• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 68 pages
Exam (elaborations)

CISA Certified Information Systems Auditor Examination: Advanced Comprehensive Practice Question Bank v3.1 a well detailed exam 2025/2026 graded A+ upgraded !!!

Document preview thumbnail
Preview 4 out of 68 pages

CISA Certified Information Systems Auditor Examination: Advanced Comprehensive Practice Question Bank v3.1 a well detailed exam 2025/2026 graded A+ upgraded !!!

Content preview

CISA Certified Information Systems Auditor
Examination: Advanced Comprehensive
Practice Question Bank v3.1 a well detailed
exam 2025/2026 graded A+ upgraded !!!




150 Multiple-Choice Questions with Detailed Rationales
Aligned with the 2024–2029 CISA Exam Content Outline
Difficulty Level: Advanced/Hard



DOMAIN 1: INFORMATION SYSTEMS AUDITING PROCESS (18%)

Questions 1–27



Question 1

An IS auditor is planning a comprehensive audit of a multinational financial institution with
operations spanning 23 countries, each with distinct regulatory requirements, varying levels of
IT maturity, and different threat landscapes. The audit budget has been reduced by 15% and the
auditor has only 10 weeks to complete the engagement. Which of the following approaches
would be MOST appropriate for determining the audit scope and allocating audit resources?

A. Apply a uniform audit program across all locations to ensure consistency and comparability of
results
B. Perform a risk-based assessment considering regulatory requirements, business criticality,
and control maturity to prioritize locations and systems
C. Focus exclusively on locations with the highest revenue contribution to maximize business
value

,D. Audit only locations that have experienced significant security incidents in the past 12
months

Correct Answer: B

Rationale: A risk-based approach is fundamental to effective IS auditing, especially when
resources are constrained. The auditor must assess regulatory requirements, business criticality,
control maturity, and threat exposure to prioritize areas of highest risk. A uniform program (A)
would waste resources on low-risk areas and potentially miss high-risk areas. Revenue focus (C)
ignores other critical risk factors such as regulatory exposure, data sensitivity, and control
weaknesses. Incident-based approach (D) is reactive and may miss areas with unexposed
vulnerabilities.



Question 2

During the execution phase of an audit of a cloud-native banking platform, the IS auditor
identifies that the organization's continuous integration/continuous deployment (CI/CD)
pipeline lacks segregation of duties between development, testing, and production deployment.
The auditor has obtained evidence through code repository analysis, pipeline configuration
reviews, and interviews with the DevOps team. Which of the following is the MOST appropriate
NEXT action?

A. Report the finding immediately to senior management as a critical control deficiency
B. Expand testing to determine the extent and impact of the segregation of duties weakness
across all applications
C. Close the audit finding as sufficient evidence has already been collected
D. Recommend immediate implementation of a change management policy without further
testing

Correct Answer: B

Rationale: When a potential material weakness is identified, the auditor must expand testing to
determine the full extent and impact before reaching a conclusion. The finding affects the entire
CI/CD pipeline and potentially all applications. Reporting prematurely (A) without complete
understanding may be inaccurate or incomplete. Closing the finding (C) without sufficient
testing violates professional standards. Recommending immediate remediation (D) before fully
understanding the issue is premature and may not address the root cause.



Question 3

,An IS auditor is evaluating the audit evidence collected during an engagement involving a
complex blockchain-based supply chain system. The auditor has obtained: (1) system-generated
transaction logs, (2) written confirmations from the blockchain network operator, (3) direct
observation of smart contract execution, and (4) inquiry of the development team. Which of the
following types of evidence is generally considered the MOST reliable and why?

A. System-generated transaction logs, because they are produced by the system itself without
human intervention
B. Written confirmations from the blockchain network operator, because they are from an
independent third party
C. Direct observation of smart contract execution, because it provides direct evidence obtained
by the auditor
D. Inquiry of the development team, because they have the most detailed technical knowledge

Correct Answer: C

Rationale: Evidence obtained directly by the auditor through observation or independent
testing is generally more reliable than evidence obtained from others. While system-generated
logs (A) may appear objective, they can be manipulated. Third-party confirmations (B) are
reliable but less so than direct observation. Inquiry (D) is the least reliable form of evidence and
must be corroborated. Direct observation provides the auditor with first-hand, verifiable
evidence of the control or process.



Question 4

An IS auditor is using statistical sampling to test the operating effectiveness of a control that is
expected to have a 2% deviation rate across a population of 25,000 transactions. The auditor
wants to achieve a 95% confidence level with a 5% tolerable deviation rate. The auditor's
preliminary sample of 100 transactions revealed a deviation rate of 3%. Which of the following
actions is MOST appropriate?

A. Accept the sample results as the deviation rate is within the tolerable range
B. Increase the sample size to achieve more precise results
C. Stop testing and report the control as ineffective
D. Reduce the confidence level to 90% to make the sample results acceptable

Correct Answer: B

Rationale: The preliminary sample deviation rate (3%) exceeds the expected rate (2%) and
approaches the tolerable rate (5%). This suggests the sample size may need to be increased to
obtain more precise results and determine whether the control is actually operating effectively.

, Accepting the results (A) without further testing is premature. Stopping testing (C) without
sufficient evidence violates professional standards. Reducing confidence level (D) compromises
the audit quality and is unethical.



Question 5

An IS auditor is reviewing the work papers of a junior auditor who performed testing on the
organization's identity and access management (IAM) controls. The junior auditor documented
that "the IAM controls appear to be operating effectively based on a sample of 50 user
accounts." The work papers contain no description of the sampling methodology, the criteria
used for account selection, or the test procedures performed. Which of the following is the
auditor's PRIMARY concern?

A. The sample size of 50 is insufficient for a meaningful conclusion
B. The work papers do not provide sufficient evidence to support the conclusion
C. The junior auditor lacked the necessary expertise to perform the testing
D. The IAM controls may not be operating effectively

Correct Answer: B

Rationale: The primary concern is that the work papers do not document the sampling
methodology, selection criteria, or test procedures, which is necessary to support the audit
conclusion. While the sample size (A) may or may not be sufficient, the lack of documentation is
the more fundamental concern. The junior auditor's expertise (C) may be a concern but is not
evidenced. The effectiveness of IAM controls (D) is unknown due to the inadequate
documentation, but the primary issue is the work paper quality.



Question 6

An IS auditor is performing a post-implementation review of a new artificial intelligence (AI)-
based loan underwriting system that was implemented six months ago. The system uses
machine learning algorithms to assess credit risk and make automated lending decisions. Which
of the following should be the auditor's PRIMARY area of focus?

A. Whether the project was completed within the original budget and timeline
B. Whether the AI model's decisions are explainable, fair, and free from bias
C. Whether the system was developed using the latest programming languages
D. Whether the system vendor provided adequate training to users

Correct Answer: B

Document information

Uploaded on
July 19, 2026
Number of pages
68
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$28.16

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopMarkStudyHub
2.5
(2)
Sold
19
Followers
0
Items
2363
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions