CISA LATEST 2026 EXAM QUESTIONS AND ANSWERS
GRADED A+
✔✔Which of the following represents an example of a preventive control with respect to
IT personnel?
Select an answer:
A.
Review of visitor logs for the data center
B.
A log server that tracks logon IP addresses of users
C.
Implementation of a badge entry system for the IT facility
D.
An accounting system that tracks employee telephone calls - ✔✔A. Review of visitor
logs is a detective control in most circumstances.
B. Review of log servers is a detective control in most circumstances.
CORRECT C. Preventive controls are used to reduce the probability of an adverse
event occurring. A badge entry system would prevent unauthorized entry to the facility.
D. Review of telephone call accounting systems is a detective control in most
circumstances.
✔✔Many organizations require employees to take a mandatory vacation each year
PRIMARILY because the organization wants to ensure that:
Select an answer:
A.
adequate cross-training exists between all functions of the organization.
B.
employee morale is maintained to ensure an effective internal control environment.
C.
potential irregularities in processing are identified by temporarily replacing an employee
in the job function.
D.
rotation of employees reduces the risk of processing errors. - ✔✔A. Cross-training is a
good practice to follow but can be achieved without the requirement for mandatory
vacation.
,B. Good employee morale and high levels of employee satisfaction are worthwhile
objectives, but they should not be considered a means to achieve an effective internal
control system.
CORRECT C. Employees who perform critical and sensitive functions within an
organization should be required to take some time off to help ensure that irregularities
and fraud are detected.
D. Although rotating employees could contribute to fewer processing errors, this is not
typically a reason to require a mandatory vacation policy.
✔✔When auditing a role-based access control system (RBAC), the IS auditor noticed
that some IT security employees have system administrator privileges on some servers,
which allows them to modify or delete transaction logs. Which would be the BEST
recommendation that the IS auditor should make?
Select an answer:
A.
Ensure that these employees are adequately supervised.
B.
Ensure that backups of the transaction logs are retained.
C.
Implement controls to detect the changes.
D.
Ensure that transaction logs are written in real time to Write Once and Read Many
(WORM) drives. - ✔✔A. IT security employees cannot be supervised in the traditional
sense unless the supervisor were to monitor each keystroke entered on a workstation,
which is obviously not a realistic option.
B. Retaining backups of the transaction logs does not prevent the files from
unauthorized modification prior to backup.
C. The log files themselves are the main evidence that an unauthorized change was
made, which is a sufficient detective control. Protecting the log files from modification
requires preventive controls such as securely writing the logs.
CORRECT D. Allowing IT security employees access to transaction logs is often
unavoidable because having system administrator privileges is required for them to do
their job. The best control in this case, to avoid unauthorized modifications of
transaction logs, is to write the transaction logs to WORM drive media in real time. It is
important to note that simply backing up the transaction logs to tape is not adequate
,because data could be modified prior (typically at night) to the daily backup job
execution.
✔✔In a review of the human resources policies and procedures within an organization,
an IS auditor would be MOST concerned with the absence of a:
Select an answer:
A.
requirement for job rotation on a periodic basis.
B.
process for formalized exit interviews.
C.
termination checklist requiring that keys and company property be returned and all
access permissions revoked upon termination.
D.
requirement for new employees to sign a nondisclosure agreement (NDA). - ✔✔A. Job
rotation is a valuable control to ensure continuity of operations, but not the most serious
human resources policy risk.
B. Holding an exit interview is desirable when possible to gain feedback, but is not a
serious risk.
CORRECT C. A termination checklist is critical to ensure the logical and physical
security of an enterprise. In addition to preventing the loss of company property issued
to the employee, there is the risk of unauthorized access, intellectual property theft and
even sabotage by a disgruntled former employee.
D. Signing a nondisclosure agreement (NDA) is a recommended human resources
practice, but a lack of an NDA is not the most serious risk listed.
✔✔From a control perspective, the key element in job descriptions is that they:
Select an answer:
A.
provide instructions on how to do the job and define authority.
B.
are current, documented and readily available to the employee.
C.
communicate management's specific job performance expectations.
D.
, establish responsibility and accountability for the employee's actions. - ✔✔A. Providing
instructions on how to do the job and defining authority addresses the managerial and
procedural aspects of the job and is a management responsibility. Job descriptions,
which are an human resources (HR)-related function, are primarily used to establish job
requirements and accountability.
B. It is important that job descriptions are current, documented and readily available to
the employee, but this, in itself, is not the key element of the job description. Job
descriptions, which are an HR-related function, are primarily used to establish job
requirements and accountability.
C. Communication of management's specific expectations for job performance would
not necessarily be included in job descriptions.
CORRECT D. From a control perspective, a job description should establish
responsibility and accountability. This will aid in ensuring that users are given system
access in accordance with their defined job responsibilities and are accountable for how
they use that access.
✔✔Which of the following would BEST provide assurance of the integrity of new staff?
Select an answer:
A.
Background screening
B.
References
C.
Bonding
D.
Qualifications listed on a résumé - ✔✔CORRECT A. A background screening is the
primary method for assuring the integrity of a prospective staff member. This may
include criminal history checks, driver's license abstracts, financial status checks,
verification of education, etc.
B. References are important and would need to be verified, but they are not as reliable
as background screening because the references themselves may not be validated as
trustworthy.
C. Bonding is directed at due-diligence compliance and does not ensure integrity.
D. Qualifications listed on a résumé may be used to demonstrate proficiency but will not
indicate the integrity of the candidate employee.
GRADED A+
✔✔Which of the following represents an example of a preventive control with respect to
IT personnel?
Select an answer:
A.
Review of visitor logs for the data center
B.
A log server that tracks logon IP addresses of users
C.
Implementation of a badge entry system for the IT facility
D.
An accounting system that tracks employee telephone calls - ✔✔A. Review of visitor
logs is a detective control in most circumstances.
B. Review of log servers is a detective control in most circumstances.
CORRECT C. Preventive controls are used to reduce the probability of an adverse
event occurring. A badge entry system would prevent unauthorized entry to the facility.
D. Review of telephone call accounting systems is a detective control in most
circumstances.
✔✔Many organizations require employees to take a mandatory vacation each year
PRIMARILY because the organization wants to ensure that:
Select an answer:
A.
adequate cross-training exists between all functions of the organization.
B.
employee morale is maintained to ensure an effective internal control environment.
C.
potential irregularities in processing are identified by temporarily replacing an employee
in the job function.
D.
rotation of employees reduces the risk of processing errors. - ✔✔A. Cross-training is a
good practice to follow but can be achieved without the requirement for mandatory
vacation.
,B. Good employee morale and high levels of employee satisfaction are worthwhile
objectives, but they should not be considered a means to achieve an effective internal
control system.
CORRECT C. Employees who perform critical and sensitive functions within an
organization should be required to take some time off to help ensure that irregularities
and fraud are detected.
D. Although rotating employees could contribute to fewer processing errors, this is not
typically a reason to require a mandatory vacation policy.
✔✔When auditing a role-based access control system (RBAC), the IS auditor noticed
that some IT security employees have system administrator privileges on some servers,
which allows them to modify or delete transaction logs. Which would be the BEST
recommendation that the IS auditor should make?
Select an answer:
A.
Ensure that these employees are adequately supervised.
B.
Ensure that backups of the transaction logs are retained.
C.
Implement controls to detect the changes.
D.
Ensure that transaction logs are written in real time to Write Once and Read Many
(WORM) drives. - ✔✔A. IT security employees cannot be supervised in the traditional
sense unless the supervisor were to monitor each keystroke entered on a workstation,
which is obviously not a realistic option.
B. Retaining backups of the transaction logs does not prevent the files from
unauthorized modification prior to backup.
C. The log files themselves are the main evidence that an unauthorized change was
made, which is a sufficient detective control. Protecting the log files from modification
requires preventive controls such as securely writing the logs.
CORRECT D. Allowing IT security employees access to transaction logs is often
unavoidable because having system administrator privileges is required for them to do
their job. The best control in this case, to avoid unauthorized modifications of
transaction logs, is to write the transaction logs to WORM drive media in real time. It is
important to note that simply backing up the transaction logs to tape is not adequate
,because data could be modified prior (typically at night) to the daily backup job
execution.
✔✔In a review of the human resources policies and procedures within an organization,
an IS auditor would be MOST concerned with the absence of a:
Select an answer:
A.
requirement for job rotation on a periodic basis.
B.
process for formalized exit interviews.
C.
termination checklist requiring that keys and company property be returned and all
access permissions revoked upon termination.
D.
requirement for new employees to sign a nondisclosure agreement (NDA). - ✔✔A. Job
rotation is a valuable control to ensure continuity of operations, but not the most serious
human resources policy risk.
B. Holding an exit interview is desirable when possible to gain feedback, but is not a
serious risk.
CORRECT C. A termination checklist is critical to ensure the logical and physical
security of an enterprise. In addition to preventing the loss of company property issued
to the employee, there is the risk of unauthorized access, intellectual property theft and
even sabotage by a disgruntled former employee.
D. Signing a nondisclosure agreement (NDA) is a recommended human resources
practice, but a lack of an NDA is not the most serious risk listed.
✔✔From a control perspective, the key element in job descriptions is that they:
Select an answer:
A.
provide instructions on how to do the job and define authority.
B.
are current, documented and readily available to the employee.
C.
communicate management's specific job performance expectations.
D.
, establish responsibility and accountability for the employee's actions. - ✔✔A. Providing
instructions on how to do the job and defining authority addresses the managerial and
procedural aspects of the job and is a management responsibility. Job descriptions,
which are an human resources (HR)-related function, are primarily used to establish job
requirements and accountability.
B. It is important that job descriptions are current, documented and readily available to
the employee, but this, in itself, is not the key element of the job description. Job
descriptions, which are an HR-related function, are primarily used to establish job
requirements and accountability.
C. Communication of management's specific expectations for job performance would
not necessarily be included in job descriptions.
CORRECT D. From a control perspective, a job description should establish
responsibility and accountability. This will aid in ensuring that users are given system
access in accordance with their defined job responsibilities and are accountable for how
they use that access.
✔✔Which of the following would BEST provide assurance of the integrity of new staff?
Select an answer:
A.
Background screening
B.
References
C.
Bonding
D.
Qualifications listed on a résumé - ✔✔CORRECT A. A background screening is the
primary method for assuring the integrity of a prospective staff member. This may
include criminal history checks, driver's license abstracts, financial status checks,
verification of education, etc.
B. References are important and would need to be verified, but they are not as reliable
as background screening because the references themselves may not be validated as
trustworthy.
C. Bonding is directed at due-diligence compliance and does not ensure integrity.
D. Qualifications listed on a résumé may be used to demonstrate proficiency but will not
indicate the integrity of the candidate employee.