor expertise and judgment in selecting appropriate parameters (confidence level, tolerable error, expected error), not less.

59
MCQeasy

Which of the following is an example of a compliance audit?

A.Evaluating whether IT controls meet SOX requirements
B.Assessing the performance of a new system
C.Reviewing the efficiency of a production line
D.Analyzing financial statement ratios
AnswerA

SOX requirements are externally mandated legal obligations, so evaluating whether IT controls satisfy them tests adherence to prescribed criteria, which is the defining characteristic of a compliance audit rather than an operational or financial statement audit.

Why this answer

A compliance audit specifically evaluates whether an organization adheres to external laws, regulations, or standards. Option A is correct because SOX (Sarbanes-Oxley Act) is a mandatory regulatory requirement, and auditing IT controls for SOX compliance directly assesses conformity with those legal obligations. This is the essence of a compliance audit—verifying adherence to prescribed rules rather than evaluating performance or efficiency.

Exam trap

CISA often tests the distinction between compliance audits (adherence to laws/regulations) and performance/operational audits (efficiency/effectiveness), so candidates must recognize that SOX requirements represent a mandatory compliance driver, not a performance metric.

How to eliminate wrong answers

Option B is wrong because assessing the performance of a new system is a performance or operational audit, which focuses on effectiveness, efficiency, and goal achievement, not regulatory adherence. Option C is wrong because reviewing the efficiency of a production line is an operational audit concerned with process optimization and productivity, not compliance with laws or standards. Option D is wrong because analyzing financial statement ratios is a financial audit technique used to assess financial health and performance, not to verify compliance with specific regulatory requirements.

60
MCQmedium

An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?

A.Understand the process and identify controls
B.Gather evidence for audit findings
C.Test the effectiveness of controls
D.Verify the accuracy of transaction data
AnswerA

A walkthrough traces a single transaction through the purchase-to-pay process from initiation to payment, letting the auditor confirm their understanding of the actual flow and pinpoint the controls embedded at each step before designing detailed testing procedures.

Why this answer

A walkthrough is a preliminary audit technique used to trace a transaction through the entire process from initiation to recording. Its primary purpose is to gain an understanding of the process flow, identify key controls, and assess the design of those controls. Unlike testing, walkthroughs do not involve sampling or verification of accuracy; they are about understanding and documenting the system.

Therefore, option A is correct.

Exam trap

CISA often tests the distinction between understanding a process (walkthrough) and testing controls (compliance testing), so candidates may confuse the purpose of a walkthrough with that of a control test.

How to eliminate wrong answers

Option B is wrong because gathering evidence for audit findings typically occurs during substantive testing or detailed control testing, not during a walkthrough, which is more about understanding. Option C is wrong because testing the effectiveness of controls involves sampling and reperformance, which is beyond the scope of a walkthrough; a walkthrough only confirms that controls exist and are designed properly. Option D is wrong because verifying the accuracy of transaction data requires vouching, reconciliation, and other substantive procedures, not a walkthrough.

61
MCQmedium

Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?

A.To test the operating effectiveness of controls
B.To collect evidence of control failures
C.To identify process owners and key personnel
D.To gain an understanding of the process and identify control points
AnswerD

A walkthrough traces a transaction through the entire process, letting the auditor observe actual procedures and pinpoint where controls are applied. This satisfies the planning objective of understanding the process and identifying control points before designing detailed tests.

Why this answer

A walkthrough is performed during audit planning to trace a transaction or process from start to finish, allowing the auditor to understand how the process actually operates and to pinpoint where controls exist. This understanding is the foundation for scoping the audit, designing test procedures, and identifying risks. It is not a test of control effectiveness — that comes later during fieldwork.

Exam trap

CISA often tests the distinction between planning-phase understanding activities (walkthroughs, inquiry, observation) and fieldwork-phase testing activities (reperformance, inspection, data analysis), so candidates who conflate 'walkthrough' with 'test of control' pick option A.

How to eliminate wrong answers

Option A is wrong because testing operating effectiveness is a fieldwork activity performed after the auditor already understands the process and has selected controls to test. Option B is wrong because collecting evidence of control failures presupposes that testing has occurred; walkthroughs are exploratory and understanding-oriented, not evidence-gathering for conclusions. Option C is wrong because although identifying process owners is a useful byproduct, it is not the primary purpose — the primary purpose is understanding the process and its control points.

62
MCQmedium

An IS auditor is documenting the audit programme for an engagement and must decide how specific the procedures should be. Which of the following BEST describes the appropriate level of detail for procedures recorded in the audit programme?

A.Specific steps identifying what is to be tested, how, and by whom
B.Broad control objectives that allow the auditor to choose procedures during fieldwork
C.The final audit opinion and the criteria against which it will be measured
D.A list of prior audit findings to be re-verified in the current engagement
AnswerA

An audit programme should specify the procedures to be performed, the population or sample, the evidence to be obtained, and the responsibility for each step. This level of detail enables supervision, supports consistent execution, and provides a basis for confirming that the planned work was actually carried out before conclusions are drawn.

Why this answer

An audit programme converts engagement objectives into executable procedures. Each step should state the procedure, the items or population to which it applies, the evidence expected, and who performs it, so that work can be supervised, reviewed, and evidenced. Objectives, prior findings, and criteria inform the programme but do not replace the specific procedural detail that makes the engagement repeatable and defensible.

Exam trap

The trap here is equating a well-written control objective with an audit programme step, when objectives describe what must be achieved while programme steps describe exactly what the auditor will do to test it.

63
MCQmedium

An IS auditor is planning an audit of a financial application. The auditor wants to ensure that audit effort is focused on areas with the highest risk. Which approach should the auditor adopt?

A.Substantive approach
B.Control self-assessment approach
C.Compliance-based approach
D.Risk-based audit approach
AnswerD

A risk-based approach directs audit resources toward the areas of highest assessed risk, satisfying the stem's constraint that effort be focused where exposure is greatest. It differs from a compliance-based or control-based approach, which tests uniformly rather than prioritising by likelihood and impact of failure.

Why this answer

A risk-based audit approach prioritizes high-risk areas for more intensive testing, aligning with ISACA standards.

64
Multi-Selectmedium

Which TWO of the following are types of statistical sampling methods? (Select TWO.)

Select 2 answers
A.Block sampling
B.Stratified sampling
C.Systematic sampling
D.Haphazard sampling
E.Judgmental sampling
AnswersB, C

Stratified sampling divides the population into homogeneous subgroups (strata) before random selection from each, satisfying the stem's requirement for a statistical sampling method. Unlike judgemental or haphazard approaches, it uses probability theory, letting auditors quantify sampling risk and project results to the full population.

Why this answer

Stratified sampling (B) is a statistical sampling method in which the population is divided into homogeneous subgroups (strata) and random samples are drawn from each stratum, ensuring representation across defined characteristics. Systematic sampling (C) is also statistical: it selects every nth item from a population after a random starting point, applying a measurable, probability-based selection interval. Both are probability-based techniques because each item has a known, non-zero chance of selection, which supports statistical inference.

By contrast, block sampling (A) is a non-statistical approach that selects contiguous groups or clusters of items, haphazard sampling (D) relies on convenience with no defined selection probability, and judgmental sampling (E) depends on the auditor's subjective judgment, so none of these are statistical sampling methods.

Exam trap

CISA often tests whether candidates can distinguish statistical from non-statistical sampling; the trap is assuming that any structured method (like systematic) is non-statistical, or that judgmental sampling is statistical because it is 'planned.'

65
MCQmedium

Which of the following is the most reliable form of audit evidence?

A.Re-performance of a control by the auditor
B.Inquiry of management about a control
C.Observation of a control being performed
D.Inspection of signed approval forms
AnswerA

Re-performance requires the auditor to independently execute the control and observe the outcome, producing evidence generated directly by the auditor rather than by the auditee. This direct, first-hand testing yields the highest reliability, exceeding inspection, observation or inquiry.

Why this answer

Reperformance by the auditor is the most reliable form of audit evidence because the auditor directly executes the control or procedure and observes the outcome, eliminating reliance on the representations or actions of others. This direct, independent verification provides strong evidence about whether the control operates effectively. Inquiry, observation, and inspection are all less reliable because they are indirect or can be manipulated.

Exam trap

The trap is confusing observation with reperformance; candidates often assume that watching a control being performed is as strong as performing it themselves, but CISA expects recognition that observation is limited by timing and the Hawthorne effect.

How to eliminate wrong answers

Option B is wrong because inquiry of management yields representations that are not independently verified and are considered the least reliable evidence. Option C is wrong because observation only shows that a control was performed at a point in time, and individuals may alter behavior when being watched (Hawthorne effect). Option D is wrong because inspection of signed approval forms provides evidence that a document exists, but signatures can be forged or applied without actual review, making it less reliable than direct reperformance.

66
MCQeasy

During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?

A.Follow-up
B.Fieldwork
C.Reporting
D.Planning
AnswerB

Fieldwork is the phase where the auditor gathers evidence by performing inquiry, observation, inspection and reperformance against the audit programme. Planning establishes scope and risk, while reporting communicates findings, so these procedures occur during fieldwork.

Why this answer

Fieldwork is the phase where the auditor executes the planned audit procedures, including inquiry, observation, inspection, reperformance, and data analysis, to gather evidence and evaluate controls. Planning is about understanding the process and designing procedures; reporting is about communicating results; follow-up addresses remediation. Therefore, the procedures listed are performed during fieldwork.

Exam trap

CISA often tests the phase boundaries; the trap is that inquiry and observation can also occur during planning, so candidates may pick planning, but the question emphasizes performing these as audit procedures, which is fieldwork.

How to eliminate wrong answers

Option A is wrong because follow-up occurs after the audit report is issued and focuses on whether management has remediated previously reported issues. Option C is wrong because reporting is the phase where findings and conclusions are communicated, not where evidence-gathering procedures are performed. Option D is wrong because planning involves understanding the entity and designing the audit approach, but the actual execution of inquiry, observation, and inspection occurs in fieldwork.

67
MCQmedium

Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?

A.Inspection
B.Observation
C.Re-performance
D.Inquiry
AnswerC

Re-performance requires the auditor to independently execute the control procedure, such as recalculating a total or re-running an authorisation check, and compare the result with the organisation's output. This directly tests operating effectiveness rather than relying on documentation or inquiry.

Why this answer

Re-performance is when the auditor independently executes a control to confirm it operates as intended.

68
MCQmedium

An IS auditor is planning a compliance audit of a payment gateway that processes credit card transactions. The auditor needs to determine whether the control environment meets the requirements of the applicable payment card industry standard. Which of the following should be the auditor's PRIMARY basis for defining the audit criteria?

A.The organization's internal information security policy manual and procedures
B.A benchmark of security controls adopted by similar payment processors in the same region
C.The requirements of the applicable payment card industry data security standard
D.The auditor's professional judgment of what constitutes adequate security for payment gateways
AnswerC

In a compliance audit, the audit criteria are the authoritative requirements imposed on the entity. For a payment gateway handling cardholder data, the applicable payment card industry data security standard defines the mandatory controls the auditor must test against. Using these requirements as the primary basis allows the auditor to conclude whether the organization complies, which is the explicit purpose of this engagement.

Why this answer

A compliance audit measures the subject against authoritative criteria imposed by an external body. Because the payment gateway processes cardholder data, the applicable payment card industry data security standard supplies the mandatory requirements the auditor must test. Internal policies, professional judgment, and peer benchmarks inform the work but cannot establish compliance with the governing standard, so they cannot serve as the primary criteria for this engagement.

Exam trap

The trap here is treating the organization's own security policy or industry benchmarks as the compliance criteria, when the governing external standard actually defines what must be met.

69
MCQhard

An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed but no evidence of follow-up exists for two anomalies identified in one review. Which of the following conclusions is MOST appropriate?

A.The control is ineffective because any deviation, regardless of cause, invalidates the entire control
B.The control is operating effectively because the reviews were performed as scheduled
C.The control should be retested with a larger sample to determine whether the exceptions are isolated
D.The exceptions should be evaluated for cause and effect before concluding on control effectiveness
AnswerD

The auditor must investigate why follow-up did not occur and what the anomalies were before judging the control. If the anomalies were benign or resolved outside the log, the control may still be effective; if they indicate a systemic gap in escalation, the control objective may not be met. Evaluation precedes conclusion.

Why this answer

When testing identifies exceptions, the auditor evaluates their nature, cause, and effect before concluding on the control. Documented reviews without documented follow-up suggest the detection element worked but the response element may not have. Determining whether the anomalies were resolved, ignored, or escalated elsewhere is essential to deciding whether the control objective was actually achieved.

Exam trap

The trap here is jumping straight to a conclusion of effectiveness because the scheduled review occurred, without examining whether the review produced the corrective action the control exists to trigger.

70
MCQhard

An IS auditor is reviewing the audit documentation from a prior year and finds that a material weakness was reported but not remediated. According to ISACA standards, which audit phase should address this?

A.Reporting
B.Fieldwork
C.Planning
D.Follow-up
AnswerD

Follow-up addresses previously reported findings to verify whether management has remediated the material weakness. This satisfies the stem's constraint because ISACA standards require auditors to determine whether corrective action was implemented, escalating unresolved issues when remediation remains outstanding beyond agreed timelines.

Why this answer

Follow-up is the audit phase specifically designed to address previously reported findings, including material weaknesses, to verify whether management has remediated them. ISACA standards require auditors to perform follow-up procedures to determine the status of prior findings. Therefore, the unremediated material weakness should be addressed during follow-up.

Exam trap

CISA often tests the phase where follow-up occurs; the trap is assuming that planning or fieldwork automatically addresses prior findings, but the dedicated follow-up phase is specifically for tracking remediation.

How to eliminate wrong answers

Option A is wrong because reporting is the phase where findings are communicated, not where remediation status is tracked. Option B is wrong because fieldwork focuses on current audit testing, not on verifying remediation of prior findings, although it may include some follow-up procedures if integrated. Option C is wrong because planning involves scoping and risk assessment, and while prior findings may inform planning, the actual follow-up on remediation occurs in the follow-up phase.

71
MCQeasy

An IS auditor is conducting an audit of a payroll application and needs to verify that user access rights match each employee's current job responsibilities. Which of the following is the MOST appropriate source of evidence for this test?

A.The payroll application's password complexity configuration settings
B.A report of failed login attempts over the past quarter
C.A walkthrough of the payroll application with the system administrator
D.The payroll application's user access list and the human resources department's current job descriptions
AnswerD

Comparing the application's user access list against current HR job descriptions directly tests whether access aligns with responsibilities. The access list shows what rights users actually hold, and HR records represent the authoritative source of current roles after transfers and promotions. Together they provide independent, documentary evidence that supports a conclusion on authorization appropriateness for the payroll application.

Why this answer

Verifying that access rights match job responsibilities requires comparing what rights exist with what rights should exist. The application's user access list establishes actual entitlements, while HR's current job descriptions establish the authorized baseline. Agreement between these two independent records supports a conclusion on access appropriateness.

Walkthroughs, failed login reports, and password settings each address different control objectives and cannot demonstrate role alignment.

Exam trap

The trap here is confusing authentication-related evidence, such as password settings or failed logins, with authorization evidence needed to prove that access rights align with current job responsibilities.

72
MCQmedium

During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?

A.Perform additional testing to confirm the finding
B.Report the lack of remediation to senior management
C.Ignore the finding since it was previously reported
D.Close the finding as accepted risk
AnswerB

Unresolved findings represent unmitigated risk that the auditor cannot accept or remediate. Escalating to senior management, who own risk acceptance and resource allocation, ensures the issue receives the authority needed to compel action, satisfying the follow-up requirement to verify remediation status.

Why this answer

When a previously reported finding remains unremediated after the agreed follow-up period, the auditor's responsibility shifts from re-testing to escalation. ISACA audit standards require that unresolved findings be reported to senior management (and ultimately the board/audit committee) so that those with authority to accept risk or allocate resources are formally made aware. Reporting the lack of remediation preserves the audit trail and forces a documented management decision (remediate, accept, or mitigate).

Exam trap

CISA often tests the boundary between the auditor's role and management's role — candidates incorrectly pick 'close as accepted risk' or 're-test' when the correct answer is always to escalate unresolved findings to those with authority to accept the risk.

How to eliminate wrong answers

Option A is wrong because additional testing only re-confirms what is already known — the finding was not remediated — and does not discharge the auditor's duty to escalate; re-testing is appropriate when management claims remediation has occurred, not when it is absent. Option C is wrong because ignoring a finding violates the auditor's obligation to follow up on prior findings and would leave a known control gap undocumented in the current audit cycle. Option D is wrong because the auditor cannot unilaterally close a finding as accepted risk — risk acceptance is a management decision that must be formally documented and approved by the appropriate authority, not assumed by the auditor.

73
MCQmedium

An IS auditor is conducting an audit of a hospital's electronic health record system. During fieldwork, the auditor discovers that several database administrators have the ability to modify patient records directly in the production database without leaving an audit trail. The auditor wants to gather sufficient appropriate evidence to determine whether this is a widespread issue. Which of the following is the MOST appropriate action?

A.Review the database administrators' job descriptions to determine if their roles include direct data modification responsibilities.
B.Use audit software to examine database user access rights and review system logs for evidence of direct modifications.
C.Interview the IT manager to confirm whether the database administrators have been authorized to modify records directly.
D.Observe a database administrator performing a routine update to confirm whether an audit trail is generated.
AnswerB

Examination of access rights and system logs using audit software provides direct, independent evidence of who can modify production data and whether such modifications are logged. This technique allows the auditor to assess the extent of the deficiency across the entire population of database administrators, yielding sufficient appropriate evidence to support a conclusion about the control weakness.

Why this answer

The auditor needs evidence about the actual access rights and logging behavior across all database administrators. Using audit software to examine user rights and review logs directly tests the control environment and provides reliable, population-wide evidence. Inquiry and inspection of documents are indirect and cannot confirm the technical capability or the absence of audit trails, while a single observation lacks coverage.

Exam trap

The trap here is relying on inquiry or documentation review as sufficient evidence when the auditor must independently verify technical access rights and logging across a population.

74
Multi-Selecteasy

Which TWO of the following are phases of the audit process? (Select two.)

Select 2 answers
A.Budgeting
B.Planning
C.Risk assessment
D.Training
E.Reporting
AnswersB, E

Planning is the initial audit phase, where scope, objectives, risk assessment and resource allocation are defined before evidence gathering begins. This satisfies the stem's requirement for a genuine audit process phase, establishing the foundation for subsequent fieldwork and reporting activities.

Why this answer

Option B, Planning, is correct because planning is the foundational phase of the audit process, where the auditor defines the audit scope, objectives, criteria, and methodology before fieldwork begins. Option E, Reporting, is correct because reporting is the concluding phase in which the auditor documents findings, conclusions, and recommendations in the audit report for management and stakeholders. The audit process is commonly structured as planning, fieldwork/execution, and reporting, so these two options align with the recognized phase model.

Option A, Budgeting, is not a distinct audit phase; budgeting is a management activity that may support planning but is not itself a phase. Option C, Risk assessment, is a technique or activity performed within the audit process (particularly during planning and fieldwork) rather than a standalone phase. Option D, Training, is an administrative or professional-development activity and is not one of the phases of the audit process.

75
MCQmedium

Which of the following is a key difference between internal and external auditors?

A.Internal auditors are required for regulatory compliance
B.Internal auditors focus only on financial controls
C.External auditors have deeper organizational knowledge
D.External auditors are more independent than internal auditors
AnswerD

External auditors report to shareholders or regulators rather than management, so they operate free of the employment relationship that constrains internal auditors. This structural detachment from the entity is the defining independence difference between the two roles.

Why this answer

External auditors are independent third parties, while internal auditors are employees of the organization.

Page 1 of 2 · 120 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information System Auditing Process questions.