Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 34 pages
Exam (elaborations)

Certified Information Systems Auditor (CISA) Practice Exam Questions And Correct Answers (Verified Answers) Plus Rationales 2025|2026 Q&A | Instant Download Pdf

Document preview thumbnail
Preview 4 out of 34 pages

Certified Information Systems Auditor (CISA) Practice Exam Questions And Correct Answers (Verified Answers) Plus Rationales 2025|2026 Q&A | Instant Download Pdf

Content preview

Certified Information Systems Auditor
(CISA) Practice Exam Questions And
Correct Answers (Verified Answers) Plus
Rationales 2025|2026 Q&A | Instant
Download Pdf


1. Which of the following is the PRIMARY objective of an IS audit?
a) To detect fraud
b) To ensure information systems safeguard assets, maintain data
integrity, and operate effectively
c) To evaluate the IT department’s performance
d) To assess employee productivity
Rationale: The IS audit’s main goal is assurance that IT controls
protect assets, maintain integrity, and support organizational goals.

2. During an IS audit, the auditor discovers evidence of a significant
fraud. What should be the auditor’s FIRST action?

, a) Notify the audit committee
b) Follow the organization’s escalation and reporting procedures
c) Contact law enforcement
d) Stop the audit immediately
Rationale: Auditors must adhere to established procedures for
reporting irregularities; immediate escalation follows organizational
policy.

3. The PRIMARY purpose of IT governance is to:
a) Improve operational efficiency
b) Enhance user satisfaction
c) Ensure IT supports and enables business goals
d) Reduce audit findings
Rationale: IT governance aligns IT strategy with business objectives,
ensuring value delivery and risk management.

4. Which of the following best describes the role of an IS auditor in risk
management?
a) Implement controls
b) Own the risk register
c) Evaluate the effectiveness of risk management processes
d) Accept residual risk
Rationale: IS auditors assess, not manage or own, risk; they evaluate
adequacy of risk management processes.

,5. Which of the following provides the best assurance that a control is
effective?
a) Control exists in policy documents
b) Control operates as designed and achieves intended results
c) Management asserts control effectiveness
d) Control has been recently implemented
Rationale: A control is effective only if it consistently functions as
designed and achieves objectives.

6. The MOST important reason to maintain audit trail logs is to:
a) Optimize performance
b) Detect software bugs
c) Reconstruct events and provide accountability
d) Reduce storage usage
Rationale: Audit trails are critical for accountability, incident
analysis, and forensic investigations.

7. Which of the following controls is MOST effective for preventing
unauthorized changes to production programs?
a) User access reviews
b) Segregation of duties between developers and operators
c) Audit logging
d) Periodic penetration tests
Rationale: Separation between development and operations
prevents unauthorized code movement to production.

, 8. An IS auditor reviewing access control to a system should FIRST verify:
a) Existence of an approved access control policy
b) Password complexity rules
c) System logging mechanisms
d) Multifactor authentication usage
Rationale: Policy defines authority, principles, and rules upon which
detailed controls depend.

9. What is the PRIMARY objective of change management?
a) To minimize the number of changes
b) To ensure changes are properly documented
c) To ensure all changes are authorized, tested, and implemented
properly
d) To accelerate deployment
Rationale: Change management ensures authorized, tested, and
approved modifications to prevent disruptions.

10. Which of the following BEST ensures that audit findings are
resolved?
a) Conducting follow-up audits annually
b) Establishing a formal follow-up and tracking process
c) Relying on management to self-report progress
d) Adding findings to risk register only
Rationale: A structured follow-up process ensures accountability and
timely remediation.

Document information

Uploaded on
October 14, 2025
Number of pages
34
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PrepPal1
4.0
(25)
Sold
107
Followers
6
Items
4590
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions