Test your IS audit Knowledge

These questions, answers and explanations are intended to introduce potential CISA candidates to the types of questions that have appeared on past CISA examinations. They are not actual questions from the exam, but have been developed as an educational resource to assist candidates to understand the structure of questions typically found on the examination. A representative number of questions from each of the CISA job areas are included to provide a sample of the subject matter covered on the CISA examination. These items have been selected from CISA Review, Answers & Explanation Manuals published by ISACA (see below).

Additional questions are available in the CISA Review, Answers & Explanations Manual 2005 and the CISA Review Questions, Answers & Explanations 2005 Supplement. These two publications collectively consist of 650 multiple choice questions and sample tests. The same 650 questions can be found on the CISA Reviews, Answers & Explanations CD-ROM 2005. These resources are available for purchase through the ISACA Bookstore.

After you answer all the questions, simply select "Check My Score".


1. P1-1 Corrective action has been taken by an auditee immediately after the identification of a reportable finding. The auditor should:

A. include the finding in the final report because the IS auditor is responsible for an accurate report of all findings.
B. not include the finding in the final report because the audit report should include only unresolved findings.
C. not include the finding in the final report because corrective action can be verified by the IS auditor during the audit.
D. include the finding in the closing meeting for discussion purposes only.

2. P1-2 In a risk-based audit approach, an IS auditor, in addition to risk, would be influenced by:

A. the availability of CAATs.
B. management's representation.
C. organizational structure and job responsibilities.
D. the existence of internal and operational controls

3. P1-3 The PRIMARY advantage of a continuous audit approach is that it:

A. does not require an IS auditor to collect evidence on system reliability while processing is taking place.
B. requires the IS auditor to review and follow up immediately on all information collected.
C. can improve system security when used in time-sharing environments that process a large number of transactions.
D. does not depend on the complexity of an organization's computer systems.

4. C1-1 Which of the following is the GREATEST risk of an inadequate policy definition for ownership of data and systems?

A. User management coordination does not exist.
B. Specific user accountability cannot be established.
C. Unauthorized users may have access to originate, modify or delete data.
D. Audit recommendations may not be implemented.

5. C1-2 IT control objectives are useful to IS auditors, as they provide the basis for understanding the:

A. desired result or purpose of implementing specific control procedures.
B. best IT security control practices relevant to a specific entity.
C. techniques for securing information.
D. security policy.

6. C1-3 In reviewing the IS short-range (tactical) plan, the IS auditor should determine whether:

A. there is an integration of IS and business staffs within projects.
B. there is a clear definition of the IS mission and vision.
C. there is a strategic information technology planning methodology in place.
D. the plan correlates business objectives to IS goals and objectives.

7. C2-1 An IS auditor is performing a network security review of a telecom company that provides Internet connection services to shopping malls for their wireless customers. The company uses wireless transport layer security (WTLS) and secure socket layers (SSL) technology for protecting their customer's payment information. The IS auditor should be MOST concerned, if a hacker:

A. compromised the wireless application protocol (WAP) gateway.
B. installed a sniffing program in front of the server.
C. stole a customer's PDA.
D. listened to the wireless transmission.

8. C2-2 An IS auditor is performing an audit of a network operating system. Which of the following is a user feature the IS auditor should review?

A. Availability of online network documentation
B. Support of terminal access to remote hosts
C. Handling file transfer between hosts and interuser communications
D. Performance management, audit and control

9. C2-3 An organization provides information to its supply-chain partners and customers through an extranet infrastructure. Which of the following should be the GREATEST concern to an IS auditor reviewing the firewall security architecture?

A. A secure sockets layer (SSL) has been implemented for user authentication and remote administration of the firewall.
B. On the basis of changing requirements, firewall policies are updated.
C. Inbound traffic is blocked unless the traffic type and connections have been specifically permitted.
D. The firewall is placed on top of the commercial operating system with all installation options.

10. C3-1 Which of the following cryptography options would increase overhead/cost?

A. The encryption is symmetric rather than asymmetric.
B. A long asymmetric encryption key is used.
C. The hash is encrypted rather than the message.
D. A secret key is used.

11. C3-2 Which of the following acts as a decoy to detect active Internet attacks?

A. Honeypots
B. Firewalls
C. Trapdoors
D. Traffic analysis

12. C3-3 Which of the following is the MOST effective control when granting temporary access to vendors?

A. Vendor access corresponds to the service level agreement (SLA).
B. User accounts are created with expiration dates and are based on services provided.
C. Administrator access is provided for a limited period.
D. User IDs are deleted when the work is completed.

13. C3-4 A certifying authority (CA) can delegate the processes of:

A. revocation and suspension of a subscriber's certificate.
B. generation and distribution of the CA public key.
C. establishing a link between the requesting entity and its public key.
D. issuing and distributing subscriber certificates.

14. C3-5 An organization with extremely high security requirements is evaluating the effectiveness of biometric systems. Which of the following performance indicators is MOST important?

A. False-acceptance rate (FAR)
B. Equal-error rate (EER)
C. False-rejection rate (FRR)
D. False-identification rate (FIR)

15. C4-1 To develop a successful business continuity plan, end-user involvement is critical during which of the following phases?

A. Business recovery strategy
B. Detailed plan development
C. Business impact analysis (BIA)
D. Testing and maintenance

16. C4-2 As updates to an online order entry system are processed, the updates are recorded on a transaction tape and a hard copy transaction log. At the end of the day, the order entry files are backed up on tape. During the backup procedure, a drive malfunctions and the order entry files are lost. Which of the following are necessary to restore these files?

A. The previous day's backup file and the current transaction tape
B. The previous day's transaction file and the current transaction tape
C. The current transaction tape and the current hard copy transaction log
D. The current hard copy transaction log and the previous day's transaction file

17. C4-3 While designing the business continuity plan (BCP) for an airline reservation system, the MOST appropriate method of data transfer/backup at an offsite location would be:

A. shadow file processing.
B. electronic vaulting.
C. hard-disk mirroring.
D. hot-site provisioning.

18. C5-1 Which of the following types of testing would determine whether a new or modified system can operate in its target environment without adversely impacting other existing systems?

A. Parallel testing
B. Pilot testing
C. Interface/integration testing
D. Sociability testing

19. C5-2 Which of the following risks could result from inadequate software baselining?

A.Scope creep
B.Sign-off delays
C. Software integrity violations
D. Inadequate controls

20. C5-3 A programmer, using firecall IDs, as provided in the manufacture's manual, gained access to the production environment and made an unauthorized change. Which of the following could have prevented this from happening?

A. Deactivation
B. Monitoring
C. Authorization
D. Resetting

21. C5-4 Which of the following is a dynamic analysis tool for the purpose of testing software modules?

A. Black box test
B. Desk checking
C. Structured walk-through
D. Design and code

22. C6-1 Online banking transactions are being posted to the database when processing suddenly comes to a halt. The integrity of the transaction processing is BEST ensured by:

A. database integrity checks.
B. validation checks.
C.input controls.
D. database commits and rollbacks.

23. C6-2 A retail company recently installed data warehousing client software at geographically diverse sites. Due to time zone differences between the sites, updates to the warehouse are not synchronized. Which of the following will be affected the MOST?

A. Data availability
B. Data completeness
C. Data redundancy
D. Data inaccuracy

24. C6-3 An IS auditor reviewing database controls discovered that changes to the database during normal working hours were handled through a standard set of procedures. However, changes made after normal hours required only an abbreviated number of steps. In this situation, which of the following would be considered an adequate set of compensating controls?

A. Allow changes to be made only with the DBA user account.
B. Make changes to the database after granting access to a normal user account
C. Use the DBA user account to make changes, log the changes and review the change log the following day.
D.Use the normal user account to make changes, log the changes and review the change log the following day.

25. C6-4 Which of the following represents the GREATEST potential risk in an EDI environment?

A. Transaction authorization
B. Loss or duplication of EDI transmissions
C. Transmission delay
D. Deletion or manipulation of transactions prior to or after establishment of application controls

Top | Certification | Bookstore | Home

Copyright © 2005 Information Systems Audit and Control Association (ISACA®) All rights reserved 3701 Algonquin Road, Suite 1010, Rolling Meadows, Illinois 60008 USA