Courseiva

CCNA Cisa Audit Process Questions

45 of 120 questions · Page 2/2 · Cisa Audit Process topic · Answers revealed

76
MCQmedium

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. The audit team has limited experience with this ERP. Which of the following is the BEST course of action?

A.Limit the audit scope to exclude the new ERP system.
B.Proceed with the audit using existing staff and hope for the best.
C.Postpone the audit until the team gains sufficient experience.
D.Engage an external specialist with ERP expertise to supplement the audit team.
AnswerD

Engaging an external specialist supplies the ERP technical competence the audit team lacks, letting them assess controls and risks accurately. This satisfies the constraint of limited in-house ERP experience while preserving audit quality and objectivity.

Why this answer

When the audit team lacks the technical competence to audit a newly implemented system, ISACA standards require the auditor to obtain the necessary expertise rather than dilute the audit. Engaging an external specialist with ERP expertise supplements the team, preserves audit independence and objectivity, and allows the audit to proceed on schedule with appropriate depth. This is explicitly endorsed in the CISA Review Manual under 'audit staffing and competence.'

Exam trap

CISA often tests whether candidates understand that competence gaps are solved by adding expertise, not by shrinking scope or delaying work — the trap is picking 'limit scope' or 'postpone' as pragmatic-sounding but non-compliant answers.

How to eliminate wrong answers

Option A is wrong because limiting the scope to exclude a newly implemented, high-risk ERP system would leave a material control environment unaudited and would violate the auditor's obligation to cover significant systems. Option B is wrong because proceeding without competence produces unreliable conclusions and breaches professional due care — 'hoping for the best' is never an acceptable audit strategy. Option C is wrong because postponing the audit indefinitely is impractical and may cause the organization to miss critical control windows during the ERP's stabilization period; the audit should proceed with the right resources, not be delayed.

77
MCQeasy

Which document is typically included in the permanent file of audit documentation?

A.Organizational chart
B.Management representation letter
C.Current year audit program
D.Working papers for testing
AnswerA

The permanent file holds enduring reference material relevant across multiple audits, such as the organisational chart, which documents structure and reporting lines. It is not engagement-specific evidence, so it stays on file rather than being refreshed each audit.

Why this answer

The permanent file contains information that is relevant for multiple audits, such as organizational charts and key contracts.

78
MCQhard

An IS auditor is evaluating the design of controls over a new financial system. Which of the following is the BEST approach to assess control design?

A.Use analytical procedures to identify anomalies
B.Review system documentation and conduct walkthroughs
C.Perform detailed testing of transactions
D.Interview management and review policies
AnswerB

Reviewing documentation establishes the intended control design, while walkthroughs trace a transaction end-to-end to confirm the control operates as documented. Together they test design adequacy before any operating-effectiveness testing, which is the objective stated in the stem.

Why this answer

Reviewing system documentation and conducting walkthroughs allows the auditor to understand the intended design and compare it to actual implementation.

79
Multi-Selectmedium

Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)

Select 2 answers
A.Ratio analysis
B.Inquiry of management
C.Inspection of documents
D.Trend analysis
E.Observation of process
AnswersA, D

Ratio analysis is an analytical procedure: it compares financial or operational relationships to identify unusual variances or trends warranting investigation. This qualifies as substantive audit evidence derived from analysis rather than direct testing of transactions or controls.

Why this answer

Ratio analysis (A) is a classic analytical procedure because it evaluates financial information by comparing relationships among accounts (e.g., current ratio, gross margin percentage) to identify unusual fluctuations or inconsistencies that may indicate misstatement. Trend analysis (D) is likewise analytical, as it compares financial data across periods (e.g., year-over-year revenue growth) to spot significant variances requiring further audit attention. Both fall under the analytical procedures defined in auditing standards (e.g., AU-C 520), which involve evaluations of financial information through analysis of plausible relationships among financial and nonfinancial data.

By contrast, inquiry of management (B) is a form of audit evidence obtained through questioning, not analysis; inspection of documents (C) is a substantive test of details involving examination of records; and observation of process (E) is a procedure of watching a process or procedure being performed, none of which constitute analytical procedures.

Exam trap

CISA often tests the distinction between evidence-gathering techniques (inquiry, inspection, observation) and analytical procedures — the trap is selecting inquiry or inspection as 'analytical' because they are common audit activities.

80
MCQmedium

Which of the following is a characteristic of non-statistical (judgmental) sampling?

A.Every item has an equal chance of selection
B.The auditor uses professional judgment to select sample items
C.The sample size is determined using statistical formulas
D.The sample results can be projected to the population with known confidence
AnswerB

Judgmental sampling relies on the auditor's professional judgement, experience and knowledge of the population to select items, rather than probabilistic methods. This satisfies the stem's requirement for a non-statistical characteristic, since selection is deliberate and subjective, with no random selection or calculable sampling risk attached.

Why this answer

Non-statistical (judgmental) sampling is characterized by the auditor's use of professional judgment to select sample items, determine sample size, and evaluate results. Unlike statistical sampling, it does not rely on probability theory or mathematical formulas. The auditor chooses items based on risk, materiality, and experience — for example, selecting all transactions above a threshold or focusing on high-risk areas.

Exam trap

CISA often tests the confusion between statistical and non-statistical sampling — the trap is picking 'equal chance of selection' or 'known confidence' as characteristics of judgmental sampling when those belong exclusively to statistical methods.

How to eliminate wrong answers

Option A is wrong because 'every item has an equal chance of selection' describes random (probability) sampling, which is a statistical method, not judgmental sampling. Option C is wrong because determining sample size using statistical formulas is a defining feature of statistical sampling — judgmental sampling uses the auditor's judgment, not formulas. Option D is wrong because projecting results to the population with known confidence requires statistical sampling; judgmental sampling cannot mathematically project results with quantified confidence levels.

81
MCQhard

An IS auditor is preparing working papers. Which of the following items should be included in the permanent file rather than the current file?

A.Audit programme for the current year
B.Testing results from current audit
C.Management responses to current findings
D.Organization chart
AnswerD

An organisation chart changes infrequently and provides ongoing context about structure, reporting lines and responsibilities, so it belongs in the permanent file. Current files hold items specific to the audit period, such as working papers and testing results.

Why this answer

The permanent audit file contains information of continuing relevance across multiple audits, such as the organization chart, long-term contracts, and standing policies. The organization chart is a stable reference document that helps auditors understand reporting lines and segregation of duties year after year. Current-year audit programmes, testing results, and management responses are engagement-specific and belong in the current file.

Exam trap

CISA often tests the permanent-versus-current file distinction by offering items that seem stable (like an audit programme) but are actually engagement-specific, or vice versa, to see if candidates understand the criterion of continuing relevance across audits.

How to eliminate wrong answers

Option A is wrong because the audit programme for the current year is specific to the current engagement and is superseded each year, so it belongs in the current file. Option B is wrong because testing results are evidence gathered during the current audit and are only relevant to that engagement's conclusions. Option C is wrong because management responses to current findings are tied to the current audit's issues and remediation timeline, making them current-file material.

82
MCQhard

During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:

A.Systematic sampling
B.Judgmental sampling
C.Random sampling
D.Stratified sampling
AnswerD

Stratified sampling divides the population into distinct subgroups (strata) and draws samples from each, directly matching the stem's description. Unlike simple random or systematic sampling, it guarantees representation across every subgroup, which suits audit populations with heterogeneous characteristics where each stratum warrants coverage.

Why this answer

Stratified sampling divides the population into homogeneous subgroups (strata) — such as by department, transaction type, or risk level — and then draws samples from each stratum, often proportionally or with higher sampling in high-risk strata. This guarantees representation of every subgroup and reduces sampling risk compared to simple random sampling. It is the standard ISACA-recommended technique when the population is heterogeneous and the auditor needs coverage across distinct categories.

Exam trap

CISA often tests the distinction between stratified and systematic sampling — candidates confuse 'dividing into subgroups' with 'selecting every nth item', but only stratified sampling involves population subdivision.

How to eliminate wrong answers

Option A is wrong because systematic sampling selects every nth item from a sequentially ordered list after a random start — it does not divide the population into subgroups. Option B is wrong because judgmental sampling relies on the auditor's professional judgment and experience to select items (e.g., high-value or unusual transactions), not on statistical subdivision of the population. Option C is wrong because simple random sampling gives every item an equal chance of selection without any stratification or subgroup structure, which can under-represent small but risky subpopulations.

83
MCQmedium

An IS auditor is conducting a follow-up review of prior audit findings. Management has implemented a new automated control but has not yet updated the risk register to reflect the residual risk. Which of the following should the auditor do FIRST?

A.Verify that the new control is operating effectively through testing before concluding on residual risk.
B.Recommend that management update the risk register before any further audit work is performed.
C.Accept management's representation that the control is effective and close the finding.
D.Report to the audit committee that management has failed to maintain the risk register.
AnswerA

The auditor should first validate the design and operating effectiveness of the implemented control, since management's assertion alone is insufficient evidence. Only after testing can the auditor assess whether residual risk has actually been reduced to an acceptable level. Updating the risk register is a management responsibility, and reporting to the audit committee is premature without verification.

Why this answer

The auditor's core duty during follow-up is to independently verify that management's remediation actually works. Testing the new control provides the evidence needed to determine whether residual risk is acceptable. Only after that verification is it appropriate to consider reporting or recommending documentation updates.

Verification must precede conclusions about risk reduction.

Exam trap

The trap here is assuming that management's implementation of a control, or its representation, is itself sufficient evidence of remediation without independent testing.

84
MCQeasy

Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?

A.External auditors follow stricter standards.
B.External auditors have more technical expertise.
C.External auditors have access to more resources.
D.External auditors are not employees of the organization.
AnswerD

External auditors sit outside the organisation's reporting line, so they owe no employment allegiance to management and face no promotion or remuneration pressure from the audited entity. This structural separation from the chain of command directly satisfies the stem's independence constraint, unlike internal auditors who remain employees subject to management authority.

Why this answer

The primary reason external auditors are considered more independent is that they are not employees of the organization, so they have no reporting line, compensation, or career dependency on the entity being audited. This structural separation reduces the risk of bias and conflicts of interest. Internal auditors, while ideally independent in function, remain employees and therefore have an inherent organizational relationship that can impair perceived independence.

Exam trap

CISA often tests the misconception that independence derives from expertise, standards, or resources, when the fundamental driver is the absence of an employment relationship with the audited organization.

How to eliminate wrong answers

Option A is wrong because both internal and external auditors follow professional standards (IIA Standards for internal, ISACA/IFAC for external); stricter standards is not the defining factor for independence. Option B is wrong because technical expertise varies by individual and engagement, not by internal versus external status, and expertise is not the basis for independence. Option C is wrong because resource access is a practical capability, not the reason external auditors are considered more independent — an internal audit function can be well-resourced yet still lack structural independence.

85
MCQmedium

An IS auditor is evaluating the results of a penetration test performed by an external vendor on a web-facing application. The report identifies a critical SQL injection vulnerability. Which of the following is the MOST appropriate action for the IS auditor to recommend FIRST?

A.Include the finding in the audit report and schedule remediation during the next quarterly patch cycle
B.Escalate the finding to the audit committee and await their direction before recommending remediation
C.Immediately remediate or mitigate the vulnerability and validate the fix before the report is finalized
D.Repeat the penetration test with a different vendor to confirm the finding is not a false positive
AnswerC

A critical exploitable vulnerability in a web-facing application represents an immediate risk of data compromise. The auditor should recommend urgent remediation or mitigation, such as applying a patch, input validation, or a web application firewall rule, and then validate that the fix works. Addressing the exposure takes precedence over documentation and longer-term process improvements.

Why this answer

A critical SQL injection vulnerability in an internet-facing application can be exploited to access or modify data, so the priority is to remediate or mitigate it immediately and confirm the fix. Reporting, re-testing by another vendor, or waiting for governance direction are appropriate supporting activities but must not delay protection of the exposed system.

Exam trap

The trap here is allowing process steps such as report finalization, vendor confirmation, or committee escalation to take precedence over immediate containment of an actively exploitable critical vulnerability.

86
MCQmedium

Which of the following types of audit evidence provides the highest level of assurance?

A.Re-performance of control procedures
B.Inquiry of process owners
C.Observation of processes
D.Inspection of documents
AnswerA

Re-performance involves the auditor independently executing the control procedure and comparing the result with the original, producing evidence generated directly by the auditor rather than the auditee. This self-generated evidence satisfies the stem's demand for the highest assurance, outranking inspection, observation and inquiry, which rely on entity personnel or documentation.

Why this answer

Re-performance provides direct evidence that a control is operating effectively.

87
MCQmedium

During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?

A.Report the increase as a finding
B.Ignore the increase if it is within budget
C.Investigate the reason for the increase
D.Expand the sample size for testing
AnswerC

A significant unexplained variance requires investigation before any conclusion is drawn, since analytical procedures identify anomalies rather than their causes. The auditor must obtain corroborating evidence, such as management explanations, supporting documentation or transaction testing, to determine whether the increase reflects error, fraud or legitimate business change.

Why this answer

Analytical procedures are used to identify unusual fluctuations that may indicate errors, fraud, or changes in the environment. A significant increase in IT expenses compared to the prior year is an unexpected variance that must be investigated to determine its cause before concluding whether it represents a finding. Only after understanding the reason can the auditor decide whether it is a reportable issue.

Exam trap

CISA often tests the misconception that any significant variance is automatically a finding, when in fact the auditor must first investigate the reason and only report it if the explanation is inadequate or indicates a control failure.

How to eliminate wrong answers

Option A is wrong because reporting the increase as a finding before investigating its cause would be premature and could result in a false positive. Option B is wrong because being within budget does not explain the variance or confirm that the expense is legitimate and properly authorized. Option D is wrong because expanding the sample size is a substantive testing response, not the appropriate next step when an analytical procedure reveals an unexplained fluctuation.

88
MCQhard

An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?

A.Systematic sampling
B.Judgmental sampling
C.Stratified sampling
D.Statistical attribute sampling
AnswerD

Statistical attribute sampling quantifies the exception rate against a defined confidence level and tolerable deviation rate, letting the auditor conclude on the 5,000-item population with measurable precision. Judgemental or block methods cannot support the stated 95% confidence and 2% tolerable error.

Why this answer

Statistical attribute sampling is the most appropriate method when the auditor wants to achieve a specified confidence level and tolerable error rate for a control that has a binary outcome (exception or no exception). It allows the auditor to project the exception rate to the population and conclude whether the control is operating effectively within the tolerable deviation rate.

Exam trap

CISA often tests the confusion between statistical and non-statistical sampling, and between attribute and variables sampling, causing candidates to choose stratified or systematic sampling when the question specifies confidence level and tolerable error rate for a control test.

How to eliminate wrong answers

Option A is wrong because systematic sampling selects every nth item and does not by itself provide a statistical basis for projecting error rates with a specified confidence level. Option B is wrong because judgmental sampling relies on auditor judgment rather than statistical probability, so it cannot support a quantified confidence level and tolerable error rate. Option C is wrong because stratified sampling divides the population into subpopulations and samples each, which is useful for reducing variability but is not the primary method for attribute testing with a specified confidence and tolerable error rate.

89
MCQhard

During a follow-up audit, an IS auditor finds that management implemented a compensating control rather than the recommended primary control to address a previously reported high-risk finding. The residual risk is now within the organization's risk appetite. How should the IS auditor respond?

A.Evaluate whether the compensating control adequately mitigates the risk and close the finding if it does.
B.Escalate the matter to the audit committee because a compensating control was used.
C.Document that management accepted the risk without implementing the recommended control.
D.Reopen the original finding because the recommended control was not implemented as specified.
AnswerA

The auditor's responsibility is to assess whether the implemented control reduces risk to an acceptable level, regardless of whether it matches the original recommendation. If the compensating control adequately mitigates the risk and residual risk falls within the risk appetite, the finding can be closed. This reflects the principle that management owns risk response while the auditor provides objective assurance on the outcome.

Why this answer

Audit recommendations describe a desired risk outcome, not a mandatory control design. When management implements a compensating control that reduces residual risk to within the organization's risk appetite, the auditor should evaluate whether that control adequately mitigates the risk and close the finding if it does. Reopening, escalating, or mislabeling the response as risk acceptance would misrepresent the outcome and ignore management's ownership of risk.

Exam trap

The trap here is treating the original recommendation as a binding requirement, when in fact management may satisfy the underlying risk reduction through an alternative compensating control.

90
MCQmedium

An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?

A.Stratified sampling
B.Random sampling
C.Systematic sampling
D.Judgmental sampling
AnswerB

Random sampling gives every transaction in the 1,000-item population an equal, non-zero chance of selection, which the random number generator enforces. This satisfies the stem's requirement for a statistically valid, unbiased sample, unlike haphazard or judgmental methods, and supports extrapolating the 50-transaction results to the full population.

Why this answer

Using a random number generator to select 50 transactions from a population of 1,000 is the definition of random sampling, where every item in the population has an equal chance of being selected. This method is a form of statistical sampling that supports projection of results to the population.

Exam trap

CISA often tests the distinction between random sampling and systematic sampling, where candidates confuse the use of a random number generator with systematic selection, or incorrectly associate random sampling with stratified or judgmental methods.

How to eliminate wrong answers

Option A is wrong because stratified sampling involves dividing the population into homogeneous subgroups and sampling from each, which is not described here. Option C is wrong because systematic sampling selects every nth item after a random start, not via a random number generator applied to the entire population. Option D is wrong because judgmental sampling relies on the auditor's judgment to select items, not on random selection.

91
MCQeasy

What is the primary purpose of the planning phase in an IS audit?

A.To execute audit tests
B.To issue the final report
C.To identify risks and define audit scope
D.To follow up on findings
AnswerC

The planning phase establishes the audit's foundation by assessing inherent and control risks, then using that risk assessment to define scope, objectives, criteria and resource allocation, ensuring fieldwork concentrates effort on the areas of greatest significance to the organisation.

Why this answer

The planning phase of an IS audit is where the auditor defines the audit objectives, identifies and assesses risks, determines the scope and criteria, and develops the audit program. This foundational phase ensures that the audit is focused on the areas of greatest risk and that resources are allocated effectively.

Exam trap

CISA often tests the sequence of audit phases, and candidates may confuse planning with fieldwork by selecting 'execute audit tests' or with reporting by selecting 'issue the final report' when asked about the primary purpose of planning.

How to eliminate wrong answers

Option A is wrong because executing audit tests occurs during the fieldwork phase, not planning. Option B is wrong because issuing the final report happens in the reporting phase, after fieldwork and review. Option D is wrong because following up on findings is part of the post-audit or follow-up phase, not planning.

92
MCQmedium

During an audit of an organization's backup and recovery process, the IS auditor finds that full backups are performed weekly and incremental backups are performed nightly. Restoration testing has not been performed in over two years. Which of the following should the auditor do FIRST?

A.Perform or observe a restoration test to evaluate the effectiveness of the backups
B.Review the backup logs to confirm that nightly jobs completed without error
C.Recommend that management immediately increase the frequency of full backups
D.Report the absence of restoration testing as a high-risk finding in the audit report
AnswerA

The most persuasive evidence about whether backups can actually be restored is a restoration test. Performing or observing a test allows the auditor to verify that the backup media are readable, that the recovery procedures work, and that recovery time objectives are realistic. This direct evidence supports a reliable conclusion about the control's operating effectiveness, which is exactly what the auditor needs before deciding whether a finding is warranted.

Why this answer

The key question is whether the backups can actually be restored, and the most persuasive evidence is a restoration test. Performing or observing a test verifies media readability, procedure effectiveness, and recovery objectives. Reporting a finding, changing backup frequency, or reviewing logs address related but different concerns and do not directly demonstrate restoration capability, so they are not the appropriate first action.

Exam trap

The trap here is treating successful backup job logs as proof that recovery will work, when only an actual restoration test demonstrates recoverability.

93
MCQmedium

An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?

A.Walkthrough
B.Re-performance
C.Inquiry
D.Observation
AnswerA

A walkthrough is itself the audit procedure being executed; the auditor traces transactions through the accounts payable process to confirm controls operate as described. This satisfies the stem directly, as the procedure's name matches the activity performed.

Why this answer

A walkthrough is an audit procedure where the auditor traces a transaction or process from start to finish, often by interviewing personnel and inspecting documents, to understand the flow of transactions and the design of controls. Performing a walkthrough of the accounts payable process is precisely executing a walkthrough procedure.

Exam trap

CISA often tests the distinction between walkthrough, inquiry, observation, and re-performance, and candidates may incorrectly select inquiry or observation when the scenario describes tracing a transaction through the entire process.

How to eliminate wrong answers

Option B is wrong because re-performance involves the auditor independently executing a control or procedure to verify its effectiveness, not tracing a process to understand it. Option C is wrong because inquiry alone involves asking questions, but a walkthrough typically combines inquiry with inspection and observation to follow the process. Option D is wrong because observation involves watching a process being performed, but a walkthrough is more comprehensive, involving tracing transactions through the system.

94
MCQhard

An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?

A.Increase the sample size for substantive testing to compensate.
B.Test the compensating controls to determine if they adequately mitigate the risk.
C.Immediately report the missing control as a material weakness.
D.Ignore the missing control since compensating controls exist.
AnswerB

Testing the compensating controls establishes whether they actually reduce the risk arising from the missing control, which is the evidence needed before concluding on control adequacy. Walkthroughs alone only confirm design; substantive testing of the compensating control's operating effectiveness satisfies the auditor's obligation to assess residual risk.

Why this answer

When a control gap is identified but management asserts compensating controls exist, the auditor cannot simply accept the assertion — the auditor must obtain evidence that the compensating controls actually operate effectively and reduce the risk to an acceptable level. Testing the compensating controls is the only way to determine whether the residual risk is adequately mitigated before concluding on the control environment.

Exam trap

CISA often tests the misconception that the existence of compensating controls automatically eliminates the need for further auditor action, when in fact the auditor must test those controls to validate their effectiveness.

How to eliminate wrong answers

Option A is wrong because increasing substantive testing sample size addresses detection risk at the transaction level but does not evaluate whether the compensating controls mitigate the identified design deficiency. Option C is wrong because a missing control is not automatically a material weakness — materiality depends on the assessed risk and whether compensating controls reduce it to an acceptable level. Option D is wrong because the auditor cannot ignore a missing control based solely on management's assertion; compensating controls must be tested and validated before reliance can be placed on them.

95
MCQhard

An IS auditor is assessing the audit risk for an engagement covering a core banking application. The auditor determines that inherent risk is high because the application processes high-value transactions in real time. The auditor also concludes that control risk is low because strong automated controls and segregation of duties are in place and have been tested. Which of the following BEST describes the appropriate response to this assessment?

A.Rely on the tested controls and reduce the extent of substantive procedures accordingly
B.Increase the extent of substantive testing because inherent risk is high
C.Reduce reliance on controls and perform more detailed transaction testing
D.Set detection risk at a low level regardless of the control assessment
AnswerA

The assessed level of control risk is low because controls are strong and have been tested. Under the audit risk model, lower control risk allows the auditor to place greater reliance on controls and reduce the extent of substantive procedures. This keeps detection risk at a level that holds overall audit risk within acceptable bounds while avoiding unnecessary testing. High inherent risk is already reflected in the assessment and is managed through this combined approach.

Why this answer

The audit risk model links inherent risk, control risk, and detection risk to overall audit risk. With strong, tested controls, control risk is assessed as low, which permits the auditor to rely on those controls and reduce the extent of substantive procedures. High inherent risk is already factored into the assessment and does not by itself justify expanding substantive testing, nor should detection risk be fixed independently of the other components.

Exam trap

The trap here is reacting to high inherent risk by expanding substantive testing, while overlooking that low, tested control risk allows reduced substantive work.

96
MCQmedium

An IS auditor is planning an audit of a small organization with limited IT staff. Which approach is most appropriate?

A.Rely solely on inquiry to reduce workload
B.Use a risk-based approach to focus on high-risk areas
C.Postpone the audit until more staff are available
D.Audit all areas equally to ensure full coverage
AnswerB

A risk-based approach directs scarce audit resources toward the areas of greatest exposure, which suits a small organisation where limited IT staff cannot support exhaustive testing. Comprehensive or cyclical coverage would over-extend the available audit capacity.

Why this answer

A risk-based approach is most appropriate because it directs limited audit resources toward the areas of highest risk and impact, which is essential when the organization has constrained IT staffing. This aligns with ISACA's risk-based auditing methodology, ensuring audit effort is proportional to risk rather than spread uniformly or reduced arbitrarily.

Exam trap

CISA often tests the misconception that limited resources justify reducing audit scope or relying on inquiry, when the correct response is to apply risk-based prioritization without compromising audit rigor.

How to eliminate wrong answers

Option A is wrong because relying solely on inquiry provides weak, unverified evidence and violates the principle that audit conclusions require corroborating evidence from multiple sources. Option C is wrong because postponing the audit does not address the risk and leaves the organization exposed; audits should be adapted, not deferred. Option D is wrong because auditing all areas equally ignores risk prioritization and wastes scarce resources on low-risk areas while high-risk areas may be under-examined.

97
MCQeasy

During which phase of the IS audit process does the auditor perform walkthroughs and test controls?

A.Reporting
B.Planning
C.Follow-up
D.Fieldwork
AnswerD

Fieldwork is the audit phase where the auditor gathers evidence, performs walkthroughs and tests controls to evaluate their design and operating effectiveness. This satisfies the stem directly, as control testing occurs after planning and before reporting.

Why this answer

Walkthroughs and control testing are performed during fieldwork, where the auditor executes planned audit procedures.

98
MCQmedium

During an operational audit, the auditor uses ratio analysis to compare current year expenses to prior years and industry benchmarks. This is an example of which type of audit evidence?

A.Analytical procedures
B.Inquiry
C.Observation
D.Inspection
AnswerA

Ratio analysis compares financial and operational data across periods and against benchmarks, which is the defining characteristic of analytical procedures. It evaluates relationships and trends rather than testing individual transactions or controls, satisfying the audit objective of identifying unusual variances warranting further investigation.

Why this answer

Analytical procedures involve evaluating financial information by analyzing plausible relationships among both financial and non-financial data. Ratio analysis comparing current expenses to prior years and industry benchmarks is a classic analytical procedure used to identify unusual fluctuations or trends. This type of evidence is indirect but highly effective for risk assessment and substantive testing.

Under ISACA standards, analytical procedures are a key method for obtaining audit evidence.

Exam trap

CISA often tests the distinction between analytical procedures and other evidence-gathering techniques like inquiry, observation, and inspection; candidates may confuse ratio analysis with inspection because both involve examining data, but inspection focuses on individual records while analytical procedures focus on relationships and trends.

How to eliminate wrong answers

Option B is wrong because inquiry involves asking questions of management or staff to gather information, which is verbal and must be corroborated. Option C is wrong because observation entails watching a process or procedure being performed, such as witnessing a physical inventory count. Option D is wrong because inspection involves examining records, documents, or physical assets, such as reviewing invoices or checking equipment.

99
Multi-Selectmedium

An IS auditor is performing a risk assessment to prioritize audit engagements for the annual audit plan. Which TWO of the following factors should the auditor consider when evaluating inherent risk? (Choose two.)

Select 2 answers
A.The level of management experience and turnover in the business unit.
B.The effectiveness of the controls currently in place over the process.
C.The audit budget allocated to the engagement by the audit committee.
D.The complexity of the technology and the volume of transactions processed.
E.The number of audit findings closed in the previous audit cycle.
AnswersA, D

Management experience and turnover affect inherent risk because unstable or inexperienced leadership increases the chance of poor decisions, inadequate oversight, and control lapses. These are environmental factors that exist independently of specific controls. ISACA guidance includes management competence and stability among inherent risk considerations, making this a valid factor when prioritizing audit engagements in the annual plan.

Why this answer

Inherent risk is assessed before considering controls and reflects conditions that make errors or failures more likely or impactful. Technology complexity, transaction volume, management experience, and turnover are classic inherent risk factors identified in ISACA guidance. Control effectiveness belongs to residual risk, while prior finding closures and audit budget are planning considerations that do not describe the inherent risk of the process itself.

Exam trap

The trap here is including control effectiveness as an inherent risk factor, when inherent risk by definition is evaluated before controls are taken into account.

100
MCQhard

In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?

A.Focus on areas where management has requested review
B.Allocate more audit resources to areas with higher risk and lower control effectiveness
C.Concentrate solely on areas with the highest inherent risk
D.Focus equally on all areas of the audited entity
AnswerB

Risk-based auditing directs limited resources toward exposures with the greatest likelihood and impact, weighted by how weakly existing controls mitigate them. Prioritising high-risk, low-control-effectiveness areas satisfies the stem's requirement, since coverage then targets residual risk rather than spreading effort uniformly.

Why this answer

A risk-based approach focuses on areas with higher inherent risk and weaker controls to maximize effectiveness.

101
MCQeasy

During an audit of a data center, the IS auditor observes that visitors are escorted at all times but the visitor log is not reconciled to the badge access system. Which of the following BEST describes the audit concern?

A.The badge access system is more reliable than the visitor log, so the log can be discarded.
B.Visitor logs are not required by any standard, so the finding should be closed.
C.The escort requirement is sufficient on its own, so no further action is needed.
D.Physical access controls are not operating effectively because the two records are not reconciled.
AnswerD

The lack of reconciliation between the visitor log and the badge system means unauthorized or unescorted access could go undetected. The control objective is to ensure all physical entries are authorized and monitored. Without reconciliation, the log and badge records cannot be relied upon to detect discrepancies, so the control is not operating effectively.

Why this answer

The audit concern is that the detective control of reconciling visitor logs with badge records is not operating, so unauthorized access could go undetected. Escorting alone is preventive and can fail. Both records have distinct value, and the absence of reconciliation is the control gap.

The finding should be documented rather than closed or dismissed.

Exam trap

The trap here is assuming that a preventive control such as escorting is sufficient without a detective control to verify it actually occurred.

102
MCQhard

An IS auditor is planning an audit of a small organization with limited IT staff. Which of the following is a key consideration for the audit approach?

A.Reduced audit scope because of limited staff
B.Greater reliance on detective and compensating controls
C.Increased reliance on preventive controls due to limited staff
D.Use of extensive substantive testing to compensate for weak controls
AnswerB

Limited IT staff means fewer preventive controls such as segregation of duties, so the auditor emphasises detective and compensating controls to obtain assurance. This approach acknowledges the resource constraint while still addressing risk through monitoring and reconciliation.

Why this answer

In a small organization with limited IT staff, the auditor should expect a greater reliance on detective and compensating controls because preventive controls such as segregation of duties and automated enforcement are often impractical. The audit approach must recognize this reality and focus on whether detective controls adequately mitigate the increased risk.

Exam trap

CISA often tests the misconception that limited staff justifies reduced audit scope or increased reliance on preventive controls, when the correct approach is to rely more on detective and compensating controls.

How to eliminate wrong answers

Option A is wrong because reduced audit scope based solely on limited staff is not justified; scope should be determined by risk, not resource constraints. Option C is wrong because increased reliance on preventive controls is unrealistic when staff is limited — preventive controls typically require more resources to implement and maintain. Option D is wrong because extensive substantive testing is not a substitute for understanding and evaluating the control environment; it increases audit effort without addressing the root control weakness.

103
MCQmedium

Which of the following is a key difference between an internal audit and an external audit?

A.External audits are always required by law, while internal audits are voluntary.
B.Internal auditors are employees of the organization, which may affect independence.
C.External auditors issue a report to management, while internal auditors report to the board.
D.Internal audits focus only on financial controls.
AnswerB

Internal auditors being employees creates a self-review threat, since they report to management and may audit areas they influence. This directly satisfies the stem's focus on a key difference: external auditors are engaged independently, whereas internal audit's employment relationship can impair objectivity and independence.

Why this answer

The key difference is that internal auditors are employees of the organization, which creates a potential impairment to independence and objectivity. External auditors are independent third parties engaged to provide an objective opinion on financial statements or specific subject matter.

Exam trap

CISA often tests the misconception that internal audits are always voluntary or that external auditors report to management, when the real distinguishing factor is the employment relationship and its impact on independence.

How to eliminate wrong answers

Option A is wrong because not all external audits are legally required — many are voluntary (e.g., SOC 2 engagements), and some internal audits are mandated by regulation. Option C is wrong because it reverses the reporting relationships: internal auditors typically report to the board or audit committee, while external auditors report to management and shareholders. Option D is wrong because internal audits cover operational, compliance, and IT controls, not just financial controls.

104
Multi-Selecteasy

Which TWO of the following are types of audit evidence recognized in IS audit practice?

Select 2 answers
A.Assumption
B.Observation
C.Conjecture
D.Re-performance
E.Hypothesis
AnswersB, D

Observation involves the auditor watching a process or control being performed, such as witnessing a backup or physical access procedure. ISACA recognises observation alongside inspection, inquiry, re-performance and analytics as a distinct audit evidence type.

Why this answer

In IS audit practice, evidence is classified by how it is obtained and its reliability, and two recognized types here are Observation (B) and Re-performance (D). Observation (B) is valid because auditors directly witness processes, controls, or personnel performing activities, yielding first-hand evidence about how a control actually operates. Re-performance (D) is valid because the auditor independently executes the control or procedure (for example, recalculating a depreciation schedule or re-running an access review) and compares the result to the client's output, producing highly reliable evidence.

The remaining options do not belong: Assumption (A), Conjecture (C), and Hypothesis (E) are speculative or unverified propositions, not evidence types, since audit evidence must be based on actual observation, inspection, inquiry, confirmation, recalculation, or re-performance rather than supposition.

105
Multi-Selecthard

Which THREE of the following are characteristics of SMART recommendations in an audit report? (Select three.)

Select 3 answers
A.Measurable
B.Vague
C.Specific
D.Rigid
E.Time-bound
AnswersA, C, E

Measurable means the recommendation states quantifiable criteria or a verifiable outcome, enabling the auditor to objectively assess whether management's corrective action has been implemented. This satisfies the SMART requirement that progress and completion be demonstrable rather than subjective.

Why this answer

Option A (Measurable) is correct because SMART recommendations must include quantifiable criteria or metrics so that auditors and management can objectively verify whether the recommendation has been implemented and its effect assessed. Option C (Specific) is correct because a SMART recommendation must clearly state the exact action, system, process, or control to be addressed, leaving no ambiguity about what is required. Option E (Time-bound) is correct because SMART recommendations must specify a deadline or target timeframe by which the action should be completed, enabling follow-up and accountability.

Option B (Vague) is incorrect because vagueness directly contradicts the Specific and Measurable criteria of SMART, making recommendations unverifiable. Option D (Rigid) is incorrect because SMART recommendations should be achievable and adaptable to the organization's context, not inflexible; rigidity is not one of the SMART attributes (Specific, Measurable, Achievable, Relevant, Time-bound).

Exam trap

CISA often tests whether candidates confuse SMART criteria with general good-writing principles, so the trap is selecting 'Rigid' or 'Vague' as characteristics when they are actually antithetical to SMART recommendations.

106
MCQeasy

Which type of audit is primarily concerned with evaluating the efficiency and effectiveness of operations?

A.Financial audit
B.Compliance audit
C.Operational audit
D.IS audit
AnswerC

Operational audits examine whether processes achieve their objectives efficiently and effectively, covering economy, efficiency and effectiveness of resource use. Unlike financial audits, which verify monetary accuracy, or compliance audits, which test adherence to rules, this type directly addresses the stem's efficiency and effectiveness focus.

Why this answer

An operational audit evaluates the efficiency and effectiveness of an organization's operations, including processes, resource utilization, and goal achievement. It goes beyond mere compliance or financial accuracy to assess whether things are being done well. This is distinct from financial, compliance, and IS audits, which focus on different objectives.

Exam trap

CISA often tests the distinction between audit types by swapping 'efficiency and effectiveness' with 'accuracy' or 'compliance' — the trap is picking financial or compliance audit when the question emphasizes operational performance.

How to eliminate wrong answers

Option A is wrong because a financial audit focuses on the accuracy and fairness of financial statements and records, not on operational efficiency. Option B is wrong because a compliance audit checks adherence to laws, regulations, and internal policies, not whether operations are efficient or effective. Option D is wrong because an IS audit focuses on the information systems' controls, security, and integrity, not on the broader efficiency and effectiveness of business operations.

107
Multi-Selectmedium

In the audit follow-up phase, which TWO actions are essential? (Select two.)

Select 2 answers
A.Assess the effectiveness of the corrective actions
B.Expand the scope of the original audit
C.Re-issue the audit report
D.Update the audit program for next year
E.Verify that management has implemented corrective actions
AnswersA, E

Follow-up must determine whether the corrective action actually remedied the reported condition, not merely that something was done. Assessing effectiveness tests the outcome against the original finding, satisfying the follow-up objective of confirming that risk has been genuinely reduced.

Why this answer

Option A is correct because the audit follow-up phase must evaluate whether the corrective actions taken actually resolved the root cause and reduced the risk to an acceptable level, not merely whether they were performed. Option E is correct because a core follow-up step is verifying that management has implemented the agreed-upon corrective actions within the committed timeframe, confirming the remediation is real and operational. Together, verification (E) establishes that the actions exist, while effectiveness assessment (A) establishes that they work, which are the two essential follow-up outcomes.

Option B is wrong because expanding the original audit scope is a new engagement decision, not a required follow-up action. Option C is wrong because re-issuing the audit report is not standard follow-up practice; follow-up results are typically reported separately. Option D is wrong because updating next year's audit program is a planning activity, not an essential action of the follow-up phase itself.

Exam trap

CISA often tests the distinction between follow-up (verify implementation and effectiveness) and other audit activities like re-issuing reports or expanding scope; candidates pick plausible-sounding but non-essential actions.

108
MCQhard

During an audit of a bank's online transaction processing system, the IS auditor discovers that batch totals are reconciled only at the end of each business day, while individual transactions are posted to customer accounts in real time. Which of the following is the GREATEST risk arising from this control design?

A.Individual transactions may be posted incorrectly without detection until the reconciliation is performed
B.The daily reconciliation may not complete within the batch window, delaying the next day's processing
C.Batch totals may not include transactions processed through channels outside the main system
D.The audit trail for individual transactions may be overwritten before the reconciliation is performed
AnswerA

Real-time posting without contemporaneous controls means errors or unauthorized transactions can affect customer balances before the daily reconciliation identifies them. The reconciliation confirms the batch total but does not prevent incorrect individual postings, so the exposure window lasts until the daily check, creating potential financial loss and customer impact.

Why this answer

Real-time posting combined with only end-of-day reconciliation leaves the entire business day exposed to incorrect or unauthorized individual postings. The reconciliation verifies batch totals but cannot retroactively prevent customer accounts from being affected. The primary risk is therefore the window during which erroneous transactions remain undetected and potentially cause financial or reputational harm.

Exam trap

The trap here is focusing on operational scheduling or speculative log issues instead of recognizing that the core weakness is the detection gap created by verifying only after real-time postings have already affected accounts.

109
MCQeasy

An IS auditor is reviewing the audit charter of an organization's internal audit function. Which of the following should the auditor expect to find as the PRIMARY purpose of the audit charter?

A.The mandate, authority, and scope of the internal audit function.
B.The qualifications and certifications required of each auditor on staff.
C.The specific testing procedures to be applied during each engagement.
D.A detailed schedule of audits planned for the next fiscal year.
AnswerA

The audit charter is the formal document that defines the internal audit function's purpose, authority, and responsibility. ISACA standards require that the charter establish the function's position within the organization and grant it access to records, personnel, and physical properties. Approval by the board or audit committee gives the function its mandate, making this the primary purpose of the charter.

Why this answer

An audit charter is the governing document approved by the board or audit committee that establishes the internal audit function's purpose, authority, and scope. It grants the function its mandate and right of access to records, people, and assets. Audit schedules, personnel qualifications, and testing procedures are handled through the annual plan, HR policies, and audit programmes respectively, not the charter.

Exam trap

The trap here is confusing the high-level governance mandate in the audit charter with tactical planning documents such as the audit schedule or audit programme.

110
MCQhard

An IS auditor is evaluating the reliability of evidence obtained from a system-generated exception report. The report is produced by a script written by a database administrator who has both the ability to modify the script and the production data. The auditor has obtained the report directly from the system. Which of the following is the MOST important factor affecting the auditor's reliance on this evidence?

A.The report contains a large number of exceptions.
B.The database administrator has access to production data.
C.The report was generated by a script that could have been modified by the administrator.
D.The report was obtained directly from the system by the auditor.
AnswerC

The administrator's ability to modify the script that generates the report undermines the reliability of the evidence because the report could be manipulated to exclude exceptions. This compromises the integrity of the evidence, making it less reliable. The auditor must consider whether the script is controlled and whether its logic is independently validated before relying on the report.

Why this answer

The reliability of system-generated evidence depends on the integrity of the process that produces it. If the script generating the report can be altered by an administrator with privileged access, the report may not accurately reflect the underlying data. This is the most critical factor because it directly questions the completeness and accuracy of the evidence, regardless of how it was obtained.

Exam trap

The trap here is focusing on the direct retrieval of the report as a strength while overlooking the possibility that the report's logic could be manipulated at the source.

111
MCQeasy

Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?

A.IS audit
B.Internal audit
C.Compliance audit
D.External audit
AnswerB

Internal audit is performed by employees of the same organisation, so the auditor reports through internal management and may lack freedom from the activities being reviewed. That structural reporting relationship creates the independence concern the stem describes, unlike external audit or third-party assessments conducted by parties outside the entity.

Why this answer

An internal audit is performed by auditors who are employees of the organization being audited. Because they report within the same organizational structure they are reviewing, their objectivity and independence can be impaired by management pressure, familiarity, or career incentives. This inherent independence concern is why ISACA emphasizes that internal auditors must maintain objectivity and why external audits are often used for higher-assurance opinions.

Exam trap

CISA often tests the confusion between audit type (IS, compliance, financial) and audit relationship (internal vs. external), so candidates who focus on the word 'audit' rather than 'employee of the organization' pick the wrong option.

How to eliminate wrong answers

Option A is wrong because 'IS audit' describes the subject matter (information systems) rather than the auditor's organizational relationship; an IS audit can be internal or external and does not by itself create an independence concern. Option C is wrong because a compliance audit is defined by its objective (testing adherence to regulations or standards) and can be conducted by internal or external parties, so it does not inherently raise independence issues. Option D is wrong because external audits are performed by independent third parties outside the organization, which is precisely the structure designed to preserve independence.

112
MCQeasy

During an audit, the IS auditor identifies that the audit team lacks the technical expertise to evaluate a specific system. According to ISACA standards, the auditor should:

A.Engage a subject matter expert with the required skills
B.Skip the evaluation of that system
C.Request management to provide training
D.Proceed with the audit and document the limitation
AnswerA

ISACA standards require the auditor to obtain sufficient, competent evidence; where the team lacks the technical skill to evaluate a system, that competence gap must be closed by engaging a subject matter expert. This preserves the audit's objectivity and evidentiary adequacy rather than issuing an uninformed opinion.

Why this answer

ISACA standards require that auditors possess or obtain the necessary skills and competence to perform the audit. When the audit team lacks technical expertise in a specific area, the standard-compliant response is to engage a subject matter expert (SME) who has the required knowledge, while the auditor retains responsibility for the audit conclusion. This preserves both the quality of the audit evidence and the auditor's professional accountability.

Exam trap

CISA often tests the misconception that documenting a limitation is an acceptable substitute for obtaining competence, so candidates who value 'transparency' over 'professional proficiency' pick option D.

How to eliminate wrong answers

Option B is wrong because skipping the evaluation of a system would leave a material scope gap, violating the requirement to obtain sufficient appropriate evidence and potentially invalidating the audit opinion. Option C is wrong because requesting management to provide training shifts responsibility for auditor competence to the auditee and does not address the immediate need for expertise during the engagement; it also creates a dependency that can compromise objectivity. Option D is wrong because proceeding without the required expertise and merely documenting the limitation does not satisfy ISACA standards — the auditor must obtain the competence, not just disclose its absence.

113
MCQeasy

An IS auditor has completed fieldwork for an audit of a data center's physical access controls and has documented several findings. Before drafting the final report, the auditor discusses the findings with the data center manager. Which of the following is the PRIMARY purpose of this discussion?

A.To obtain management's agreement on the corrective actions and target dates
B.To determine whether the findings should be excluded from the final report
C.To validate the accuracy and completeness of the findings with the auditee
D.To reduce the amount of evidence the auditor needs to gather for each finding
AnswerC

Discussing findings with the auditee before finalizing the report confirms that the facts, conditions, and evidence are accurate and complete, and it gives management an opportunity to correct misunderstandings or provide additional context. This validation step strengthens the reliability of the report and reduces the risk of factual errors. It is a fundamental quality control activity in the audit process and the primary reason for the discussion.

Why this answer

Before issuing the report, the auditor discusses findings with the auditee to confirm that the facts and evidence are accurate and complete. This validation protects against factual errors, allows management to provide clarifying information, and gives the auditee a chance to respond. It is not a negotiation to reduce evidence, exclude valid findings, or obtain remediation commitments, although management responses are captured for the report.

Exam trap

The trap here is confusing the validation discussion with the later agreement on corrective actions, when the immediate purpose is to confirm factual accuracy.

114
MCQmedium

An IS auditor is conducting a follow-up review of a previously identified high-risk finding. Management has implemented a compensating control instead of the recommended control. Which of the following is the MOST appropriate action for the auditor to take?

A.Evaluate and test the compensating control to determine whether it effectively mitigates the risk.
B.Report to the audit committee that management has failed to implement the recommended control.
C.Reissue the original finding with a revised due date for implementation of the recommended control.
D.Accept the compensating control as a satisfactory resolution without further testing.
AnswerA

When management implements a compensating control in lieu of the recommended control, the auditor must assess whether the alternative control adequately addresses the original risk. This involves testing the design and operating effectiveness of the compensating control to ensure it reduces the risk to an acceptable level. Only after such evaluation can the auditor conclude on the status of the finding.

Why this answer

In follow-up audits, when management implements a compensating control instead of the originally recommended control, the IS auditor must assess whether the alternative control effectively mitigates the identified risk. This requires testing the design and operating effectiveness of the compensating control. If it is found to be effective, the auditor can consider the finding resolved.

If not, the finding remains open and may be escalated. Simply accepting or rejecting without evaluation is inappropriate.

Exam trap

The trap here is assuming that only the exact recommended control is acceptable, or conversely, that any management response resolves the finding without verification.

115
MCQmedium

An IS auditor is executing a compliance test of change management controls over a core banking application. The audit programme requires evidence that all production changes were approved before implementation. Which of the following techniques provides the MOST persuasive evidence for this test?

A.Observing the change advisory board during one weekly meeting
B.Reviewing the change management policy approved by the IT steering committee
C.Inspecting the change tickets for documented approvals and comparing approval dates to deployment dates
D.Interviewing the change manager about the approval workflow
AnswerC

Inspecting change tickets produces documentary evidence and directly tests the control: the audit programme asks whether approvals preceded implementation. By comparing the approval timestamp on each ticket with the deployment timestamp in the same record, the auditor can detect changes deployed before authorization. This is the most persuasive technique available here because it is independent of verbal assertions and covers the actual population of changes.

Why this answer

Documentary evidence of approvals linked to deployment records directly addresses the control objective: approvals occurring before implementation. Comparing dates on the change tickets themselves allows the auditor to identify exceptions rather than relying on what people say or what policy intends. Interviews, policy review, and single-meeting observation each provide weaker or incomplete evidence for concluding on operating effectiveness across the change population.

Exam trap

The trap here is treating review of the approved change management policy as sufficient evidence, when a compliance test of operating effectiveness requires evidence that approvals actually occurred before each deployment.

116
MCQmedium

An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?

A.Inherent risk
B.Detection risk
C.Control risk
D.Audit risk
AnswerB

Detection risk is the component the auditor directly controls through the nature, timing and extent of substantive testing. With inherent risk high and control risk low, the auditor adjusts testing to keep detection risk at a level that holds overall audit risk within acceptable bounds.

Why this answer

Detection risk is the risk that the auditor's procedures will not detect a material misstatement. It is directly influenced by the auditor's testing strategy: the nature, timing, and extent of audit procedures. When inherent risk is high and control risk is low, the auditor can accept a higher detection risk, but the testing strategy (e.g., more substantive testing) affects detection risk.

Inherent and control risks are assessed, not affected by testing.

Exam trap

The trap is thinking that inherent or control risk can be changed by testing; candidates may confuse the assessed risks with the risk that testing can influence, which is detection risk.

How to eliminate wrong answers

Option A is wrong because inherent risk is the susceptibility of an assertion to material misstatement before considering controls; it is assessed, not changed by the auditor's testing strategy. Option C is wrong because control risk is the risk that controls will not prevent or detect misstatements; it is also assessed, not affected by testing. Option D is wrong because audit risk is the overall risk that the auditor expresses an inappropriate opinion; it is a combination of inherent, control, and detection risks, but the testing strategy directly impacts detection risk, not audit risk as a whole.

117
MCQmedium

After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?

A.To update the permanent audit file
B.To close the audit engagement
C.To identify new risks for the next audit
D.To verify that corrective actions have been implemented effectively
AnswerD

Follow-up confirms management actually remediated the reported findings, testing whether agreed corrective actions were implemented and are operating effectively. This closes the loop after the final report, satisfying the stem's requirement to determine that risks previously identified have genuinely been addressed rather than merely promised.

Why this answer

Follow-up ensures that management has taken corrective actions to address the findings and that the risks have been mitigated.

118
Multi-Selectmedium

An IS auditor is assessing the sufficiency of audit evidence gathered for a conclusion about database access controls. Which TWO of the following characteristics must the evidence possess to be considered appropriate? (Choose two.)

Select 2 answers
A.A minimum sample size of thirty items drawn from the population
B.Agreement of the evidence with management's written assertions
C.Relevance to the control objective being tested
D.Reliability of the source and the nature of the evidence
E.Permanent retention of the evidence in the engagement file
AnswersC, D

Evidence must bear a logical relationship to the control objective. For database access controls, configuration extracts, access listings, and approval records are relevant because they speak directly to who can access the database and whether access was authorized, whereas unrelated material cannot support a conclusion no matter how voluminous.

Why this answer

Appropriateness of audit evidence is judged by relevance and reliability. Relevance ties the evidence to the specific control objective, while reliability reflects the source and how the evidence was obtained, with independent, system-generated data generally ranking higher than auditee representations. Sufficiency, by contrast, concerns quantity and is influenced by risk and materiality, so fixed sample counts or retention practices do not make evidence appropriate.

Exam trap

The trap here is treating a fixed sample size as a measure of evidence quality, when quantity addresses sufficiency while relevance and reliability address appropriateness.

119
MCQmedium

An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?

A.Comparing current-year expenses to prior-year expenses
B.Observing the inventory count
C.Inspecting authorization forms for signatures
D.Confirming account balances with third parties
AnswerA

Analytical procedures evaluate financial information through plausible relationships among data. Comparing current-year expenses against prior-year figures is a substantive analytical comparison that highlights unexpected fluctuations or trends, unlike inquiry, observation or inspection, which are tests of controls or detail.

Why this answer

Analytical procedures involve evaluating financial information by analyzing plausible relationships among data — comparing current-year expenses to prior-year expenses is a textbook example of such a comparison. It helps the auditor identify unusual fluctuations or trends that warrant further investigation during planning. This is distinct from tests of details and substantive procedures that involve direct evidence gathering.

Exam trap

CISA often tests whether candidates can distinguish analytical procedures (analysis of relationships/trends) from other evidence-gathering techniques like observation, inspection, and confirmation — the trap is picking a procedure that gathers direct evidence instead of one that analyzes financial relationships.

How to eliminate wrong answers

Option B is wrong because observing the inventory count is a physical observation procedure (a test of controls/substantive test), not an analytical procedure — it involves watching a process, not analyzing financial relationships. Option C is wrong because inspecting authorization forms for signatures is inspection of documentation, a test of details that verifies existence and approval, not an analytical comparison. Option D is wrong because confirming account balances with third parties is a confirmation procedure (external evidence gathering), which is a substantive test of details rather than an analytical procedure.

120
MCQeasy

An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?

A.Only the audit findings
B.Only the recommendations
C.Findings, recommendations, and management action plans
D.The audit program and procedures
AnswerC

ISACA standards require the final report to document findings, their risk implications, recommendations, and management's agreed action plans with target dates. Including all three elements ensures the report is complete, actionable, and supports follow-up of remediation.

Why this answer

According to ISACA's IT Audit Framework and the ISACA Code of Professional Ethics, the final audit report must include the audit findings, recommendations, and management's action plans. Findings describe the condition, criteria, cause, and effect; recommendations provide guidance for remediation; and management action plans document the agreed-upon corrective steps and timelines. This triad ensures the report is complete, actionable, and supports follow-up.

Exam trap

CISA often tests the misconception that the audit report should only include findings or recommendations, or that the audit program is part of the report, when in fact ISACA standards require the triad of findings, recommendations, and management action plans.

How to eliminate wrong answers

Option A is wrong because findings alone lack the necessary recommendations and management commitments for remediation. Option B is wrong because recommendations without findings lack context and evidence, and without management action plans there is no accountability. Option D is wrong because the audit program and procedures are internal working documents that detail the audit methodology; they are not part of the final report to management and the board.

← PreviousPage 2 of 2 · 120 questions total

Ready to test yourself?

Try a timed practice session using only Cisa Audit Process questions.