100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

CISA EXAM 2 QUESTIONS AND 100% CORRECT ANSWERS

Rating
-
Sold
-
Pages
23
Grade
A+
Uploaded on
28-08-2025
Written in
2025/2026

CISA EXAM 2 QUESTIONS AND 100% CORRECT ANSWERS

Institution
CISA
Course
CISA










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CISA
Course
CISA

Document information

Uploaded on
August 28, 2025
Number of pages
23
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CISA EXAM 2 QUESTIONS AND
100% CORRECT ANSWERS!!
The final decision to include a material finding in an audit report should be made by the:
audit committee.
auditee's manager.
IS auditor.
chief executive officer of the organization.

C

An organization uses a bank to process its weekly payroll. Time sheets and payroll
adjustment forms (e.g., hourly rate changes, terminations) are completed and delivered to
the bank, which prepares checks and reports for distribution. To BEST ensure payroll data
accuracy:
payroll reports should be compared to input forms.
gross payroll should be recalculated manually.
checks should be compared to input forms.
checks should be reconciled with output reports.

A

An external IS auditor issues an audit report pointing out the lack of firewall protection
features at the perimeter network gateway and recommending a specific vendor product
to address this vulnerability. The IS auditor has failed to exercise: professional
independence.
organizational independence.
technical competence.
professional competence.

A

A long-term IT employee with a strong technical background and broad managerial
experience has applied for a vacant position in the IS audit department. Determining

,whether to hire this individual for this position should be PRIMARILYbased on the
individual's experience and:
length of service, because this will help ensure technical competence.
age, because training in audit techniques may be impractical.
IT knowledge, because this will bring enhanced credibility to the audit
function. ability,

D

During a risk analysis, an IS auditor identifies threats and potential impacts. Next, the
IS auditor should:
ensure the risk assessment is aligned to management's risk assessment process.
identify information assets and the underlying systems.
disclose the threats and impacts to management.
identify and evaluate the existing controls.

D

Which of the following controls would an IS auditor look for in an environment where
duties cannot be appropriately segregated? Overlapping controls


Boundary controls
Access controls
Compensating controls

D

In planning an IS audit, the MOST critical step is the identification of the:
areas of significant risk.
skill sets of the audit staff.
test steps in the audit.
time allotted for the audit.

A

, The purpose of a checksum on an amount field in an electronic data
interchange communication of financial transactions is to ensure: integrity.


authenticity.
authorization.
nonrepudiation.

A

While planning an IS audit, an assessment of risk should be made to provide:
reasonable assurance that the audit will cover material items.
definite assurance that material items will be covered during the audit work.
reasonable assurance that all items will be covered by the audit.
sufficient assurance that all items will be covered during the audit work.

A

An audit charter should:
be dynamic and change to coincide with the changing nature of technology and the
audit profession.
clearly state audit objectives for, and the delegation of, authority to the maintenance and
review of internal controls.
document the audit procedures designed to achieve the planned audit objectives.
outline the overall authority, scope and responsibilities of the audit function.

D

An IS auditor who has discovered unauthorized transactions during a review of electronic
data interchange (EDI) transactions is likely to recommend improving the: EDI trading
partner agreements.
physical controls for terminals.
authentication techniques for sending and receiving messages.
program change control procedures.

C

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
QUINTER New York College Of Dentistry
View profile
Follow You need to be logged in order to follow users or courses
Sold
352
Member since
2 year
Number of followers
104
Documents
38721
Last sold
2 days ago

3.4

59 reviews

5
26
4
8
3
7
2
2
1
16

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions