• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 29 pages
Exam (elaborations)

CISA Exam 2026/2027 – Certified Information Systems Auditor | 100 Practice Questions with Answers & Comprehensive Study Guide

Document preview thumbnail
Preview 3 out of 29 pages

This CISA practice test covers core Certified Information Systems Auditor topics through 100 exam-style questions designed for certification preparation. It supports review of information systems auditing, IT governance, risk management, security, controls, and related audit concepts. Ideal for structured CISA exam practice and comprehensive review.

Content preview

CISA PRACTICE TEST 2026/2027 · Information systems auditor practice examination




CISA EXAM 2026/2027 — CERTIFIED INFORMATION
SYSTEMS AUDITOR PRACTICE TEST WITH 100 QUESTIONS
ISACA job-practice outline in effect since August 2024 · Five domains, study weights / 12 /

Answers integrated · Rationales included · For study and review
Disclaimer. This is an original practice test written for education. It is not an official, verified, authenticated, or
endorsed examination of ISACA, and it does not reproduce ISACA sample items or any live examination question. CISA
and ISACA are used only to identify the examination being studied. A result on this practice test does not predict or
guarantee a certification result. Confirm the current exam content outline, candidate guide, and standards before
relying on an item. Keyed choices are printed in readable cyan-blue (#007C8A) rather than pure cyan (#00FFFF),
which is nearly invisible on a white page.

Section 1: Brief Introduction
The CISA examination consists of 150 multiple-choice questions across five job-practice
domains, weighted 18, 18, 12, 26, and 26 percent on the outline in effect since August 2024, and
candidates have four hours. A passing result is a scaled score of 450 or higher on a 200-to-800
scale, which ISACA does not publish as a percentage of items correct. This 100-item set follows
those weights for study and is not an official or verified ISACA examination.

Section 2: The Complete Exam
Each item is self-contained. Select the single best answer. The keyed choice is set in bold cyan-blue
(#007C8A, used because pure #00FFFF disappears on white). A rationale follows every item.

Information System Auditing Process
Risk-based planning, evidence, sampling, reporting, follow-up, and the independence of the audit function.
Eighteen percent of the live outline.
1. What is the primary purpose of an audit charter?
A. To document management's risk acceptance.
B. To grant the audit function its authority, scope, and responsibility, normally from
the board or audit committee.
C. To replace the engagement letter for each audit.
D. To list every control the auditor will test during the year.
Rationale: The charter establishes organizational authority and independence. It is not the
annual plan, the engagement letter, or a risk-acceptance record. Without it, access and
reporting lines are unclear.




Original practice material · Not an official ISACA examination · Page 1

,CISA PRACTICE TEST 2026/2027 · Information systems auditor practice examination




2. Which reporting line best protects the independence of the IS audit function?
A. The chief audit executive reports functionally to the audit committee and
administratively to executive management.
B. The external financial auditor directs the internal IS audit plan.
C. The IS audit manager reports only to the chief information officer.
D. Auditors report to the manager of the system they are reviewing.
Rationale: Functional reporting to the board or audit committee protects independence.
Reporting only to the CIO, or to the manager of the audited system, impairs it. External auditors
do not own the internal audit plan.


3. An auditor helped design a new access-control process last quarter. Management now wants
that auditor to provide assurance on the same process. What should happen?
A. The auditor should audit it and omit the design work from the report.
B. Independence applies only to financial statement audits.
C. The auditor may audit it because familiarity will make the work faster.
D. The auditor should not provide the assurance opinion, because designing the
control impairs independence on that engagement.
Rationale: An auditor does not assess a control the auditor designed. Another auditor can
perform the assurance work. Familiarity is not a substitute for objectivity, and the limit is not
confined to financial audits.


4. What should drive the annual IS audit plan?
A. Repeating last year's plan so every system is audited on a fixed rotation only.
B. The preferences of the managers who are most willing to be audited.
C. A risk assessment of the audit universe, aligned with business objectives and risk
appetite.
D. The number of findings the team needs in order to justify its budget.
Rationale: ISACA practice is risk-based. Rotation and management requests are inputs, not the
plan itself. Selecting audits to manufacture findings would bias the work.


5. In the audit-risk model, which component can the auditor most directly reduce by changing
the nature, timing, and extent of procedures?
A. Detection risk.
B. Inherent risk.
C. Control risk as it exists before any audit procedure.
D. The organization's risk appetite.
Rationale: Audit risk is a function of inherent risk, control risk, and detection risk. The auditor
assesses the first two and reduces detection risk through procedures. The auditor does not set
management's risk appetite.




Original practice material · Not an official ISACA examination · Page 2

, CISA PRACTICE TEST 2026/2027 · Information systems auditor practice examination




6. Which evidence is generally the most reliable for concluding that a control operated?
A. A copy of the policy, with no evidence that anyone followed it.
B. Reperformance of the control by the auditor, using a complete population or a
properly drawn sample.
C. A manager's oral statement that the control always works.
D. An unsigned slide from a project kickoff.
Rationale: Evidence is stronger when it is obtained directly by the auditor than when it is an
uncorroborated inquiry. A policy shows design, not operating effectiveness. Oral evidence is the
weakest of these sources.


7. An auditor uses attribute sampling on change approvals. The sample deviation rate exceeds
the tolerable deviation rate. What is the appropriate conclusion?
A. The control is effective because most changes were approved.
B. The auditor switches the conclusion to a dollar-misstatement opinion without further
work.
C. Sampling risk has been eliminated.
D. The control cannot be relied on at the planned level; the auditor expands testing
or reports a finding.
Rationale: Attribute sampling supports a conclusion about the deviation rate, not about a
dollar amount. Exceeding the tolerable rate means the planned reliance is not supported.
Ignoring the exceptions would overstate assurance.


8. Which statement about sampling risk is correct?
A. Increasing the sample size reduces sampling risk, but it does not remove
nonsampling risk such as a poorly defined population or a misunderstood control.
B. A larger sample eliminates every form of audit risk.
C. Sampling risk is the risk that the auditor uses the wrong criteria.
D. Judgmental sampling quantifies sampling risk as precisely as statistical sampling.
Rationale: Sampling risk comes from testing less than the whole population. Nonsampling risk
comes from human and design errors and is not cured by a bigger sample. Only statistical
sampling supports a numerical measure of sampling risk.


9. Why would an auditor use discovery sampling?
A. When the expected deviation rate is near zero and the objective is to find at least
one occurrence, such as a suspected fraud indicator.
B. When the population cannot be identified.
C. When the objective is to estimate a financial total.
D. When management has already agreed there are many known exceptions.
Rationale: Discovery sampling is designed to provide a probability of finding at least one
exception. It is not a variables-sampling method and it cannot be used if the population itself is
unknown.


Original practice material · Not an official ISACA examination · Page 3

Document information

Uploaded on
September 25, 2026
Number of pages
29
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TutorAgness
3.8
(10)
Sold
66
Followers
5
Items
1965
Last sold
17 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions