CISA Information Systems Auditing Process practice questions
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

CISA Information Systems Auditing Process: 89 practice questions

CISA 89 questions 12 shown free

12 of the 89 Information Systems Auditing Process questions in the Certsqill CISA bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CISA? Take the free 5-min readiness check →

1. Standards are mandatory requirements: Within ISACA's Information Technology Assurance Framework (ITAF), what i

Easy
Within ISACA's Information Technology Assurance Framework (ITAF), what is the defining difference between an IS audit standard and an IS audit guideline?
  1. Standards are mandatory requirements, while guidelines provide guidance on how to apply the standards.
    Correct. In ITAF, standards define mandatory requirements for IS audit and assurance work, whereas guidelines offer non-mandatory direction on applying those standards.
  2. Standards apply only to external auditors, while guidelines apply only to internal auditors.
    Incorrect. ITAF applies to IS audit and assurance professionals regardless of internal or external status; the distinction is mandatory versus advisory, not audience.
  3. Guidelines are mandatory requirements, while standards describe optional leading practices.
    Incorrect. This reverses the relationship; guidelines are the advisory layer and standards are the mandatory layer.
  4. Standards are set by regulators, while guidelines are set by ISACA.
    Incorrect. Both ITAF standards and guidelines are issued by ISACA; regulators do not author ITAF.
The trap
Believing guidelines carry the same mandatory weight as standards, or reversing which layer is binding.

ITAF standards are mandatory; guidelines are advisory guidance on how to meet the standards.

2. Compliance audit: Which type of audit is this?

Easy
A regional credit union engages an IS auditor to determine whether its card-processing environment adheres to the contractual security requirements imposed by its payment brand. Which type of audit is this?
  1. Compliance audit
    Correct. A compliance audit evaluates adherence to specific external or contractual rules, regulations, or standards, which is exactly what payment-brand security requirements represent.
  2. Financial audit
    Incorrect. A financial audit expresses an opinion on the fairness of financial statements, not adherence to security requirements.
  3. Operational audit
    Incorrect. An operational audit evaluates the efficiency and effectiveness of operations, not conformance to a defined external requirement set.
  4. Integrated audit
    Incorrect. An integrated audit combines financial and IS/operational testing; the scope here is limited to conformance with defined security rules.
The trap
Assuming any security-focused engagement is automatically an operational or security audit rather than a compliance audit against a defined requirement set.

Testing adherence to a defined external/contractual rule set is a compliance audit.

3. To direct limited audit resources toward the areas: What is the PRIMARY reason an IS audit function adopts a r

Easy
What is the PRIMARY reason an IS audit function adopts a risk-based approach when building its annual audit plan?
  1. To direct limited audit resources toward the areas of greatest risk to the organization.
    Correct. Risk-based planning concentrates finite audit effort where the potential impact and likelihood of adverse events are highest, maximizing assurance value.
  2. To guarantee that every application and infrastructure system across the organization is formally audited at least once during each calendar year.
    Incorrect. Risk-based planning deliberately does not cover everything annually; it prioritizes higher-risk areas over uniform coverage.
  3. To reduce the total number of controls the organization must maintain.
    Incorrect. Audit planning does not remove control obligations; management owns controls regardless of the audit schedule.
  4. To eliminate the need for management to perform its own risk assessment.
    Incorrect. The audit function's risk assessment does not replace management's responsibility for risk management; they are separate.
The trap
Thinking risk-based planning aims for complete annual coverage of the entire audit universe.

Risk-based planning aligns scarce audit resources with the highest-risk areas.

4. Detective: This control is BEST classified as which type?

Easy
A logistics company configures its systems to generate a daily report listing every user account that accessed the freight-billing database outside of business hours. This control is BEST classified as which type?
  1. Detective
    Correct. The report identifies events that have already occurred so they can be investigated, which is the defining purpose of a detective control.
  2. Preventive
    Incorrect. A preventive control would block the off-hours access before it happens; a report produced after the fact does not prevent anything.
  3. Corrective
    Incorrect. A corrective control restores or remediates after an event; the report detects but does not itself fix or reverse the access.
  4. Deterrent
    Incorrect. A deterrent discourages action through awareness of consequences; a back-office report users may not know about does not primarily deter.
The trap
Labeling any security-related monitoring output as 'preventive' because it involves access control.

An after-the-fact report that surfaces events for investigation is a detective control.

5. The auditor's independence is impaired because they would: What is the MAIN concern with this assignment?

Easy
An IS auditor is asked to audit a customer onboarding platform that the same auditor personally configured and deployed one year earlier while working in the IT operations team. What is the MAIN concern with this assignment?
  1. The auditor's independence is impaired because they would be auditing their own prior work (self-review).
    Correct. Auditing work you performed yourself creates a self-review threat that impairs objectivity and independence.
  2. The auditor lacks the technical knowledge and hands-on operational familiarity needed to assess the customer onboarding platform in sufficient depth.
    Incorrect. Having built the platform means the auditor has more, not less, technical knowledge; the problem is objectivity, not competence.
  3. The audit will take longer than a normal assignment.
    Incorrect. Duration is not the governing concern; the fundamental issue is the impairment to independence.
  4. The auditor cannot sign a non-disclosure agreement for a system they built.
    Incorrect. NDAs are unrelated to the self-review threat and would not resolve the independence impairment.
The trap
Assuming deep familiarity with a system is always an asset and overlooking the self-review independence threat it creates.

Auditing your own prior implementation work is a self-review threat that impairs independence.

6. A statement of the desired result or purpose to be: Which statement BEST describes what a 'control objective'

Easy
An IS auditor is reviewing the stated purpose behind a set of implemented controls before testing them. Which statement BEST describes what a 'control objective' is?
  1. A statement of the desired result or purpose to be achieved by implementing controls.
    Correct. A control objective states the intended outcome (for example, 'only authorized changes are moved to production'); specific controls are the means of achieving it.
  2. The specific technical configuration and parameter settings that are used to enforce a particular security rule within the application.
    Incorrect. A specific configuration is a control activity, not the objective; the objective is the outcome the configuration is meant to achieve.
  3. The residual risk remaining after all controls are applied.
    Incorrect. Residual risk is what remains after controls operate; it is not the statement of intended purpose.
  4. The list of audit findings produced at the end of an engagement.
    Incorrect. Findings are audit results; a control objective is defined before testing as the target the control should meet.
The trap
Confusing the control objective (desired outcome) with the specific control activity (the mechanism) or with residual risk.

A control objective is the intended outcome that controls are designed to achieve.

7. Consulting engagement: This engagement is BEST characterized as a(n):

Easy
A telecom operator's internal audit team is asked to advise a project team on how to design segregation-of-duties controls for a new provisioning system still under development, without expressing an opinion. This engagement is BEST characterized as a(n):
  1. Consulting (advisory) engagement
    Correct. Providing advice and recommendations without issuing an assurance opinion is the hallmark of a consulting/advisory engagement.
  2. Assurance engagement
    Incorrect. An assurance engagement results in an independent opinion or conclusion on a subject matter; here no opinion is expressed.
  3. Forensic investigation
    Incorrect. A forensic investigation examines a suspected irregularity or fraud for potential legal use; nothing here suggests wrongdoing.
  4. Certification audit
    Incorrect. A certification audit tests conformance to a standard to grant certification; the team is advising on design, not certifying.
The trap
Treating every internal audit activity as an assurance engagement that produces an opinion.

Advising without expressing an opinion is a consulting/advisory engagement.

8. The audit committee approves the audit plan: Which arrangement would MOST effectively protect the audit functi

Medium
At a pharmaceutical manufacturer, the IS audit manager reports functionally to the audit committee but administratively to the CIO, whose function is a frequent audit subject. Which arrangement would MOST effectively protect the audit function's independence?
  1. The audit committee approves the audit plan, budget, and the hiring and removal of the audit manager.
    Correct. Functional reporting to the audit committee over the plan, budget, and personnel decisions insulates audit from the influence of the CIO it audits.
  2. The CIO reviews, edits where necessary, and formally approves all audit findings before they are released to the audit committee.
    Incorrect. Letting an audited executive gate findings directly impairs independence and enables suppression of adverse results.
  3. The audit manager rotates reporting between the CIO and the CFO each quarter.
    Incorrect. Rotating among operational executives keeps audit under management influence rather than establishing board-level oversight.
  4. The audit manager submits the audit plan to the CIO for prioritization.
    Incorrect. Allowing the audited CIO to set audit priorities lets a subject shape its own scrutiny, undermining independence.
The trap
Assuming administrative reporting to the CIO is inherently disqualifying, when it is the CIO's control over plan, findings, or the auditor's tenure that actually impairs independence.

Functional reporting to the audit committee for plan, budget, and personnel decisions best protects independence.

9. Inherent risk: Which risk should the auditor evaluate FIRST for this purpose?

Medium
While ranking the audit universe for a solar-energy utility, an IS auditor wants to identify which systems warrant the most audit attention regardless of the controls management has already deployed. Which risk should the auditor evaluate FIRST for this purpose?
  1. Residual risk
    Incorrect. Residual risk reflects exposure after controls; the auditor specifically wants the picture 'regardless of controls,' which is inherent risk.
  2. Detection risk
    Incorrect. Detection risk is the chance the audit itself fails to catch a material issue; it is a property of the audit approach, not a basis for ranking the audit universe by significance.
  3. Control risk
    Incorrect. Control risk concerns the likelihood controls fail to prevent or detect an issue; it presumes controls exist and is not the 'regardless of controls' view requested.
  4. Inherent risk
    Correct. Inherent risk is the exposure before considering controls, so it reveals which systems are intrinsically most significant when ranking the audit universe.
The trap
Reaching for residual risk when the question explicitly excludes the effect of existing controls, which points to inherent risk.

Inherent risk (before controls) drives which systems are intrinsically most significant when ranking the audit universe.

10. Independent daily review of a report of all disbursements: Which measure is the BEST compensating control?

Medium
At a rural community bank, a legacy loan-origination application cannot technically enforce segregation of duties, so one clerk can both create and approve loan disbursements. Replacing the application is not feasible this year. Which measure is the BEST compensating control?
  1. Encrypting the loan-origination database at rest.
    Incorrect. Encryption protects data confidentiality; it does nothing to address the segregation-of-duties weakness.
  2. Independent daily review of a report of all disbursements against supporting approvals by a supervisor who cannot enter transactions.
    Correct. When the preferred preventive control (system-enforced SoD) is not feasible, an independent detective review by someone without transaction access compensates for the missing separation.
  3. Requiring the clerk to change their application password every 30 days.
    Incorrect. Password rotation addresses credential hygiene, not the concentration of incompatible duties in one person.
  4. Adding a prominent on-screen warning banner that reminds each clerk not to approve their own loan disbursements and states that violations may be reviewed later.
    Incorrect. A banner is a weak deterrent that does not detect or prevent the clerk from actually self-approving disbursements.
The trap
Selecting a control that addresses a different risk (passwords, encryption) instead of one that actually offsets the specific segregation-of-duties weakness.

An independent detective review by someone without transaction access compensates for unenforceable SoD.

11. Integrated audit: Which audit type BEST fits this need?

Medium
An insurance company's audit committee wants a single engagement that evaluates both the accuracy of premium revenue reported in the financial statements and the effectiveness of the IT general controls over the policy-administration system that produces those figures. Which audit type BEST fits this need?
  1. Compliance audit
    Incorrect. A compliance audit checks conformance to a rule set; the committee wants financial accuracy plus IT control effectiveness, not conformance to external rules.
  2. Integrated audit
    Correct. An integrated audit combines financial/business process testing with IS controls testing in one coordinated engagement, matching the committee's need.
  3. Financial audit only
    Incorrect. A financial-only audit would not deliberately evaluate the effectiveness of the IT general controls as a coordinated objective.
  4. Operational audit
    Incorrect. An operational audit focuses on efficiency and effectiveness of operations, not the coordinated financial-accuracy-plus-ITGC scope described.
The trap
Splitting the objective and picking a single-discipline audit, missing that the coordinated financial-plus-IT scope defines an integrated audit.

Combining financial-statement accuracy with IT general control effectiveness in one engagement is an integrated audit.

12. Independently verify the bucket configurations through: Applying due professional care under ITAF, what should

Medium
During a cloud migration audit at a media streaming firm, an IS auditor receives verbal assurance from the DevOps lead that all storage buckets are private. Applying due professional care under ITAF, what should the auditor do?
  1. Independently verify the bucket configurations through direct examination before concluding.
    Correct. Due professional care requires the auditor to obtain sufficient and appropriate evidence rather than rely on unsubstantiated inquiry; direct examination corroborates the claim.
  2. Accept the DevOps lead's statement because they own the environment and know it best.
    Incorrect. Verbal inquiry alone is the weakest evidence; relying on it without corroboration breaches due professional care.
  3. Document the assurance as a management representation and issue an unqualified conclusion.
    Incorrect. A management representation supplements but does not replace independent evidence for a testable technical control.
  4. Expand the scope to include the firm's on-premises data center for comparison.
    Incorrect. Broadening scope to an unrelated environment does not address the need to verify the specific claim at hand.
The trap
Treating a knowledgeable insider's verbal assurance as sufficient evidence instead of independently testing a verifiable technical control.

Due professional care means corroborating verbal claims with independent, direct evidence.

77 more Information Systems Auditing Process questions

The remaining 77 questions in this domain are part of the full CISA bank — 496 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CISA readiness — free

Other CISA domains

Part of the Certsqill CISA question bank · Information Systems Auditing Process · Every answer, right and wrong, comes with its own explanation.