(VERIFIED ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.
Core Domains:
*Domain 1: Information System Auditing Process*
*Domain 2: Governance and Management of IT*
*Domain 3: Information Systems Acquisition, Development, and Implementation*
*Domain 4: Information Systems Operations and Business Resilience*
*Domain 5: Protection of Information Assets*
*Domain 6: IT Service Delivery and Infrastructure Support*
, *Domain 7: Enterprise Architecture and Risk Management*
*Domain 8: Regulatory Compliance and Professional Ethics*
Introduction:
The Certified Information Systems Auditor (CISA) examination assessment is designed to validate the
knowledge, skills, and expertise required to effectively audit, control, monitor, and assess an organization’s
information technology and business systems. This comprehensive test bank features a rigorous blend of
foundational theory, applied professional knowledge, and complex, scenario-based questions that mirror real-
world information systems environments. Candidates are evaluated on their critical thinking capabilities,
regulatory compliance knowledge, and strategic decision-making proficiency. Every question is structured to
simulate the high-stakes environment of the actual examination, ensuring professionals can confidently
demonstrate operational and governance excellence across all core IT audit domains.
Section One: Questions 1–100
Question 1
An IS auditor is reviewing an organization's IT strategic plan. Which of the following is the MOST important
element to ensure alignment with business objectives?
A. The presence of a defined budget for IT projects
B. The involvement of the Chief Information Officer in business planning sessions
C. Explicit mapping of IT initiatives to specific business goals
D. A comprehensive inventory of current IT infrastructure
,🟢 C. Explicit mapping of IT initiatives to specific business goals
🔴 RATIONALE: To ensure alignment, IT strategic plans must explicitly demonstrate how technological
investments and projects support and advance business objectives. While executive involvement and
budgeting are critical, direct mapping provides the definitive evidence of strategic alignment.
Question 2
During a post-implementation review of an enterprise resource planning (ERP) system, an IS auditor notes that
several data fields contain duplicate customer records. Which of the following controls should the auditor
recommend implementing at the data entry stage?
A. Reasonableness check
B. Completeness check
C. Validity check
D. Sequence check
🟢 C. Validity check
🔴 RATIONALE: A validity check compares entered data against predefined criteria or existing master records
to ensure accuracy and uniqueness, effectively preventing duplicate entries. Completeness and sequence
checks do not validate the unique identity of the data packet.
Question 3
Which of the following would be the GREATEST concern for an IS auditor reviewing an organization's business
continuity plan (BCP)?
A. The plan has not been updated in the last six months.
B. The recovery time objective (RTO) is shorter than the recovery point objective (RPO).
C. The backup media are stored in an offsite location managed by a third party.
, D. The plan has not been tested against realistic disaster scenarios.
🟢 D. The plan has not been tested against realistic disaster scenarios.
🔴 RATIONALE: An untested business continuity plan cannot be verified for efficacy or operational readiness.
Lack of testing introduces systemic risk, making it a critical vulnerability compared to update frequency or
external media storage arrangements.
Question 4
An IS auditor discovers that a database administrator (DBA) also possesses the user rights to modify
application program code in production. What type of control deficiency does this represent?
A. Inadequate configuration management
B. Lack of segregation of duties
C. Deficient change control authorization
D. Poor access control monitoring
🟢 B. Lack of segregation of duties
🔴 RATIONALE: Combining database administration rights with production application code modification
privileges violates the principle of segregation of duties, as it allows an individual to make unapproved structural
and operational changes without independent oversight.
Question 5
When evaluating the effectiveness of a network vulnerability scanning process, an IS auditor should first verify
that:
A. Scans are performed daily during peak business hours.
B. The scanning tool signatures are updated regularly.