Certified Information Systems Auditor
(CISA) Examination Practice Exam
Questions with Answers and Rationales
Question And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A
|Instant Download Pdf
1. What is the PRIMARY purpose of an IS audit?
A. Detect fraud
B. Provide assurance on controls
C. Evaluate employee performance
D. Identify security vulnerabilities
Rationale: The main purpose of an IS audit is assurance that controls are
adequate and effective.
2. Which risk response involves accepting the outcome without action?
A. Mitigation
B. Transfer
C. Avoidance
D. Acceptance
Rationale: Acceptance means taking no action and tolerating the risk outcome.
3. The MOST important element of change management is:
,A. User training
B. Hardware upgrades
C. Formal approval process
D. Improved documentation
Rationale: Control relies on authorized and approved changes before
implementation.
4. Which access control model is based on predefined classification labels?
A. RBAC
B. DAC
C. MAC
D. ABAC
Rationale: Mandatory Access Control uses system-enforced classifications.
5. What is the PRIMARY goal of segregation of duties?
A. Increase productivity
B. Reduce opportunities for fraud
C. Improve efficiency
D. Enhance system speed
Rationale: SoD prevents one person from controlling all critical steps, reducing
fraud risk.
6. What is the MOST reliable evidence type in IS auditing?
A. Inquiry
B. Observation
C. Documentation
D. Reperformance
Rationale: Reperforming controls provides highest assurance via direct auditor
verification.
7. Which testing method evaluates system components as a whole?
A. Unit testing
B. Regression testing
, C. Load testing
D. Integration testing
Rationale: Integration testing checks interactions among combined components.
8. Which encryption ensures non-repudiation?
A. Symmetric key
B. Hashing
C. Transport encryption
D. Digital signatures
Rationale: Digital signatures bind identity and prevent denial of actions.
9. The PRIMARY objective of incident response is:
A. Punish offenders
B. Eliminate risks
C. Restore normal operations
D. Produce compliance reports
Rationale: Rapid recovery and minimizing impact are the core IR goals.
10. Which backup method copies only data changed since the last full backup?
A. Hot backup
B. Incremental backup
C. Differential backup
D. Image backup
Rationale: Incremental backups copy changes since the last full or incremental.
11. Which of the following BEST ensures business continuity during a disaster?
A. Firewall redundancy
B. Network monitoring
C. Effective disaster recovery plan
D. Incident logging
Rationale: A DRP enables continuation or restoration of critical operations.
12. Which is the MOST important first step in developing an IS audit plan?
(CISA) Examination Practice Exam
Questions with Answers and Rationales
Question And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A
|Instant Download Pdf
1. What is the PRIMARY purpose of an IS audit?
A. Detect fraud
B. Provide assurance on controls
C. Evaluate employee performance
D. Identify security vulnerabilities
Rationale: The main purpose of an IS audit is assurance that controls are
adequate and effective.
2. Which risk response involves accepting the outcome without action?
A. Mitigation
B. Transfer
C. Avoidance
D. Acceptance
Rationale: Acceptance means taking no action and tolerating the risk outcome.
3. The MOST important element of change management is:
,A. User training
B. Hardware upgrades
C. Formal approval process
D. Improved documentation
Rationale: Control relies on authorized and approved changes before
implementation.
4. Which access control model is based on predefined classification labels?
A. RBAC
B. DAC
C. MAC
D. ABAC
Rationale: Mandatory Access Control uses system-enforced classifications.
5. What is the PRIMARY goal of segregation of duties?
A. Increase productivity
B. Reduce opportunities for fraud
C. Improve efficiency
D. Enhance system speed
Rationale: SoD prevents one person from controlling all critical steps, reducing
fraud risk.
6. What is the MOST reliable evidence type in IS auditing?
A. Inquiry
B. Observation
C. Documentation
D. Reperformance
Rationale: Reperforming controls provides highest assurance via direct auditor
verification.
7. Which testing method evaluates system components as a whole?
A. Unit testing
B. Regression testing
, C. Load testing
D. Integration testing
Rationale: Integration testing checks interactions among combined components.
8. Which encryption ensures non-repudiation?
A. Symmetric key
B. Hashing
C. Transport encryption
D. Digital signatures
Rationale: Digital signatures bind identity and prevent denial of actions.
9. The PRIMARY objective of incident response is:
A. Punish offenders
B. Eliminate risks
C. Restore normal operations
D. Produce compliance reports
Rationale: Rapid recovery and minimizing impact are the core IR goals.
10. Which backup method copies only data changed since the last full backup?
A. Hot backup
B. Incremental backup
C. Differential backup
D. Image backup
Rationale: Incremental backups copy changes since the last full or incremental.
11. Which of the following BEST ensures business continuity during a disaster?
A. Firewall redundancy
B. Network monitoring
C. Effective disaster recovery plan
D. Incident logging
Rationale: A DRP enables continuation or restoration of critical operations.
12. Which is the MOST important first step in developing an IS audit plan?