Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

CISA Certification Exam 2026 Latest Comprehensive Study Guide with Practice Questions

Document preview thumbnail
Preview 4 out of 48 pages

CISA Certification Exam 2026 Latest Comprehensive Study Guide with Practice Questions

Content preview

CISA Certification Exam 2026 Latest Comprehensive
Study Guide with Practice Questions

Five Exam Domains (August 2024 Content Outline, effective 2026):

Domain Weight

Domain 1: Information Systems Auditing Process 18%

Domain 2: Governance and Management of IT 18%

Domain 3: Information Systems Acquisition, Development & Implementation 12%

Domain 4: Information Systems Operations and Business Resilience 26%

Domain 5: Protection of Information Assets 26%

Note: Domains 4 and 5 together account for 52% of the exam—these are the
highest-weighted areas and should receive significant study focus. The exam
follows ISACA's CISA Job Practice and references ITAF™ (ISACA IT Audit
Framework) , COBIT® 2019, and ISACA's Code of Professional Ethics.


SECTION 1: DOMAIN 1 — INFORMATION SYSTEMS AUDITING
PROCESS (18%) (Questions 1-20)


Question 1
Which of the following is the PRIMARY objective of an information systems
audit?
A) To identify all security vulnerabilities in an organization's IT infrastructure
B) To evaluate the design, effectiveness, and efficiency of controls over
information systems

,C) To ensure compliance with all applicable laws and regulations
D) To recommend cost-saving measures for IT operations
Correct Answer: B
Rationale: The primary objective of an IS audit is to evaluate the design,
effectiveness, and efficiency of controls over information systems. While
identifying vulnerabilities (A), ensuring compliance (C), and recommending cost
savings (D) may be part of an audit, they are not the primary objective. The IS
auditor's core responsibility is to assess whether controls are properly designed,
implemented, and operating effectively to protect organizational assets, ensure data
integrity, and support business objectives.


Question 2
An IS auditor is planning an audit of a financial system. According to ISACA
standards, which of the following should the auditor do FIRST?
A) Develop detailed audit procedures
B) Perform a risk assessment to determine the audit scope
C) Interview system users to gather evidence
D) Review the system's access control logs
Correct Answer: B
Rationale: According to ISACA auditing standards, the auditor should perform a
risk assessment to determine the audit scope as the first step in audit planning.
The risk assessment identifies areas of highest risk and informs the development of
the audit plan, including the scope, objectives, and procedures. Developing
detailed audit procedures (A), interviewing users (C), and reviewing logs (D) occur
after the risk assessment and scope definition.


Question 3
Which of the following ISACA standards addresses the auditor's responsibility to
maintain professional competence?
A) Standard S1 — Audit Charter
B) Standard S2 — Independence

,C) Standard S3 — Professional Skepticism
D) Standard S4 — Competence
Correct Answer: D
Rationale: Standard S4 — Competence addresses the IS auditor's responsibility
to maintain professional knowledge and skills to perform their duties effectively.
This includes ongoing professional development, staying current with emerging
technologies and threats, and knowing when to seek expert assistance. S1 (Audit
Charter), S2 (Independence), and S3 (Professional Skepticism) address other
aspects of professional practice.


Question 4
During an audit, an IS auditor identifies a material weakness in the organization's
access control system. What is the auditor's MOST appropriate course of action?
A) Document the finding and report it to senior management and the audit
committee
B) Fix the access control issue immediately
C) Ignore the finding since it is outside the audit scope
D) Report the finding only to the IT department manager
Correct Answer: A
Rationale: When a material weakness is identified, the IS auditor must document
the finding and report it to senior management and the audit committee.
Material weaknesses represent significant deficiencies that could materially affect
the organization's ability to achieve its objectives. The auditor's role is to report
and recommend, not to fix the issue directly (B). Ignoring the finding (C) violates
professional standards. Reporting only to the IT manager (D) may not ensure
appropriate oversight.


Question 5
Which of the following is the BEST example of a preventive control?
A) Intrusion detection system (IDS)
B) Firewall with access control rules

, C) Security incident response plan
D) Disaster recovery testing
Correct Answer: B
Rationale: A firewall with access control rules is a preventive control because
it is designed to prevent unauthorized access from occurring in the first place.
Preventive controls stop errors or irregularities before they happen. An intrusion
detection system (A) is a detective control—it identifies problems after they occur.
A security incident response plan (C) and disaster recovery testing (D) are
corrective controls—they address problems after they have been detected.


Question 6
When performing a risk-based audit, an IS auditor should prioritize audit activities
based on:
A) The age of the systems being audited
B) The preferences of the audit committee
C) The level of risk and the impact on business objectives
D) The cost of the audit procedures
Correct Answer: C
Rationale: In a risk-based audit, the auditor should prioritize audit activities
based on the level of risk and the impact on business objectives. This approach
ensures that the most critical areas—those with the highest potential impact on the
organization—receive the most attention. System age (A), committee preferences
(B), and audit cost (D) are not the primary drivers of audit prioritization in a risk-
based approach.


Question 7
An IS auditor is evaluating evidence collected during an audit. Which of the
following types of evidence is generally considered the MOST reliable?
A) Oral evidence from an employee interview
B) Documentary evidence from a third party (e.g., bank statement)

Document information

Uploaded on
August 11, 2026
Number of pages
48
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.69

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
18
Followers
0
Items
2497
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions