CISA InFo Domain 1 Questions and Answers Already Passed
CISA InFo Domain 1 Questions and Answers Already Passed A long-term IS employee with a strong technical background and broad managerial experience has applied for a vacant position in the IS audit department. Determine whether to hire this individual for this position should be based on the individual's experience and: A. Ability as an IS auditors to be independent of existing IS relationship. B. Age as training in audit techniques may be impractical. C. the length of service since this will help ensure technical competence. D. IS knowledge since this will bring enhance credibility to the audit function. A. Ability, as an IS auditor to be independent of existing IS relationships. Independence should be continually assessed by auditor and management. This assessment should consider such factors as changes in personal relationships, financial interest and prior job assignments and responsibilities. The fact that the employee has worked in IS for many years may not in itself ensure credibility. The audit department's needs should be defined and any candidate should be evaluated against those requirements. In additional, the length of service will not ensure technical competency and evaluating and evaluating an individual's qualifications based on the age of the individual is not a good criterion and is illegal in many parts of the world. An IS Auditor is evaluating management's risk assessment of information system. The IS Auditor should FIRST review: A. The effectiveness of the controls in place. B. The mechanism for monitoring the risk related to the asset C. The threats/vulnerabilities affecting the assets D. The controls already in place C. The threats/vulnerabilities affecting the assets. One of the key factors to be considered while assessing the risks related to the use of various information systems is the threat and vulnerabilities affecting the assets. The risks related to the use of information assets should be evaluated in isolation from the installed controls. An IS Auditor using systematic sampling for a population of 10,000 items determines that a sample size of 200 would be sufficient to accomplish the test objectives. The sample interval would be: A. 50 B. 200 C. 100 D. 500 A. 50 10,000 divided by 200 equal 50. In a population of 10,000 selecting every 50th item would produce a sample of 200. At the completion of the general controls review, the IS Auditor should be able to answer which of the following questions? A. What controls are in place to assure that only authorized transactions are processed? B. Does the organization of the IS Department provide adequate separation of functions? C. Which user has access to create a purchase order? D. How do input controls provide reasonable assurance that rejected data is re-entered? B. Does the organization of the IS Department provide adequate separation of functions? Answer A,C and D all deal with questions that are normally addressed during the completion of an Application Review. The B best because it deals with a question that ITauditorswould ask as high level review or general controls
Escuela, estudio y materia
- Institución
- CISA InFo Domain 1
- Grado
- CISA InFo Domain 1
Información del documento
- Subido en
- 8 de junio de 2024
- Número de páginas
- 15
- Escrito en
- 2023/2024
- Tipo
- Examen
- Contiene
- Preguntas y respuestas
Temas
-
cisa info domain 1 questions and answers already
Documento también disponible en un lote