AUDITOR (CISA) EXAMINATION
QUESTIONS AND CORRECT ANSWERS
(VERIFIED ANSWERS) PLUS RATIONALES
2026 Q&A | INSTANT DOWNLOAD PDF
1. An IS auditor is primarily responsible for:
A. Designing IT systems
B. Managing network infrastructure
C. Evaluating controls within information systems
D. Writing application code
Correct Answer: C
Rationale: IS auditors are independent evaluators who assess whether
information systems, controls, and governance processes are properly designed
and operating effectively. They do not design systems or perform operational IT
tasks, as independence is essential for objective assurance.
2. The main purpose of IT governance is to:
A. Reduce hardware costs
B. Ensure alignment of IT with business objectives
C. Eliminate all IT risks
D. Replace management decision-making
Correct Answer: B
Rationale: IT governance ensures that IT strategies, investments, and operations
align with organizational goals and deliver value. It does not eliminate risk
entirely but ensures risk is managed within acceptable levels.
, 3. Which of the following is the MOST important attribute of an IS auditor?
A. Programming expertise
B. Independence
C. Sales ability
D. Network configuration skills
Correct Answer: B
Rationale: Independence ensures auditors can provide unbiased and objective
assessments. Without independence, audit findings may be influenced or
compromised.
4. A risk assessment primarily helps an organization to:
A. Eliminate all vulnerabilities
B. Identify and prioritize risks
C. Replace internal controls
D. Avoid audits
Correct Answer: B
Rationale: Risk assessment is used to identify threats and vulnerabilities and
prioritize them based on impact and likelihood, enabling better control selection
and resource allocation.
5. Which control is designed to prevent unauthorized access?
A. Detective control
B. Corrective control
C. Preventive control
D. Compensating control
Correct Answer: C
Rationale: Preventive controls stop security incidents before they occur, such as
authentication mechanisms and access control systems.
6. An example of a detective control is:
A. Firewall
B. Antivirus installation
C. Audit logs review
, D. Encryption
Correct Answer: C
Rationale: Detective controls identify and report events after they occur. Log
reviews help detect suspicious activities or breaches.
7. The PRIMARY goal of an IS audit is to:
A. Fix system vulnerabilities
B. Provide assurance on controls
C. Develop software applications
D. Replace IT management
Correct Answer: B
Rationale: IS audits provide independent assurance that controls are effective
and risks are managed properly, not to fix or manage systems.
8. Which phase comes FIRST in an audit process?
A. Fieldwork
B. Reporting
C. Planning
D. Follow-up
Correct Answer: C
Rationale: Audit planning defines scope, objectives, and methodology before
fieldwork begins to ensure a structured audit approach.
9. A firewall is an example of:
A. Physical control
B. Preventive logical control
C. Detective control
D. Administrative control
Correct Answer: B
Rationale: Firewalls prevent unauthorized network access and are technical
preventive controls implemented at the system level.