Exam
Full Professional Practice Examination
Question 1
Which of the following is the PRIMARY objective of an information systems audit?
A. To eliminate all organizational risks B. To ensure that IT investments generate profit C. To provide
assurance that controls support business objectives and mitigate risks D. To replace management
oversight responsibilities
Answer: C. To provide assurance that controls support business objectives and mitigate risks
Rationale: The primary objective of an information systems audit is to provide independent assurance
that controls are properly designed and operating effectively to support organizational goals while
mitigating risks. Auditors evaluate governance, risk management, and control processes to determine
whether systems safeguard assets, maintain data integrity, support operational effectiveness, and
comply with applicable laws and policies. Eliminating all risks is impossible, and management—not
auditors—retains responsibility for oversight and operational decisions.
Question 2
Which of the following provides the MOST reliable audit evidence?
A. Verbal confirmation from management B. Copies of internally generated reports C. Auditor
observation of a control being performed D. Evidence obtained directly from an independent external
source
Answer: D. Evidence obtained directly from an independent external source
Rationale: Evidence obtained directly from independent external sources is generally considered the
most reliable because it is less likely to be biased or manipulated. External confirmations, such as
bank statements or third-party confirmations, carry higher evidentiary value than internally generated
reports or verbal representations. Observation is useful but only reflects conditions at a specific point
in time.
Question 3
During audit planning, an IS auditor should FIRST:
A. Conduct substantive testing B. Review prior audit findings C. Develop the final audit report D. Notify
regulators of the engagement
Answer: B. Review prior audit findings
1
,Rationale: Reviewing prior audit findings helps the auditor understand historical weaknesses,
recurring issues, and areas of elevated risk. This information supports effective planning, risk
assessment, and scoping. Substantive testing occurs later in the audit process, while reporting and
regulatory notifications are not initial planning activities.
Question 4
Which type of control is designed to identify errors after processing has occurred?
A. Preventive control B. Detective control C. Directive control D. Corrective control
Answer: B. Detective control
Rationale: Detective controls identify errors or irregularities after they occur. Examples include
reconciliations, audit logs, exception reports, and intrusion detection systems. Preventive controls stop
errors before occurrence, directive controls guide behavior, and corrective controls restore systems or
processes after an issue has been detected.
Question 5
An IS auditor discovers that developers have unrestricted access to production systems. What is the
GREATEST concern?
A. Increased software licensing costs B. Reduced system performance C. Lack of segregation of duties
D. Delayed incident response
Answer: C. Lack of segregation of duties
Rationale: Allowing developers unrestricted access to production systems creates a serious
segregation-of-duties conflict. Developers may introduce unauthorized changes, conceal fraud, or
bypass established change management controls. Proper segregation ensures that development,
testing, and production responsibilities are separated to reduce the risk of errors and intentional
misconduct.
Question 6
Which of the following BEST indicates effective IT governance?
A. IT strategies are aligned with business objectives B. All IT decisions are centralized within the IT
department C. IT auditors approve all technology purchases D. End users manage cybersecurity policies
independently
Answer: A. IT strategies are aligned with business objectives
Rationale: Effective IT governance ensures that IT investments and operations support organizational
objectives, optimize resources, and manage risk appropriately. Alignment between business and IT
strategies is a fundamental principle of governance frameworks such as COBIT. Centralized decision-
making alone does not guarantee governance effectiveness, and auditors should remain independent
rather than approving operational decisions.
2
, Question 7
The PRIMARY purpose of a risk assessment during audit planning is to:
A. Eliminate all audit procedures B. Determine the audit scope and focus areas C. Replace management
controls D. Reduce staffing requirements
Answer: B. Determine the audit scope and focus areas
Rationale: Risk assessment enables auditors to identify high-risk areas requiring greater audit
attention. By evaluating inherent and residual risks, auditors can allocate resources efficiently and
define an appropriate scope. The purpose is not to eliminate procedures or replace management
responsibilities.
Question 8
Which of the following controls would BEST protect against unauthorized system access?
A. Data classification standards B. Role-based access control C. Network performance monitoring D.
Software asset inventory
Answer: B. Role-based access control
Rationale: Role-based access control (RBAC) restricts system access according to job responsibilities
and the principle of least privilege. This minimizes unauthorized access and reduces security risk. Data
classification supports information management, while performance monitoring and asset inventories
address different operational concerns.
Question 9
An organization’s disaster recovery plan should be tested primarily to:
A. Meet software licensing requirements B. Ensure backup media are encrypted C. Validate the
effectiveness of recovery procedures D. Eliminate the need for business continuity planning
Answer: C. Validate the effectiveness of recovery procedures
Rationale: Disaster recovery testing ensures that recovery procedures, personnel, systems, and
resources function effectively during an actual disruption. Testing identifies gaps, validates recovery
time objectives, and increases organizational preparedness. It does not eliminate the need for broader
business continuity planning.
Question 10
Which audit sampling method gives every item in a population an equal chance of selection?
A. Judgmental sampling B. Haphazard sampling C. Statistical random sampling D. Discovery sampling
Answer: C. Statistical random sampling
3