1. An organization's information security policy states, 'All employees shall protect company information assets.' However, the policy does not define what constitutes 'company information assets,' nor does it specify protection measures or consequences for non-compliance. What is the MOST significant implication of this policy's wording for information security governance?
Domain 2: Governance and Management of IT
A.The organization may be viewed as having a weak security posture by external auditors.
B.Training programs for information security will be difficult to develop.
C.The policy is legally unenforceable in its current form.
D.Employees may inadvertently expose sensitive information due to a lack of clear guidance.
Show answerAnswer
D. Employees may inadvertently expose sensitive information due to a lack of clear guidance.
An effective information security policy must be clear, specific, and actionable. Vague wording that fails to define key terms or specify expected behaviors and consequences makes it impossible for employees to understand or comply with their obligations, leading to inconsistent application and potential security breaches.
2. A CISA is auditing an organization's IT asset management process. The CISA discovers that while hardware assets are meticulously tracked from acquisition to disposal, software licenses are only tracked at the point of purchase, with no ongoing monitoring of usage or installation. What is the MOST significant risk introduced by this practice?
Domain 2: Governance and Management of IT
A.Challenges in accurately forecasting future software budget requirements.
B.Higher likelihood of non-compliance with software vendor licensing agreements.
C.Reduced operational efficiency due to manual software inventory processes.
D.Increased difficulty in performing software upgrades and patches.
Show answerAnswer
B. Higher likelihood of non-compliance with software vendor licensing agreements.
Without ongoing monitoring of software installations and usage, an organization runs a significant risk of being over-licensed (wasting money) or, more critically, under-licensed, leading to non-compliance with software vendor agreements. This can result in hefty fines, legal action, and reputational damage.
3. An IS auditor is reviewing the project management practices for a new data analytics platform. The project manager reports that the project is on schedule and within budget, but key stakeholders express concerns about the solution's ability to meet their evolving business intelligence needs. Which of the following is the MOST likely underlying issue?
Domain 3: Information Systems Acquisition, Development and Implementation
A.Poor change control procedures.
B.Lack of continuous requirements validation.
C.Insufficient benefits realization management.
D.Inadequate risk management planning.
Show answerAnswer
B. Lack of continuous requirements validation.
The scenario indicates that while the project is technically on track (on schedule, within budget), the delivered solution might not meet 'evolving business intelligence needs.' This points to a failure in continuously validating that the system being built still aligns with current and future business requirements, especially in dynamic environments like data analytics.
4. A CISA is evaluating the effectiveness of an organization's IT governance structure. The CISA observes that the IT department consistently implements new technologies without formal approval from a cross-functional steering committee, despite such a committee being documented in the governance framework. What is the MOST likely consequence of this situation?
Domain 2: Governance and Management of IT
A.Reduced employee morale within the IT department.
B.Misalignment of IT investments with business strategy.
C.Difficulty in attracting and retaining skilled IT personnel.
D.Increased IT operational costs due to redundant systems.
Show answerAnswer
B. Misalignment of IT investments with business strategy.
If IT implements new technologies without formal cross-functional approval, it indicates a lack of effective governance oversight. This bypasses the mechanism designed to ensure IT projects align with overall business objectives, leading to potential investments in technologies that do not support strategic goals or create unintended business risks.
5. An organization is considering replacing its existing IT governance framework with a new, industry-standard framework. During the evaluation, the CISA notes that the proposed framework requires significant cultural changes and new reporting structures that are fundamentally different from the current organizational culture and existing management hierarchy. What is the PRIMARY challenge the organization will face in implementing the new framework?
Domain 2: Governance and Management of IT
A.Resistance from management and employees to adapt to new processes and responsibilities.
B.Increased complexity in integrating the new framework with existing IT operations.
C.Difficulty in obtaining budget approval for the new framework's tools and training.
D.Challenges in measuring the return on investment (ROI) of the framework implementation.
Show answerAnswer
A. Resistance from management and employees to adapt to new processes and responsibilities.
Significant cultural changes and new reporting structures directly challenge established norms and power dynamics within an organization. Resistance from management and employees to adapt to these fundamental shifts is a common and often the most difficult barrier to successful implementation of new governance frameworks or any organizational change.
6. A CISA is evaluating an organization's human resources management practices related to IT. The CISA observes that new IT employees are granted broad system access immediately upon joining, with access reviews conducted only annually. What is the MOST significant risk associated with this practice?
Domain 2: Governance and Management of IT
A.Elevated risk of unauthorized access and data breaches.
B.Difficulty in conducting effective IT audits.
C.Reduced employee productivity due to access complexity.
D.Increased cost due to unnecessary software licenses.
Show answerAnswer
A. Elevated risk of unauthorized access and data breaches.
Granting broad access immediately and conducting infrequent reviews creates a significant window of opportunity for unauthorized actions, whether accidental or malicious. This practice directly increases the risk of data breaches and compromises system integrity, as access is not aligned with the principle of least privilege or need-to-know.
7. An IS auditor is evaluating the controls over a new financial reporting system still in the development phase. Which of the following would be the MOST effective control to ensure that only authorized and tested code changes are promoted to the production environment?
Domain 3: Information Systems Acquisition, Development and Implementation
A.Automated regression testing after every code commit.
B.Segregation of duties between development, testing, and production environments.
C.Daily code reviews by peer developers.
D.Mandatory use of a version control system.
Show answerAnswer
B. Segregation of duties between development, testing, and production environments.
Segregation of duties (SoD) between development, testing, and production environments is a fundamental control that prevents unauthorized or untested code from being promoted to production. It ensures that no single individual or team has control over all stages of the software development lifecycle, thereby reducing the risk of fraud or errors.
8. During an audit of an organization's human resources management, the CISA notes that security awareness training is conducted only for new hires and is not repeated annually for existing employees. What is the MOST significant risk associated with this practice?
Domain 2: Governance and Management of IT
A.Difficulty in obtaining cyber insurance coverage.
B.Erosion of the organization's security posture over time.
C.Increased cost of onboarding new employees.
D.Decreased employee satisfaction due to lack of professional development.
Show answerAnswer
B. Erosion of the organization's security posture over time.
Security awareness is not a one-time event; threats evolve, and human memory fades. Without regular, ongoing training, employees' understanding of security policies and best practices will diminish, leading to a weakened human firewall and an increased susceptibility to social engineering attacks, phishing, and other security incidents, thereby eroding the overall security posture.
9. An IS auditor is reviewing the go-live readiness assessment for a new critical online banking system. The assessment indicates that all functional and performance tests passed, and user acceptance testing (UAT) was signed off. However, the auditor notes that the disaster recovery plan (DRP) for the new system has not yet been fully integrated or tested with the new system's specific configurations. Which of the following is the MOST significant risk to address before go-live?
Domain 3: Information Systems Acquisition, Development and Implementation
A.Inability to recover the system in the event of a major disruption after go-live.
B.Decreased user confidence if a disaster occurs shortly after launch.
C.Non-compliance with internal audit policies requiring tested DRPs.
D.Potential for increased operational costs due to lack of DRP testing.
Show answerAnswer
A. Inability to recover the system in the event of a major disruption after go-live.
For a critical online banking system, the inability to recover from a major disruption (due to an untested DRP for the new system) poses the most significant and immediate threat to business continuity, customer trust, and regulatory obligations post-go-live.
10. A CISA is evaluating an organization's business continuity plan (BCP). The CISA notes that while the BCP identifies critical business processes and their recovery time objectives (RTOs), it lacks detailed procedures for data backup and restoration, particularly for complex, interconnected databases. What is the MOST likely consequence of this deficiency during a business disruption?
Domain 2: Governance and Management of IT
A.Difficulty in communicating recovery status to stakeholders.
B.Increased risk of data corruption during the recovery process.
C.Extended downtime for critical applications due to inefficient data recovery.
D.Failure to meet regulatory compliance requirements for data retention.
Show answerAnswer
C. Extended downtime for critical applications due to inefficient data recovery.
Without detailed data backup and restoration procedures, especially for complex systems, the actual recovery process will be inefficient, error-prone, and significantly prolonged. This directly translates to exceeding established RTOs and extended downtime for critical business applications.
11. A CISA is auditing an organization that uses a third-party cloud provider for its critical business applications. The organization's information security policy states that 'all data stored in the cloud must meet the same security standards as on-premise data.' However, the CISA finds no evidence of regular security audits or reviews of the cloud provider's environment by the organization. What is the MOST significant implication of this finding?
Domain 2: Governance and Management of IT
A.The cloud provider might be operating inefficiently.
B.The organization's internal IT staff skills may degrade over time.
C.The organization's policy statement is effectively unenforceable and non-compliant.
D.The organization may be overpaying for cloud services.
Show answerAnswer
C. The organization's policy statement is effectively unenforceable and non-compliant.
Without regular security audits or reviews of the cloud provider, the organization has no way to verify if its policy requirement ('same security standards as on-premise data') is actually being met. This renders the policy unenforceable in practice and exposes the organization to unknown security risks, making it non-compliant with its own stated policy.
12. An organization relies on a highly customized, mission-critical application developed in-house over 20 years ago. The original developers have long since left the company, and documentation is sparse. The organization's disaster recovery plan (DRP) lists this application as critical but provides only generic restoration steps. What is the MOST significant challenge this poses to the DRP's effectiveness?
Domain 2: Governance and Management of IT
A.High probability of recovery failures due to lack of specialized knowledge.
B.Increased licensing costs for legacy operating systems and databases.
C.Inability to accurately estimate recovery time objectives (RTOs) for the application.
D.Difficulty in identifying and procuring compatible hardware for recovery.
Show answerAnswer
A. High probability of recovery failures due to lack of specialized knowledge.
Given the application's age, customization, lack of original developers, and sparse documentation, the most significant challenge is the high likelihood that recovery efforts will fail due to the absence of the specific, specialized knowledge required to effectively restore and configure such a unique and complex legacy system. Generic steps are insufficient.
13. During an audit of an organization's IT governance structure, the CISA observes that the IT department frequently initiates projects without formal approval from business units, leading to scope creep and unmet business expectations. Which of the following is the MOST significant implication of this observation?
Domain 2: Governance and Management of IT
A.Lack of alignment between IT initiatives and business objectives.
B.Difficulty in tracking project progress and reporting to stakeholders.
C.Potential for security vulnerabilities in hastily developed systems.
D.Increased operational costs due to inefficient resource allocation.
Show answerAnswer
A. Lack of alignment between IT initiatives and business objectives.
When IT projects are initiated without formal business unit approval, it indicates a fundamental breakdown in the alignment between IT and the business. This directly leads to projects that may not support strategic organizational goals, making lack of alignment the most significant implication.
14. A CISA is auditing an organization's approach to information security. The CISA observes that the security policies are largely descriptive, outlining what 'should be done' but lacking specific instructions or measurable outcomes. Which of the following is the MOST significant concern for the CISA regarding these policies?
Domain 2: Governance and Management of IT
A.They can be easily misinterpreted by employees due to their general nature.
B.They require frequent updates to remain relevant to technological changes.
C.They make it difficult to enforce compliance and measure effectiveness.
D.They may not adequately address emerging threats and vulnerabilities.
Show answerAnswer
C. They make it difficult to enforce compliance and measure effectiveness.
Descriptive policies that lack specific instructions and measurable outcomes severely hinder the organization's ability to enforce compliance and objectively assess whether the policies are achieving their intended security goals. Without clear metrics and actionable directives, it is challenging to hold individuals accountable or to demonstrate policy effectiveness.
15. An organization is implementing a new enterprise resource planning (ERP) system. The CISA observes that the project team is highly technical, but business unit representatives are only minimally involved in requirements gathering and testing phases. From an IT governance perspective, what is the MOST significant concern?
Domain 2: Governance and Management of IT
A.The project budget may be exceeded due to technical complexity.
B.Technical documentation for the ERP system may be inadequate.
C.The system may not effectively support critical business processes.
D.The project timeline may be extended due to a lack of technical resources.
Show answerAnswer
C. The system may not effectively support critical business processes.
Effective IT governance requires strong alignment between IT projects and business needs. Minimal involvement of business representatives in requirements and testing significantly increases the risk that the new ERP system will not meet actual business process needs, leading to low user adoption and failure to achieve strategic objectives.
16. A CISA is auditing an organization that has recently outsourced its entire IT infrastructure management to a third-party service provider. The contract explicitly states the service level agreements (SLAs) for uptime and performance. However, there is no formal mechanism for the organization to monitor the provider's adherence to these SLAs. What is the MOST critical control weakness in this scenario?
Domain 2: Governance and Management of IT
A.Potential for increased costs due to unmonitored service usage.
B.Lack of a clear exit strategy in the outsourcing contract.
C.Insufficient oversight to ensure vendor performance meets contractual obligations.
D.Absence of an independent audit clause for the service provider.
Show answerAnswer
C. Insufficient oversight to ensure vendor performance meets contractual obligations.
While all options represent weaknesses, the most critical is the lack of a mechanism to monitor SLA adherence. Without this, the organization cannot verify if the service provider is meeting its contractual obligations, effectively nullifying the purpose of having SLAs and exposing the organization to operational and financial risks without recourse.
17. An IS auditor is reviewing controls over system acquisition for a new enterprise resource planning (ERP) system. The project team has developed a detailed Request for Proposal (RFP) and received multiple vendor responses. Which of the following criteria should the IS auditor recommend as the MOST important to evaluate vendor proposals against for a complex ERP system?
Domain 3: Information Systems Acquisition, Development and Implementation
A.The proposed implementation timeline and project plan.
B.The vendor's reputation and market share.
C.The vendor's ability to meet critical business requirements.
D.The lowest total cost of ownership (TCO).
Show answerAnswer
C. The vendor's ability to meet critical business requirements.
For a complex system like ERP, the vendor's ability to meet critical business requirements is paramount. Without this, even a low-cost, reputable vendor with a fast timeline will deliver a system that fails to support core business operations, leading to significant financial and operational losses.
18. An organization is updating its human resources management practices related to IT. The CISA reviews the onboarding process for new IT employees and notes that while background checks are conducted, there is no formal process for revoking access rights immediately upon an employee's termination. Which of the following is the MOST critical risk this omission poses?
Domain 2: Governance and Management of IT
A.Difficulty in tracking software license usage.
B.Increased administrative burden on IT helpdesk staff.
C.Potential for unauthorized access to sensitive systems and data.
D.Delayed onboarding of new employees due to resource allocation.
Show answerAnswer
C. Potential for unauthorized access to sensitive systems and data.
Failure to promptly revoke access rights for terminated employees creates a critical window of opportunity for unauthorized access, potentially leading to data breaches, system compromise, or malicious activity, which is a severe security risk.
19. An organization is updating its information security policy. The draft policy includes a statement: 'All sensitive data must be encrypted in transit.' However, it does not specify the encryption algorithms, key lengths, or protocols to be used. What is the MOST significant shortcoming of this policy statement from an audit perspective?
Domain 2: Governance and Management of IT
A.It does not assign responsibility for implementing the encryption.
B.It lacks clarity regarding the types of sensitive data covered.
C.It is not sufficiently actionable or enforceable due to lack of specificity.
D.It fails to address encryption for data at rest, only data in transit.
Show answerAnswer
C. It is not sufficiently actionable or enforceable due to lack of specificity.
From an audit perspective, a policy statement must be clear, measurable, and enforceable. Without specifying 'how' encryption should be achieved (algorithms, key lengths, protocols), the policy becomes difficult to implement consistently and impossible to audit for compliance effectively, making it not actionable or enforceable.
20. An IS auditor is reviewing the software maintenance process for an internally developed legacy system. The auditor observes that maintenance requests are often implemented directly into production without prior testing in a separate environment. What is the MOST likely consequence of this practice?
Domain 3: Information Systems Acquisition, Development and Implementation
A.Non-compliance with software licensing agreements.
B.Difficulty in attracting and retaining skilled developers.
C.Increased software development costs over time.
D.Reduced system availability due to new defects introduced.
Show answerAnswer
D. Reduced system availability due to new defects introduced.
Implementing changes directly into production without testing in a separate environment significantly increases the risk of introducing new defects, regressions, or incompatibilities. These untested changes can lead to system crashes, data corruption, or unexpected behavior, directly resulting in reduced system availability and service disruptions.
21. A CISA is reviewing an organization's IT organizational structure. The CISA notes that the Chief Information Security Officer (CISO) reports directly to the Chief Information Officer (CIO). Which of the following is the MOST significant risk associated with this reporting structure?
Domain 2: Governance and Management of IT
A.Security priorities may be deprioritized in favor of IT operational efficiency.
B.The CISO may struggle to obtain adequate budget for security initiatives.
C.The CISO's technical recommendations may not be understood by the CIO.
D.The CISO's career progression within the organization may be limited.
Show answerAnswer
A. Security priorities may be deprioritized in favor of IT operational efficiency.
When the CISO reports to the CIO, there's an inherent conflict of interest. The CIO's primary focus is often on IT service delivery, operational efficiency, and project completion, while the CISO's role is to ensure security, which can sometimes impose constraints on operations. This structure can lead to security concerns being overlooked or deprioritized to meet operational goals.
22. An IS auditor is reviewing the system development lifecycle (SDLC) for a critical customer-facing web application. The development team uses an Agile methodology. Which of the following practices BEST ensures that security requirements are adequately addressed throughout the development process?
Domain 3: Information Systems Acquisition, Development and Implementation
A.Relying on penetration testing by an external vendor once per year.
B.Providing security awareness training to all developers at the beginning of the project.
C.Conducting a comprehensive security audit just before the final production release.
D.Integrating security activities, such as threat modeling and secure code reviews, into each sprint.
Show answerAnswer
D. Integrating security activities, such as threat modeling and secure code reviews, into each sprint.
Integrating security activities into each sprint (often called 'shifting left') ensures that security is built into the application incrementally, addressing vulnerabilities early and reducing remediation costs.
23. An IS auditor is evaluating the project management practices for a new data analytics platform. The project manager reports a Budgeted Cost of Work Performed (BCWP) of $750,000, an Actual Cost of Work Performed (ACWP) of $800,000, and a Budgeted Cost of Work Scheduled (BCWS) of $700,000. What is the Cost Performance Index (CPI)?
Domain 3: Information Systems Acquisition, Development and Implementation
A.1.143
B.1.071
C.0.875
D.0.938
Show answerAnswer
D. 0.938
The Cost Performance Index (CPI) measures the cost efficiency of a project. It is calculated as BCWP / ACWP. In this case, $750,000 / $800,000 = 0.9375, which rounds to 0.938.
24. A CISA is evaluating an organization's IT organizational structure. The CISA discovers that a single individual is responsible for developing, testing, and deploying critical business application code, as well as managing the production database. What is the MOST significant risk associated with this arrangement?
Domain 2: Governance and Management of IT
A.Opportunities for fraud, errors, or unauthorized changes are significantly increased.
B.The development lifecycle for new features will be excessively long.
C.The organization may struggle to attract and retain skilled IT personnel.
D.The individual may experience burnout due to an excessive workload.
Show answerAnswer
A. Opportunities for fraud, errors, or unauthorized changes are significantly increased.
This scenario describes a severe lack of segregation of duties (SoD). Allowing one person to control development, testing, deployment, and production database management creates an environment where malicious acts, errors, or unauthorized changes could occur undetected and unprevented, leading to significant integrity and security risks.
25. An IS auditor is reviewing the controls over software maintenance for an internally developed application. User feedback indicates that system performance has degraded significantly after recent production updates. Which of the following controls is MOST likely to have failed?
Domain 3: Information Systems Acquisition, Development and Implementation
A.Formal change request and approval process.
B.Version control for software code and configurations.
C.Segregation of duties between development and production environments.
D.Adequate testing of changes before deployment.
Show answerAnswer
D. Adequate testing of changes before deployment.
Significant performance degradation after production updates strongly suggests that the changes were not adequately tested for their impact on system performance, stability, or resource utilization before being deployed to the live environment.
An actionable security policy is clearly written, defines key terms, specifies required behaviors, outlines responsibilities, and details consequences for non-compliance, enabling effective implementation and enforcement.
Provides clear guidance to employees.
Defines scope, responsibilities, and expectations.
The practice of managing and optimizing the purchase, deployment, maintenance, utilization, and disposal of software applications within an organization to ensure compliance and cost-effectiveness.
Prevents over-licensing (waste) and under-licensing (non-compliance).
Requires continuous monitoring of installations and usage.
An ongoing process throughout the system development lifecycle to ensure that the evolving system design and implementation consistently align with current and anticipated business needs and stakeholder expectations.
The degree to which an organization's IT governance framework successfully ensures that IT delivers value, manages risks, and aligns with business objectives.
The successful implementation of an IT governance framework significantly depends on its alignment with the organization's culture and the willingness of management and employees to adapt to new processes, roles, and reporting structures.
Cultural resistance is a major barrier to change.
New frameworks often require changes in behavior and mindset.
Management buy-in and employee engagement are crucial.
A control principle that divides critical functions among different individuals or teams to prevent any single person from having complete control over a process, thereby reducing the risk of error, fraud, or misuse.
Prevents a single point of failure or compromise.
Enhances internal control effectiveness.
Commonly applied in financial, IT, and operational processes.
An ongoing program designed to educate all employees regularly about current information security threats, policies, and best practices to maintain a strong security culture.
Go-Live DRP Readiness refers to the state where the disaster recovery plan for a new system has been fully developed, integrated, and validated to ensure the system can be recovered post-implementation.
DRP must be specific to the new system's architecture.
Detailed, step-by-step instructions within a Disaster Recovery Plan (DRP) for backing up, restoring, and ensuring the integrity of critical data and systems following a disruptive event.
Cloud security oversight involves the organization's responsibility to ensure that cloud service providers adhere to its security policies and regulatory requirements through regular audits, reviews, and contractual agreements.
Difficulties in developing and executing a Disaster Recovery Plan (DRP) for older, highly customized, or poorly documented systems, often due to lack of expertise, compatible hardware, or insufficient documentation.
The process of ensuring that IT strategies, initiatives, and operations are integrated with and support the organization's overarching business goals and objectives.
Crucial for maximizing IT value.
Requires strong governance and communication.
Prevents IT projects from becoming 'solutions looking for a problem'.
Business-IT alignment ensures that IT strategies, projects, and operations are consistent with and support the organization's overall business objectives and priorities.
Critical for achieving business value from IT investments.
Requires active involvement of business stakeholders.
The process of continually tracking and evaluating an outsourced service provider's performance against agreed-upon service level agreements (SLAs) and contractual obligations.
Ensures value for money and service quality.
Requires defined metrics and reporting mechanisms.
Critical for managing vendor risk and accountability.
Vendor proposal evaluation criteria are the standards used to assess and compare bids from potential suppliers for system acquisition, ensuring the chosen solution best meets organizational needs.
Should be defined before proposals are received.
Includes functional, technical, financial, and support aspects.
Critical business requirements are usually weighted highest.
Access revocation is the immediate removal of all system and data access rights for an employee upon their termination or change in role, as a critical security control measure.
The hierarchical placement of the Chief Information Security Officer (CISO) within an organization, which significantly impacts the CISO's authority, independence, and effectiveness in managing information security risks.
Ideal reporting lines include CEO, CRO, or Board.
Reporting to CIO can create conflicts of interest.
Independence is crucial for objective security oversight.
Embedding security practices and considerations throughout all phases of an Agile development lifecycle, rather than as a separate, late-stage activity.
Known as 'shifting left' security.
Includes continuous threat modeling, secure coding, and testing.
Reduces cost and effort of fixing vulnerabilities later.
The Cost Performance Index (CPI) is an Earned Value Management (EVM) metric that measures the cost efficiency of budgeted resources for work performed.
The process of verifying that modifications to software function as intended, do not introduce new defects, and do not negatively impact existing functionality or performance before deployment.
A documented plan outlining the procedures, responsibilities, and technical requirements for migrating data and applications out of a cloud provider's environment.
Ensures data ownership and access upon termination.
Prevents vendor lock-in.
Addresses data format, transfer methods, and timelines.
Internal control objectives for IT operations define the desired state for the security, integrity, availability, and efficiency of information systems and data within an organization.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.