Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CISA Practice Exam

Total questions: 75

Worksheet time: 38mins

Name
Class
Date
1.

Which of the following processes will be MOST effective in reducing the risk that unauthorized software on a backup server is distributed to a production server?

a)

Manually copy files to accomplish replication

b)

Review changes in the software version control system.

c)

Ensure that developers do not have access to the backup server

d)

Review the access control log of the backup server

2.

While performing an audit of an accounting application’s internal data integrity controls, an information systems (IS) auditor identifies a major control deficiency in the change management software supporting the accounting application. The MOST appropriate action for the IS auditor to take is to:

a)

continue to test the accounting application controls and inform the IT manager about the control deficiency and recommend possible solutions.

b)

complete the audit and not report the control deficiency because it is not part of the audit scope.

c)

continue to test the accounting application controls and include the deficiency in the final report.

d)

cease all audit activity until the control deficiency is resolved

3.

When reviewing a hardware maintenance program, an information systems (IS) auditor should assess whether:

a)

the schedule of all unplanned maintenance is maintained

b)

it is in line with historical trends

c)

it has been approved by the IS steering committee

d)

the program is validated against vendor specifications

4.

When reviewing the desktop software compliance of an organization, the information systems (IS) auditor should be MOST concerned if the installed software:

a)

is installed, but not documented in the IT department records

b)

is being used by users not properly trained in its use

c)

is not listed in the approved software standards document

d)

has a license that will expire in the next 15 days

5.

When an employee is terminated from service, the MOST important action is to:

a)

hand over all of the employee’s files to another designated employee

b)

complete a backup of the employee’s work

c)

notify other employees of the termination

d)

disable the employee’s logical access

6.

While evaluating software development practices in an organization, an information systems (IS) auditor notes that the quality assurance (QA) function reports to project management. The MOST important concern for an IS auditor is the:

a)

effectiveness of the QA function because it should interact between project management and user management.

b)

efficiency of the QA function because it should interact with the project implementation team.

c)

effectiveness of the project manager because the project manager should interact with the QA function

d)

efficiency of the project manager because the QA function needs to communicate with the project implementation team.

7.

Change control for business application systems being developed using prototyping can be complicated by the:

a)

iterative nature of prototyping

b)

rapid pace of modifications in requirements and design

c)

emphasis on reports and screens

d)

lack of integrated tools

8.

During an information systems (IS) audit of the disaster recovery plan of a global enterprise, the auditor observes that some remote offices have very limited local IT resources. Which of the following observations is the MOST critical for the IS auditor?

a)

A test has not been made to ensure that local resources can maintain security and service standards when recovering from a disaster or incident.

b)

The corporate business continuity plan (BCP) plan does not accurately document the systems that exist at remote offices.

c)

Corporate security measures have not been incorporated into the test plan

d)

A test has not been made to ensure that backups from the remote offices are usable

9.

During an information systems (IS) risk assessment of a health care organization regarding protected health information (PHI), an IS auditor interviews IS management. Which of the following findings from the interviews would be of MOST concern to the IS auditor?

a)

The organization does not encrypt all of its outgoing email messages

b)

Staff have to type [PHI] in the subject field of email messages to be encrypted

c)

An individual’s computer screen saver function is disabled.

d)

Server configuration requires the user to change the password annually.

10.

An information systems (IS) auditor reviewing wireless network security determines that the Dynamic Host Configuration Protocol is disabled at all wireless access points. This practice:

a)

reduces the risk of unauthorized access to the network

b)

is not suitable for small networks

c)

automatically provides an Internet Protocol (IP) address to anyone

d)

increases the risk associated with Wireless Encryption Protocol

11.

Which of the following is MOST indicative of the effectiveness of an information security awareness program?

a)

Employees report more information regarding security incidents

b)

All employees have signed the information security policy

c)

Most employees have attended an awareness session

d)

Information security responsibilities have been included in job descriptions

12.

An information systems (IS) auditor performing a review of application controls evaluates the:

a)

efficiency of the application in meeting the business processes

b)

impact of any exposures discovered

c)

business processes served by the application

d)

application optimization

13.

Which of the following processes should an information systems (IS) auditor recommend to assist in the recording of baselines for software releases?

a)

User acceptance testing (UAT)

b)

Backup and recovery

c)

Incident management

d)

Configuration management

14.

Which of the following does a lack of adequate controls represent?

a)

An impact

b)

A vulnerability

c)

An asset

d)

A threat

15.

Which of the following sampling methods is MOST useful when testing for compliance?

a)

Attribute sampling

b)

Variable sampling

c)

Stratified mean-per-unit sampling

d)

Difference estimation sampling

16.

The PRIMARY goal of a website certificate is:

a)

authentication of the website that will be surfed.

b)

authentication of the user who surfs through that site.

c)

preventing surfing of the website by hackers.

d)

the same purpose as that of a digital certificate.

17.

An information systems (IS) auditor discovers several IT-based projects were implemented and not approved by the steering committee. What is the GREATEST concern for the IS auditor?

a)

The IT department’s projects will not be adequately funded.

b)

IT projects are not following the system development life cycle (SDLC) process.

c)

IT projects are not consistently formally approved.

d)

The IT department may not be working toward a common goal.

18.

Which of the following is an advantage of prototyping?

a)

The finished system normally has strong internal controls.

b)

Prototype systems can provide significant time and cost savings.

c)

Change control is often less complicated with prototype systems.

d)

Prototyping ensures that functions or extras are not added to the intended system.

19.

Which of the following provides the GREATEST assurance for database password encryption?

a)

Secure hash algorithm-256

b)

Advanced encryption standard (AES)

c)

Secure Shell (SSH)

d)

Triple DES (3DES)

20.

An information systems (IS) auditor reviewing the authentication controls of an enterprise should be MOST concerned if:

a)

user accounts are not locked out after five failed attempts

b)

passwords can be reused by employees within a defined time frame

c)

system administrators use shared login credentials

d)

password expiration is not automated

21.

What is the PRIMARY reason for an information systems (IS) auditor to exercise due professional care?

a)

To get reasonable assurance that IS controls are well-designed and effective

b)

To eliminate inherent, control and detection risk associated with IS audit

c)

To detect errors, misstatements or fraudulent transactions in IS and report them

d)

To make sure that evidence collected during the IS audit is appropriate and sufficient

22.

When developing a security architecture, which of the following steps should be executed FIRST?

a)

Developing security procedures

b)

Defining a security policy

c)

Specifying an access control methodology

d)

Defining roles and responsibilities

23.

Which of the following preventive controls BEST helps secure a web application?

a)

Password masking

b)

Developer training

c)

Use of encryption

d)

Vulnerability testing

24.

An organization is implementing an enterprise resource planning (ERP) application. Of the following, who is PRIMARILY responsible for overseeing the project to ensure that it is progressing in accordance with the project plan and that it will deliver the expected results?

a)

Project sponsor

b)

System development project team

c)

Project steering committee

d)

User project team

25.

The BEST method for assessing the effectiveness of a business continuity plan (BCP) is to review the:

a)

plans and compare them to appropriate standards

b)

results from previous tests

c)

emergency procedures and employee training

d)

offsite storage and environmental controls

26.

Which of the following does an information systems (IS) auditor consider to be MOST important when evaluating an organization’s IT strategy? That it:

a)

was approved by line management

b)

does not vary from the IT department’s preliminary budget

c)

complies with procurement procedures

d)

supports the business objectives of the organization

27.

Which of the following should an information systems (IS) auditor recommend to BEST enforce alignment of an IT project portfolio with strategic organizational priorities?

a)

Define a balanced scorecard (BSC) for measuring performance

b)

Consider user satisfaction in the key performance indicators (KPIs)

c)

Select projects according to business benefits and risk

d)

Modify the yearly process of defining the project portfolio

28.

An offsite information processing facility (IPF) with electrical wiring, air conditioning and flooring, but no computer or communications equipment, is a:

a)

cold site

b)

warm site

c)

dial-up site

d)

duplicate processing facility

29.

Which of the following reports should an information systems (IS) auditor use to check compliance with a service level agreement’s requirement for uptime?

a)

Utilization reports

b)

Hardware error reports

c)

System logs

d)

Availability reports

30.

From an IT governance perspective, what is the PRIMARY responsibility of the board of directors? To ensure that the IT strategy:

a)

is cost-effective.

b)

is forward thinking and innovative.

c)

is aligned with the business strategy.

d)

has the appropriate priority level assigned.

31.

Which of the following distinguishes a business impact analysis (BIA) from a risk assessment?

a)

Inventory of critical assets

b)

Identification of vulnerabilities

c)

Listing of threats

d)

Determination of acceptable downtime

32.

Which of the following is an implementation risk within the process of decision support systems (DSSs)?

a)

Management control

b)

Semi-structured dimensions

c)

Inability to specify purpose and usage patterns

d)

Changes in decision processes

33.

Which of the following types of testing determines whether a new or modified system can operate in its target environment without adversely impacting other existing systems?

a)

Parallel testing

b)

Pilot testing

c)

Interface/integration testing

d)

Sociability testing

34.

Which of the following is the BEST audit procedure to determine if a firewall is configured in compliance with the enterprise security policy?

a)

Review the parameter settings.

b)

Interview the firewall administrator.

c)

Review the actual procedures.

d)

Review the device’s log file for recent attacks.

35.

A legacy payroll application was migrated to a new application. Which of the following stakeholders should be PRIMARILY responsible for reviewing and signing off on the accuracy and completeness of the data before going live?

a)

Information systems (IS) auditor

b)

Database administrator (DBA)

c)

Project manager

d)

Data owner

36.

During an assessment of software development practices, an information systems (IS) auditor finds that open-source software components were used in an application designed for a client. What is the GREATEST concern that the auditor has about the use of open-source software?

a)

The client did not pay for the open-source software components

b)

The organization and client must comply with open-source software license terms

c)

Open-source software has security vulnerabilities

d)

Open-source software is unreliable for commercial use

37.

Which of the following types of transmission media provide the BEST security against unauthorized access?

a)

Copper wire

b)

Shielded twisted pair

c)

Fiber-optic cables

d)

Coaxial cables

38.

Corrective action has been taken by an auditee immediately after the identification of a reportable finding. The information systems (IS) auditor should:

a)

include the finding in the final report because the IS auditor is responsible for an accurate report of all findings.

b)

not include the finding in the final report because management resolved the item.

c)

not include the finding in the final report because corrective action can be verified by the IS auditor during the audit.

d)

include the finding in the closing meeting for discussion purposes only.

39.

An information systems (IS) auditor is developing an audit plan for an environment that includes new systems. Enterprise management wants the IS auditor to focus on recently implemented systems. How should the IS auditor respond?

a)

Audit the new systems as requested by management

b)

Audit systems not included in last year’s scope

c)

Determine the highest-risk systems and plan accordingly

d)

Audit systems not in last year’s scope and the new systems

40.

The Transport Layer Security (TLS) protocol ensures the confidentiality of data and message by using:

a)

symmetric encryption

b)

message authentication codes

c)

hash function

d)

digital signature certificates

41.

What is the MAJOR benefit of conducting a control self-assessment (CSA) over a traditional audit?

a)

It detects risk sooner.

b)

It replaces the internal audit function.

c)

It reduces the audit workload.

d)

It reduces audit resource requirements.

42.

Which of the following tasks should be performed FIRST when preparing a disaster recovery plan (DRP)?

a)

Develop a recovery strategy

b)

Perform a business impact analysis (BIA)

c)

Map software systems, hardware and network components

d)

Appoint recovery teams with defined personnel, roles and hierarchy

43.

Which of the following would be a MAJOR concern for an information systems (IS) auditor reviewing a business continuity plan (BCP)?

a)

The plan is approved by the chief information officer.

b)

The plan contact lists have not been updated.

c)

Test results are not adequately documented.

d)

The training schedule for recovery personnel is not included.

44.

An information systems (IS) auditor wants to analyze audit trails on critical servers to discover potential anomalies in user or system behavior. Which of the following is the MOST suitable for performing that task?

a)

Computer-aided software engineering tools

b)

Embedded data collection tools

c)

Trend/variance detection tools

d)

Heuristic scanning tools

45.

When testing program change requests for a remote system, an information systems (IS) auditor finds that the number of changes available for sampling does not provide a reasonable level of assurance. What is the MOST appropriate action for the IS auditor to take?

a)

Develop an alternate testing procedure

b)

Report the finding to management

c)

Perform a walkthrough of the change management process

d)

Create additional sample data to test additional changes

46.

The final decision to include a material finding in an audit report should be made by the:

a)

audit committee

b)

auditee’s manager

c)

information systems (IS) auditor

d)

chief executive officer

47.

Which of the following BEST provides assurance of the integrity of new staff?

a)

Background screening

b)

References

c)

Bonding

d)

Qualifications listed on a resume

48.

An information systems (IS) auditor of a health care organization is reviewing contractual terms and conditions of a third-party cloud provider being considered to host patient health information. Which of the following contractual terms is the GREATEST risk to the customer organization?

a)

Data ownership is retained by the customer organization.

b)

The third-party provider reserves the right to access data to perform certain operations.

c)

Bulk data withdrawal mechanisms are undefined.

d)

The customer organization is responsible for backup, archiving and restoration.

49.

An information systems (IS) auditor is assigned to review an organization’s information security policy. Which of the following issues represents the HIGHEST potential risk?

a)

The policy has not been updated in more than one year.

b)

The policy includes no revision history.

c)

The policy is approved by the security administrator.

d)

The organization does not have an information security policy committee.

50.

The information systems (IS) auditor is reviewing the implementation of a storage area network (SAN). The SAN administrator indicates that logging and monitoring is active, hard zoning is used to isolate data belonging to different business units and all unused SAN ports are disabled. The administrator implemented the system, performed and documented security testing during implementation and is the only user with administrative rights to the system. What should the IS auditor’s initial determination be?

a)

There is no significant potential risk.

b)

Soft zoning presents a potential risk.

c)

Disabling unused ports presents a potential risk.

d)

The SAN administrator presents a potential risk.

51.

Which of the following is MOST critical for the successful implementation and maintenance of a security policy?

a)

Assimilation of the framework and intent of a written security policy by all appropriate parties

b)

Management support and approval for the implementation and maintenance of a security policy

c)

Enforcement of security rules by providing punitive actions for any violation of security rules

d)

Stringent implementation, monitoring and enforcing of rules by the security officer through access control software

52.

Enterprise governance of IT frameworks has been developed MAINLY to help an organization’s leaders:

a)

use resources responsibly and manage information systems risk.

b)

realize benefits and manage the performance of practices and processes.

c)

deliver value to stakeholders and preserve the value created.

d)

establish accountability and manage information security risk.

53.

Which of the following is the MOST important skill that an information systems (IS) auditor should develop to understand the constraints of conducting an audit?

a)

Managing audit staff

b)

Allocating resources

c)

Project management

d)

Attention to detail

54.

If inadequate, which of the following is the MOST likely contributor to a denial-of-service (DoS) attack?

a)

Router configuration and rules

b)

Design of the internal network

c)

Updates to the router system software

d)

Audit testing and review techniques

55.

The cost of ongoing operations when a disaster recovery plan (DRP) is in place, compared to not having a DRP, will MOST likely:

a)

increase

b)

decrease

c)

remain the same

d)

be unpredictable

56.

Which one of the following can be used to provide automated assurance that proper data files are being used during processing?

a)

File header record

b)

Version usage

c)

Parity checking

d)

File security controls

57.

A database administrator (DBA) who needs to make emergency changes to a database after normal working hours should log in:

a)

with their named account to make the changes.

b)

with the shared DBA account to make the changes.

c)

to the server administrative account to make the changes.

d)

to the user’s account to make the changes.

58.

An enterprise has established a guest network for visitor access. Which of the following should be of GREATEST concern to an information systems (IS) auditor?

a)

A login screen is not displayed for guest users

b)

The guest network is not segregated from the production network

c)

Guest users who are logged in are not isolated from each other

d)

A single-factor authentication technique is used to grant access

59.

The BEST overall quantitative measure of the performance of biometric control devices is:

a)

false-rejection rate (FRR)

b)

false-acceptance rate (FAR)

c)

equal error rate (EER)

d)

estimated-error rate

60.

Which of the following must exist to ensure the viability of a duplicate information processing facility (IPF)?

a)

The site is near the primary site to ensure quick and efficient recovery

b)

The site contains the most advanced hardware available

c)

The workload of the primary site is monitored to ensure adequate backup is available

d)

The hardware is tested when it is installed to ensure it is working properly

61.

Which of the following groups would create the MOST concern to an information systems (IS) auditor if the group has full access to the production database?

a)

Application developers

b)

System administrators

c)

Business users

d)

Information security team

62.

Which of the following is the MOST important consideration when defining recovery point objectives (RPOs)?

a)

Minimum operating requirements

b)

Acceptable data loss

c)

Mean time between failures

d)

Acceptable time for recovery

63.

To address an organization’s disaster recovery requirements, backup intervals should not exceed the:

a)

service level objective

b)

recovery time objective (RTO)

c)

recovery point objective (RPO)

d)

maximum acceptable outage (MAO)

64.

An organization sells books and music online on its secure website. Transactions are transferred to the accounting and delivery systems every hour to be processed. Which of the following controls BEST ensures that sales processed on the secure website are transferred to both systems?

a)

Transaction totals are recorded daily in the sales systems. Daily sales system totals are aggregated and totaled.

b)

Transactions are automatically numerically sequenced. Sequences are checked and gaps in continuity are accounted for.

c)

Processing systems check for duplicated transaction numbers. If a transaction number is duplicated (already present), it is rejected.

d)

System time is synchronized hourly using a centralized time server. All transactions have a date/time stamp.

65.

Which of the following is of GREATEST concern to an information systems (IS) auditor when performing an audit of a client relationship management system migration project?

a)

The technical migration is planned for a Friday preceding a long weekend, and the time window is too short for completing all tasks.

b)

Employees pilot testing the system are concerned that the data representation in the new system is completely different from the old system.

c)

A single implementation is planned, immediately decommissioning the legacy system.

d)

Five weeks prior to the target date, there are still numerous defects in the printing functionality of the new system’s software.

66.

An information systems (IS) auditor reviewing a cloud computing environment that is managed by a third party should be MOST concerned when:

a)

The enterprise is not permitted to assess the controls in the participating vendor’s site.

b)

The service level agreement (SLA) does not address the responsibility of the vendor in the case of a security breach.

c)

Laws and regulations are different in the countries of the enterprise and the vendor.

d)

The enterprise is using an older version of a browser and is vulnerable to certain types of security risk.

67.

When reviewing system parameters, an information systems (IS) auditor’s PRIMARY concern should be that:

a)

they are set to meet both security and performance requirements

b)

changes are recorded in an audit trail and periodically reviewed

c)

changes are authorized and supported by appropriate documents

d)

access to parameters in the system is restricted

68.

What BEST describes the risk that information collected may contain a material error that may go undetected during information systems (IS) auditing?

a)

Inherent risk

b)

Audit risk

c)

Control risk

d)

Detection risk

69.

The PRIMARY objective of performing a postincident review is that it presents an opportunity to:

a)

improve the internal control process.

b)

harden the network to industry good practices.

c)

highlight the importance of incident response management to management.

d)

improve employee awareness of the incident response process.

70.

Which of the following would be the BEST overall control for an Internet business looking for confidentiality, reliability and integrity of data?

a)

Transport Layer Security (TLS)

b)

Intrusion detection system (IDS)

c)

Public key infrastructure

d)

Virtual private network (VPN)

71.

An organization has contracted with a vendor for a turnkey solution for its electronic toll collection system (ETCS). The vendor has provided its proprietary application software as part of the solution. The contract should require that:

a)

a backup server is available to run ETCS operations with up-to-date data

b)

a backup server is loaded with all relevant software and data

c)

the systems staff of the organization is trained to handle any event

d)

source code of the ETCS application is placed in escrow

72.

When reviewing an enterprise’s logical access security to its remote systems, which of the following would be of GREATEST concern to an information systems (IS) auditor?

a)

Passwords are shared.

b)

Unencrypted passwords are used.

c)

Redundant logon IDs exist.

d)

Third-party users possess administrator access.

73.

On which of the following factors should an information systems (IS) auditor PRIMARILY focus when determining the appropriate level of protection for an information asset?

a)

Results of a risk assessment

b)

Relative value to the business

c)

Results of a vulnerability assessment

d)

Cost of security controls

74.

An information systems (IS) auditor performing a review of a major software development project finds that it is on schedule and under budget even though the software developers have worked considerable amounts of unplanned overtime. The IS auditor should:

a)

conclude that the project is progressing as planned because dates are being met.

b)

question the project manager further to identify whether overtime costs are being tracked accurately.

c)

conclude that the programmers are intentionally working slowly to earn extra overtime pay.

d)

investigate further to determine whether the project plan may not be accurate.

75.

Value delivery from IT to the business is MOST effectively achieved by:

a)

aligning the IT strategy with the enterprise strategy

b)

embedding accountability in the enterprise

c)

providing a positive return on investment

d)

establishing an enterprisewide risk management process