CISA STUDY GUIDE 2026 EXAM QUESTIONS AND ANSWERS
GRADED A+
✔✔To aid management in achieving IT and business alignment, an IS auditor should
recommend the use of:
Select an answer:
A.
control self-assessments.
B.
a business impact analysis (BIA).
C.
an IT balanced scorecard (BSC).
D.
business process reengineering (BPR). - ✔✔You are correct, the answer is C.
A. Control self-assessments (CSAs) are used to improve monitoring of security controls,
but are not used to align IT with organizational objectives.
B. A business impact analysis (BIA) is used to calculate the impact on the business in
the event of an incident that affects business operations, but it is not used to align IT
with organizational objectives.
C. An IT balanced scorecard (BSC) provides the bridge between IT objectives and
business objectives by supplementing the traditional financial evaluation with measures
to evaluate customer satisfaction, internal processes and the ability to innovate.
D. Business process reengineering (BPR) is an excellent tool to review and improve
business processes, but is not focused on aligning IT with organizational objectives.
✔✔When reviewing the IT strategic planning process, an IS auditor should ensure that
the plan:
Select an answer:
A.
incorporates state of the art technology.
B.
addresses the required operational controls.
C.
articulates the IT mission and vision.
,D.
specifies project management practices. - ✔✔You answered B. The correct answer is
C.
A. The plan does not need to address state of the art technology; the decision to
implement new technology is dependent on the approach to risk and management
strategy.
B. The plan does not need to address operational controls because those are too
granular for strategic planning.
C. The IT strategic plan must include a clear articulation of the IT mission and vision.
D. The plan should be implemented with proper project management, but the plan does
not need to address project management practices.
✔✔When reviewing an organization's strategic IT plan, an IS auditor should expect to
find:
Select an answer:
A.
an assessment of the fit of the organization's application portfolio with business
objectives.
B.
actions to reduce hardware procurement cost.
C.
a listing of approved suppliers of IT contract resources.
D.
a description of the technical architecture for the organization's network perimeter
security. - ✔✔You are correct, the answer is A.
A. An assessment of how well an organization's application portfolio supports the
organization's business objectives is a key component of the overall IT strategic
planning process. This drives the demand side of IT planning and should convert into a
set of strategic IT intentions. Further assessment can then be made of how well the
overall IT organization, encompassing applications, infrastructure, services,
management processes, etc., can support the business objectives. The purpose of an
IT strategic plan is to set out how IT will be used to achieve or support an organization's
business objectives.
B. Operational efficiency initiatives, including cost reduction of purchasing and
maintenance activities of systems, belong to tactical planning, not strategic planning.
,C. A list of approved suppliers of IT contract resources is a tactical rather than a
strategic concern.
D. An IT strategic plan would not normally include detail of a specific technical
architecture.
✔✔The MOST important point of consideration for an IS auditor while reviewing an
enterprise's project portfolio is that it:
Select an answer:
A.
does not exceed the existing IT budget.
B.
is aligned with the investment strategy.
C.
has been approved by the IT steering committee.
D.
is aligned with the business plan. - ✔✔You are correct, the answer is D.
A. It should be identified if the project portfolio exceeds the IT budget, but it is not as
critical as ensuring that it is aligned with the business plan.
B. The project portfolio should be aligned with the investment strategy, but it is most
important that it is aligned with the business plan.
C. Appropriate approval of the project portfolio should be granted. However, not every
enterprise has an IT steering committee, and this is not as critical as ensuring that the
projects are aligned with the business plan.
D. Portfolio management takes a holistic view of an enterprise's overall IT strategy,
which, in turn, should be aligned with the business strategy. A business plan provides
the justification for each of the projects in the project portfolio, and that is the major
consideration for an IS auditor.
✔✔Which of the following is the BEST enabler for strategic alignment between business
and IT?
Select an answer:
A.
A maturity model
B.
Goals and metrics
, C.
Control objectives
D.
A responsible, accountable, consulted and informed (RACI) chart - ✔✔You are correct,
the answer is B.
A. Maturity models enable assessment of current process capability and could be used
for process improvement and measuring the maturity of the alignment process, but they
do not directly enable strategic alignment.
B. Goals and metrics ensure that IT goals are set based on business goals, and they
are the best enablers of strategic alignment.
C. Control objectives facilitate the implementation of controls in the related processes
according to business requirements.
D. RACI charts enable the assignment of responsibility to key functionaries but do not
ensure strategic alignment.
✔✔Which of the following is the BEST reason to implement a policy which places
conditions on secondary employment for IT employees?
Select an answer:
A.
To prevent the misuse of corporate resources
B.
To prevent conflicts of interest
C.
To prevent employee performance issues
D.
To prevent theft of IT assets - ✔✔You are correct, the answer is B.
A. The misuse of corporate resources is an issue that must be addressed but is not
necessarily related to secondary employment.
B. The best reason to implement and enforce a policy governing secondary employment
is to prevent conflicts of interest. Policies should be in place to control IT employees
seeking secondary employment from releasing sensitive information or working for a
competing company. Conflicts of interest could result in serious risk such as fraud, theft
of intellectual property or other improprieties.
GRADED A+
✔✔To aid management in achieving IT and business alignment, an IS auditor should
recommend the use of:
Select an answer:
A.
control self-assessments.
B.
a business impact analysis (BIA).
C.
an IT balanced scorecard (BSC).
D.
business process reengineering (BPR). - ✔✔You are correct, the answer is C.
A. Control self-assessments (CSAs) are used to improve monitoring of security controls,
but are not used to align IT with organizational objectives.
B. A business impact analysis (BIA) is used to calculate the impact on the business in
the event of an incident that affects business operations, but it is not used to align IT
with organizational objectives.
C. An IT balanced scorecard (BSC) provides the bridge between IT objectives and
business objectives by supplementing the traditional financial evaluation with measures
to evaluate customer satisfaction, internal processes and the ability to innovate.
D. Business process reengineering (BPR) is an excellent tool to review and improve
business processes, but is not focused on aligning IT with organizational objectives.
✔✔When reviewing the IT strategic planning process, an IS auditor should ensure that
the plan:
Select an answer:
A.
incorporates state of the art technology.
B.
addresses the required operational controls.
C.
articulates the IT mission and vision.
,D.
specifies project management practices. - ✔✔You answered B. The correct answer is
C.
A. The plan does not need to address state of the art technology; the decision to
implement new technology is dependent on the approach to risk and management
strategy.
B. The plan does not need to address operational controls because those are too
granular for strategic planning.
C. The IT strategic plan must include a clear articulation of the IT mission and vision.
D. The plan should be implemented with proper project management, but the plan does
not need to address project management practices.
✔✔When reviewing an organization's strategic IT plan, an IS auditor should expect to
find:
Select an answer:
A.
an assessment of the fit of the organization's application portfolio with business
objectives.
B.
actions to reduce hardware procurement cost.
C.
a listing of approved suppliers of IT contract resources.
D.
a description of the technical architecture for the organization's network perimeter
security. - ✔✔You are correct, the answer is A.
A. An assessment of how well an organization's application portfolio supports the
organization's business objectives is a key component of the overall IT strategic
planning process. This drives the demand side of IT planning and should convert into a
set of strategic IT intentions. Further assessment can then be made of how well the
overall IT organization, encompassing applications, infrastructure, services,
management processes, etc., can support the business objectives. The purpose of an
IT strategic plan is to set out how IT will be used to achieve or support an organization's
business objectives.
B. Operational efficiency initiatives, including cost reduction of purchasing and
maintenance activities of systems, belong to tactical planning, not strategic planning.
,C. A list of approved suppliers of IT contract resources is a tactical rather than a
strategic concern.
D. An IT strategic plan would not normally include detail of a specific technical
architecture.
✔✔The MOST important point of consideration for an IS auditor while reviewing an
enterprise's project portfolio is that it:
Select an answer:
A.
does not exceed the existing IT budget.
B.
is aligned with the investment strategy.
C.
has been approved by the IT steering committee.
D.
is aligned with the business plan. - ✔✔You are correct, the answer is D.
A. It should be identified if the project portfolio exceeds the IT budget, but it is not as
critical as ensuring that it is aligned with the business plan.
B. The project portfolio should be aligned with the investment strategy, but it is most
important that it is aligned with the business plan.
C. Appropriate approval of the project portfolio should be granted. However, not every
enterprise has an IT steering committee, and this is not as critical as ensuring that the
projects are aligned with the business plan.
D. Portfolio management takes a holistic view of an enterprise's overall IT strategy,
which, in turn, should be aligned with the business strategy. A business plan provides
the justification for each of the projects in the project portfolio, and that is the major
consideration for an IS auditor.
✔✔Which of the following is the BEST enabler for strategic alignment between business
and IT?
Select an answer:
A.
A maturity model
B.
Goals and metrics
, C.
Control objectives
D.
A responsible, accountable, consulted and informed (RACI) chart - ✔✔You are correct,
the answer is B.
A. Maturity models enable assessment of current process capability and could be used
for process improvement and measuring the maturity of the alignment process, but they
do not directly enable strategic alignment.
B. Goals and metrics ensure that IT goals are set based on business goals, and they
are the best enablers of strategic alignment.
C. Control objectives facilitate the implementation of controls in the related processes
according to business requirements.
D. RACI charts enable the assignment of responsibility to key functionaries but do not
ensure strategic alignment.
✔✔Which of the following is the BEST reason to implement a policy which places
conditions on secondary employment for IT employees?
Select an answer:
A.
To prevent the misuse of corporate resources
B.
To prevent conflicts of interest
C.
To prevent employee performance issues
D.
To prevent theft of IT assets - ✔✔You are correct, the answer is B.
A. The misuse of corporate resources is an issue that must be addressed but is not
necessarily related to secondary employment.
B. The best reason to implement and enforce a policy governing secondary employment
is to prevent conflicts of interest. Policies should be in place to control IT employees
seeking secondary employment from releasing sensitive information or working for a
competing company. Conflicts of interest could result in serious risk such as fraud, theft
of intellectual property or other improprieties.