CERTIFIED INFORMATION SYSTEMS AUDITOR (CISA)
CERTIFICATION: COMPLETE PRACTICE EXAM WITH
ANSWERS AND RATIONALES (QUESTIONS 1-100)
1. Which of the following is the primary objective of an IS audit?
A) Identify all software vulnerabilities
B) Evaluate and improve the effectiveness of risk management, control, and governance processes
C) Implement new security technologies
D) Replace management oversight
Answer: B
Rationale: The IS audit's main goal is to provide assurance and recommendations to improve risk
management, controls, and governance, not to implement technologies or replace management .
2. During planning, the most important factor in determining audit scope is:
A) Auditor preference
B) Management's request only
C) Risk assessment and materiality of processes
D) Previous year's audit scope
Answer: C
Rationale: Scope should be driven by risk and materiality to focus resources where they provide the
most assurance .
3. Which control type detects and reports incidents after they occur?
A) Preventive controls
B) Detective controls
C) Corrective controls
D) Directive controls
Answer: B
,Rationale: Detective controls identify incidents when they occur (e.g., intrusion detection systems, logs),
while preventive controls aim to stop them .
4. The best way for an auditor to confirm the existence of a physical asset is:
A) Review the asset register only
B) Interview the asset custodian
C) Perform a physical inspection and reconcile to records
D) Rely on management representation
Answer: C
Rationale: A physical inspection provides direct evidence of existence, and reconciliation ensures
completeness and accuracy of records .
5. Which of the following best describes risk appetite?
A) The probability of a threat occurring
B) The level of risk an organization is willing to accept to achieve objectives
C) The same as residual risk
D) A list of all threats
Answer: B
Rationale: Risk appetite defines acceptable risk levels to enable strategy and decision-making, distinct
from measured or residual risk .
6. Which technique is most appropriate to test the effectiveness of a backup process?
A) Review backup schedules only
B) Observe backups run without restoration testing
C) Perform a restoration from backup and verify data integrity
D) Ask the system administrator if backups are successful
Answer: C
Rationale: Restoring from backups validates both the completion of backups and the integrity/usability
of backed-up data .
, 7. What is the primary purpose of IT governance?
A) IT projects are profitable
B) IT strategy aligns with business objectives
C) All employees have IT skills
D) The help desk is efficient
Answer: B
Rationale: Governance focuses on alignment of IT with business goals to ensure value delivery and
appropriate risk management .
8. Change management controls are designed primarily to:
A) Prevent all changes
B) Ensure that changes are authorized, tested, and documented
C) Speed up deployment of changes
D) Replace the need for testing
Answer: B
Rationale: Proper change controls provide assurance that changes are controlled to prevent unintended
consequences and maintain integrity .
9. Business continuity planning (BCP) should be based on:
A) Desktop procedures only
B) Results of Business Impact Analysis (BIA) and recovery time objectives (RTOs)
C) Historical incidents only
D) Backup schedules alone
Answer: B
Rationale: BCP must prioritize critical processes identified in the BIA and establish RTOs/RPOs to meet
business needs .
10. Which of the following best describes the role of an IS auditor during system development?
A) Designing system controls
B) Writing application code
CERTIFICATION: COMPLETE PRACTICE EXAM WITH
ANSWERS AND RATIONALES (QUESTIONS 1-100)
1. Which of the following is the primary objective of an IS audit?
A) Identify all software vulnerabilities
B) Evaluate and improve the effectiveness of risk management, control, and governance processes
C) Implement new security technologies
D) Replace management oversight
Answer: B
Rationale: The IS audit's main goal is to provide assurance and recommendations to improve risk
management, controls, and governance, not to implement technologies or replace management .
2. During planning, the most important factor in determining audit scope is:
A) Auditor preference
B) Management's request only
C) Risk assessment and materiality of processes
D) Previous year's audit scope
Answer: C
Rationale: Scope should be driven by risk and materiality to focus resources where they provide the
most assurance .
3. Which control type detects and reports incidents after they occur?
A) Preventive controls
B) Detective controls
C) Corrective controls
D) Directive controls
Answer: B
,Rationale: Detective controls identify incidents when they occur (e.g., intrusion detection systems, logs),
while preventive controls aim to stop them .
4. The best way for an auditor to confirm the existence of a physical asset is:
A) Review the asset register only
B) Interview the asset custodian
C) Perform a physical inspection and reconcile to records
D) Rely on management representation
Answer: C
Rationale: A physical inspection provides direct evidence of existence, and reconciliation ensures
completeness and accuracy of records .
5. Which of the following best describes risk appetite?
A) The probability of a threat occurring
B) The level of risk an organization is willing to accept to achieve objectives
C) The same as residual risk
D) A list of all threats
Answer: B
Rationale: Risk appetite defines acceptable risk levels to enable strategy and decision-making, distinct
from measured or residual risk .
6. Which technique is most appropriate to test the effectiveness of a backup process?
A) Review backup schedules only
B) Observe backups run without restoration testing
C) Perform a restoration from backup and verify data integrity
D) Ask the system administrator if backups are successful
Answer: C
Rationale: Restoring from backups validates both the completion of backups and the integrity/usability
of backed-up data .
, 7. What is the primary purpose of IT governance?
A) IT projects are profitable
B) IT strategy aligns with business objectives
C) All employees have IT skills
D) The help desk is efficient
Answer: B
Rationale: Governance focuses on alignment of IT with business goals to ensure value delivery and
appropriate risk management .
8. Change management controls are designed primarily to:
A) Prevent all changes
B) Ensure that changes are authorized, tested, and documented
C) Speed up deployment of changes
D) Replace the need for testing
Answer: B
Rationale: Proper change controls provide assurance that changes are controlled to prevent unintended
consequences and maintain integrity .
9. Business continuity planning (BCP) should be based on:
A) Desktop procedures only
B) Results of Business Impact Analysis (BIA) and recovery time objectives (RTOs)
C) Historical incidents only
D) Backup schedules alone
Answer: B
Rationale: BCP must prioritize critical processes identified in the BIA and establish RTOs/RPOs to meet
business needs .
10. Which of the following best describes the role of an IS auditor during system development?
A) Designing system controls
B) Writing application code