ISACA Certified Information Systems Auditor (CISA) Exam practice questions

247 free questions with answers and explanations.

Practice test
  1. 101.A CISA is reviewing the IT organizational structure of a growing startup. The CISA observes that the head of IT reports directly to the Chief Financial Officer (CFO), and there is no dedicated Chief Information Security Officer (CISO). Security responsibilities are distributed among various IT staff members. What is the MOST significant governance risk associated with this structure?Domain 2: Governance and Management of IT
  2. 102.A CISA is auditing an organization's IT governance framework. The CISA observes that the IT Steering Committee meets quarterly but primarily focuses on reviewing operational IT performance metrics (e.g., uptime, ticket resolution times) rather than strategic IT investments or alignment with business goals. What is the MOST significant implication of this focus?Domain 2: Governance and Management of IT
  3. 103.An IS auditor is reviewing the system development lifecycle (SDLC) for a new customer relationship management (CRM) system. The project team has delivered the system to end-users for initial testing. Which of the following phases of the SDLC is the project currently in?Domain 3: Information Systems Acquisition, Development and Implementation
  4. 104.An IS auditor is evaluating the controls over system development for a new e-commerce platform. The auditor discovers that security requirements were only considered during the final testing phase, rather than being integrated throughout the system development lifecycle (SDLC). Which of the following is the MOST significant implication of this approach?Domain 3: Information Systems Acquisition, Development and Implementation
  5. 105.An IS auditor is reviewing controls over system acquisition for a new cloud-based human resources (HR) platform. The organization plans to integrate this platform with its existing on-premise payroll system. Which of the following is the MOST critical consideration for the IS auditor at this stage?Domain 3: Information Systems Acquisition, Development and Implementation
  6. 106.A CISA is auditing an organization's network security. The organization uses a demilitarized zone (DMZ) to host public-facing web servers. During the review, the CISA observes that the firewall rules between the DMZ and the internal network allow all outbound traffic from the DMZ to any port on the internal network. What is the MOST significant security risk posed by this configuration?Domain 5: Protection of Information Assets
  7. 107.A CISA is auditing an organization's information security strategy. The CISA observes that while the strategy addresses technical controls and compliance requirements, it lacks specific objectives for fostering a security-conscious culture among employees. Which of the following is the MOST significant risk posed by this omission?Domain 5: Protection of Information Assets
  8. 108.A CISA is auditing an organization's vulnerability management program. The CISA reviews the vulnerability scan reports and observes that while critical vulnerabilities are identified, the average time to remediate them is 90 days, significantly exceeding the organization's policy of 30 days for critical issues. Upon further investigation, the CISA finds that the remediation team is frequently delayed waiting for patch approvals and change management windows. What is the MOST appropriate recommendation for the CISA to make?Domain 5: Protection of Information Assets
  9. 109.A CISA is reviewing the network security architecture of an organization. The organization has implemented a robust firewall and an intrusion prevention system (IPS) at its network perimeter. However, the CISA notes that there is no internal network segmentation, and all servers and workstations reside on a flat network. What is the MOST significant risk introduced by this flat network architecture?Domain 5: Protection of Information Assets
  10. 110.A CISA is auditing the identity and access management (IAM) system of a large financial institution. The institution uses a role-based access control (RBAC) model. The CISA discovers that several employees who have changed departments still retain access permissions associated with their previous roles, in addition to their new roles. What is the MOST significant risk introduced by this situation?Domain 5: Protection of Information Assets
  11. 111.A CISA is evaluating an organization's network security, specifically focusing on protection against denial-of-service (DoS) attacks. The organization hosts several public-facing web applications that are critical for its business operations. Which of the following is the MOST effective control to implement at the network edge to mitigate large-scale volumetric DoS attacks?Domain 5: Protection of Information Assets
  12. 112.A CISA is evaluating the effectiveness of a new data loss prevention (DLP) solution. The DLP solution is configured to monitor outbound email and web traffic for sensitive data. During testing, the CISA observes that while the DLP successfully blocks emails containing credit card numbers, it fails to detect sensitive data being exfiltrated via encrypted chat applications or personal cloud storage services. What is the MOST critical recommendation the CISA should make?Domain 5: Protection of Information Assets
  13. 113.A CISA is reviewing an organization's data backup and recovery strategy. The organization performs daily full backups to tape, which are stored offsite. The CISA learns that the organization has never performed a full restoration test of its critical systems from these offsite tapes. What is the MOST significant risk associated with this finding?Domain 5: Protection of Information Assets
  14. 114.A CISA is evaluating an organization's security incident management process. The organization has recently implemented a Security Information and Event Management (SIEM) system. During the review, the CISA observes that while the SIEM collects logs from various sources, there is no established process for regularly tuning correlation rules or updating threat intelligence feeds. What is the MOST likely consequence of this oversight?Domain 5: Protection of Information Assets
  15. 115.A CISA is evaluating the effectiveness of data loss prevention (DLP) controls. An organization stores highly confidential customer financial data in both on-premise databases and a cloud storage service. Which of the following is the MOST effective approach for the CISA to confirm that sensitive data is not being exfiltrated?Domain 5: Protection of Information Assets
  16. 116.A CISA is reviewing the network security controls of an organization that utilizes a demilitarized zone (DMZ) for its public-facing web servers. The CISA observes that the firewall rules between the DMZ and the internal production network allow 'ANY' traffic from the web servers to the internal database servers on port 1433 (SQL Server). What is the MOST immediate and significant security concern for the CISA?Domain 5: Protection of Information Assets
  17. 117.An organization is implementing a new cloud-based customer relationship management (CRM) system. As a CISA, you are evaluating the effectiveness of data encryption and key management for sensitive customer data stored in this system. Which of the following is the MOST important consideration for ensuring data confidentiality in this cloud environment?Domain 5: Protection of Information Assets
  18. 118.A CISA is evaluating an organization's business continuity plan (BCP) and disaster recovery (DR) strategy. The organization has defined a Recovery Point Objective (RPO) of 4 hours for its critical financial systems. However, daily full backups are performed at 2 AM, and transaction logs are shipped offsite every 6 hours. What is the MOST likely impact on the organization's RPO during a disaster?Domain 5: Protection of Information Assets
  19. 119.A CISA is reviewing an organization's information security strategy. The organization has recently acquired several smaller companies, each with its own established security practices. Which of the following is the MOST critical first step for the CISA to evaluate regarding the overall strategy's effectiveness?Domain 5: Protection of Information Assets
  20. 120.A CISA is reviewing an organization's security controls for its software development lifecycle (SDLC). The CISA notes that security testing, including static and dynamic analysis, is performed only at the end of the development cycle, just before deployment. What is the PRIMARY risk associated with this approach?Domain 5: Protection of Information Assets
  21. 121.A CISA is auditing an organization's endpoint security. The organization uses a variety of operating systems (Windows, macOS, Linux) and mobile devices (iOS, Android) across its environment. The CISA notes that the current antivirus solution only supports Windows and macOS, and there is no centralized management for mobile device security. What is the MOST immediate and significant risk this scenario presents?Domain 5: Protection of Information Assets
  22. 122.A CISA is auditing an organization's access control system. The organization uses a role-based access control (RBAC) model. The CISA observes that when an employee changes departments, their old roles are sometimes deactivated, but their new roles are not always immediately provisioned, leading to temporary access gaps. Conversely, in other instances, employees retain access from their old department while also gaining new access, leading to excessive privileges. Which of the following is the MOST effective control to address these issues?Domain 5: Protection of Information Assets
  23. 123.A CISA is auditing an organization's information security policy framework. During the review, the CISA notes that the organization's security policies are high-level statements of management's intent, while the security procedures provide detailed, step-by-step instructions for employees. Which of the following is the MOST critical finding for the CISA to report?Domain 5: Protection of Information Assets
  24. 124.A CISA is evaluating an organization's data encryption strategy. The organization uses symmetric encryption for bulk data storage and asymmetric encryption for key exchange and digital signatures. The CISA discovers that a single, master encryption key for all stored data is backed up on an unencrypted network share. What is the MOST significant risk associated with this finding?Domain 5: Protection of Information Assets
  25. 125.An organization relies heavily on a third-party managed security service provider (MSSP) for its network security monitoring and incident response. A CISA is evaluating the effectiveness of this arrangement. The CISA finds that while the MSSP provides detailed monthly reports on detected incidents, the organization's internal IT team is not actively involved in reviewing or validating these reports, nor do they participate in incident post-mortems with the MSSP. What is the MOST significant long-term risk of this lack of internal engagement?Domain 5: Protection of Information Assets
  26. 126.A CISA is reviewing an organization's security architecture following a recent acquisition. The acquired company's infrastructure includes several legacy systems that are critical for business operations but cannot support modern encryption protocols (e.g., TLS 1.2 or higher). The CISA observes that these systems communicate with newer, external partner systems that enforce strong encryption. How should the CISA BEST advise the organization to mitigate the security risks associated with this scenario?Domain 5: Protection of Information Assets
  27. 127.A CISA is evaluating an organization's security awareness training program. The program consists of annual online modules that all employees are required to complete. During interviews, the CISA learns that many employees perceive the training as a 'checkbox exercise' and do not find the content relevant to their daily tasks. What is the MOST effective approach for the CISA to recommend to improve the program's effectiveness?Domain 5: Protection of Information Assets
  28. 128.A CISA is evaluating an organization's information security policy framework. The organization has recently expanded its operations into several new international markets, each with distinct data privacy regulations. Which of the following is the MOST critical consideration for the CISA to ensure the policy framework remains effective and compliant?Domain 5: Protection of Information Assets
  29. 129.A CISA is evaluating an organization's incident response plan (IRP) following a recent phishing attack that compromised several employee credentials. The CISA notes that the IRP effectively details steps for containment and eradication but lacks clear guidance on how to assess the financial and reputational impact after an incident. What is the MOST significant risk posed by this deficiency?Domain 5: Protection of Information Assets
  30. 130.A CISA is reviewing an organization's security incident management process. During the review, the CISA discovers that while security incidents are logged and initial containment actions are taken, there is no formal process for conducting post-incident reviews or incorporating lessons learned into updated security controls or policies. What is the MOST significant long-term consequence of this deficiency?Domain 5: Protection of Information Assets
  31. 131.A CISA is reviewing an organization's approach to securing its software development lifecycle (SDLC). The organization currently focuses security testing primarily on the User Acceptance Testing (UAT) phase, just before deployment. What is the MOST significant drawback of this approach?Domain 5: Protection of Information Assets
  32. 132.A CISA is evaluating an organization's network security, specifically its intrusion detection system (IDS). The CISA notes that the IDS is configured to only detect known attack signatures and is not updated frequently. Furthermore, no intrusion prevention system (IPS) is in place. What is the MOST significant limitation of this setup?Domain 5: Protection of Information Assets
  33. 133.A CISA is evaluating the effectiveness of vulnerability management within an organization. The organization has a large and complex IT infrastructure with a mix of legacy systems and new cloud-native applications. Which of the following metrics is MOST indicative of a mature and effective vulnerability management program?Domain 5: Protection of Information Assets
  34. 134.A CISA is reviewing an organization's network security architecture. The organization operates a highly distributed environment with numerous remote offices and mobile users, all requiring secure access to internal resources. Which security control is MOST crucial for protecting against unauthorized access originating from these diverse endpoints?Domain 5: Protection of Information Assets
  35. 135.A CISA is reviewing an organization's business continuity plan (BCP) and disaster recovery plan (DRP). The organization has defined a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour for its critical financial application. The CISA discovers that backups for this application are performed daily at midnight, and the restoration process typically takes 3 hours. What is the MOST critical finding for the CISA to report?Domain 5: Protection of Information Assets
  36. 136.A CISA is evaluating an organization's security incident management process. The organization uses a Security Information and Event Management (SIEM) system. The CISA discovers that many security alerts generated by the SIEM are false positives, leading security analysts to ignore legitimate threats. Additionally, the SIEM is not integrating feeds from a newly deployed threat intelligence platform. What corrective action should the CISA recommend FIRST to improve the SIEM's effectiveness?Domain 5: Protection of Information Assets
  37. 137.A CISA is reviewing an organization's identity and access management (IAM) system. The organization uses a single sign-on (SSO) solution across multiple cloud services. Which of the following is the MOST critical risk when a single point of failure exists in the SSO infrastructure?Domain 5: Protection of Information Assets
  38. 138.A CISA is evaluating an organization's approach to securing its software development lifecycle (SDLC). The organization currently focuses security testing primarily during the 'Testing' phase, just before deployment. The CISA recommends shifting security activities earlier in the SDLC. What is the MOST significant benefit of this 'shift-left' security approach?Domain 5: Protection of Information Assets
  39. 139.A CISA is auditing an organization's privileged access management (PAM) system. The PAM solution requires administrators to request temporary access, which is then approved by a manager, and sessions are recorded. However, the CISA discovers that a critical set of 'break-glass' administrator accounts, designed for emergency use, are exempt from the request/approval workflow and have their activities logged only locally on the target systems, with logs not centralized. What is the MOST significant control weakness in this 'break-glass' account management?Domain 5: Protection of Information Assets
  40. 140.An organization relies heavily on a third-party managed security service provider (MSSP) for its security operations, including threat monitoring, incident response, and vulnerability management. A CISA is auditing the organization's security posture. The CISA observes that the organization has very limited internal security staff and relies almost entirely on the MSSP for all security decision-making and operational tasks. What is the MOST significant long-term risk posed by this over-reliance on the MSSP?Domain 5: Protection of Information Assets
  41. 141.A CISA is auditing the endpoint security controls of a manufacturing company. The company uses industrial control systems (ICS) and operational technology (OT) in its production environment, which are isolated from the corporate IT network. The CISA observes that antivirus software on these OT endpoints is rarely updated, and intrusion detection systems (IDS) are not deployed within the OT network. However, the OT network has strict physical access controls and is air-gapped from the internet. What is the MOST significant residual risk the CISA should highlight?Domain 5: Protection of Information Assets
  42. 142.A CISA is auditing an organization's privileged access management (PAM) system. The organization has implemented a solution that stores credentials in a secure vault and rotates them automatically. However, the CISA observes that 'break-glass' accounts (emergency access accounts) are not regularly audited or tested, and their access logs are not systematically reviewed. What is the MOST significant risk posed by this oversight?Domain 5: Protection of Information Assets
  43. 143.A CISA is evaluating the access controls for a critical financial application. The application processes high-value transactions and is accessed by different user roles (e.g., data entry, approvers, auditors). The organization's policy mandates segregation of duties (SoD). Which of the following is the MOST effective method to ensure that SoD is properly enforced within the application?Domain 5: Protection of Information Assets
  44. 144.A CISA is auditing an organization's privileged access management (PAM) system. The organization has implemented a 'break-glass' account for emergency access to critical systems when normal authentication mechanisms fail. The CISA observes that the password for this account is stored in a shared, unencrypted document accessible by several IT administrators. What is the MOST significant security risk in this scenario?Domain 5: Protection of Information Assets
  45. 145.A CISA is evaluating an organization's security policies. The organization recently implemented a 'Bring Your Own Device' (BYOD) policy. Which of the following is the MOST critical policy component that the CISA should verify is adequately addressed to mitigate associated risks?Domain 5: Protection of Information Assets
  46. 146.A CISA is auditing the endpoint security controls of a manufacturing company. The company operates an Operational Technology (OT) network that controls industrial machinery, which is air-gapped from the corporate IT network. However, engineers occasionally use USB drives to transfer firmware updates and diagnostic logs between the IT network (where updates are downloaded) and the OT network. What is the MOST significant security vulnerability introduced by this practice?Domain 5: Protection of Information Assets
  47. 147.A CISA is reviewing an organization's data backup and recovery strategy. The organization uses tape backups, which are stored off-site. The CISA discovers that while backups are performed nightly, a full restoration test has not been conducted in over two years. What is the MOST significant risk this presents to the organization's information assets?Domain 5: Protection of Information Assets
  48. 148.A CISA is evaluating an organization's data loss prevention (DLP) solution. The DLP solution is currently configured only to monitor outbound email for sensitive data. The CISA identifies that employees frequently use cloud-based file-sharing services and instant messaging applications for internal and external communication, which are not covered by the DLP. What is the MOST critical recommendation the CISA should make to enhance the effectiveness of the DLP solution?Domain 5: Protection of Information Assets
  49. 149.A CISA is evaluating an organization's security configuration management program. The organization uses multiple operating systems and applications across its IT environment. Which of the following is the MOST effective approach to ensure consistent and secure baseline configurations across this diverse environment?Domain 5: Protection of Information Assets
  50. 150.A CISA is auditing an organization's security incident management process. The organization has recently experienced several phishing attacks leading to credential compromise. Which of the following areas should the CISA prioritize for evaluation to improve the organization's response capability?Domain 5: Protection of Information Assets