CISA Domain 1 Questions & 100%
Correct Answers
An IS auditor is conducting a compliance test to determine whether controls
support management policies and procedures. The test will assist the IS auditor to
determine:
✓ :~~ That the control is operating as designed
Compliance tests can be used to test the existence and effectiveness of a defined
process. Understanding the objective of a compliance test is important. IS auditors
want reasonable assurance that the controls they are relying on are effective. An
effective control is one that meets management expectations and objectives.
When developing a risk management program, what is the first activity to be
performed?
✓ :~~ Inventory of assets.
Identification of the assets to be protected is the first step in developing a risk
management program.
The primary purpose of an IT forensic audit is:
Master01 | September, 2024/2025 | Latest update
, 2 | P a g e | © copyright 2024/2025 | Grade A+
✓ :~~ The systemic collection and analysis of evidence after a system
irregularity.
Due to resource constraints of the IS audit team, the audit plan as originally
approved cannot be completed. Assuming that the situation is communicated in
the audit report, which course of action is most acceptable:
Test the adequacy of the control design
Test the operational effectiveness of the control
Focus on auditing high risk areas
Relying on management testing of controls.
✓ :~~ Focus on high risk areas. Reducing the scope and focusing on auditing
high-risk areas is the bets course of action.
While planning an IS audit, an assessment of risk should be made to provide:
✓ :~~ Reasonable assurance that the audit will cover material items.
ISACA IS Audit and Assurance Guideline 2202 (Risk Assessment in Planning) states
that the applied risk assessment approach should help with the prioritization and
scheduling process of the IS audit and assurance work. It should support the
selection process of areas and items of audit interest and the decision process to
design and conduct particular IS audit engagements.
Master01 | September, 2024/2025 | Latest update
, 3 | P a g e | © copyright 2024/2025 | Grade A+
Which of the following best describes the purpose of performing a risk assessment
in the planning phase of an IS audit:
Establish adequate staffing requirements to complete the IS audit
To provide reasonable assurance that all material items will be addressed
To determine the skills required to perform the IS audit
To develop the audit program and procedures
✓ :~~ To provide reasonable assurance that all material items will be
addressed.
A risk assessment helps focus the audit procedures on the highest risk areas
included in the scope of the audit.
A financial institution with multiple branch offices has an automated control that
requires the branch manager to approve transactions more than a certain amount.
What type of audit control is this?
✓ :~~ Preventative.
An IS auditor is validating a control that involved a review of system generated
exception reports. Which of the following is the best evidence of the effectiveness
of the control.
Master01 | September, 2024/2025 | Latest update
, 4 | P a g e | © copyright 2024/2025 | Grade A+
1- Walkthrough with the reviewer of the operation of the control
2- System generated exception report for the review period with the reviewers
sign off
3- A sample system generated exceptions report for the review period, with
follow-up action items noted by the reviewer
4- Management's confirmation of the effectiveness of the control for the review
period.
✓ :~~ A sample system generated exceptions report for the review period,
with follow-up action items noted by the reviewer.
A sample of a system generated report with evidence that the reviewer followed
up on the exception represents the best possible evidence of the effective
operation of the control because there is documented evidence that the reviewer
has reviewed and taken actions based on the exception report.
Which of the following is the most important skill an IS auditor should develop to
understand the constraints of conducting an audit:
1 - Contingency Planning
2 - IS Management resource allocation
3 - Project Management
Master01 | September, 2024/2025 | Latest update