Cisa 2 Questions & 100% Correct
Answers
An IS auditor is reviewing access to an application to determine whether the 10
most recent "new user" forms were correctly authorized. This is an example of:
✓ :~~ compliance testing.
The decisions and actions of an IS auditor are MOST likely to affect which of the
following risks?
✓ :~~ Detection
Overall business risk for a particular threat can be expressed as:
✓ :~~ a product of the probability and magnitude of the impact if a threat
successfully exploits a vulnerability.
Which of the following is a substantive test?
✓ :~~ Using a statistical sample to inventory the tape library
Which of the following is a benefit of a risk-based approach to audit planning?
Audit:
✓ :~~ resources are allocated to the areas of highest concern
Master01 | September, 2024/2025 | Latest update
, 2 | P a g e | © copyright 2024/2025 | Grade A+
An audit charter should:
✓ :~~ outline the overall authority, scope and responsibilities of the audit
function.
The MAJOR advantage of the risk assessment approach over the baseline approach
to information security management is that it ensures:
✓ :~~ appropriate levels of protection are applied to information assets.
Which of the following sampling methods is MOST useful when testing for
compliance?
✓ :~~ Attribute sampling
Which of the following is the MOST likely reason why e-mail systems have become
a useful source of evidence for litigation?
✓ :~~ Multiple cycles of backup files remain available.
An IS auditor is assigned to perform a postimplementation review of an application
system. Which of the following situations may have impaired the independence of
the IS auditor? The IS auditor:
✓ :~~ implemented a specific control during the development of the
application system.
Master01 | September, 2024/2025 | Latest update
, 3 | P a g e | © copyright 2024/2025 | Grade A+
The PRIMARY advantage of a continuous audit approach is that it:
✓ :~~ can improve system security when used in time-sharing environments
that process a large number of transactions.
The PRIMARY purpose of audit trails is to:
✓ :~~ establish accountability and responsibility for processed transactions.
When developing a risk-based audit strategy, an IS auditor should conduct a risk
assessment to ensure that:
✓ :~~ vulnerabilities and threats are identified.
To ensure that audit resources deliver the best value to the organization, the
FIRST step would be to:
✓ :~~ develop the audit plan on the basis of a detailed risk assessment.
An organization's IS audit charter should specify the:
✓ :~~ role of the IS audit function.
An IS auditor is evaluating management's risk assessment of information systems.
The IS auditor should FIRST review:
✓ :~~ the threats/vulnerabilities affecting the assets.
Master01 | September, 2024/2025 | Latest update