Courseiva
← Back to Certified Information Systems Auditor CISA questions

Scenario-based practice

Hard Difficulty Questions

Practise Certified Information Systems Auditor CISA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISA
exam code
ISACA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE of the following are key considerations when selecting a software development methodology for a project?

Question 2hardmulti select
Full question →

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Question 3hardmultiple choice
Full question →

An IS auditor is evaluating how an organization manages its backup and restoration process for a critical financial application. The backup job completes successfully each night and writes to a tape library. Management states that recovery capability has been proven because the backup job reports success. Which audit procedure would BEST test whether the backups are actually restorable?

Question 4hardmultiple choice
Full question →

An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed but no evidence of follow-up exists for two anomalies identified in one review. Which of the following conclusions is MOST appropriate?

Question 5hardmultiple choice
Full question →

Refer to the exhibit. A security analyst notices that users on the INSIDE network (10.1.1.0/24) can browse HTTPS websites but cannot resolve domain names. What is the most likely cause?

Exhibit

Refer to the exhibit.

Exhibit: Firewall rule excerpt (Cisco ASA)

access-list INSIDE extended permit tcp 10.1.1.0 255.255.255.0 any eq 443
access-list INSIDE extended permit udp 10.1.1.0 255.255.255.0 host 10.2.2.10 eq 53
access-list INSIDE extended deny ip any any

interface GigabitEthernet0/0
 nameif INSIDE
 security-level 100
 ip address 10.1.1.1 255.255.255.0

interface GigabitEthernet0/1
 nameif OUTSIDE
 security-level 0
 ip address 192.168.1.1 255.255.255.0

route OUTSIDE 0.0.0.0 0.0.0.0 192.168.1.254 1
Question 6hardmulti select
Full question →

An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)

Question 7hardmulti select
Full question →

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Question 8hardmulti select
Full question →

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

Question 9hardmulti select
Full question →

An organization is planning to implement a data loss prevention (DLP) solution to protect sensitive data. Which THREE of the following are essential steps to ensure the effectiveness of the DLP program?

Question 10hardmultiple choice
Full question →

A security review of the above Apache configuration identifies a critical vulnerability. Which of the following is the MOST significant issue?

Exhibit

Refer to the exhibit.

```
<VirtualHost *:80>
    DocumentRoot "/var/www/html"
    <Directory "/var/www/html">
        Options Indexes FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>
```
Question 11hardmultiple choice
Full question →

An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?

Question 12hardmultiple choice
Full question →

Refer to the exhibit. Which perspective shows the greatest deviation from target?

Exhibit

IT BSC Report Q1 2025:
- Financial: Actual 80% of plan (Target 90%)
- Customer: Satisfaction score 4.2/5 (Target 4.0)
- Internal Process: SLA compliance 95% (Target 99%)
- Learning & Growth: Training hours 120 (Target 150)
Question 13hardmultiple choice
Full question →

During a spiral model SDLC project, an IS auditor is reviewing risk assessment documentation. Which of the following would be the GREATEST concern?

Question 14hardmultiple choice
Full question →

During a system development project, the project manager notices that the actual cost is significantly higher than the planned cost at the 50% completion point. The earned value (EV) is $500,000, the actual cost (AC) is $600,000, and the planned value (PV) is $550,000. Which of the following is the MOST appropriate action?

Question 15hardmultiple choice
Full question →

An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?

Question 16hardmultiple choice
Full question →

An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?

Question 17hardmultiple choice
Full question →

An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?

Question 18hardmultiple choice
Full question →

A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:

Question 19hardmultiple choice
Full question →

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

Question 20hardmultiple choice
Full question →

An IS auditor reviews the exhibit from a cloud access policy. Which of the following is a potential security concern?

Exhibit

Refer to the exhibit.
```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::confidential-data/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/8"
        }
      }
    }
  ]
}
```

These CISA practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.