CISA Domain 1: Process of Auditing Information
Systems Comprehensive Questions And
Answers Recent Solution
Save
Terms in this set (88)
That the control is operating as designed
An IS auditor is
conducting a compliance
Compliance tests can be used to test the existence
test to determine
and effectiveness of a defined process.
whether controls support
Understanding the objective of a compliance test is
management policies
important. IS auditors want reasonable assurance
and procedures. The test
that the controls they are relying on are effective.
will assist the IS auditor
An effective control is one that meets management
to determine:
expectations and objectives.
When developing a risk Inventory of assets.
management program,
what is the first activity to Identification of the assets to be protected is the
be performed? first step in developing a risk management program.
The primary purpose of The systemic collection and analysis of evidence
an IT forensic audit is: after a system irregularity.
,Due to resource Focus on high risk areas. Reducing the scope and
constraints of the IS audit focusing on auditing high-risk areas is the bets
team, the audit plan as course of action.
originally approved
cannot be completed.
Assuming that the
situation is
communicated in the
audit report, which
course of action is most
acceptable:
Test the adequacy of the
control design
Test the operational
effectiveness of the
control
Focus on auditing high
risk areas
Relying on management
testing of controls.
Reasonable assurance that the audit will cover
material items.
ISACA IS Audit and Assurance Guideline 2202 (Risk
While planning an IS
Assessment in Planning) states that the applied risk
audit, an assessment of
assessment approach should help with the
risk should be made to
prioritization and scheduling process of the IS audit
provide:
and assurance work. It should support the selection
process of areas and items of audit interest and the
decision process to design and conduct particular
IS audit engagements.
,Which of the following To provide reasonable assurance that all material
best describes the items will be addressed.
purpose of performing a
risk assessment in the A risk assessment helps focus the audit procedures
planning phase of an IS on the highest risk areas included in the scope of
audit: the audit.
Establish adequate
staffing requirements to
complete the IS audit
To provide reasonable
assurance that all
material items will be
addressed
To determine the skills
required to perform the
IS audit
To develop the audit
program and procedures
A financial institution with Preventative.
multiple branch offices
has an automated control
that requires the branch
manager to approve
transactions more than a
certain amount. What
type of audit control is
this?
, An IS auditor is validating A sample system generated exceptions report for
a control that involved a the review period, with follow-up action items noted
review of system by the reviewer.
generated exception
reports. Which of the A sample of a system generated report with
following is the best evidence that the reviewer followed up on the
evidence of the exception represents the best possible evidence of
effectiveness of the the effective operation of the control because there
control. is documented evidence that the reviewer has
reviewed and taken actions based on the exception
1- Walkthrough with the report.
reviewer of the operation
of the control
2- System generated
exception report for the
review period with the
reviewers sign off
3- A sample system
generated exceptions
report for the review
period, with follow-up
action items noted by the
reviewer
4- Management's
confirmation of the
effectiveness of the
control for the review
period.
Systems Comprehensive Questions And
Answers Recent Solution
Save
Terms in this set (88)
That the control is operating as designed
An IS auditor is
conducting a compliance
Compliance tests can be used to test the existence
test to determine
and effectiveness of a defined process.
whether controls support
Understanding the objective of a compliance test is
management policies
important. IS auditors want reasonable assurance
and procedures. The test
that the controls they are relying on are effective.
will assist the IS auditor
An effective control is one that meets management
to determine:
expectations and objectives.
When developing a risk Inventory of assets.
management program,
what is the first activity to Identification of the assets to be protected is the
be performed? first step in developing a risk management program.
The primary purpose of The systemic collection and analysis of evidence
an IT forensic audit is: after a system irregularity.
,Due to resource Focus on high risk areas. Reducing the scope and
constraints of the IS audit focusing on auditing high-risk areas is the bets
team, the audit plan as course of action.
originally approved
cannot be completed.
Assuming that the
situation is
communicated in the
audit report, which
course of action is most
acceptable:
Test the adequacy of the
control design
Test the operational
effectiveness of the
control
Focus on auditing high
risk areas
Relying on management
testing of controls.
Reasonable assurance that the audit will cover
material items.
ISACA IS Audit and Assurance Guideline 2202 (Risk
While planning an IS
Assessment in Planning) states that the applied risk
audit, an assessment of
assessment approach should help with the
risk should be made to
prioritization and scheduling process of the IS audit
provide:
and assurance work. It should support the selection
process of areas and items of audit interest and the
decision process to design and conduct particular
IS audit engagements.
,Which of the following To provide reasonable assurance that all material
best describes the items will be addressed.
purpose of performing a
risk assessment in the A risk assessment helps focus the audit procedures
planning phase of an IS on the highest risk areas included in the scope of
audit: the audit.
Establish adequate
staffing requirements to
complete the IS audit
To provide reasonable
assurance that all
material items will be
addressed
To determine the skills
required to perform the
IS audit
To develop the audit
program and procedures
A financial institution with Preventative.
multiple branch offices
has an automated control
that requires the branch
manager to approve
transactions more than a
certain amount. What
type of audit control is
this?
, An IS auditor is validating A sample system generated exceptions report for
a control that involved a the review period, with follow-up action items noted
review of system by the reviewer.
generated exception
reports. Which of the A sample of a system generated report with
following is the best evidence that the reviewer followed up on the
evidence of the exception represents the best possible evidence of
effectiveness of the the effective operation of the control because there
control. is documented evidence that the reviewer has
reviewed and taken actions based on the exception
1- Walkthrough with the report.
reviewer of the operation
of the control
2- System generated
exception report for the
review period with the
reviewers sign off
3- A sample system
generated exceptions
report for the review
period, with follow-up
action items noted by the
reviewer
4- Management's
confirmation of the
effectiveness of the
control for the review
period.