AUDITOR EXAMINATION QUESTIONS
AND CORRECT ANSWERS (VERIFIED
ANSWERS) PLUS RATIONALES 2026 Q&A
| INSTANT DOWNLOAD PDF
1. What is the primary purpose of an information systems audit?
A) To design software systems
B) To evaluate controls and risks in information systems
C) To manage IT projects
D) To develop databases
Answer: B
Rationale: The primary purpose of an IS audit is to evaluate the adequacy
and effectiveness of controls, risk management, and governance
processes.
2. Which framework is commonly used for IT governance?
A) COBIT
B) SDLC
C) ITIL
D) ISO 9000
Answer: A
Rationale: COBIT is specifically designed for IT governance and control.
,3. What is the main objective of risk assessment in auditing?
A) Eliminate all risks
B) Identify and prioritize risks
C) Increase system speed
D) Design software architecture
Answer: B
Rationale: Risk assessment focuses on identifying and prioritizing risks for
proper control implementation.
4. Which control ensures only authorized users access systems?
A) Detective control
B) Preventive control
C) Corrective control
D) Directive control
Answer: B
Rationale: Preventive controls stop unauthorized access before it occurs.
5. What is the purpose of a firewall?
A) Data backup
B) Network segmentation
C) Access control and traffic filtering
D) Database encryption
Answer: C
Rationale: Firewalls monitor and control incoming and outgoing network
traffic.
6. What type of audit evidence is most reliable?
A) Oral evidence
B) Photocopies
C) External confirmations
, D) Internal memos
Answer: C
Rationale: External confirmations are more reliable because they come
from independent sources.
7. Which is a key element of IT security?
A) User interface design
B) Confidentiality, integrity, availability
C) Software licensing
D) Database normalization
Answer: B
Rationale: CIA triad forms the foundation of information security.
8. What does vulnerability refer to?
A) A security threat
B) A weakness in a system
C) A type of firewall
D) A recovery plan
Answer: B
Rationale: A vulnerability is a weakness that can be exploited by threats.
9. Which audit type focuses on compliance with laws and regulations?
A) Operational audit
B) Financial audit
C) Compliance audit
D) Forensic audit
Answer: C
Rationale: Compliance audits ensure adherence to laws and regulations.