CISA COMPREHENSIVE EXAM QUESTIONS
AND SOLUTIONS STUDY GUIDE
●● What is the purpose of ethics?
Answer: To mandate the professional and personal conduct of auditors
●● According to the ISACA Code of Ethics is an auditor allowed to
share the results of an audit with other personnel?
Answer: The auditor must maintain confidentiality of the audit unless
required by legal authority
●● Should the IS audit plan be integrated into the overall audit plan for
the organization?
Answer: The IS Audit function must fulfill all organizational audit
objectives.
●● An IS Auditor is best advised to follow the standards provided by
ISACA for conducting an planning IS Audits
Answer: ISACA audit standards are recommendations for planning IS
audits.
●● ISACA Audit standard S2 Independence refers to what?
Answer: An Auditor should be independent of the area being audited
, ●● Standard S4 Professional Competence, requires the auditor to have
the skills to conduct the audit?
Answer: appropriate continuing professional education
●● The basis for an audit plan should be what?
Answer: Risk
●● Audit findings and conclusions are supported by what?
Answer: Evidence
●● When an auditor uses the assistance of outside experts, what
obligations does the auditor have to review the work of the experts?
Answer: The auditor must apply additional test procedures if the work of
outside experts is not adequate
●● When an auditor is planning an information system audit and
suspects a potential control weakness, what are they obligated to do?
Answer: The auditor must consider the materiality of the weakness and
plan the audit accordingly.
●● What role does risk assessment have in audit planning?
Answer: Risk assessment is used to determine the priorities for audit and
allocation of audit resources.
AND SOLUTIONS STUDY GUIDE
●● What is the purpose of ethics?
Answer: To mandate the professional and personal conduct of auditors
●● According to the ISACA Code of Ethics is an auditor allowed to
share the results of an audit with other personnel?
Answer: The auditor must maintain confidentiality of the audit unless
required by legal authority
●● Should the IS audit plan be integrated into the overall audit plan for
the organization?
Answer: The IS Audit function must fulfill all organizational audit
objectives.
●● An IS Auditor is best advised to follow the standards provided by
ISACA for conducting an planning IS Audits
Answer: ISACA audit standards are recommendations for planning IS
audits.
●● ISACA Audit standard S2 Independence refers to what?
Answer: An Auditor should be independent of the area being audited
, ●● Standard S4 Professional Competence, requires the auditor to have
the skills to conduct the audit?
Answer: appropriate continuing professional education
●● The basis for an audit plan should be what?
Answer: Risk
●● Audit findings and conclusions are supported by what?
Answer: Evidence
●● When an auditor uses the assistance of outside experts, what
obligations does the auditor have to review the work of the experts?
Answer: The auditor must apply additional test procedures if the work of
outside experts is not adequate
●● When an auditor is planning an information system audit and
suspects a potential control weakness, what are they obligated to do?
Answer: The auditor must consider the materiality of the weakness and
plan the audit accordingly.
●● What role does risk assessment have in audit planning?
Answer: Risk assessment is used to determine the priorities for audit and
allocation of audit resources.