ISACA Certified Information Systems Auditor (CISA) Exam practice questions
247 free questions with answers and explanations.
- 151.A CISA is auditing an organization's identity and access management (IAM) system. The organization uses a role-based access control (RBAC) model. The CISA observes that many users have been granted 'temporary' elevated privileges that have not been revoked for several months, and the process for reviewing these temporary privileges is ad hoc. What is the MOST significant risk introduced by this situation?Domain 5: Protection of Information Assets
- 152.A CISA is evaluating an organization's incident response plan (IRP). The IRP outlines steps for detection, analysis, containment, eradication, recovery, and post-incident review. However, the CISA finds that the plan lacks specific procedures for handling incidents involving personally identifiable information (PII) that crosses national borders, which is a common occurrence for the organization. What is the MOST significant implication of this omission?Domain 5: Protection of Information Assets
- 153.A CISA is auditing the implementation of security controls in a new data center. The organization handles highly sensitive personal data. The CISA observes that physical access to the server racks is controlled by a badge reader, but the badge reader logs are only reviewed quarterly. Which of the following is the MOST significant risk associated with this finding?Domain 5: Protection of Information Assets
- 154.A CISA is performing an audit of an organization's security awareness training program. The CISA reviews training materials, completion records, and survey feedback. The CISA notes that while 95% of employees complete the annual training, phishing simulation tests consistently show a click-through rate of 25%, and a significant number of help desk tickets relate to users reporting suspicious emails that are actually legitimate. What is the MOST likely root cause of these issues?Domain 5: Protection of Information Assets
- 155.A CISA is auditing an organization's network security architecture. The organization uses network segmentation to isolate critical systems. However, the CISA discovers that a single, flat network segment contains both development servers and production database servers for a critical application. What is the MOST significant security risk introduced by this configuration?Domain 5: Protection of Information Assets
- 156.A CISA is evaluating an organization's security awareness training program. The program consists of annual, mandatory online modules that cover general security topics for all employees. However, a recent phishing simulation revealed that employees in the finance department were disproportionately susceptible to emails impersonating senior management, leading to credential harvesting. What is the MOST effective recommendation to address this specific vulnerability?Domain 5: Protection of Information Assets
- 157.A CISA is evaluating an organization's data encryption strategy for data at rest. The organization stores highly sensitive customer data in a database and uses full disk encryption on the database servers. Which of the following is the MOST critical control gap to address regarding the protection of the encryption keys?Domain 5: Protection of Information Assets
- 158.An organization is implementing a new enterprise resource planning (ERP) system that will handle highly sensitive financial data. The CISA is tasked with evaluating the data encryption strategy for this system. The organization plans to use symmetric encryption for data at rest. Which of the following is the MOST critical control to ensure the long-term effectiveness and security of this encryption strategy?Domain 5: Protection of Information Assets
- 159.A CISA is auditing an organization's network security, specifically its intrusion detection system (IDS). The IDS is primarily signature-based. Recently, the organization experienced a breach that involved a novel zero-day exploit for which no known signatures existed. What is the MOST significant limitation of a purely signature-based IDS highlighted by this incident?Domain 5: Protection of Information Assets
- 160.An IS auditor is reviewing the organization's business continuity plan (BCP). The auditor notes that while the BCP documents recovery procedures for critical IT systems, it lacks detailed instructions for restoring data from off-site backups to the recovery site. What is the MOST significant implication of this omission?Domain 4: Information Systems Operations and Business Resilience
- 161.An IS auditor is conducting a post-implementation review of a new financial reporting system. The project utilized an agile development methodology. What is the MOST critical aspect for the IS auditor to verify regarding system documentation in an agile environment?Domain 1: Information System Auditing Process
- 162.An IS auditor is assessing an organization's change management process. The auditor notes that emergency changes are frequently implemented without thorough testing or formal approval, bypassing the standard change control board (CCB) review. While these changes often resolve immediate issues, they occasionally introduce new, severe defects that lead to further incidents. Which of the following recommendations should the IS auditor make to BEST mitigate this risk without unduly hindering emergency response?Domain 4: Information Systems Operations and Business Resilience
- 163.An IS auditor is evaluating an organization's business continuity plan (BCP) testing program. The auditor finds that while the BCP is regularly tested through tabletop exercises, a full simulation exercise involving all critical systems and personnel has not been conducted in three years. The organization has experienced significant changes to its IT infrastructure and key personnel during this period. What is the MOST significant risk associated with this finding?Domain 4: Information Systems Operations and Business Resilience
- 164.An IS auditor is performing an audit of the software development lifecycle (SDLC) process. The organization uses an agile development methodology. The auditor observes that user stories are frequently changed during sprints, and formal sign-offs for requirements are often skipped to maintain development speed. What is the PRIMARY audit concern in this scenario?Domain 1: Information System Auditing Process
- 165.An IS auditor is evaluating an organization's information systems operations. The auditor observes that critical system backups are performed weekly, but the organization's Recovery Point Objective (RPO) for these systems is 24 hours. What is the MOST significant risk identified by the auditor?Domain 4: Information Systems Operations and Business Resilience
- 166.An IS auditor is assessing an organization's business continuity capabilities. The organization relies heavily on a third-party cloud provider for its critical applications. The auditor notes that while the organization has a DRP for its on-premise infrastructure, it has not formally reviewed the cloud provider's disaster recovery capabilities or their Service Level Agreements (SLAs) for recovery. What is the MOST significant risk in this scenario?Domain 4: Information Systems Operations and Business Resilience
- 167.An IS auditor is planning an audit of a newly deployed customer relationship management (CRM) system that handles personally identifiable information (PII). The organization operates globally and is subject to various data privacy regulations (e.g., GDPR, CCPA). Which of the following should be the auditor's PRIMARY focus during the planning phase?Domain 1: Information System Auditing Process
- 168.An IS auditor is reviewing an organization's internal procedures for managing third-party vendor access to sensitive systems. The auditor notes that the procedures require annual review of vendor access rights, but there is no documented process for *revoking* access immediately upon contract termination or project completion. What type of control weakness does this MOST directly represent?Domain 1: Information System Auditing Process
- 169.An IS auditor is reviewing an organization's incident management process. The auditor notes that while incidents are promptly identified and resolved, there is a lack of structured analysis to prevent recurrence. This indicates a weakness primarily in which of the following areas?Domain 4: Information Systems Operations and Business Resilience
- 170.An IS auditor is conducting a post-implementation review of a newly deployed customer relationship management (CRM) system. The project was completed on time and within budget, and initial user feedback is generally positive. However, during the review, the auditor discovers that the system's data backup and recovery procedures were not formally tested prior to going live. What should be the IS auditor's PRIMARY concern?Domain 1: Information System Auditing Process
- 171.An IS auditor is planning an audit of a new enterprise-wide data retention and deletion policy. The policy mandates specific retention periods for various data types, including sensitive customer information, and requires automated deletion after these periods expire. Which of the following is the MOST important consideration for the auditor during the planning phase?Domain 1: Information System Auditing Process
- 172.During a risk-based audit planning process, an IS auditor identifies that a critical legacy system, which processes sensitive customer data, has not been updated with security patches for over two years. This system also lacks a dedicated security architect. Based on this information, which of the following represents the HIGHEST inherent risk to the organization?Domain 1: Information System Auditing Process
- 173.An IS auditor is conducting an audit of a critical financial application. The organization uses a complex, custom-developed batch processing system for daily transactions. The auditor wants to ensure the integrity of the data processed by this system. Which of the following audit techniques would be MOST effective for verifying the completeness and accuracy of batch processing?Domain 1: Information System Auditing Process
- 174.A large e-commerce company experiences a significant database corruption due to a software bug, leading to an outage. The incident response team quickly restores service from the latest backup, but the underlying software bug is not identified or addressed. An IS auditor observing this scenario should conclude that the organization's problem management process is MOST likely deficient in which area?Domain 4: Information Systems Operations and Business Resilience
- 175.An IS auditor is evaluating the organization's information systems maintenance program. The auditor discovers that a significant portion of maintenance activities is reactive, focusing on fixing issues after they occur, rather than proactive. Which of the following metrics would BEST highlight the financial impact of this reactive approach?Domain 4: Information Systems Operations and Business Resilience
- 176.An IS auditor is evaluating an organization's information systems operations. The auditor observes that critical batch jobs frequently fail, leading to delays in financial reporting. Which of the following is the MOST appropriate initial action for the auditor to recommend?Domain 4: Information Systems Operations and Business Resilience
- 177.An IS auditor is reviewing an organization's change management process for critical production systems. The auditor observes that a significant number of emergency changes are implemented without prior testing in a non-production environment. What type of risk does this situation PRIMARILY represent?Domain 1: Information System Auditing Process
- 178.An IS auditor is planning an audit of a newly deployed customer relationship management (CRM) system. The organization has recently undergone a significant merger, integrating several disparate customer databases into the new CRM. Management is concerned about data integrity and consistency. Which of the following audit procedures would be MOST effective in addressing these concerns?Domain 1: Information System Auditing Process
- 179.A global financial institution is implementing a new core banking system. Due to the critical nature of the system, the project team plans to conduct extensive User Acceptance Testing (UAT) with key business users before go-live. An IS auditor reviewing the project plan notes that the UAT environment is a clone of the production environment, but the data used for testing is anonymized and synthetically generated. What is the MOST significant risk an IS auditor should identify regarding this UAT approach?Domain 4: Information Systems Operations and Business Resilience
- 180.An IS auditor is reviewing an organization's business continuity plan (BCP) and disaster recovery plan (DRP). The organization relies heavily on a third-party cloud provider for its critical applications and data storage. The auditor notes that the BCP/DRP primarily focuses on on-premise infrastructure recovery and lacks specific provisions for cloud service outages. What is the MOST significant risk introduced by this deficiency?Domain 1: Information System Auditing Process
- 181.An IS auditor is evaluating an organization's configuration management database (CMDB). The auditor observes that while all hardware and software components are logged, the relationships and interdependencies between these configuration items (CIs) are not consistently documented. What is the PRIMARY impact of this deficiency?Domain 4: Information Systems Operations and Business Resilience
- 182.An IS auditor is reviewing an organization's patch management process. The auditor finds that critical security patches are consistently delayed for production systems, citing concerns about system instability. This directly increases which type of risk?Domain 1: Information System Auditing Process
- 183.An IS auditor is reviewing an organization's data management practices related to data archiving. The auditor notes that old, non-essential data is regularly moved from active production databases to an archive system. However, there is no documented process for periodic testing of the archived data's recoverability or integrity. What is the MOST significant risk this poses to the organization?Domain 4: Information Systems Operations and Business Resilience
- 184.A financial institution utilizes a highly customized legacy core banking system that handles all transactions. An IS auditor discovers that the system relies on a single, aging hardware server with no redundancy or failover capabilities. The organization's IT budget has consistently deprioritized upgrades for this system due to its perceived stability and the high cost of customization. What is the MOST significant long-term risk this situation poses to the organization's information systems operations and business resilience?Domain 4: Information Systems Operations and Business Resilience
- 185.During the planning phase of an audit, an IS auditor identifies that the organization recently implemented a new, highly complex data analytics platform. Management has expressed concerns about the system's accuracy and integrity due to its novelty and the specialized skills required to operate it. What type of risk does this situation PRIMARILY represent from an audit perspective?Domain 1: Information System Auditing Process
- 186.A global manufacturing company uses an Enterprise Resource Planning (ERP) system to manage its supply chain, production, and finance. The IS auditor observes that the ERP system is hosted in a public cloud environment, but the organization has not implemented any specific controls or agreements to ensure data residency requirements are met, despite operating in multiple countries with varying data protection laws. What is the MOST significant risk this oversight presents?Domain 4: Information Systems Operations and Business Resilience
- 187.An IS auditor is reviewing an organization's business continuity plan (BCP). The auditor discovers that the BCP relies heavily on a third-party hot site for disaster recovery, but the contract with the hot site vendor has not been reviewed or updated in five years. What is the MOST significant risk this poses to the organization's business resilience?Domain 4: Information Systems Operations and Business Resilience
- 188.An IS auditor is reviewing an organization's business continuity plan (BCP) and disaster recovery plan (DRP). The organization has recently migrated critical applications to a new cloud provider. What is the MOST important aspect for the IS auditor to verify regarding the updated BCP/DRP?Domain 1: Information System Auditing Process
- 189.An IS auditor is reviewing the organization's data management practices for compliance with data retention policies. The auditor finds that while data is backed up regularly, the backup retention periods are not explicitly aligned with the organization's legal and regulatory data retention requirements. What is the MOST significant risk this poses?Domain 4: Information Systems Operations and Business Resilience
- 190.An IS auditor is evaluating an organization's business continuity plan (BCP). The auditor notes that the plan identifies critical business functions and their dependencies but lacks specific procedures for activating and managing a recovery team. What is the MOST significant implication of this deficiency?Domain 4: Information Systems Operations and Business Resilience
- 191.An IS auditor is evaluating an organization's data management practices, specifically focusing on data retention. The auditor discovers that several critical financial records are being deleted after five years, while regulatory requirements mandate a seven-year retention period. Which of the following is the MOST significant risk associated with this finding?Domain 4: Information Systems Operations and Business Resilience
- 192.An IS auditor is planning an audit of a complex, critical financial application. Management has expressed concerns about minimizing disruption to business operations during the audit. Which of the following approaches should the IS auditor prioritize to address management's concerns while still achieving audit objectives?Domain 1: Information System Auditing Process
- 193.An IS auditor is preparing to communicate audit findings to senior management regarding significant control weaknesses identified in the organization's critical payment processing system. The auditor has gathered sufficient evidence and formulated clear recommendations. Which of the following communication strategies would be MOST effective in ensuring management's understanding and prompt action?Domain 1: Information System Auditing Process
- 194.A software development company is experiencing frequent production incidents related to new code deployments. An IS auditor discovers that developers often push code directly to production after local testing, bypassing formal Quality Assurance (QA) and User Acceptance Testing (UAT) stages to meet tight deadlines. What is the MOST effective control to mitigate this risk?Domain 4: Information Systems Operations and Business Resilience
- 195.During an audit of an organization's change management process, an IS auditor observes that emergency changes are frequently implemented without prior testing in a non-production environment. Which of the following is the PRIMARY risk associated with this practice?Domain 4: Information Systems Operations and Business Resilience
- 196.An IS auditor is reviewing an organization's vendor management process for critical IT service providers. The organization relies on a third-party for its core financial processing system. Which of the following audit procedures would provide the MOST assurance regarding the security and control environment of the third-party provider?Domain 1: Information System Auditing Process
- 197.An IS auditor is assessing an organization's configuration management database (CMDB). The auditor finds that while the CMDB accurately lists all IT assets, it lacks established baselines for critical configurations. What is the MOST significant implication of this finding?Domain 4: Information Systems Operations and Business Resilience
- 198.An IS auditor is evaluating the organization's data management practices. The auditor discovers that different departments maintain their own copies of customer data, and there is no centralized process for data entry or updates. This leads to inconsistencies in customer records across various systems. Which of the following data management principles is PRIMARILY being violated?Domain 4: Information Systems Operations and Business Resilience
- 199.An IS auditor is evaluating the appropriateness of audit evidence collected during an audit of an organization's cloud security controls. The audit objective was to determine if data stored in the cloud is encrypted at rest according to policy. The auditor reviewed a screenshot of the cloud provider's console showing a checkbox for 'encryption enabled' and a signed statement from the cloud administrator confirming encryption. Which of the following statements BEST describes the sufficiency and reliability of this evidence?Domain 1: Information System Auditing Process
- 200.An IS auditor is preparing to conduct an audit of an organization's new cloud-based customer relationship management (CRM) system. Management has expressed concerns about the security of customer data hosted by the third-party cloud provider. Which of the following is the MOST important step for the IS auditor to perform first?Domain 1: Information System Auditing Process