Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

Certified Information Systems Auditor (CISA) Exam

Rating
-
Sold
-
Pages
25
Grade
A+
Uploaded on
01-06-2026
Written in
2025/2026

Certified Information Systems Auditor (CISA) Exam

Institution
Certified Information Systems Auditor
Course
Certified Information Systems Auditor

Content preview

Certified Information Systems Auditor (CISA)
Exam
Full Professional Practice Examination

Question 1

Which of the following is the PRIMARY objective of an information systems audit?


A. To eliminate all organizational risks B. To ensure that IT investments generate profit C. To provide
assurance that controls support business objectives and mitigate risks D. To replace management
oversight responsibilities


Answer: C. To provide assurance that controls support business objectives and mitigate risks


Rationale: The primary objective of an information systems audit is to provide independent assurance
that controls are properly designed and operating effectively to support organizational goals while
mitigating risks. Auditors evaluate governance, risk management, and control processes to determine
whether systems safeguard assets, maintain data integrity, support operational effectiveness, and
comply with applicable laws and policies. Eliminating all risks is impossible, and management—not
auditors—retains responsibility for oversight and operational decisions.


Question 2

Which of the following provides the MOST reliable audit evidence?


A. Verbal confirmation from management B. Copies of internally generated reports C. Auditor
observation of a control being performed D. Evidence obtained directly from an independent external
source


Answer: D. Evidence obtained directly from an independent external source


Rationale: Evidence obtained directly from independent external sources is generally considered the
most reliable because it is less likely to be biased or manipulated. External confirmations, such as
bank statements or third-party confirmations, carry higher evidentiary value than internally generated
reports or verbal representations. Observation is useful but only reflects conditions at a specific point
in time.


Question 3

During audit planning, an IS auditor should FIRST:


A. Conduct substantive testing B. Review prior audit findings C. Develop the final audit report D. Notify
regulators of the engagement


Answer: B. Review prior audit findings




1

,Rationale: Reviewing prior audit findings helps the auditor understand historical weaknesses,
recurring issues, and areas of elevated risk. This information supports effective planning, risk
assessment, and scoping. Substantive testing occurs later in the audit process, while reporting and
regulatory notifications are not initial planning activities.


Question 4

Which type of control is designed to identify errors after processing has occurred?


A. Preventive control B. Detective control C. Directive control D. Corrective control


Answer: B. Detective control


Rationale: Detective controls identify errors or irregularities after they occur. Examples include
reconciliations, audit logs, exception reports, and intrusion detection systems. Preventive controls stop
errors before occurrence, directive controls guide behavior, and corrective controls restore systems or
processes after an issue has been detected.


Question 5

An IS auditor discovers that developers have unrestricted access to production systems. What is the
GREATEST concern?


A. Increased software licensing costs B. Reduced system performance C. Lack of segregation of duties
D. Delayed incident response


Answer: C. Lack of segregation of duties


Rationale: Allowing developers unrestricted access to production systems creates a serious
segregation-of-duties conflict. Developers may introduce unauthorized changes, conceal fraud, or
bypass established change management controls. Proper segregation ensures that development,
testing, and production responsibilities are separated to reduce the risk of errors and intentional
misconduct.


Question 6

Which of the following BEST indicates effective IT governance?


A. IT strategies are aligned with business objectives B. All IT decisions are centralized within the IT
department C. IT auditors approve all technology purchases D. End users manage cybersecurity policies
independently


Answer: A. IT strategies are aligned with business objectives


Rationale: Effective IT governance ensures that IT investments and operations support organizational
objectives, optimize resources, and manage risk appropriately. Alignment between business and IT
strategies is a fundamental principle of governance frameworks such as COBIT. Centralized decision-
making alone does not guarantee governance effectiveness, and auditors should remain independent
rather than approving operational decisions.




2

, Question 7

The PRIMARY purpose of a risk assessment during audit planning is to:


A. Eliminate all audit procedures B. Determine the audit scope and focus areas C. Replace management
controls D. Reduce staffing requirements


Answer: B. Determine the audit scope and focus areas


Rationale: Risk assessment enables auditors to identify high-risk areas requiring greater audit
attention. By evaluating inherent and residual risks, auditors can allocate resources efficiently and
define an appropriate scope. The purpose is not to eliminate procedures or replace management
responsibilities.


Question 8

Which of the following controls would BEST protect against unauthorized system access?


A. Data classification standards B. Role-based access control C. Network performance monitoring D.
Software asset inventory


Answer: B. Role-based access control


Rationale: Role-based access control (RBAC) restricts system access according to job responsibilities
and the principle of least privilege. This minimizes unauthorized access and reduces security risk. Data
classification supports information management, while performance monitoring and asset inventories
address different operational concerns.


Question 9

An organization’s disaster recovery plan should be tested primarily to:


A. Meet software licensing requirements B. Ensure backup media are encrypted C. Validate the
effectiveness of recovery procedures D. Eliminate the need for business continuity planning


Answer: C. Validate the effectiveness of recovery procedures


Rationale: Disaster recovery testing ensures that recovery procedures, personnel, systems, and
resources function effectively during an actual disruption. Testing identifies gaps, validates recovery
time objectives, and increases organizational preparedness. It does not eliminate the need for broader
business continuity planning.


Question 10

Which audit sampling method gives every item in a population an equal chance of selection?


A. Judgmental sampling B. Haphazard sampling C. Statistical random sampling D. Discovery sampling


Answer: C. Statistical random sampling




3

Written for

Institution
Certified Information Systems Auditor
Course
Certified Information Systems Auditor

Document information

Uploaded on
June 1, 2026
Number of pages
25
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$23.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
masterystudyhub Teachme2-tutor
View profile
Follow You need to be logged in order to follow users or courses
Sold
16
Member since
7 months
Number of followers
1
Documents
6168
Last sold
1 week ago
masterystudyhub

Welcome to MasteryStudyHub – Your Trusted Learning Partner MasteryStudyHub is dedicated to helping students, professionals, and lifelong learners achieve academic and career success through reliable, well-organized, and up-to-date study resources. Our collection includes comprehensive study guides, certification exam preparation materials, practice tests, review guides, nursing resources, healthcare documents, assignment support, case studies, discussion posts, and educational materials across business, finance, IT, cybersecurity, engineering, education, public safety, legal studies, and many other disciplines. Every resource is carefully reviewed to ensure accuracy, clarity, and relevance to current certification standards, licensing requirements, and academic curricula. Whether you\'re preparing for a professional certification, licensing exam, university course, or career advancement, our materials are designed to strengthen your knowledge, improve exam readiness, and boost your confidence. Why choose MasteryStudyHub? • High-quality, professionally organized study materials • Updated content aligned with current exam objectives • Comprehensive resources for academic and professional success • Instant digital downloads for convenient access • Customized study packages for specific learning needs Our mission is to provide affordable, accessible, and dependable educational resources that empower learners to excel in their studies and professional careers. Customer satisfaction is our priority, and we continuously improve our materials based on user feedback. Thank you for choosing MasteryStudyHub. Invest in your future, master your studies, and take the next step toward academic excellence and professional success.

Read more Read less
5.0

1 reviews

5
1
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions