Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 65 pages
Exam (elaborations)

CISA Domain 1 Questions & 100% Correct Answers

Document preview thumbnail
Preview 4 out of 65 pages

An IS auditor is conducting a compliance test to determine whether controls support management policies and procedures. The test will assist the IS auditor to determine: :~~ That the control is operating as designed Compliance tests can be used to test the existence and effectiveness of a defined process. Understanding the objective of a compliance test is important. IS auditors want reasonable assurance that the controls they are relying on are effective. An effective control is one that meets management expectations and objectives. When developing a risk management program, what is the first activity to be performed? :~~ Inventory of assets. Identification of the assets to be protected is the first step in developing a risk management program. The primary purpose of an IT forensic audit is: 2 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update :~~ The systemic collection and analysis of evidence after a system irregularity. Due to resource constraints of the IS audit team, the audit plan as originally approved cannot be completed. Assuming that the situation is communicated in the audit report, which course of action is most acceptable: Test the adequacy of the control design Test the operational effectiveness of the control Focus on auditing high risk areas Relying on management testing of controls. :~~ Focus on high risk areas. Reducing the scope and focusing on auditing high-risk areas is the bets course of action. While planning an IS audit, an assessment of risk should be made to provide: :~~ Reasonable assurance that the audit will cover material items. ISACA IS Audit and Assurance Guideline 2202 (Risk Assessment in Planning) states that the applied risk assessment approach should help with the prioritization and scheduling process of the IS audit and assurance work. It should support the selection process of areas and items of audit interest and the decision process to design and conduct particular IS audit engagements. 3 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update Which of the following best describes the purpose of performing a risk assessment in the planning phase of an IS audit: Establish adequate staffing requirements to complete the IS audit To provide reasonable assurance that all material items will be addressed To determine the skills required to perform the IS audit To develop the audit program and procedures :~~ To provide reasonable assurance that all material items will be addressed. A risk assessment helps focus the audit procedures on the highest risk areas included in the scope of the audit. A financial institution with multiple branch offices has an automated control that requires the branch manager to approve transactions more than a certain amount. What type of audit control is this? :~~ Preventative.

Content preview

1 | P a g e | © copyright 2024/2025 | Grade A+




CISA Domain 1 Questions & 100%
Correct Answers
An IS auditor is conducting a compliance test to determine whether controls

support management policies and procedures. The test will assist the IS auditor to

determine:


✓ :~~ That the control is operating as designed




Compliance tests can be used to test the existence and effectiveness of a defined

process. Understanding the objective of a compliance test is important. IS auditors

want reasonable assurance that the controls they are relying on are effective. An

effective control is one that meets management expectations and objectives.




When developing a risk management program, what is the first activity to be

performed?

✓ :~~ Inventory of assets.




Identification of the assets to be protected is the first step in developing a risk

management program.




The primary purpose of an IT forensic audit is:




Master01 | September, 2024/2025 | Latest update

, 2 | P a g e | © copyright 2024/2025 | Grade A+


✓ :~~ The systemic collection and analysis of evidence after a system

irregularity.




Due to resource constraints of the IS audit team, the audit plan as originally

approved cannot be completed. Assuming that the situation is communicated in

the audit report, which course of action is most acceptable:




Test the adequacy of the control design

Test the operational effectiveness of the control

Focus on auditing high risk areas

Relying on management testing of controls.

✓ :~~ Focus on high risk areas. Reducing the scope and focusing on auditing

high-risk areas is the bets course of action.




While planning an IS audit, an assessment of risk should be made to provide:

✓ :~~ Reasonable assurance that the audit will cover material items.




ISACA IS Audit and Assurance Guideline 2202 (Risk Assessment in Planning) states

that the applied risk assessment approach should help with the prioritization and

scheduling process of the IS audit and assurance work. It should support the

selection process of areas and items of audit interest and the decision process to

design and conduct particular IS audit engagements.



Master01 | September, 2024/2025 | Latest update

, 3 | P a g e | © copyright 2024/2025 | Grade A+




Which of the following best describes the purpose of performing a risk assessment

in the planning phase of an IS audit:




Establish adequate staffing requirements to complete the IS audit

To provide reasonable assurance that all material items will be addressed

To determine the skills required to perform the IS audit

To develop the audit program and procedures

✓ :~~ To provide reasonable assurance that all material items will be

addressed.




A risk assessment helps focus the audit procedures on the highest risk areas

included in the scope of the audit.




A financial institution with multiple branch offices has an automated control that

requires the branch manager to approve transactions more than a certain amount.

What type of audit control is this?

✓ :~~ Preventative.




An IS auditor is validating a control that involved a review of system generated

exception reports. Which of the following is the best evidence of the effectiveness

of the control.


Master01 | September, 2024/2025 | Latest update

, 4 | P a g e | © copyright 2024/2025 | Grade A+




1- Walkthrough with the reviewer of the operation of the control

2- System generated exception report for the review period with the reviewers

sign off

3- A sample system generated exceptions report for the review period, with

follow-up action items noted by the reviewer

4- Management's confirmation of the effectiveness of the control for the review

period.

✓ :~~ A sample system generated exceptions report for the review period,

with follow-up action items noted by the reviewer.




A sample of a system generated report with evidence that the reviewer followed

up on the exception represents the best possible evidence of the effective

operation of the control because there is documented evidence that the reviewer

has reviewed and taken actions based on the exception report.




Which of the following is the most important skill an IS auditor should develop to

understand the constraints of conducting an audit:




1 - Contingency Planning

2 - IS Management resource allocation

3 - Project Management



Master01 | September, 2024/2025 | Latest update

Document information

Uploaded on
September 9, 2024
Number of pages
65
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Axpert
3.8
(126)
Sold
560
Followers
167
Items
29320
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions