ISACA Certified Information Systems Auditor (CISA) Exam practice questions
247 free questions with answers and explanations.
- 1.An IS auditor is reviewing the controls over software maintenance for an internally developed application. User feedback indicates that system performance has degraded significantly after recent production updates. Which of the following controls is MOST likely to have failed?Domain 3: Information Systems Acquisition, Development and Implementation
- 2.An organization is evaluating its disaster recovery plan (DRP). The current DRP focuses primarily on restoring IT systems and data but does not explicitly address the recovery of specialized operational technology (OT) systems critical for manufacturing, which have unique hardware and software requirements. Which of the following is the MOST significant risk uncovered by this DRP deficiency?Domain 2: Governance and Management of IT
- 3.During an audit of an organization's human resources management, the CISA notes that security awareness training is conducted only for new hires and is not repeated annually for existing employees. What is the MOST significant risk associated with this practice?Domain 2: Governance and Management of IT
- 4.A CISA is evaluating an organization's IT organizational structure. The CISA discovers that a single individual is responsible for developing, testing, and deploying critical business application code, as well as managing the production database. What is the MOST significant risk associated with this arrangement?Domain 2: Governance and Management of IT
- 5.A CISA is reviewing an organization's information security policy. The policy states that 'all employees must protect sensitive information' but does not define what constitutes 'sensitive information' or provide examples. What is the MOST likely impact of this policy statement?Domain 2: Governance and Management of IT
- 6.An IS auditor is evaluating the business case for a proposed investment in a new customer relationship management (CRM) system. The project has an initial cost of $750,000. It is expected to generate incremental annual cash flows of $200,000 for the next five years. The organization's required rate of return (discount rate) is 10%. What is the Net Present Value (NPV) of this investment?Domain 3: Information Systems Acquisition, Development and Implementation
- 7.A CISA is reviewing an organization's information security policy. The policy states that 'all data must be protected' but provides no further details on classification, responsibilities, or specific controls. What is the MOST significant deficiency in this policy statement?Domain 2: Governance and Management of IT
- 8.An IS auditor is evaluating the controls over a new financial reporting system still in the development phase. Which of the following would be the MOST effective control to ensure that only authorized and tested code changes are promoted to the production environment?Domain 3: Information Systems Acquisition, Development and Implementation
- 9.A CISA is auditing an organization that has recently outsourced its entire IT infrastructure management to a third-party service provider. The contract explicitly states the service level agreements (SLAs) for uptime and performance. However, there is no formal mechanism for the organization to monitor the provider's adherence to these SLAs. What is the MOST critical control weakness in this scenario?Domain 2: Governance and Management of IT
- 10.An IS auditor is evaluating the project management practices for a new data analytics platform. The project manager reports a Budgeted Cost of Work Performed (BCWP) of $750,000, an Actual Cost of Work Performed (ACWP) of $800,000, and a Budgeted Cost of Work Scheduled (BCWS) of $700,000. What is the Cost Performance Index (CPI)?Domain 3: Information Systems Acquisition, Development and Implementation
- 11.An IS auditor is evaluating the project management practices for a new data analytics platform. The project is 50% complete according to the work breakdown structure (WBS), has spent $150,000, and was budgeted for $200,000 at this stage. The total project budget is $400,000. What is the Schedule Performance Index (SPI) for this project?Domain 3: Information Systems Acquisition, Development and Implementation
- 12.A CISA is evaluating an organization's business continuity plan (BCP). The CISA notes that while the BCP details recovery strategies for IT systems and data, it lacks specific procedures for communicating with key external stakeholders (e.g., customers, regulators, media) during a prolonged disruption. Which of the following is the MOST significant gap in the BCP?Domain 2: Governance and Management of IT
- 13.A project steering committee is reviewing the progress of a critical system implementation project. The project manager reports that the project is currently 20% complete and has spent $150,000 of its $500,000 budget. The planned value (PV) for the work completed so far was $120,000. What is the Cost Performance Index (CPI) for this project?Domain 3: Information Systems Acquisition, Development and Implementation
- 14.A business unit proposes a new system investment with a projected lifespan of 5 years. The initial investment is $200,000. Annual cash inflows are estimated at $60,000 for the first 3 years and $40,000 for the last 2 years. Using a simple payback period calculation, how long will it take to recoup the initial investment?Domain 3: Information Systems Acquisition, Development and Implementation
- 15.A CISA is evaluating an organization's business continuity plan (BCP). The CISA notes that while the BCP identifies critical business processes and their recovery time objectives (RTOs), it lacks detailed procedures for data backup and restoration, particularly for complex, interconnected databases. What is the MOST likely consequence of this deficiency during a business disruption?Domain 2: Governance and Management of IT
- 16.An organization's information security policy states, 'All employees shall protect company information assets.' However, the policy does not define what constitutes 'company information assets,' nor does it specify protection measures or consequences for non-compliance. What is the MOST significant implication of this policy's wording for information security governance?Domain 2: Governance and Management of IT
- 17.A CISA is evaluating the effectiveness of an organization's IT governance structure. The CISA observes that the IT department consistently implements new technologies without formal approval from a cross-functional steering committee, despite such a committee being documented in the governance framework. What is the MOST likely consequence of this situation?Domain 2: Governance and Management of IT
- 18.A CISA is evaluating an organization's human resources management practices related to IT. The CISA observes that new IT employees are granted broad system access immediately upon joining, with access reviews conducted only annually. What is the MOST significant risk associated with this practice?Domain 2: Governance and Management of IT
- 19.An organization relies on a highly customized, mission-critical application developed in-house over 20 years ago. The original developers have long since left the company, and documentation is sparse. The organization's disaster recovery plan (DRP) lists this application as critical but provides only generic restoration steps. What is the MOST significant challenge this poses to the DRP's effectiveness?Domain 2: Governance and Management of IT
- 20.An organization is implementing a new enterprise resource planning (ERP) system. The CISA observes that the project team is highly technical, but business unit representatives are only minimally involved in requirements gathering and testing phases. From an IT governance perspective, what is the MOST significant concern?Domain 2: Governance and Management of IT
- 21.An organization is updating its information security policy. The draft policy includes a statement: 'All sensitive data must be encrypted in transit.' However, it does not specify the encryption algorithms, key lengths, or protocols to be used. What is the MOST significant shortcoming of this policy statement from an audit perspective?Domain 2: Governance and Management of IT
- 22.An IS auditor is reviewing the system development lifecycle (SDLC) for a critical customer-facing web application. The development team uses an Agile methodology. Which of the following practices BEST ensures that security requirements are adequately addressed throughout the development process?Domain 3: Information Systems Acquisition, Development and Implementation
- 23.A CISA is auditing an organization's IT organizational structure. The CISA observes that the Head of Development also serves as the Head of Quality Assurance (QA) for all new software releases. Which of the following is the MOST significant risk introduced by this structure?Domain 2: Governance and Management of IT
- 24.An IS auditor is reviewing the requirements gathering process for a new enterprise content management (ECM) system. The project team, adopting an agile approach, has conducted several workshops with key stakeholders. To ensure that the gathered requirements are complete and accurately reflect business needs, which of the following is the MOST effective technique?Domain 3: Information Systems Acquisition, Development and Implementation
- 25.An organization's information security policy mandates that all critical data must be encrypted both in transit and at rest. During a review, the CISA discovers that while data in transit is consistently encrypted using strong protocols, a significant portion of critical data stored on internal file servers and databases is not encrypted at rest. What is the MOST immediate security risk to the organization?Domain 2: Governance and Management of IT
- 26.An IS auditor is reviewing the change management process for a critical production system. The auditor notes that emergency changes are implemented without prior testing, with testing occurring only after the change is live. Which of the following is the MOST appropriate recommendation for the IS auditor to make?Domain 3: Information Systems Acquisition, Development and Implementation
- 27.During a review of an organization's human resources management, the CISA notes that background checks for new IT employees are conducted only after they have been granted access to production systems. What is the MOST significant risk introduced by this practice?Domain 2: Governance and Management of IT
- 28.A CISA is auditing an organization's IT organizational structure. The CISA observes that the database administrators (DBAs) also perform system administration functions, including managing operating system patches and network configurations on the database servers. Which of the following is the MOST significant concern for the CISA?Domain 2: Governance and Management of IT
- 29.An IS auditor is reviewing the system acquisition process for a new enterprise resource planning (ERP) system. The project team has identified several potential vendors and is now evaluating their proposals. Which of the following is the MOST critical control for the IS auditor to verify at this stage?Domain 3: Information Systems Acquisition, Development and Implementation
- 30.An organization relies heavily on a cloud service provider (CSP) for its core business applications and data storage. During an audit, the CISA finds that the organization's disaster recovery plan (DRP) primarily focuses on on-premise infrastructure recovery and does not explicitly address the responsibilities and recovery procedures involving the CSP. Which of the following is the MOST significant risk identified by the CISA?Domain 2: Governance and Management of IT
- 31.A CISA is evaluating an organization's IT governance framework. The CISA observes that the framework emphasizes compliance with external regulations (e.g., GDPR, HIPAA) but provides minimal guidance on internal control objectives for IT operations. Which of the following is the MOST significant risk resulting from this imbalance?Domain 2: Governance and Management of IT
- 32.An organization is developing its business continuity plan (BCP). The CISA notes that while the BCP addresses technical recovery and alternate site activation, it lacks specific procedures for communicating with external stakeholders such as customers, suppliers, and regulatory bodies during a disruption. What is the MOST critical risk introduced by this omission?Domain 2: Governance and Management of IT
- 33.An IS auditor is reviewing the software maintenance process for an internally developed legacy system. The auditor observes that changes are implemented directly into the production environment without being first deployed to a staging environment. Which of the following is the MOST significant risk associated with this practice?Domain 3: Information Systems Acquisition, Development and Implementation
- 34.An IS auditor is reviewing the change management process for a critical production system. A recent emergency patch was implemented without following the standard testing and approval procedures due to an urgent security vulnerability. What is the MOST critical control to ensure the integrity of the system after such an emergency change?Domain 3: Information Systems Acquisition, Development and Implementation
- 35.A CISA is auditing an organization's IT asset management process. The CISA discovers that while hardware assets are meticulously tracked from acquisition to disposal, software licenses are only tracked at the point of purchase, with no ongoing monitoring of usage or installation. What is the MOST significant risk introduced by this practice?Domain 2: Governance and Management of IT
- 36.An IS auditor is reviewing the project management practices for a new data analytics platform. The project manager reports that the project is on schedule and within budget, but key stakeholders express concerns about the solution's ability to meet their evolving business intelligence needs. Which of the following is the MOST likely underlying issue?Domain 3: Information Systems Acquisition, Development and Implementation
- 37.An organization is considering replacing its existing IT governance framework with a new, industry-standard framework. During the evaluation, the CISA notes that the proposed framework requires significant cultural changes and new reporting structures that are fundamentally different from the current organizational culture and existing management hierarchy. What is the PRIMARY challenge the organization will face in implementing the new framework?Domain 2: Governance and Management of IT
- 38.An organization is migrating its data center to a cloud provider. The IS auditor is evaluating the contract with the cloud service provider (CSP). Which of the following clauses is MOST critical for the auditor to verify to ensure data ownership and transferability upon contract termination?Domain 3: Information Systems Acquisition, Development and Implementation
- 39.An IS auditor is reviewing the go-live readiness assessment for a new critical online banking system. The assessment indicates that all functional and performance tests passed, and user acceptance testing (UAT) was signed off. However, the auditor notes that the disaster recovery plan (DRP) for the new system has not yet been fully integrated or tested with the new system's specific configurations. Which of the following is the MOST significant risk to address before go-live?Domain 3: Information Systems Acquisition, Development and Implementation
- 40.A CISA is auditing an organization that uses a third-party cloud provider for its critical business applications. The organization's information security policy states that 'all data stored in the cloud must meet the same security standards as on-premise data.' However, the CISA finds no evidence of regular security audits or reviews of the cloud provider's environment by the organization. What is the MOST significant implication of this finding?Domain 2: Governance and Management of IT
- 41.During an audit of an organization's IT governance structure, the CISA observes that the IT department frequently initiates projects without formal approval from business units, leading to scope creep and unmet business expectations. Which of the following is the MOST significant implication of this observation?Domain 2: Governance and Management of IT
- 42.A CISA is auditing an organization's approach to information security. The CISA observes that the security policies are largely descriptive, outlining what 'should be done' but lacking specific instructions or measurable outcomes. Which of the following is the MOST significant concern for the CISA regarding these policies?Domain 2: Governance and Management of IT
- 43.An IS auditor is reviewing controls over system acquisition for a new enterprise resource planning (ERP) system. The project team has developed a detailed Request for Proposal (RFP) and received multiple vendor responses. Which of the following criteria should the IS auditor recommend as the MOST important to evaluate vendor proposals against for a complex ERP system?Domain 3: Information Systems Acquisition, Development and Implementation
- 44.An organization is updating its human resources management practices related to IT. The CISA reviews the onboarding process for new IT employees and notes that while background checks are conducted, there is no formal process for revoking access rights immediately upon an employee's termination. Which of the following is the MOST critical risk this omission poses?Domain 2: Governance and Management of IT
- 45.An IS auditor is reviewing the software maintenance process for an internally developed legacy system. The auditor observes that maintenance requests are often implemented directly into production without prior testing in a separate environment. What is the MOST likely consequence of this practice?Domain 3: Information Systems Acquisition, Development and Implementation
- 46.A CISA is reviewing an organization's IT organizational structure. The CISA notes that the Chief Information Security Officer (CISO) reports directly to the Chief Information Officer (CIO). Which of the following is the MOST significant risk associated with this reporting structure?Domain 2: Governance and Management of IT
- 47.A CISA is reviewing an organization's IT asset management practices. The CISA observes that while hardware assets are meticulously tracked from acquisition to disposal, there is no formal process for managing software licenses, including procurement, deployment, and decommissioning. What is the MOST significant risk posed by this oversight?Domain 2: Governance and Management of IT
- 48.A CISA is auditing an organization's disaster recovery plan (DRP). The DRP specifies a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour for a critical financial application. However, the CISA observes that the current backup strategy only performs daily full backups, and the recovery procedures involve manual restoration processes that typically take 6-8 hours. What is the MOST critical finding for the CISA?Domain 2: Governance and Management of IT
- 49.An IS auditor is evaluating controls over system maintenance for a critical production database. The organization uses a change management system that logs all changes. However, the auditor discovers that database administrators (DBAs) can make direct changes to the production database without formal approval or prior testing if they deem it an emergency. What is the MOST significant risk this practice introduces?Domain 3: Information Systems Acquisition, Development and Implementation
- 50.During an audit of an organization's IT governance structure, the CISA observes that the IT steering committee meets regularly but its recommendations are frequently disregarded by business unit leaders. Which of the following is the MOST significant concern for the CISA?Domain 2: Governance and Management of IT