ISACA Certified Information Systems Auditor (CISA) Exam practice questions
247 free questions with answers and explanations.
- 51.A CISA is reviewing an organization's information security policy. The policy states, 'All sensitive data must be protected.' However, it provides no definitions for 'sensitive data,' no criteria for 'protection,' and no specific examples or mandatory controls. Which of the following is the MOST significant deficiency of this policy?Domain 2: Governance and Management of IT
- 52.An IS auditor is evaluating the business case for a proposed investment in a new enterprise resource planning (ERP) system. The project has an initial cost of $1,500,000. It is expected to generate annual savings of $400,000 for the first three years, $300,000 for the next two years, and then no further savings. What is the simple payback period for this investment?Domain 3: Information Systems Acquisition, Development and Implementation
- 53.An organization's information security management system (ISMS) includes a policy requiring annual security awareness training for all employees. During an audit, the CISA finds evidence that while training materials are up-to-date, a significant portion of employees (approximately 30%) have not completed the mandatory annual training for the current year. What is the MOST immediate risk to the organization?Domain 2: Governance and Management of IT
- 54.An IS auditor is reviewing the acquisition process for a new enterprise resource planning (ERP) system. The auditor notes that the organization's legal department was only involved at the final contract signing stage. What is the MOST significant risk associated with this approach?Domain 3: Information Systems Acquisition, Development and Implementation
- 55.A project manager is overseeing the development of a complex financial reporting system. During the testing phase, several critical defects are identified. The project sponsor demands an expedited release. What is the IS auditor's PRIMARY recommendation regarding this demand?Domain 3: Information Systems Acquisition, Development and Implementation
- 56.An IS auditor is evaluating an organization's disaster recovery plan (DRP) for its critical systems. The DRP includes a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour for the primary transaction processing system. Which of the following is the MOST important control to ensure these objectives are achievable?Domain 3: Information Systems Acquisition, Development and Implementation
- 57.An IS auditor is reviewing the system development lifecycle (SDLC) for a highly critical financial application. The project team has adopted an Agile methodology. Which of the following audit procedures would be MOST effective in evaluating control over requirements stability and traceability in an Agile environment?Domain 3: Information Systems Acquisition, Development and Implementation
- 58.An IS auditor is reviewing the change management process for a database supporting a critical financial application. The auditor notes that all database schema changes are approved by the application owner, but there is no independent review or testing of the changes before they are applied to production. Which of the following is the MOST significant control weakness?Domain 3: Information Systems Acquisition, Development and Implementation
- 59.An IS auditor is reviewing the readiness of a new enterprise resource planning (ERP) system for implementation. The system is intended to replace several legacy applications across finance, human resources, and supply chain departments. Which of the following is the MOST critical readiness factor to assess before 'go-live'?Domain 3: Information Systems Acquisition, Development and Implementation
- 60.A CISA is reviewing an organization's human resources management processes related to IT. The CISA notes that while background checks are performed for all new hires, there is no formal process for reviewing or updating these checks for existing employees who are promoted to more sensitive IT roles (e.g., from help desk to system administrator). What is the MOST significant risk this practice introduces?Domain 2: Governance and Management of IT
- 61.An IS auditor is evaluating the change management process for a critical production system. The organization recently implemented a new policy requiring emergency changes to undergo a post-implementation review within 48 hours. What is the PRIMARY purpose of this specific timeframe for the review?Domain 3: Information Systems Acquisition, Development and Implementation
- 62.A CISA is auditing an organization's IT governance framework. The CISA observes that IT steering committee meetings are consistently focused on operational issues and tactical project updates, with little discussion on long-term IT strategy or alignment with business objectives. What is the MOST significant implication of this observation?Domain 2: Governance and Management of IT
- 63.A CISA is reviewing an organization's IT governance structure. The CISA notes that the IT department operates largely in isolation, with minimal interaction with business unit managers regarding IT project prioritization and resource allocation. Which of the following is the MOST likely consequence of this operational model?Domain 2: Governance and Management of IT
- 64.An organization is migrating its core banking application to a new cloud platform. The IS auditor is reviewing the data migration strategy. Which of the following is the MOST critical control for ensuring data integrity during this migration?Domain 3: Information Systems Acquisition, Development and Implementation
- 65.During a post-implementation review of a new customer relationship management (CRM) system, an IS auditor identifies that user acceptance testing (UAT) sign-offs were obtained from department managers, but not from actual end-users. Which of the following is the MOST significant risk associated with this finding?Domain 3: Information Systems Acquisition, Development and Implementation
- 66.An organization relies heavily on a single, highly customized legacy system for its core business operations. The disaster recovery plan (DRP) primarily focuses on restoring data backups to new hardware. Which of the following is the MOST critical missing element in this DRP?Domain 2: Governance and Management of IT
- 67.A CISA is reviewing an organization's IT risk management framework. The CISA notes that while the organization has identified numerous IT risks, the risk register lacks a consistent methodology for quantifying potential financial impacts or likelihood of occurrence, and risk appetite is not clearly defined. What is the MOST significant consequence of this deficiency for IT governance?Domain 2: Governance and Management of IT
- 68.An IS auditor is reviewing the system acquisition process for a new cloud-based human resources (HR) system. The organization plans to integrate this new system with its existing on-premise payroll system. Which of the following is the MOST critical consideration during the vendor selection phase regarding this integration?Domain 3: Information Systems Acquisition, Development and Implementation
- 69.A CISA is auditing an organization's IT organizational structure. The CISA observes that the IT department reports directly to the Chief Financial Officer (CFO). While the CFO is highly effective in financial management, they have limited understanding of complex IT security and operational risks. What is the MOST significant concern for the organization's IT governance?Domain 2: Governance and Management of IT
- 70.A CISA is auditing an organization's disaster recovery plan (DRP). The CISA notes that while the DRP outlines technical recovery steps, it lacks clear guidance on how to assess the financial and operational impact of a disaster. Which of the following is the MOST significant implication of this omission?Domain 2: Governance and Management of IT
- 71.An organization is considering outsourcing its IT infrastructure management. From an IT governance perspective, which of the following is the MOST important control to implement when engaging with an external service provider?Domain 2: Governance and Management of IT
- 72.A CISA is auditing an organization's IT governance framework. The CISA observes that the IT department consistently prioritizes technical innovation projects over initiatives directly supporting the organization's strategic business objectives, despite a formal IT strategy document outlining business alignment. Which of the following is the MOST significant finding?Domain 2: Governance and Management of IT
- 73.During a post-implementation review of a new financial reporting system, an IS auditor observes that several critical reports are generated using data that is manually extracted, manipulated in spreadsheets, and then re-uploaded to the system. Which of the following is the MOST significant risk associated with this practice?Domain 3: Information Systems Acquisition, Development and Implementation
- 74.An organization's business continuity plan (BCP) includes a comprehensive business impact analysis (BIA) that identifies critical business processes and their associated recovery time objectives (RTOs) and recovery point objectives (RPOs). However, the plan does not specify the roles and responsibilities for activating and managing the BCP during an actual event. What is the MOST significant risk resulting from this omission?Domain 2: Governance and Management of IT
- 75.A CISA is auditing an organization's IT organizational structure. The CISA observes that the database administrators (DBAs) also have full administrative access to the operating systems and network devices that host the databases. What is the MOST significant concern from an IT governance perspective?Domain 2: Governance and Management of IT
- 76.An IS auditor is reviewing an organization's change management process for critical production systems. The auditor notes that emergency changes, while documented post-implementation, often bypass standard testing and approval procedures. What is the MOST critical risk introduced by this practice?Domain 3: Information Systems Acquisition, Development and Implementation
- 77.An IS auditor is evaluating controls over system development for a new financial application. The auditor observes that developers have direct write access to the production environment during development phases for 'quick fixes' and testing. Which of the following is the PRIMARY control weakness identified?Domain 3: Information Systems Acquisition, Development and Implementation
- 78.A CISA is reviewing an organization's information security policy. The policy states that 'all critical data must be encrypted in transit.' However, the policy does not specify the encryption algorithms, key management procedures, or minimum acceptable strength. What is the MOST significant weakness of this policy statement?Domain 2: Governance and Management of IT
- 79.A CISA is reviewing an organization's human resources management practices. The CISA discovers that access permissions for employees who have transferred departments are often not updated for several weeks, allowing them to retain access to their previous department's sensitive data. Which of the following is the MOST significant risk exposed by this practice?Domain 2: Governance and Management of IT
- 80.A CISA is reviewing an organization's human resources management practices related to IT. The CISA finds that all IT employees, regardless of their role, are granted administrative privileges on their workstations and several production servers for 'convenience'. What is the MOST significant risk introduced by this practice?Domain 2: Governance and Management of IT
- 81.An IS auditor is evaluating the readiness of a new critical online banking system for implementation. The user acceptance testing (UAT) phase has concluded, but several high-severity defects remain unresolved, albeit with workarounds in place. The project manager proposes to go live as scheduled, citing business pressure. What should be the IS auditor's PRIMARY recommendation?Domain 3: Information Systems Acquisition, Development and Implementation
- 82.During a post-implementation review of a newly developed HR system, an IS auditor discovers that the system's user role matrix was approved by the HR department head but not by the IT security department. What is the MOST significant risk this finding represents?Domain 3: Information Systems Acquisition, Development and Implementation
- 83.An organization's disaster recovery plan (DRP) has not been reviewed or tested in three years. During this period, several critical systems have been upgraded, and new applications have been deployed. What is the PRIMARY concern for a CISA auditing this DRP?Domain 2: Governance and Management of IT
- 84.An IS auditor is assessing the controls over system maintenance for a critical production database. The organization uses a 'break-fix' model where database administrators (DBAs) directly modify the production database to resolve urgent issues. Which of the following controls would BEST mitigate the risk of unauthorized or erroneous changes in this scenario?Domain 3: Information Systems Acquisition, Development and Implementation
- 85.An organization is developing an information security policy. Which of the following is the MOST critical initial step in this process?Domain 2: Governance and Management of IT
- 86.An organization is considering implementing a new customer relationship management (CRM) system. The business case estimates a net present value (NPV) of $500,000 using a 10% discount rate. If the discount rate were increased to 12% due to higher perceived risk, what would be the MOST likely impact on the NPV?Domain 3: Information Systems Acquisition, Development and Implementation
- 87.An organization is implementing a new cloud-based enterprise resource planning (ERP) system. The CISA notes that the organization's existing information security policy, written for on-premise systems, has not been updated to reflect cloud-specific security considerations, shared responsibility models, or vendor contractual obligations. What is the MOST immediate governance concern?Domain 2: Governance and Management of IT
- 88.An IS auditor is evaluating the controls over software development for a critical in-house application. The development team frequently uses open-source libraries. Which of the following is the MOST important control to ensure the ongoing security of the application?Domain 3: Information Systems Acquisition, Development and Implementation
- 89.An IS auditor is reviewing the go-live readiness assessment for a new critical financial system. The assessment indicates that all functional requirements have been met, and user acceptance testing (UAT) was successful. However, the disaster recovery plan (DRP) has not yet been fully tested with the new system. What is the auditor's PRIMARY recommendation?Domain 3: Information Systems Acquisition, Development and Implementation
- 90.A CISA is evaluating an organization's business continuity plan (BCP). The CISA finds that while the BCP documents extensive recovery procedures for IT systems, it lacks a Business Impact Analysis (BIA) that identifies critical business functions, their dependencies, and acceptable downtime. What is the MOST significant implication of this omission?Domain 2: Governance and Management of IT
- 91.An organization has recently implemented a new IT governance framework. During an audit, the CISA observes that while the framework defines clear roles and responsibilities for IT decision-making, there is a lack of communication channels and processes for escalating IT-related risks and issues to senior management. Which of the following areas of the IT governance structure is MOST likely to be ineffective?Domain 2: Governance and Management of IT
- 92.An IS auditor is assessing the project management practices for a large-scale system integration project. The project is currently 60% complete, but only 40% of the budget has been expended. The Earned Value (EV) is $240,000, and the Actual Cost (AC) is $160,000. What is the Cost Performance Index (CPI) of this project?Domain 3: Information Systems Acquisition, Development and Implementation
- 93.A CISA is reviewing an organization's information security awareness training program. The CISA observes that while initial training is provided to all new hires, there is no annual refresher training or regular communication on emerging threats. What is the MOST likely consequence of this approach?Domain 2: Governance and Management of IT
- 94.An IS auditor is reviewing the system acquisition process for a new cloud-based human resources (HR) management system. The organization plans to integrate this new system with its existing payroll and enterprise resource planning (ERP) systems. Which of the following should the auditor primarily focus on to ensure successful integration and data flow?Domain 3: Information Systems Acquisition, Development and Implementation
- 95.An IS auditor is evaluating the business case for a proposed investment in a new data warehousing solution. The project cost is estimated at $2 million, with expected annual benefits of $400,000. The project has a projected lifespan of 8 years. What is the simple payback period for this investment?Domain 3: Information Systems Acquisition, Development and Implementation
- 96.A CISA is evaluating an organization's IT governance framework. The CISA observes that while the IT department has defined clear roles and responsibilities for system administration, there is no formal mechanism for business units to provide input or approve IT service levels and priorities. Which of the following is the MOST likely consequence of this observation?Domain 2: Governance and Management of IT
- 97.A CISA is reviewing an organization's IT strategy and notices that it is heavily focused on implementing cutting-edge technologies (e.g., AI, blockchain) without a clear articulation of how these technologies support specific business goals. Which of the following is the MOST significant concern for the CISA?Domain 2: Governance and Management of IT
- 98.A CISA is auditing an organization's business continuity plan (BCP). The CISA finds that the BCP includes detailed recovery procedures for critical IT systems but lacks clear communication protocols for notifying external stakeholders (e.g., customers, regulators) during a disruption. What is the MOST significant implication of this finding?Domain 2: Governance and Management of IT
- 99.An IS auditor is evaluating the organization's disaster recovery plan (DRP) for its critical financial system. The DRP outlines detailed procedures for restoring the system at an alternate site. However, the auditor finds no evidence of the DRP having been tested in the last two years. Which of the following is the MOST significant risk associated with this finding?Domain 3: Information Systems Acquisition, Development and Implementation
- 100.An organization relies heavily on a third-party managed security service provider (MSSP) for its security operations, including incident detection and response. During an audit, a CISA discovers that the contract with the MSSP does not clearly define roles and responsibilities for incident communication, escalation procedures, or recovery actions. Which of the following is the MOST critical implication for the organization?Domain 2: Governance and Management of IT