Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 175 pages
Exam (elaborations)

CISA Study Guide Questions & 100% Correct Answers

Document preview thumbnail
Preview 4 out of 175 pages

Most important step in risk analysis is to identify a. Competitors b. controls c. vulnerabilities d. liabilities :~~ c. vulnerabilities In a risk based audit planning, an IS auditor's first step is to identify: a. responsibilities of stakeholders b. high-risk areas within the organization c. cost centre d. profit centre :~~ b. high-risk areas within the organization When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that: 2 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update a. segregation of duties to mitigate risks is in place b. all the relevant vulnerabilities and threats are identified c. regularity compliance is adhered to d. business is profitable :~~ b. all the relevant vulnerabilities and threats are identified IS auditor identified certain threats and vulnerabilities in a business process. Next, an IS auditor should: a. identify stakeholder for that business process b. identifies information. assets and the underlying systems c. discloses the threats and impacts to management d. identifies and evaluates the existing controls :~~ d. identifies and evaluates the existing controls Major advantaged of risk based approach for audit planning is: a. Audit planning can be communicated to client in advance b. Audit activity can be completed within allotted budget c. use of latest technology for audit activities 3 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update d. Appropriate utilisation of resources for high risk areas :~~ d. Appropriate utilisation of resources for high risk areas While determining the appropriate level of protection for an information asset an IS auditor should primarily focus on: a. Criticality of information assets b. cost of information assets c. Owner of information asset d. result of vulnerability assessment :~~ a. Criticality of information assets The decisions and actions of an IS auditor are MOST likely to affect which of the following risks? a. Inherent b. Detection c. Control d. Business :~~ b. Detection 4 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update The risk of an IS auditor certifying existence of proper system and procedures without using an inadequate test procedure is an example of: a. internet risk b. control risk c. detection risk d. audit risk :~~ c. Detection risk Overall business risk for a particular threat can be expressed as: a. a product of the probability. and impact b. probability of occurrence c. magnitude of impact d. assumption of the risk assessment team :~~ a. a product of the

Content preview

1 | P a g e | © copyright 2024/2025 | Grade A+




CISA Study Guide Questions & 100%
Correct Answers
Most important step in risk analysis is to identify




a. Competitors

b. controls

c. vulnerabilities

d. liabilities

✓ :~~ c. vulnerabilities




In a risk based audit planning, an IS auditor's first step is to identify:




a. responsibilities of stakeholders

b. high-risk areas within the organization

c. cost centre

d. profit centre

✓ :~~ b. high-risk areas within the organization




When developing a risk-based audit strategy, an IS auditor should conduct a risk

assessment to ensure that:




Master01 | September, 2024/2025 | Latest update

, 2 | P a g e | © copyright 2024/2025 | Grade A+




a. segregation of duties to mitigate risks is in place

b. all the relevant vulnerabilities and threats are identified

c. regularity compliance is adhered to

d. business is profitable

✓ :~~ b. all the relevant vulnerabilities and threats are identified




IS auditor identified certain threats and vulnerabilities in a business process. Next,

an IS auditor should:




a. identify stakeholder for that business process

b. identifies information. assets and the underlying systems

c. discloses the threats and impacts to management

d. identifies and evaluates the existing controls

✓ :~~ d. identifies and evaluates the existing controls




Major advantaged of risk based approach for audit planning is:




a. Audit planning can be communicated to client in advance

b. Audit activity can be completed within allotted budget

c. use of latest technology for audit activities


Master01 | September, 2024/2025 | Latest update

, 3 | P a g e | © copyright 2024/2025 | Grade A+


d. Appropriate utilisation of resources for high risk areas

✓ :~~ d. Appropriate utilisation of resources for high risk areas




While determining the appropriate level of protection for an information asset an

IS auditor should primarily focus on:




a. Criticality of information assets

b. cost of information assets

c. Owner of information asset

d. result of vulnerability assessment

✓ :~~ a. Criticality of information assets




The decisions and actions of an IS auditor are MOST likely to affect which of the

following risks?




a. Inherent

b. Detection

c. Control

d. Business

✓ :~~ b. Detection




Master01 | September, 2024/2025 | Latest update

, 4 | P a g e | © copyright 2024/2025 | Grade A+


The risk of an IS auditor certifying existence of proper system and procedures

without using an inadequate test procedure is an example of:




a. internet risk

b. control risk

c. detection risk

d. audit risk


✓ :~~ c. Detection risk




Overall business risk for a particular threat can be expressed as:




a. a product of the probability. and impact

b. probability of occurrence

c. magnitude of impact

d. assumption of the risk assessment team

✓ :~~ a. a product of the probability. and impact




An IS auditor is evaluating management's risk assessment of information systems.

The IS auditor should FIRST review:




a. the controls already in place



Master01 | September, 2024/2025 | Latest update

Document information

Uploaded on
September 9, 2024
Number of pages
175
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Axpert
3.8
(126)
Sold
560
Followers
167
Items
29320
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions