CERTIFIED INFORMATION SYSTEMS
AUDITOR (CISA) CERTIFICATION: COMPLETE
PRACTICE EXAM WITH ANSWERS AND
RATIONALES
DOMAIN 1: INFORMATION SYSTEMS AUDITING PROCESS
Question 1
What is the primary objective of an information systems audit?
A) To ensure financial statements are accurate
B) To evaluate and provide assurance on the organization's information systems
and related controls
C) To develop new security policies for the organization
D) To replace the internal audit function
Answer: B
Rationale: The primary objective of an IS audit is to evaluate the design,
effectiveness, and efficiency of controls over information systems and provide
assurance to stakeholders. Financial statement accuracy (A) is the domain of
financial audits. Developing security policies (C) is a management function, and IS
audit does not replace internal audit (D) but complements it .
Question 2
Which of the following is the most important reason for an IS auditor to adopt a
risk-based approach?
,A) To minimize audit costs
B) To ensure all controls are tested equally
C) To focus audit resources on areas with the highest risk to the organization
D) To comply with regulatory requirements
Answer: C
Rationale: A risk-based approach prioritizes audit activities on areas where the
potential for loss or harm is greatest, making efficient use of limited audit
resources. Cost minimization (A) and equal testing (B) are not appropriate
objectives—resources should be allocated where risk is highest. Regulatory
compliance (D) is one consideration but not the primary reason .
Question 3
During the planning phase of an IS audit, the auditor should first:
A) Develop detailed test procedures
B) Obtain an understanding of the entity's business environment and industry
C) Prepare the final audit report
D) Select the audit team members
Answer: B
Rationale: Before developing procedures (A), the auditor must understand the
business environment, industry, and regulatory landscape to identify relevant risks
and scope the audit appropriately. Preparing the report (C) occurs at the end, and
team selection (D) follows scoping decisions.
Question 4
What is the purpose of a "walkthrough" in an IS audit?
,A) To test the physical security of the data center
B) To trace a single transaction from initiation to completion to understand the
process and identify control gaps
C) To interview all employees in a department
D) To perform a full data extraction
Answer: B
Rationale: A walkthrough involves selecting one or a few transactions and
following them through the entire process to understand the flow and identify
where controls should be applied. Physical security testing (A), interviewing all
employees (C), and full data extraction (D) are not walkthroughs .
Question 5
Which of the following should be specified in an IS audit charter?
A) Detailed audit procedures for each engagement
B) Specific audit objectives for the upcoming year
C) The overall authority, scope, and responsibilities of the audit function
D) Names of audit staff assigned to each engagement
Answer: C
Rationale: The audit charter is a formal document approved by the board or audit
committee that establishes the internal audit function's purpose, authority, and
accountability. Detailed procedures (A), specific objectives (B), and staff
assignments (D) are operational and not part of the charter .
Question 6
Which type of testing determines whether a control is operating as designed?
, A) Substantive testing
B) Compliance testing
C) Integrated testing
D) Forensic testing
Answer: B
Rationale: Compliance testing (also called control testing) determines whether
controls are being applied as designed and operating effectively. Substantive
testing (A) verifies data accuracy. Integrated testing (C) and forensic testing (D) are
different types of procedures .
Question 7
Which type of audit evidence is considered most reliable?
A) Oral statements from management
B) System-generated log files with integrity controls
C) A memo from the system administrator
D) User survey results
Answer: B
Rationale: System-generated logs with integrity controls provide objective,
independent evidence. Oral statements (A) are least reliable. Memos (C) and
surveys (D) are subjective and potentially biased. Original documents obtained
directly by the auditor are also highly reliable .
Question 8
An IS auditor is planning to use sampling to test a large population of transactions.
Which factor has the greatest impact on determining the sample size?
AUDITOR (CISA) CERTIFICATION: COMPLETE
PRACTICE EXAM WITH ANSWERS AND
RATIONALES
DOMAIN 1: INFORMATION SYSTEMS AUDITING PROCESS
Question 1
What is the primary objective of an information systems audit?
A) To ensure financial statements are accurate
B) To evaluate and provide assurance on the organization's information systems
and related controls
C) To develop new security policies for the organization
D) To replace the internal audit function
Answer: B
Rationale: The primary objective of an IS audit is to evaluate the design,
effectiveness, and efficiency of controls over information systems and provide
assurance to stakeholders. Financial statement accuracy (A) is the domain of
financial audits. Developing security policies (C) is a management function, and IS
audit does not replace internal audit (D) but complements it .
Question 2
Which of the following is the most important reason for an IS auditor to adopt a
risk-based approach?
,A) To minimize audit costs
B) To ensure all controls are tested equally
C) To focus audit resources on areas with the highest risk to the organization
D) To comply with regulatory requirements
Answer: C
Rationale: A risk-based approach prioritizes audit activities on areas where the
potential for loss or harm is greatest, making efficient use of limited audit
resources. Cost minimization (A) and equal testing (B) are not appropriate
objectives—resources should be allocated where risk is highest. Regulatory
compliance (D) is one consideration but not the primary reason .
Question 3
During the planning phase of an IS audit, the auditor should first:
A) Develop detailed test procedures
B) Obtain an understanding of the entity's business environment and industry
C) Prepare the final audit report
D) Select the audit team members
Answer: B
Rationale: Before developing procedures (A), the auditor must understand the
business environment, industry, and regulatory landscape to identify relevant risks
and scope the audit appropriately. Preparing the report (C) occurs at the end, and
team selection (D) follows scoping decisions.
Question 4
What is the purpose of a "walkthrough" in an IS audit?
,A) To test the physical security of the data center
B) To trace a single transaction from initiation to completion to understand the
process and identify control gaps
C) To interview all employees in a department
D) To perform a full data extraction
Answer: B
Rationale: A walkthrough involves selecting one or a few transactions and
following them through the entire process to understand the flow and identify
where controls should be applied. Physical security testing (A), interviewing all
employees (C), and full data extraction (D) are not walkthroughs .
Question 5
Which of the following should be specified in an IS audit charter?
A) Detailed audit procedures for each engagement
B) Specific audit objectives for the upcoming year
C) The overall authority, scope, and responsibilities of the audit function
D) Names of audit staff assigned to each engagement
Answer: C
Rationale: The audit charter is a formal document approved by the board or audit
committee that establishes the internal audit function's purpose, authority, and
accountability. Detailed procedures (A), specific objectives (B), and staff
assignments (D) are operational and not part of the charter .
Question 6
Which type of testing determines whether a control is operating as designed?
, A) Substantive testing
B) Compliance testing
C) Integrated testing
D) Forensic testing
Answer: B
Rationale: Compliance testing (also called control testing) determines whether
controls are being applied as designed and operating effectively. Substantive
testing (A) verifies data accuracy. Integrated testing (C) and forensic testing (D) are
different types of procedures .
Question 7
Which type of audit evidence is considered most reliable?
A) Oral statements from management
B) System-generated log files with integrity controls
C) A memo from the system administrator
D) User survey results
Answer: B
Rationale: System-generated logs with integrity controls provide objective,
independent evidence. Oral statements (A) are least reliable. Memos (C) and
surveys (D) are subjective and potentially biased. Original documents obtained
directly by the auditor are also highly reliable .
Question 8
An IS auditor is planning to use sampling to test a large population of transactions.
Which factor has the greatest impact on determining the sample size?