CISA Information Systems Auditing Process: 89 practice questions
12 of the 89 Information Systems Auditing Process questions in the Certsqill CISA bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CISA? Take the free 5-min readiness check →
1. Standards are mandatory requirements: Within ISACA's Information Technology Assurance Framework (ITAF), what i
- Standards are mandatory requirements, while guidelines provide guidance on how to apply the standards. ✓Correct. In ITAF, standards define mandatory requirements for IS audit and assurance work, whereas guidelines offer non-mandatory direction on applying those standards.
- Standards apply only to external auditors, while guidelines apply only to internal auditors.Incorrect. ITAF applies to IS audit and assurance professionals regardless of internal or external status; the distinction is mandatory versus advisory, not audience.
- Guidelines are mandatory requirements, while standards describe optional leading practices.Incorrect. This reverses the relationship; guidelines are the advisory layer and standards are the mandatory layer.
- Standards are set by regulators, while guidelines are set by ISACA.Incorrect. Both ITAF standards and guidelines are issued by ISACA; regulators do not author ITAF.
ITAF standards are mandatory; guidelines are advisory guidance on how to meet the standards.
2. Compliance audit: Which type of audit is this?
- Compliance audit ✓Correct. A compliance audit evaluates adherence to specific external or contractual rules, regulations, or standards, which is exactly what payment-brand security requirements represent.
- Financial auditIncorrect. A financial audit expresses an opinion on the fairness of financial statements, not adherence to security requirements.
- Operational auditIncorrect. An operational audit evaluates the efficiency and effectiveness of operations, not conformance to a defined external requirement set.
- Integrated auditIncorrect. An integrated audit combines financial and IS/operational testing; the scope here is limited to conformance with defined security rules.
Testing adherence to a defined external/contractual rule set is a compliance audit.
3. To direct limited audit resources toward the areas: What is the PRIMARY reason an IS audit function adopts a r
- To direct limited audit resources toward the areas of greatest risk to the organization. ✓Correct. Risk-based planning concentrates finite audit effort where the potential impact and likelihood of adverse events are highest, maximizing assurance value.
- To guarantee that every application and infrastructure system across the organization is formally audited at least once during each calendar year.Incorrect. Risk-based planning deliberately does not cover everything annually; it prioritizes higher-risk areas over uniform coverage.
- To reduce the total number of controls the organization must maintain.Incorrect. Audit planning does not remove control obligations; management owns controls regardless of the audit schedule.
- To eliminate the need for management to perform its own risk assessment.Incorrect. The audit function's risk assessment does not replace management's responsibility for risk management; they are separate.
Risk-based planning aligns scarce audit resources with the highest-risk areas.
4. Detective: This control is BEST classified as which type?
- Detective ✓Correct. The report identifies events that have already occurred so they can be investigated, which is the defining purpose of a detective control.
- PreventiveIncorrect. A preventive control would block the off-hours access before it happens; a report produced after the fact does not prevent anything.
- CorrectiveIncorrect. A corrective control restores or remediates after an event; the report detects but does not itself fix or reverse the access.
- DeterrentIncorrect. A deterrent discourages action through awareness of consequences; a back-office report users may not know about does not primarily deter.
An after-the-fact report that surfaces events for investigation is a detective control.
5. The auditor's independence is impaired because they would: What is the MAIN concern with this assignment?
- The auditor's independence is impaired because they would be auditing their own prior work (self-review). ✓Correct. Auditing work you performed yourself creates a self-review threat that impairs objectivity and independence.
- The auditor lacks the technical knowledge and hands-on operational familiarity needed to assess the customer onboarding platform in sufficient depth.Incorrect. Having built the platform means the auditor has more, not less, technical knowledge; the problem is objectivity, not competence.
- The audit will take longer than a normal assignment.Incorrect. Duration is not the governing concern; the fundamental issue is the impairment to independence.
- The auditor cannot sign a non-disclosure agreement for a system they built.Incorrect. NDAs are unrelated to the self-review threat and would not resolve the independence impairment.
Auditing your own prior implementation work is a self-review threat that impairs independence.
6. A statement of the desired result or purpose to be: Which statement BEST describes what a 'control objective'
- A statement of the desired result or purpose to be achieved by implementing controls. ✓Correct. A control objective states the intended outcome (for example, 'only authorized changes are moved to production'); specific controls are the means of achieving it.
- The specific technical configuration and parameter settings that are used to enforce a particular security rule within the application.Incorrect. A specific configuration is a control activity, not the objective; the objective is the outcome the configuration is meant to achieve.
- The residual risk remaining after all controls are applied.Incorrect. Residual risk is what remains after controls operate; it is not the statement of intended purpose.
- The list of audit findings produced at the end of an engagement.Incorrect. Findings are audit results; a control objective is defined before testing as the target the control should meet.
A control objective is the intended outcome that controls are designed to achieve.
7. Consulting engagement: This engagement is BEST characterized as a(n):
- Consulting (advisory) engagement ✓Correct. Providing advice and recommendations without issuing an assurance opinion is the hallmark of a consulting/advisory engagement.
- Assurance engagementIncorrect. An assurance engagement results in an independent opinion or conclusion on a subject matter; here no opinion is expressed.
- Forensic investigationIncorrect. A forensic investigation examines a suspected irregularity or fraud for potential legal use; nothing here suggests wrongdoing.
- Certification auditIncorrect. A certification audit tests conformance to a standard to grant certification; the team is advising on design, not certifying.
Advising without expressing an opinion is a consulting/advisory engagement.
8. The audit committee approves the audit plan: Which arrangement would MOST effectively protect the audit functi
- The audit committee approves the audit plan, budget, and the hiring and removal of the audit manager. ✓Correct. Functional reporting to the audit committee over the plan, budget, and personnel decisions insulates audit from the influence of the CIO it audits.
- The CIO reviews, edits where necessary, and formally approves all audit findings before they are released to the audit committee.Incorrect. Letting an audited executive gate findings directly impairs independence and enables suppression of adverse results.
- The audit manager rotates reporting between the CIO and the CFO each quarter.Incorrect. Rotating among operational executives keeps audit under management influence rather than establishing board-level oversight.
- The audit manager submits the audit plan to the CIO for prioritization.Incorrect. Allowing the audited CIO to set audit priorities lets a subject shape its own scrutiny, undermining independence.
Functional reporting to the audit committee for plan, budget, and personnel decisions best protects independence.
9. Inherent risk: Which risk should the auditor evaluate FIRST for this purpose?
- Residual riskIncorrect. Residual risk reflects exposure after controls; the auditor specifically wants the picture 'regardless of controls,' which is inherent risk.
- Detection riskIncorrect. Detection risk is the chance the audit itself fails to catch a material issue; it is a property of the audit approach, not a basis for ranking the audit universe by significance.
- Control riskIncorrect. Control risk concerns the likelihood controls fail to prevent or detect an issue; it presumes controls exist and is not the 'regardless of controls' view requested.
- Inherent risk ✓Correct. Inherent risk is the exposure before considering controls, so it reveals which systems are intrinsically most significant when ranking the audit universe.
Inherent risk (before controls) drives which systems are intrinsically most significant when ranking the audit universe.
10. Independent daily review of a report of all disbursements: Which measure is the BEST compensating control?
- Encrypting the loan-origination database at rest.Incorrect. Encryption protects data confidentiality; it does nothing to address the segregation-of-duties weakness.
- Independent daily review of a report of all disbursements against supporting approvals by a supervisor who cannot enter transactions. ✓Correct. When the preferred preventive control (system-enforced SoD) is not feasible, an independent detective review by someone without transaction access compensates for the missing separation.
- Requiring the clerk to change their application password every 30 days.Incorrect. Password rotation addresses credential hygiene, not the concentration of incompatible duties in one person.
- Adding a prominent on-screen warning banner that reminds each clerk not to approve their own loan disbursements and states that violations may be reviewed later.Incorrect. A banner is a weak deterrent that does not detect or prevent the clerk from actually self-approving disbursements.
An independent detective review by someone without transaction access compensates for unenforceable SoD.
11. Integrated audit: Which audit type BEST fits this need?
- Compliance auditIncorrect. A compliance audit checks conformance to a rule set; the committee wants financial accuracy plus IT control effectiveness, not conformance to external rules.
- Integrated audit ✓Correct. An integrated audit combines financial/business process testing with IS controls testing in one coordinated engagement, matching the committee's need.
- Financial audit onlyIncorrect. A financial-only audit would not deliberately evaluate the effectiveness of the IT general controls as a coordinated objective.
- Operational auditIncorrect. An operational audit focuses on efficiency and effectiveness of operations, not the coordinated financial-accuracy-plus-ITGC scope described.
Combining financial-statement accuracy with IT general control effectiveness in one engagement is an integrated audit.
12. Independently verify the bucket configurations through: Applying due professional care under ITAF, what should
- Independently verify the bucket configurations through direct examination before concluding. ✓Correct. Due professional care requires the auditor to obtain sufficient and appropriate evidence rather than rely on unsubstantiated inquiry; direct examination corroborates the claim.
- Accept the DevOps lead's statement because they own the environment and know it best.Incorrect. Verbal inquiry alone is the weakest evidence; relying on it without corroboration breaches due professional care.
- Document the assurance as a management representation and issue an unqualified conclusion.Incorrect. A management representation supplements but does not replace independent evidence for a testable technical control.
- Expand the scope to include the firm's on-premises data center for comparison.Incorrect. Broadening scope to an unrelated environment does not address the need to verify the specific claim at hand.
Due professional care means corroborating verbal claims with independent, direct evidence.
77 more Information Systems Auditing Process questions
The remaining 77 questions in this domain are part of the full CISA bank — 496 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CISA readiness — freeOther CISA domains
- Information Systems Operations and Business Resilience — 129 questions →
- Protection of Information Assets — 129 questions →
- Governance and Management of IT — 89 questions →
- Information Systems Acquisition, Development and Implementation — 60 questions →
- All 496 CISA questions →