CISA Studying Questions & 100%
Correct Answers
Which of the following BEST describes the purpose of performing a risk assessment
in the planning phase of an IS audit?
A.
To establish adequate staffing requirements to complete the IS audit
B.
To provide reasonable assurance that all material items will be addressed
C.
To determine the skills required to perform the IS audit
Incorrect D.
To develop the audit program and procedures to perform the IS audit
✓ :~~ You answered D. The correct answer is B.
A. A risk assessment does not directly influence staffing requirements.
Master01 | September, 2024/2025 | Latest update
, 2 | P a g e | © copyright 2024/2025 | Grade A+
B. A risk assessment helps focus the audit procedures on the highest risk areas
included in the scope of the audit. The concept of reasonable assurance is
important as well.
C. A risk assessment does not identify the skills required to perform an IS audit.
D. A risk assessment is not used in the development of the audit program and
procedures.
Which of the following controls would BEST detect intrusion?
A.
User IDs and user privileges are granted through authorized procedures.
B.
Automatic logoff is used when a workstation is inactive for a particular period of
time.
Incorrect C.
Automatic logoff of the system occurs after a specified number of unsuccessful
attempts.
Master01 | September, 2024/2025 | Latest update
, 3 | P a g e | © copyright 2024/2025 | Grade A+
D.
Unsuccessful logon attempts are monitored by the security administrator.
✓ :~~ You answered C. The correct answer is D.
A. User IDs and the granting of user privileges define a policy. This is a type of
administrative or managerial control that may prevent intrusion but would not
detect it.
B. Automatic logoff is a method of preventing access through unattended or
inactive terminals, but is not a detective control.
C. Unsuccessful attempts to log on are a method for preventing intrusion, not
detecting it.
D. Intrusion is detected by the active monitoring and review of unsuccessful logon
attempts.
Which testing approach is MOST appropriate to ensure that internal application
interface errors are identified as soon as possible?
A.
Master01 | September, 2024/2025 | Latest update
, 4 | P a g e | © copyright 2024/2025 | Grade A+
Bottom-up testing
B.
Sociability testing
C.
Top-down testing
Incorrect D.
System testing
✓ :~~ You answered D. The correct answer is C.
A. A bottom-up approach to testing begins with atomic units, such as programs and
modules, and works upward until a complete system test has taken place.
B. Sociability testing takes place at a later stage in the development process.
C. The top-down approach to testing ensures that interface errors are detected
early and that testing of major functions is conducted early.
D. System tests take place at a later stage in the development process.
Master01 | September, 2024/2025 | Latest update