(Cisa) Exam Questions And Correct
Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant
Download Pdf
QUESTION 1
Which is the PRIMARY purpose of an information systems audit?
A. To design new IT systems
B. To evaluate controls and ensure risk is managed appropriately
C. To replace IT management decisions
D. To develop software applications
Correct Answer: B
Rationale: The primary purpose of an IS audit is to evaluate whether an
organization’s information systems, processes, and controls are operating
effectively to manage risk, ensure data integrity, and support business
objectives. Auditors do not design systems or replace management functions;
instead, they provide independent assurance. Option B correctly reflects the
governance and assurance role of auditing, whereas A and D describe
development responsibilities, and C incorrectly suggests auditors make
operational decisions.
QUESTION 2
Which of the following BEST describes IT governance?
A. Daily management of IT infrastructure
B. Technical configuration of servers
,C. Ensuring IT supports business objectives and risk is managed
D. Writing application code for business systems
Correct Answer: C
Rationale: IT governance ensures that IT investments and operations align with
business goals, deliver value, and manage risk effectively. It is a strategic
responsibility rather than operational or technical. Options A, B, and D describe
operational IT tasks, not governance, which focuses on oversight, accountability,
and alignment.
QUESTION 3
What is the PRIMARY function of an audit risk assessment?
A. To eliminate all organizational risks
B. To determine audit scope and priorities
C. To assign IT staff responsibilities
D. To configure firewall rules
Correct Answer: B
Rationale: Audit risk assessment helps auditors identify areas of highest risk so
they can prioritize audit efforts and define scope effectively. It does not
eliminate risk entirely (A), assign operational roles (C), or implement technical
controls like firewalls (D).
QUESTION 4
Which control is MOST effective in preventing unauthorized system access?
A. Detective controls
B. Preventive controls
C. Corrective controls
D. Recovery controls
Correct Answer: B
,Rationale: Preventive controls are designed to stop security incidents before
they occur, such as authentication systems, access controls, and encryption.
Detective controls identify incidents after they occur, corrective controls fix
issues, and recovery controls restore systems after disruption.
QUESTION 5
What is the MAIN purpose of a firewall?
A. To detect internal fraud
B. To prevent unauthorized network traffic
C. To develop secure applications
D. To store encrypted backups
Correct Answer: B
Rationale: A firewall filters incoming and outgoing network traffic based on
security rules to prevent unauthorized access. It does not detect fraud, develop
applications, or handle backup storage.
QUESTION 6
Which document defines the scope and objectives of an audit engagement?
A. Audit charter
B. Audit report
C. System log
D. Change request
Correct Answer: A
Rationale: The audit charter formally defines the authority, scope, and
objectives of the audit function. Audit reports summarize findings, system logs
record system activity, and change requests relate to IT modifications.
, QUESTION 7
Which of the following is an example of a detective control?
A. Password policy enforcement
B. Firewall rules
C. Intrusion detection system
D. Data encryption
Correct Answer: C
Rationale: Intrusion detection systems monitor and alert on suspicious activity,
making them detective controls. Password policies and firewalls are preventive,
while encryption protects data confidentiality.
QUESTION 8
What is the PRIMARY purpose of segregation of duties?
A. Increase processing speed
B. Reduce risk of fraud and error
C. Simplify system design
D. Improve user experience
Correct Answer: B
Rationale: Segregation of duties ensures no single individual has control over all
aspects of a critical process, reducing the risk of fraud and errors. It is a key
internal control principle.
QUESTION 9
Which audit type focuses on compliance with laws and regulations?
A. Operational audit
B. Financial audit
C. Compliance audit
D. Technical audit