Certified Information Systems Auditor (CISA)
Practice Test Exam
1. What is the primary purpose of an IS audit?
A) Detect fraud only
B) Provide assurance that controls are in place and effective
C) Manage IT projects
D) Develop IT policies
Correct Answer: B
Rationale: IS audits evaluate the adequacy and effectiveness of
IT controls to support business objectives. The primary purpose
is to provide independent assurance, not to detect fraud
exclusively or manage projects .
2. Which framework is widely used for IT governance and
controls?
A) ITIL
B) COBIT
C) ISO 9001
,D) NIST Cybersecurity Framework
Correct Answer: B
Rationale: COBIT provides a comprehensive framework for IT
governance, controls, and audit alignment. ITIL focuses on
service management, ISO 9001 on quality, and NIST on
cybersecurity .
3. What is the FIRST step in planning an IS audit?
A) Select the sample
B) Understand the business and its risks, then define scope and
objectives based on a risk assessment
C) Test controls
D) Write the report
Correct Answer: B
Rationale: Risk-based planning directs limited audit effort
toward what matters. Understanding the business and
performing a risk assessment must precede sampling and
testing .
,4. Which evidence is considered most reliable by an IS auditor?
A) A verbal statement from the system owner
B) Evidence obtained directly by the auditor from an
independent external source
C) An internal report provided by the auditee
D) A policy document
Correct Answer: B
Rationale: Reliability rises with auditor-obtained, external, and
objective evidence. Auditor observation is also reliable, but
evidence from independent external sources is particularly
strong .
5. An IS auditor discovers a control deficiency during fieldwork.
What is the auditor's BEST course of action?
A) Fix it immediately
B) Document the finding with evidence, assess its risk, discuss it
with management, and report it
C) Report it to the regulator first
D) Ignore it if it is minor
, Correct Answer: B
Rationale: Implementing the fix destroys the auditor's
independence. The auditor's product is a documented,
evidenced finding and a recommendation; remediation belongs
to management .
6. Which control type is a detective control?
A) Firewall
B) Backup procedures
C) Intrusion detection systems (IDS)
D) Segregation of duties
Correct Answer: C
Rationale: Detective controls identify incidents after they occur
to allow corrective action. Firewalls and segregation of duties
are preventive; backups are corrective .
7. What is the primary purpose of a disaster recovery plan
(DRP)?
A) Ensure IT projects are completed on time
B) Maintain business continuity during disruptions
Practice Test Exam
1. What is the primary purpose of an IS audit?
A) Detect fraud only
B) Provide assurance that controls are in place and effective
C) Manage IT projects
D) Develop IT policies
Correct Answer: B
Rationale: IS audits evaluate the adequacy and effectiveness of
IT controls to support business objectives. The primary purpose
is to provide independent assurance, not to detect fraud
exclusively or manage projects .
2. Which framework is widely used for IT governance and
controls?
A) ITIL
B) COBIT
C) ISO 9001
,D) NIST Cybersecurity Framework
Correct Answer: B
Rationale: COBIT provides a comprehensive framework for IT
governance, controls, and audit alignment. ITIL focuses on
service management, ISO 9001 on quality, and NIST on
cybersecurity .
3. What is the FIRST step in planning an IS audit?
A) Select the sample
B) Understand the business and its risks, then define scope and
objectives based on a risk assessment
C) Test controls
D) Write the report
Correct Answer: B
Rationale: Risk-based planning directs limited audit effort
toward what matters. Understanding the business and
performing a risk assessment must precede sampling and
testing .
,4. Which evidence is considered most reliable by an IS auditor?
A) A verbal statement from the system owner
B) Evidence obtained directly by the auditor from an
independent external source
C) An internal report provided by the auditee
D) A policy document
Correct Answer: B
Rationale: Reliability rises with auditor-obtained, external, and
objective evidence. Auditor observation is also reliable, but
evidence from independent external sources is particularly
strong .
5. An IS auditor discovers a control deficiency during fieldwork.
What is the auditor's BEST course of action?
A) Fix it immediately
B) Document the finding with evidence, assess its risk, discuss it
with management, and report it
C) Report it to the regulator first
D) Ignore it if it is minor
, Correct Answer: B
Rationale: Implementing the fix destroys the auditor's
independence. The auditor's product is a documented,
evidenced finding and a recommendation; remediation belongs
to management .
6. Which control type is a detective control?
A) Firewall
B) Backup procedures
C) Intrusion detection systems (IDS)
D) Segregation of duties
Correct Answer: C
Rationale: Detective controls identify incidents after they occur
to allow corrective action. Firewalls and segregation of duties
are preventive; backups are corrective .
7. What is the primary purpose of a disaster recovery plan
(DRP)?
A) Ensure IT projects are completed on time
B) Maintain business continuity during disruptions