Certified Information Systems Auditor

ISACA_CISA
ProfessionalVersion 2024.1Official exam guide โ†—

Ready to test yourself?

A timed, blueprint-proportional exam drawn fresh from this bank โ€” with a per-domain score report.

๐Ÿ”’ Unlock the simulation โ†’

๐Ÿ”“ Free preview: showing 10 of 150 questions. Unlock the full bank โ€” every question, explanation, and reference.

Unlock all 150 questions โ†’

10 questions across 5 topics. Choose an answer for each question, then check it to see the correct answer and explanation.

Filter by topic

All 10 questions

D1_AUDIT

Information System Auditing Process

10 questions in topic

Audit standards and ethics, risk-based planning, evidence and sampling, testing techniques, CAATs, reporting, and follow-up.

1
Single choice~110s

An IS auditor concludes that control risk is high for a key process. Holding audit risk constant, what must the auditor do to detection risk?

2
Single choice~110s

An auditor is engaged to review a system that the same audit firm designed two years earlier. Which safeguard is MOST appropriate?

3
Single choice~110s

An auditor tests 50 change records and finds 4 without evidence of approval. Management explains that 3 relate to one contractor who has since left. What is the MOST appropriate next step?

4
Single choice~110s

Which combination of evidence provides the STRONGEST basis for concluding that terminated employees' access was removed timely?

5
Single choice~110s

An auditor plans to rely on a control self-assessment programme to reduce substantive testing. What must be evaluated FIRST?

6
Single choice~110s

During an audit the auditor identifies a material weakness that management asks to omit because remediation is already funded and scheduled. The auditor should:

7
Single choice~110s

Which situation MOST undermines the value of an exception report as audit evidence?

8
Single choice~110s

An auditor must conclude on whether a control operated throughout a 12-month period but can obtain evidence only for the final quarter because logs were overwritten. What should be reported?

9
Single choice~110s

Which sampling approach is appropriate when the auditor must estimate the frequency with which an approval control was bypassed?

10
Single choice~110s

An auditor uses generalized audit software to test 100% of a transaction population. Which risk is eliminated and which remains?