Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 80 páginas
Examen

CISA Certification Exam 2026–2027 Comprehensive Study Guide with Audit Practice Questions, Detailed Explanations & Success Review

Document preview thumbnail
Vista previa 4 fuera de 80 páginas

CISA Certification Exam 2026–2027 Comprehensive Study Guide with Audit Practice Questions, Detailed Explanations & Success Review

Vista previa del contenido

CISA Certification Exam 2026–2027 Comprehensive
Study Guide with Audit Practice Questions, Detailed
Explanations & Success Review

1. An IS auditor is planning an audit of a financial institution's core banking
system. Which of the following is the MOST important factor in determining the
audit scope?
• A. The number of system users
• B. The results of a comprehensive risk assessment
• C. The budget allocated for the audit
• D. The system's age and upgrade history
Correct Answer: B
Rationale: Risk-based audit planning is a foundational concept in Domain 1. The
audit scope should be determined by risk assessment, which identifies which areas
pose the greatest risk to the organization. User count (A), budget (C), and system
age (D) are secondary considerations that inform but do not drive scope
determination.


2. During an audit, an IS auditor identifies that management has overridden several
key controls. What is the auditor's BEST course of action?
• A. Accept the overrides as management's prerogative
• B. Document the overrides, assess their impact, and report the findings
• C. Immediately halt the audit
• D. Discuss the overrides with the system vendor
Correct Answer: B
Rationale: When control overrides are identified, the auditor must document them,
evaluate the risk and impact, and include the findings in the audit report. This

,aligns with IS audit standards requiring thorough evidence collection and
reporting.


3. Which of the following is a key principle of ISACA's Code of Professional
Ethics?
• A. Maximizing audit fees
• B. Maintaining independence and objectivity
• C. Prioritizing management's interests
• D. Avoiding all communication with auditees
Correct Answer: B
Rationale: Independence and objectivity are cornerstone principles of the ISACA
Code of Professional Ethics. Auditors must remain independent and objective in
their work, not allowing personal or organizational pressures to compromise their
judgment.


4. An IS auditor is conducting a compliance audit. Which of the following BEST
describes the primary objective of this type of audit?
• A. To assess the efficiency of system operations
• B. To verify that the organization is following applicable laws,
regulations, and policies
• C. To evaluate the security of the IT infrastructure
• D. To identify cost-saving opportunities
Correct Answer: B
Rationale: Compliance audits verify adherence to laws, regulations, contracts, and
internal policies. Efficiency (A) relates to operational audits. Security (C) relates to
security audits. Cost savings (D) relates to financial or value-for-money audits.


5. Which audit testing technique involves examining a sample of transactions to
verify that controls are operating as intended?

, • A. Compliance testing
• B. Substantive testing
• C. Integrated testing
• D. Parallel testing
Correct Answer: A
Rationale: Compliance testing (or tests of controls) verifies that controls are
operating effectively. Substantive testing (B) validates the accuracy of financial or
operational data. Integrated testing (C) and parallel testing (D) are specific testing
methodologies.


6. An auditor is reviewing evidence collected during an engagement. Which
characteristic of evidence is MOST important?
• A. It should be inexpensive to obtain
• B. It should be sufficient, reliable, and relevant
• C. It should be easy to understand
• D. It should be provided by management
Correct Answer: B
Rationale: Audit evidence must be sufficient (enough quantity), reliable (from
credible sources), and relevant (directly related to the audit objective). Cost (A)
and ease of understanding (C) are secondary. Evidence from management (D) is
less reliable than independent sources.


7. An IS auditor is performing a post-implementation review of a new ERP system.
What is the PRIMARY objective of this review?
• A. To verify that the project was completed within budget
• B. To ensure that the system meets business requirements and delivers
expected benefits
• C. To assess the vendor's performance

, • D. To document lessons learned for future projects
Correct Answer: B
Rationale: Post-implementation reviews assess whether the system is meeting
business requirements and delivering expected benefits. While budget (A), vendor
performance (C), and lessons learned (D) may be part of the review, the primary
objective is business value validation.


8. Which of the following is a characteristic of statistical sampling in audit testing?
• A. It relies on the auditor's professional judgment
• B. It allows the auditor to quantify sampling risk
• C. It is less reliable than judgmental sampling
• D. It requires no documentation
Correct Answer: B
Rationale: Statistical sampling allows the auditor to quantify sampling risk and
draw statistically valid conclusions. Judgmental sampling (A, C) relies on
professional judgment and does not quantify risk. Documentation (D) is required
for all sampling methods.


9. An IS auditor finds that an organization has not documented its IT policies and
procedures. What is the auditor's PRIMARY concern?
• A. Employees may not know how to perform their jobs
• B. The absence of documentation creates inconsistency and makes it
difficult to enforce compliance
• C. The organization may be violating licensing agreements
• D. The IT department may be understaffed
Correct Answer: B
Rationale: Policies and procedures provide the foundation for consistent
operations and compliance enforcement. Without documentation, there is no basis
for measuring compliance, training staff, or holding individuals accountable. While

Información del documento

Subido en
20 de julio de 2026
Número de páginas
80
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$25.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
5
Seguidores
0
Artículos
1603
Última venta
2 días hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes