Questions with complete solution
2026
The IA department has written some scripts that are used for continuous auditing of some IS. The IT
department has asked for copies of the scripts so that they can use them for setting up a continuous
monitoring process on key systems. Would sharing these scripts with IT affect the ability of the US
auditors to independently audit the IT functions? - correct answer ✔Sharing the scripts is permissible
as long as IT recognized that audits may still be conducted in areas not covered in scripts
Which of the following is the BEST factors for determining the required extent of data collection during
the planning phase of an IS compliance audit? - correct answer ✔Purpose, objectivity, and scope of the
audit
An IS auditor is developing an audit plan for an environment that includes new systems. The co's mgt
wants the IS auditor to focus on recently implemented systems. How should the IS auditor respond? -
correct answer ✔Determine the highest risk systems and plan accordingly
An IS auditor is reviewing security controls for a critical web-based system prior to implementation. The
results of the penetration tests are inconclusive, and the results will not be finalized prior to
implementation. Which of the following is the BEST option for the IS auditor? - correct answer
✔Publish a report based on the available info, highlighting the potential security weakness and the
requirement for followup auditing.
An IS auditor is verifying IT policies and found that some of the policies have not been approved by
management, but the employees strictly follow the policies. What should the IS auditor do FIRST? -
correct answer ✔Report the absence of documented approval
An IS auditor found that the enterprise architecture (EA) recently adopted by an organization has an
adequate current-state representation. However, the organization has started a separate project to
develop a future-state representation. The IS auditor should - correct answer ✔report this issue as a
finding in the audit report
, What is the PRIMARY requirement that a data mining and auditing software tool should meet? The
software tool should: - correct answer ✔accurately capture data from the orgs systems without causing
excessive performance problems
A long-term IT employee with a strong technical background and broad managerial experience has
applied for a vacant position in the IS audit department. Determining whether to hire this individual for
this position should be primarily based on the individual's experience and: - correct answer ✔ability,
and an IS auditor, to be independent of existing IT relationships
For a retail business with a large volume of transactions, which of the following audit techniques is most
appropriate for addressing emerging risk? - correct answer ✔Continuous auditing
An IS auditor is reviewing access to an application to determine whether recently added accounts were
appropriately authorized. This is an example of: - correct answer ✔Compliance testing
The decisions and actions of an IS auditor are most likely to affect which of the following types of risk? -
correct answer ✔Detection
Which of the following is the MOST critical step when planning and IS audit? - correct answer
✔Perform a risk assessment
An audit charter should: - correct answer ✔outline the overall authority, scope, and responsibilities of
the audit function
An IS auditor finds a small number of user access requests that had not been authorized by managers
through the normal predicted workflow steps and escalation rules. The IS auditor should: - correct
answer ✔Perform an additional analysis
When testing program change requests for a remote system, an IS auditor finds that the number of
changes available for sampling would not provide a reasonable level of assurance. What is the most