Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 16 pages
Exam (elaborations)

Cisa 2 Questions & 100% Correct Answers

Document preview thumbnail
Preview 3 out of 16 pages

An IS auditor is reviewing access to an application to determine whether the 10 most recent "new user" forms were correctly authorized. This is an example of: :~~ compliance testing. The decisions and actions of an IS auditor are MOST likely to affect which of the following risks? :~~ Detection Overall business risk for a particular threat can be expressed as: :~~ a product of the probability and magnitude of the impact if a threat successfully exploits a vulnerability. Which of the following is a substantive test? :~~ Using a statistical sample to inventory the tape library Which of the following is a benefit of a risk-based approach to audit planning? Audit: :~~ resources are allocated to the areas of highest concern 2 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update An audit charter should: :~~ outline the overall authority, scope and responsibilities of the audit function. The MAJOR advantage of the risk assessment approach over the baseline approach to information security management is that it ensures: :~~ appropriate levels of protection are applied to information assets. Which of the following sampling methods is MOST useful when testing for compliance? :~~ Attribute sampling Which of the following is the MOST likely reason why e-mail systems have become a useful source of evidence for litigation? :~~ Multiple cycles of backup files remain available. An IS auditor is assigned to perform a postimplementation review of an application system. Which of the following situations may have impaired the independence of the IS auditor? The IS auditor: :~~ implemented a specific control during the development of the application system. 3 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update The PRIMARY advantage of a continuous audit approach is that it: :~~ can improve system security when used in time-sharing environments that process a large number of transactions. The PRIMARY purpose of audit trails is to: :~~ establish accountability and responsibility for processed transactions. When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that: :~~ vulnerabilities and threats are identified. To ensure that audit resources deliver the best value to the organization, the FIRST step would be to:

Content preview

1 | P a g e | © copyright 2024/2025 | Grade A+




Cisa 2 Questions & 100% Correct
Answers
An IS auditor is reviewing access to an application to determine whether the 10

most recent "new user" forms were correctly authorized. This is an example of:

✓ :~~ compliance testing.




The decisions and actions of an IS auditor are MOST likely to affect which of the

following risks?

✓ :~~ Detection




Overall business risk for a particular threat can be expressed as:

✓ :~~ a product of the probability and magnitude of the impact if a threat

successfully exploits a vulnerability.




Which of the following is a substantive test?

✓ :~~ Using a statistical sample to inventory the tape library




Which of the following is a benefit of a risk-based approach to audit planning?

Audit:

✓ :~~ resources are allocated to the areas of highest concern




Master01 | September, 2024/2025 | Latest update

, 2 | P a g e | © copyright 2024/2025 | Grade A+


An audit charter should:

✓ :~~ outline the overall authority, scope and responsibilities of the audit

function.




The MAJOR advantage of the risk assessment approach over the baseline approach

to information security management is that it ensures:

✓ :~~ appropriate levels of protection are applied to information assets.




Which of the following sampling methods is MOST useful when testing for

compliance?


✓ :~~ Attribute sampling




Which of the following is the MOST likely reason why e-mail systems have become

a useful source of evidence for litigation?

✓ :~~ Multiple cycles of backup files remain available.




An IS auditor is assigned to perform a postimplementation review of an application

system. Which of the following situations may have impaired the independence of

the IS auditor? The IS auditor:

✓ :~~ implemented a specific control during the development of the

application system.




Master01 | September, 2024/2025 | Latest update

, 3 | P a g e | © copyright 2024/2025 | Grade A+


The PRIMARY advantage of a continuous audit approach is that it:

✓ :~~ can improve system security when used in time-sharing environments

that process a large number of transactions.




The PRIMARY purpose of audit trails is to:


✓ :~~ establish accountability and responsibility for processed transactions.




When developing a risk-based audit strategy, an IS auditor should conduct a risk

assessment to ensure that:

✓ :~~ vulnerabilities and threats are identified.




To ensure that audit resources deliver the best value to the organization, the

FIRST step would be to:

✓ :~~ develop the audit plan on the basis of a detailed risk assessment.




An organization's IS audit charter should specify the:

✓ :~~ role of the IS audit function.




An IS auditor is evaluating management's risk assessment of information systems.

The IS auditor should FIRST review:

✓ :~~ the threats/vulnerabilities affecting the assets.




Master01 | September, 2024/2025 | Latest update

Document information

Uploaded on
September 9, 2024
Number of pages
16
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Axpert
3.8
(126)
Sold
560
Followers
167
Items
29320
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions