Certified Information Systems Auditor CISA Exam Questions & Answers

Practice 105 free Certified Information Systems Auditor CISA exam questions with answers and community-discussed explanations. Each question has its own page where you can reveal the correct answer and debate it in the comments.

All 105 questions

  1. Q1 You are conducting an audit of a organization's disposal process and have noted several findings. Which of the following should be your…
  2. Q2 You are an information system auditor at HDA Inc. You are currently reviewing the capacity management process of the organization. You observed…
  3. Q3 You are an information system auditor at HDA Inc. You are reviewing a newly acquired system for a critical process. You should…
  4. Q4 Which process is an intellectual effort that seeks to determine whether a specific change or set of changes in business processes and…
  5. Q5 Control measures are implemented to achieve control objectives by:
  6. Q6 Which of the following is the primary objective of a configuration management system?
  7. Q7 What is the purpose of a transaction log in the change management process?
  8. Q8 You are an information system auditor of HDA Inc. You are auditing the controls in place to address SQL injection vulnerabilities. In…
  9. Q9 You are an information system auditor of HDA Inc. You are currently auditing the business continuity activities of the organization. As part…
  10. Q10 You are an information system auditor at HDA Inc. You are reviewing the IT portfolio management of the HDA. Which of the…
  11. Q11 How are emergency changes related to problem and incident management?
  12. Q12 You are auditing a company, and during the audit, you discover that employees are permitted to connect their personal devices to company-owned…
  13. Q13 You are an information system auditor of HDA Inc. You discover during a follow-up audit that certain recommendations were not implemented, and…
  14. Q14 Which of the following is a key aspect of managing and monitoring audit projects?
  15. Q15 Which deployment model of cloud computing allows services to be reduced or increased based on organizational requirements?
  16. Q16 An IT balanced scorecard indicates:
  17. Q17 Which of the following process would be most helpful in matching project and service demand with available resources to support business objectives?
  18. Q18 You are an information system auditor of HDA Inc. You need to figure out which factor would help IT management the most…
  19. Q19 You are an information system auditor of HDA Inc. You are auditing and have identified that a company executive is promoting employee…
  20. Q20 The choices of risk treatment are:
  21. Q21 What is the purpose of CSA in relation to risk detection?
  22. Q22 Which testing methodology focuses on testing each separate program or module?
  23. Q23 Which of the following describes a staging environment?
  24. Q24 You are an information system auditor of HDA Inc. In a system for accounts payable in which segregation of duties (SoD) cannot…
  25. Q25 You are an information system auditor of HDA Inc. You are auditing a software system that is still in regular use but…
  26. Q26 You are an information system auditor of HDA Inc., and you have set a goal to cut down on the amount of…
  27. Q27 What is the purpose of business continuity planning?
  28. Q28 What should be clearly defined and documented for effective incident management?
  29. Q29 Blowfish is an example of which type of encryption algorithm?
  30. Q30 Which alternate recovery site is considered an exact replica of the primary site?
  31. Q31 What should be considered to protect user authentication and mail data in email communication?
  32. Q32 Which of the following protocols may be used to encrypt a clientless VPN connection?
  33. Q33 You are an information system auditor of HDA Inc.  You need to figure out the BEST way to destroy sensitive information saved…
  34. Q34 A risk analysis that is carried out by an auditor is distinct and separate from the risk analysis that is performed as…
  35. Q35 You are an information system auditor of HDA Inc. You are auditing the third-party consultant's management of the replacement of an accounting…
  36. Q36 What is the role of an IS auditor in the implementation of CSA?
  37. Q37 You are an information system auditor of HDA Inc. The management has informed you that an internal control within the organization is…
  38. Q38 What is the purpose of the IT strategy committee?
  39. Q39 You are an information system auditor of HDA Inc., and you have been involved in designing an application. You are now required…
  40. Q40 Which encryption standard is considered the strongest for wireless connections?
  41. Q41 During which phase of the SDLC are requirements compared with the application design to ensure that they agree?
  42. Q42 You are auditing HDA Inc. as an information system auditor, and your task is to evaluate the effectiveness of signature-based intrusion detection…
  43. Q43 What is the purpose of MAC filtering in wireless network security?
  44. Q44 Which evidence-gathering technique provides better evidence than other techniques?
  45. Q45 An auditor is auditing a computer user account provisioning process. After selecting a statistical sample, the auditor examines the samples to see…
  46. Q46 Why is regression testing important to the release process?
  47. Q47 The set of activities that ensures the efficient and effective delivery of IT services through active management and the continuous improvement of…
  48. Q48 You are an information system auditor of HDA Inc. You are reviewing the forensic data collection and preservation procedures. Which of the…
  49. Q49 Which of the following terms describes a cryptographic operation on a block of data that returns a fixed-length string of characters used…
  50. Q50 Who should the information security policy be disseminated to?
  51. Q51 You are an information system auditor of HDA Inc. You are auditing and reviewing an organization's information security policies. In conducting this…
  52. Q52 You are an information system auditor of HDA Inc. You are auditing an ongoing project, and management requests a briefing on the…
  53. Q53 An organization’s director of business continuity needs to understand the priority of business processes. What activity should be performed?
  54. Q54 A system that filters incoming power spikes and other noise and supplies power for short periods through a bank of batteries is…
  55. Q55 COBIT is composed of how many key IT processes?
  56. Q56 What is the main objective of a Database Management System ?
  57. Q57 You are an information system auditor of HDA Inc. You are auditing and tasked with verifying the accuracy and completeness of migrated…
  58. Q58 To make use of access controls to enforce database security, what must occur?
  59. Q59 Which of the following is a high-level statement of direction issued by management?
  60. Q60 You are an information system auditor of HDA Inc. Your organization is implementing a new health records system to replace a legacy…
  61. Q61 You are performing  a follow-up audit. While auditing you learnt that management has decided not to implement some previously accepted recommendations. Your…
  62. Q62 You are an information system auditor for HDA Inc., and you are helping to set up the privacy program for an organization.…
  63. Q63 Sender of the message wants to ensure that the message should not change during the delivery process. To ensure this, he creates…
  64. Q64 You are an information system auditor of HDA Inc. You are performing a risk assessment prior to an audit engagement. Which of…
  65. Q65 Which segregation of duties control requires two (or more) persons to approve certain transactions?
  66. Q66 Which step of the BCP life cycle involves identifying the processes of strategic importance for attaining business objectives?
  67. Q67 When is the use of compensating controls necessary?
  68. Q68 You are an information system auditor of HDA Inc. You are auditing the risks associated with enabled services within firewall rules. Among…
  69. Q69 What is the purpose of the risk assessment prior to the audit?
  70. Q70 What is the best type of tool to use for making a forensic copy of a system’s hard drive?
  71. Q71 Which of the following post-implementation items should be audited to ensure that systems and infrastructures meet organizational requirements and are subject to…
  72. Q72 You are an information system auditor of HDA Inc. You are auditing the performance of an IS department. Which of the  following…
  73. Q73 You are an information system auditor of HDA Inc. You are auditing and assessing the adequacy of an organization's information security policy.…
  74. Q74 You are auditing HDA Inc. as an information system auditor, and your task is to verify that an application's audit trail fulfills…
  75. Q75 Which of the following actions is MOST likely to compromise the control provided by a digital signature created using RSA encryption?
  76. Q76 What does the term "reasonable assurance" imply in the context of an IS audit?
  77. Q77 Advantages of control self-assessments include all of the following EXCEPT:
  78. Q78 You are an information system auditor of HDA Inc., and you are auditing the effectiveness of information security controls implemented by a…
  79. Q79 You are an information system auditor of HDA Inc.You have been assigned a audit and you have completed your field audit work.…
  80. Q80 What is the main objective of a Disaster Recovery Plan (DRP)?
  81. Q81 You are auditing HDA Inc. as an information system auditor, and your objective is to determine if a firewall is configured in…
  82. Q82 Which of the following is an example of a corrective control?
  83. Q83 You are the information system auditor of HDA Inc. You have been engaged to evaluate the IT governance framework of a target…
  84. Q84 You are an information system auditor of HDA Inc. You are auditing and have been assigned the responsibility of assisting in the…
  85. Q85 What is the primary objective of an IT balanced scorecard?
  86. Q86 You are the information system auditor of HDA Inc. You are auditing the company's systems and have noticed a continuous decline in…
  87. Q87 An auditor has insufficient local storage to collect evidence during an audit. What is the auditor’s best course of action?
  88. Q88 You are an information system auditor at HDA Inc. You are evaluating data backup procedures of the organization. Which of the following…
  89. Q89 All of the following are risk treatment methods EXCEPT:
  90. Q90 You are an information system auditor of HDA Inc., and you are involved in a system development project during the detailed design…
  91. Q91 You are auditing data disposal controls to ensure they align with the organization's strategic objectives. Which of the following would provide you…
  92. Q92 You are an information system auditor of HDA Inc. You are auditing and assessing the suitability of the waterfall life cycle model…
  93. Q93 Who is responsible for setting overall strategic direction and policy, ensuring that IT strategy is in alignment with the organization’s strategy and…
  94. Q94 You are the information system auditor of HDA Inc. You are assessing different controls in place for managing incidents. Which of the…
  95. Q95 You are an information system auditor of HDA Inc. You are assessing the alignment of IT and business strategy within the organization.…
  96. Q96 You are an information system auditor of HDA Inc. You are auditing the threat assessment for a data center. In this context,…
  97. Q97 You are an information system auditor of HDA Inc. You have noted that an application was generating transactions without the proper sequence,…
  98. Q98 What are the two types of risk assessment used in auditing?
  99. Q99 Which of the following best describes the term “crossover error rate” in the context of biometric authentication mechanisms?
  100. Q100 You are the information system auditor of HDA Inc. You are auditing an organization's firewall. What is the MOST crucial aspect for…
  101. Q101 What is the primary purpose of control measures?
  102. Q102 Which biometric identifier is considered the most reliable with the lowest FAR?
  103. Q103 Which sampling technique provides more detailed information than attribute sampling?
  104. Q104 All of the following activities take place in the post-implementation phase EXCEPT:
  105. Q105 Which device joins two networks together and uses logical Internet Protocol addresses to determine where packets must be sent?

More ISACA certifications

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need