CISA ACTUAL TEST PAPER QUESTIONS
AND ANSWERS VERIFIED REVIEW
●● D
Answer: Major advantage of risk based approach for audit planning is:
A. Audit planning can be communicated to client in advance.
B. Audit activity can be completed within allotted budget.
C. Use of latest technology for audit activities.
D. Appropriate utilisation of resources for high risk areas.
●● B
Answer: The decisions and actions of an IS auditor are MOST likely to
affect which of the following risks?
A. Inherent
B. Detection
C. Control
D. Business
●● A
,Answer: In planning an audit, the MOST critical step is the
identification of the:
A. areas of high risk.
B. skill sets of the audit staff.
C. test steps in the audit.
D. time allotted for the audit.
●● A
Answer: Risk assessment process is :
A. subjective.
B. objective.
C. mathematical.
D. statistical.
●● C
Answer: The result of risk management process is used for:
A. forecasting profit
B. post implementation review.
C. designing controls
,D. user acceptance testing.
(7) IS Auditor is developing a risk
●● C
Answer: IS Auditor is developing a risk management program, , the
FIRST activity to be performed is a(n):
A. vulnerability assessment.
B. evaluation of control.
C. identification of assets.
D. gap analysis.
●● B
Answer: Benefit of development of organizational policies by bottom-up
approach is that they:
A. covers whole organization.
B. are derived as a result of a risk assessment.
C. will be in line with overall corporate policy.
D. ensures consistency across the organization.
●● A
Answer: Risk can be mitigated by:
, A. Implementing controls
B. Insurance
C. Audit and certification
D. Contracts and service level agreements (SLAs)
●● A
Answer: Most important factor while evaluating controls is to ensure
that the controls:
A. addresses the risk
B. do not reduce productivity.
C. is less costly than risk.
D. is automotive.
●● C
Answer: A key element in a risk analysis is:
A. audit planning.
B. controls.
C. vulnerabilities.
D. liabilities.
AND ANSWERS VERIFIED REVIEW
●● D
Answer: Major advantage of risk based approach for audit planning is:
A. Audit planning can be communicated to client in advance.
B. Audit activity can be completed within allotted budget.
C. Use of latest technology for audit activities.
D. Appropriate utilisation of resources for high risk areas.
●● B
Answer: The decisions and actions of an IS auditor are MOST likely to
affect which of the following risks?
A. Inherent
B. Detection
C. Control
D. Business
●● A
,Answer: In planning an audit, the MOST critical step is the
identification of the:
A. areas of high risk.
B. skill sets of the audit staff.
C. test steps in the audit.
D. time allotted for the audit.
●● A
Answer: Risk assessment process is :
A. subjective.
B. objective.
C. mathematical.
D. statistical.
●● C
Answer: The result of risk management process is used for:
A. forecasting profit
B. post implementation review.
C. designing controls
,D. user acceptance testing.
(7) IS Auditor is developing a risk
●● C
Answer: IS Auditor is developing a risk management program, , the
FIRST activity to be performed is a(n):
A. vulnerability assessment.
B. evaluation of control.
C. identification of assets.
D. gap analysis.
●● B
Answer: Benefit of development of organizational policies by bottom-up
approach is that they:
A. covers whole organization.
B. are derived as a result of a risk assessment.
C. will be in line with overall corporate policy.
D. ensures consistency across the organization.
●● A
Answer: Risk can be mitigated by:
, A. Implementing controls
B. Insurance
C. Audit and certification
D. Contracts and service level agreements (SLAs)
●● A
Answer: Most important factor while evaluating controls is to ensure
that the controls:
A. addresses the risk
B. do not reduce productivity.
C. is less costly than risk.
D. is automotive.
●● C
Answer: A key element in a risk analysis is:
A. audit planning.
B. controls.
C. vulnerabilities.
D. liabilities.