Courseiva
← Back to Certified Information Systems Auditor CISA questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Certified Information Systems Auditor CISA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

13
scenario questions
CISA
exam code
ISACA
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CISA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymultiple choice
Full question →

Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?

Exhibit

Refer to the exhibit.

```
Error Log Entry:
Timestamp: 2024-03-20 10:15:32
Source: BackupServer01
EventID: 213
Level: Error
Message: Backup job 'DailyBackup' failed. Source volume: \\FileServer\Shares, Destination: \\BackupServer01\Backup\Shares. Error code: 0x80070002 (The system cannot find the file specified.)
```
Question 2easymultiple choice
Full question →

Based on the exhibit, what is the security risk of this bucket policy?

Network Topology
# s3api get-bucket-policybucket example-bucketRefer to the exhibit.```"Policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":\"*\",\"Action\":\"s3:GetObject\",\"Resource\":\"arn:aws:s3:::example-bucket/*\"}]}"
Question 3hardmultiple choice
Full question →

Based on the exhibit, which control is most likely missing to prevent this type of event?

Exhibit

Refer to the exhibit.

syslog output:
Mar 15 10:23:45 server01 sshd[1234]: Failed password for root from 10.0.0.99 port 22 ssh2
Mar 15 10:23:46 server01 sshd[1234]: Failed password for root from 10.0.0.99 port 22 ssh2
Mar 15 10:23:47 server01 sshd[1234]: Failed password for root from 10.0.0.99 port 22 ssh2
Mar 15 10:23:48 server01 sshd[1234]: Failed password for root from 10.0.0.99 port 22 ssh2
Mar 15 10:23:49 server01 sshd[1234]: Failed password for root from 10.0.0.99 port 22 ssh2
Question 4mediummultiple choice
Full question →

Based on the exhibit, what is the MOST likely security risk?

Exhibit

Refer to the exhibit.

```
access-list 101 permit tcp any host 192.168.1.100 eq 80
access-list 101 permit tcp any host 192.168.1.100 eq 443
access-list 101 deny ip any host 192.168.1.100
access-list 101 permit ip any any
```
Question 5easymultiple choice
Full question →

Refer to the exhibit. An auditor finds that the file 'sensitive.txt' has world-writable permissions. Which of the following is the most appropriate remediation action?

Exhibit

-rw-rw-rw- 1 root root 1024 Jan 1 12:00 sensitive.txt
Question 6hardmultiple choice
Full question →

A company's endpoint protection solution alerts on a file that is digitally signed by a trusted software vendor but exhibits malicious behavior on execution. What type of threat does this scenario most likely depict?

Question 7hardmultiple choice
Full question →

Based on the exhibit, what should the IS auditor MOST likely recommend?

Exhibit

Refer to the exhibit.
```
Change Management Log Extract:
CR-2024-001: Approved | Implemented 01/15 14:00
CR-2024-002: Approved | Implemented 01/20 09:30
CR-2024-003: Emergency (post-approved) | Implemented 01/25 22:15
CR-2024-004: Approved | Implemented 02/01 11:00
CR-2024-005: Emergency (post-approved) | Implemented 02/10 23:45
CR-2024-006: Approved | Implemented 02/15 10:00
CR-2024-007: Emergency (post-approved) | Implemented 02/20 21:30
```
Question 8mediummultiple choice
Full question →

Based on the exhibit, what is the most likely control weakness that allowed this condition?

Exhibit

Refer to the exhibit.

Audit Finding Report Excerpt:

Finding ID: F-001
Control: User Account Management
Observation: Review of Active Directory logs from 01-Mar-2024 to 07-Mar-2024 revealed that the default administrator account (Administrator) was used to perform 45% of all privileged actions. No evidence of secondary approval or time-based restrictions.

Configuration snippet from domain controller:

Set-ADUser -Identity Administrator -PasswordNeverExpires $true
Set-ADUser -Identity Administrator -CannotChangePassword $true

Audit Recommendation: Implement a privileged access management (PAM) solution and enforce use of individual privileged accounts.
Question 9hardmultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. During a security audit, an IS analyst identifies that a critical business application hosted on 192.168.1.100:443 is unreachable from the 10.0.1.0/24 subnet. Which of the following is the MOST likely cause?

Exhibit

access-list extended BLOCK-MALICIOUS
deny ip 10.0.1.0 0.0.0.255 any
deny tcp any host 192.168.1.100 eq 443
permit ip 10.0.0.0 0.0.255.255 any
Question 10easymultiple choice
Full question →

Based on the exhibit, what is the MOST appropriate action for IT management?

Exhibit

Refer to the exhibit.
The following is an excerpt from an IT balanced scorecard:
Perspective: Customer
Objective: Improve user satisfaction
KPI: User satisfaction survey score
Target: >85%
Actual: 82%
Question 11mediummultiple choice
Full question →

Refer to the exhibit. An application log shows an error. What is the MOST likely cause of this error?

Exhibit

Refer to the exhibit.

```
ERROR 2019-11-15 14:23:45,123 [main] com.example.App - Error processing record ID 1045
java.sql.SQLIntegrityConstraintViolationException: ORA-00001: unique constraint (USERS.UK_USERNAME) violated
	at com.example.dao.UserDao.insert(UserDao.java:45)
	... 8 more
```
Question 12easymultiple choice
Full question →

An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?

Exhibit

Refer to the exhibit.
```
Feb 20 10:15:32 firewall %ASA-4-106023: Deny tcp src outside:10.0.0.1/3389 dst inside:192.168.1.100/3389 by access-group "outside_in" [0x0, 0x0]
```
Question 13hardmultiple choice
Full question →

Refer to the exhibit. This log entry MOST likely indicates:

Exhibit

Event 4648: A logon was attempted using explicit credentials.
Subject: Account Name: svc_backup
Target Account: KORP\administrator
Target Server: FILESRV01
Process Name: C:\Windows\System32\wbem\wmiprvse.exe

These CISA practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.