Certified Information Systems Auditor
(CISA) Practice Exam Questions And
Correct Answers (Verified Answers) Plus
Rationales 2025|2026 Q&A | Instant
Download Pdf
1. Which of the following is the primary objective of an IS audit?
A. Identify all software vulnerabilities
B. Evaluate and improve the effectiveness of risk management,
control, and governance processes
C. Implement new security technologies
D. Replace management oversight
B. Evaluate and improve the effectiveness of risk management,
control, and governance processes
Rationale: The IS audit’s main goal is to provide assurance and
recommendations to improve risk management, controls, and
governance, not to implement technologies or replace management.
,2. During planning, the most important factor in determining audit scope
is:
A. Auditor preference
B. Management’s request only
C. Risk assessment and materiality of processes
D. Previous year’s audit scope
C. Risk assessment and materiality of processes
Rationale: Scope should be driven by risk and materiality to focus
resources where they provide the most assurance.
3. Which control type detects and reports incidents after they occur?
A. Preventive controls
B. Detective controls
C. Corrective controls
D. Directive controls
B. Detective controls
Rationale: Detective controls identify incidents when they occur (e.g.,
intrusion detection systems, logs), while preventive controls aim to
stop them.
4. The best way for an auditor to confirm the existence of a physical
asset is:
A. Review the asset register only
B. Interview the asset custodian
C. Perform a physical inspection and reconcile to records
, D. Accept management’s representation
C. Perform a physical inspection and reconcile to records
Rationale: Physical inspection with reconciliation provides direct
evidence of existence and condition and validates records.
5. Segregation of duties (SoD) most directly helps prevent:
A. System downtime
B. Unauthorized physical access
C. Fraud and error by reducing collusion opportunities
D. External attacks
C. Fraud and error by reducing collusion opportunities
Rationale: SoD splits critical functions among individuals to prevent a
single person from committing and concealing fraud or errors.
6. Which of the following is a logical access control?
A. Biometric door lock
B. Firewall rule set
C. Locked server room
D. Visitor log book
B. Firewall rule set
Rationale: Logical controls manage access to systems and data (e.g.,
authentication, access lists, firewalls). Physical controls protect the
environment.
7. When assessing IT governance, the auditor should first determine
whether:
, A. IT projects are profitable
B. IT strategy aligns with business objectives
C. All employees have IT skills
D. The help desk is efficient
B. IT strategy aligns with business objectives
Rationale: Governance focuses on alignment of IT with business
goals to ensure value delivery and appropriate risk management.
8. Which technique is most appropriate to test the effectiveness of a
backup process?
A. Review backup schedules only
B. Observe backups run without restoration testing
C. Perform a restoration from backup and verify data integrity
D. Ask the system administrator if backups are successful
C. Perform a restoration from backup and verify data integrity
Rationale: Restoring from backups validates both the completion of
backups and the integrity/usability of backed-up data.
9. Change management controls are designed primarily to:
A. Prevent all changes
B. Ensure that changes are authorized, tested, and documented
C. Speed up deployment of changes
D. Replace the need for testing
B. Ensure that changes are authorized, tested, and documented
Rationale: Proper change controls provide assurance that changes
(CISA) Practice Exam Questions And
Correct Answers (Verified Answers) Plus
Rationales 2025|2026 Q&A | Instant
Download Pdf
1. Which of the following is the primary objective of an IS audit?
A. Identify all software vulnerabilities
B. Evaluate and improve the effectiveness of risk management,
control, and governance processes
C. Implement new security technologies
D. Replace management oversight
B. Evaluate and improve the effectiveness of risk management,
control, and governance processes
Rationale: The IS audit’s main goal is to provide assurance and
recommendations to improve risk management, controls, and
governance, not to implement technologies or replace management.
,2. During planning, the most important factor in determining audit scope
is:
A. Auditor preference
B. Management’s request only
C. Risk assessment and materiality of processes
D. Previous year’s audit scope
C. Risk assessment and materiality of processes
Rationale: Scope should be driven by risk and materiality to focus
resources where they provide the most assurance.
3. Which control type detects and reports incidents after they occur?
A. Preventive controls
B. Detective controls
C. Corrective controls
D. Directive controls
B. Detective controls
Rationale: Detective controls identify incidents when they occur (e.g.,
intrusion detection systems, logs), while preventive controls aim to
stop them.
4. The best way for an auditor to confirm the existence of a physical
asset is:
A. Review the asset register only
B. Interview the asset custodian
C. Perform a physical inspection and reconcile to records
, D. Accept management’s representation
C. Perform a physical inspection and reconcile to records
Rationale: Physical inspection with reconciliation provides direct
evidence of existence and condition and validates records.
5. Segregation of duties (SoD) most directly helps prevent:
A. System downtime
B. Unauthorized physical access
C. Fraud and error by reducing collusion opportunities
D. External attacks
C. Fraud and error by reducing collusion opportunities
Rationale: SoD splits critical functions among individuals to prevent a
single person from committing and concealing fraud or errors.
6. Which of the following is a logical access control?
A. Biometric door lock
B. Firewall rule set
C. Locked server room
D. Visitor log book
B. Firewall rule set
Rationale: Logical controls manage access to systems and data (e.g.,
authentication, access lists, firewalls). Physical controls protect the
environment.
7. When assessing IT governance, the auditor should first determine
whether:
, A. IT projects are profitable
B. IT strategy aligns with business objectives
C. All employees have IT skills
D. The help desk is efficient
B. IT strategy aligns with business objectives
Rationale: Governance focuses on alignment of IT with business
goals to ensure value delivery and appropriate risk management.
8. Which technique is most appropriate to test the effectiveness of a
backup process?
A. Review backup schedules only
B. Observe backups run without restoration testing
C. Perform a restoration from backup and verify data integrity
D. Ask the system administrator if backups are successful
C. Perform a restoration from backup and verify data integrity
Rationale: Restoring from backups validates both the completion of
backups and the integrity/usability of backed-up data.
9. Change management controls are designed primarily to:
A. Prevent all changes
B. Ensure that changes are authorized, tested, and documented
C. Speed up deployment of changes
D. Replace the need for testing
B. Ensure that changes are authorized, tested, and documented
Rationale: Proper change controls provide assurance that changes