• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Start selling Create your account
Document preview thumbnail
Preview 3 out of 30 pages
Exam (elaborations)

2026 Cisa Certification Exam|Verified Questions And 100% Correct Solutions|Updated Version !!!|A+ Graded|Exam Ready|95% Success Rate

Document preview thumbnail
Preview 3 out of 30 pages

2026 CISA Certification Exam Comprehensive Study Guide: Featuring Verified Questions, Guaranteed 100% Accurate Solutions, Presenting the Most Up-to-Date Information Available, Assuring an A+ Grade, Complete Exam Preparation, and a Remarkable 95% Success Rate for Exam Takers.

Content preview

QUESTIONS AND 100% CORRECT
SOLUTIONS|UPDATED VERSION !!!|A+

Which of the following would be MOST important for an IS auditor to verify while
conducting a business continuity audit?

A.Data backups are performed on a timely basis.

B.A recovery site is contracted for and available as needed.

C.Human safety procedures are in place.

D.Insurance coverage is adequate and premiums are current. - ANSWER C.Human
safety procedures are in place.



Explanation: The most important element in any business continuity process is the
protection of human life. This takes precedence over all other aspects of the plan.



A comprehensive and effective email policy should address the issues of email structure,
policy enforcement, monitoring and:

A.recovery.

B.retention.

C.rebuilding.

D.reuse. - ANSWER B.retention.



Explanation:Besides being a good practice, laws and regulations may require an organization
to keep information that has an impact on the financial statements. The prevalence of
lawsuits in which email communication is held in the same regard as the official form of
classic paper makes the retention policy of corporate email a necessity. All email generated
on an organization's hardware is the property of the organization, and an email policy should
address the retention of messages, considering both known and unforeseen litigation. The
policy should also address the destruction of emails after a specified time to protect the
nature and confidentiality of the messages themselves.


1

,An IS auditor who was involved in designing an organization's business continuity plan (BCP)
has been assigned to audit the plan. The IS auditor should:

A.decline the assignment.

B.inform management of the possible conflict of interest after completing the audit
assignment.

C.inform the BCP team of the possible conflict of interest prior to beginning the assignment.

D.communicate the possibility of conflict of interest to audit management prior to starting
the assignment. - ANSWER D. communicate the possibility of conflict of interest to
audit management prior to starting the assignment.



Explanation:A possible conflict of interest, likely to affect the IS auditor's independence,
should be brought to the attention of management prior to starting the assignment.



Which of the following is the MOST critical element to effectively execute a disaster recovery
plan?

A.Offsite storage of backup data

B.Up-to-date list of key disaster recovery contacts

C.Availability of a replacement data center

D.Clearly defined recovery time objective (RTO) - ANSWER A.Offsite storage of backup
data



Explanation: Remote storage of backups is the most critical disaster recovery plan (DRP)
element of the items listed because access to backup data is required to restore systems.



An IS auditor found that the enterprise architecture (EA) recently adopted by an organization
has an adequate current-state representation. However, the organization has started a
separate project to develop a future-state representation. The IS auditor should:

A.recommend that this separate project be completed as soon as possible.

B.report this issue as a finding in the audit report.

C.recommend the adoption of the Zachmann framework.


2

, D.re-scope the audit to include the separate project as part of the current audit. -
ANSWER B. report this issue as a finding in the audit report.



Explanation: It is critical for the EA to include the future state because the gap between the
current state and the future state will determine IT strategic and tactical plans. If the EA does
not include a future-state representation, it is not complete, and this issue should be
reported as a finding.



What is the PRIMARY consideration for an IS auditor reviewing the prioritization and
coordination of IT projects and program management?

A.Projects are aligned with the organization's strategy.

B.Identified project risk is monitored and mitigated.

C.Controls related to project planning and budgeting are appropriate.

D.IT project metrics are reported accurately. - ANSWER A.Projects are aligned with the
organization's strategy.



Explanation: The primary goal of IT projects is to add value to the business, so they must be
aligned with the business strategy to achieve the intended results. Therefore, the IS auditor
should first focus on ensuring this alignment.



When selecting audit procedures, an IS auditor should use professional judgment to ensure
that:

A.sufficient evidence will be collected.

B.significant deficiencies will be corrected within a reasonable period.

C.all material weaknesses will be identified.

D.audit costs will be kept at a minimum level. - ANSWER A.sufficient evidence will be
collected.



Explanation:Procedures are processes that an IS auditor may follow in an audit engagement.
In determining the appropriateness of any specific procedure, an IS auditor should use
professional judgment that is appropriate to the specific circumstances. Professional
judgment involves a subjective and often qualitative evaluation of conditions arising during

3

Document information

Uploaded on
February 20, 2026
Number of pages
30
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
£11.66

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
THESTUDYVAULT
3.4
(20)
Sold
157
Followers
6
Items
14231
Last sold
2 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions