Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 113 pages
Exam (elaborations)

CISA Domain 1 Exam Questions And Answers & Rationale 12th Ed Graded A+

Document preview thumbnail
Preview 4 out of 113 pages

CISA Domain 1 Exam Questions And Answers & Rationale 12th Ed Graded A+

Content preview

CISA Domain 1 Exam 2025-2026 Questions And
Answers & Rationale 12th Ed Graded A+



A1-3 An IS auditor is developing an audit plan for an environment that includes new systems.
The organization's management wants the IS auditor to focus on recently implemented systems.
How should the IS auditor respond?



A. Audit the new systems as requested by management.

B. Audit systems not included in last year's scope.

C. Determine the highest-risk systems and plan accordingly.

D.Auditboththesystemsnotinlastyear'sscopeandthenewsystems.

C is the correct answer.

Justification:

A. Auditing the new system does not reflect a risk-based approach. Although the system can
contain sensitive data and may present risk of data loss or disclosure to the organization, without
a risk assessment, the decision to solely audit the newly implemented system is not a risk-based
decision.

B. Auditing systems not included in the previous year's scope does not reflect a risk-based
approach.

In addition, management may know about problems with the new system and may be
intentionally trying to steer the audit away from that vulnerable area. Although, at first, the new
system may seem to be the riskiest area, an assessment must be conducted rather than relying on
the judgment of the IS auditor or IT manager.

C. The best action is to conduct a risk assessment and design the audit plan to cover the areas of

,highest risk. ISACA IS Audit and Assurance Standard 1202 (Risk Assessment in Planning),
statement 1202.1: "The IS audit and assurance function shall use an appropriate risk assessment
approach and supporting methodology to develop the overall IS audit plan and determine
priorities for the effective allocation of IS audit resources."

D. The creation of the audit plan should be performed in cooperation with management and
based on

risk. The IS auditor should not arbitrarily decide on what needs to be audited.




Al-l The internal audit department wrote some scripts that are used for continuous auditing of
some information systems. The IT department asked for copies of the scripts so that they can use
them for setting up a continuous monitoring process on key systems. Does sharing these scripts
with IT affect the ability of the IS auditors to independently and objectively audit the IT
function?



A. Sharing the scripts is not permitted because it gives IT the ability to pre-audit systems and
avoid an accurate, comprehensive audit.

B. Sharing the scripts is required because IT must have the ability to review all programs and
software that run on IS systems regardless of audit independence.

C. Sharing the scripts is permissible if IT recognizes that audits may still be conducted in areas
not covered in the scripts.

D. Sharing the scripts is not permitted because the IS auditors who wrote the scripts would not be

permitted toaudi

C is the correct answer.

Justification:

A. The ability of IT to continuously monitor and address any issues on IT systems does not affect
the ability of IS audit to perform a comprehensive audit.

,B. Sharing the scripts may be required by policy for quality assurance and configuration
management, but that does not impair the ability to audit.

C. IS audit can still review all aspects of the systems. They may not be able to review the

effectiveness of the scripts, but they can still audit the systems.

D. An audit of an 'IS system encompasses more than just the controls covered in the scripts.




Al-2 Which of the following is the BEST, factor for determining the required extent of data
collection during the planning phase of an IS compliance audit?



A. Complexity of the organization's operation

B. Findings and issues noted from the prior year

C. Purpose, objective and scope of the audit

D. Auditor's familiarity with the organization

C is the correct answer. Justification:

A. The complexity of the organization's operation is a factor in the planning of an audit but does
not

directly affect the 'determination of how much data to collect. The extent of data collection is
subject

to the intensity, scope and purpose of the audit.

B. Prior findings and issues are factors in the planning of an audit but do not directly affect the
determination of how much data to collect. Data must be collected outside of areas of previous
findings.

C. The extent to which data will be collected during an IS audit is related directly to the purpose,
objective and scope of the audit. An audit with a narrow purpose and limited objective and scope
is most likely to result in less data collection than an audit with a wider purpose and scope.
Statistical analysis mayalso determine the extent of data collection, such as sample size or means
of data collection.

, D. An auditor's familiarity with the organization is a factor in the planning of an audit but does
not

directly affect the determination of how much data to collect. The audit must be based on
sufficient evidence of the monitoring of controls and not unduly influenced by the auditor's
familiarity with the organization.




A1-4 An IS auditor is reviewing security controls for a critical web-based system prior to
implementation. The results of the penetration test are inconclusive, and the results will not be
finalized prior to implementation. Which of the following is the BEST option for the IS auditor?



A. Publish a report based on the available information, highlighting the potential security
weaknesses and the requirement for follow-up audit testing.

B. Publish a report omitting the areas where the evidence obtained from testing was
inconclusive.

C. Request a delay ofthe implementation date until additional security testing can be completed
and evidence of appropriate controls can be obtained.

D. Inform management that audit work cannot be completed prior to implementation and
recommend that the audit be postponed.

A is the correct answer. Justification:

A. If the IS auditor cannot gain sufficient assurance for a critical system within the agreed-on
time frame, this fact should be highlighted in the audit report and follow-up testing should be
scheduled for a later date. Management can then determine whether any of the potential
weaknesses identified were significant enough to delay the go-live date for the system.

B. It is not acceptable for the IS auditor to ignore areas of potential weakness because conclusive

evidence could not be obtained within the agreed-on audit t~meframe. IS~.cA IS Audit and
Assurance

Standards are violated if these areas are omitted from the audit report.

C. Extending the time frame for the audit and delaying the go-live date is unlikely to be
acceptable in this scenario where the system involved is business-critical. In any case, a delay to
the go-live date must be the decision of business management, not the IS auditor. In this

Document information

Uploaded on
November 25, 2025
Number of pages
113
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
LiamJones
3.5
(37)
Sold
182
Followers
38
Items
4988
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions