ISACA CISA — Certified Information Systems Auditor · Difficulty

Hard CISA practice questions

Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 11 hard questions available — no sign-up, always free.

Question 1 of 11

An IS auditor is testing whether user access requests are properly approved before provisioning. Using attribute sampling, the auditor sets a tolerable deviation rate of 5% and tests 60 access requests. The auditor finds 4 requests that were provisioned without documented approval, yielding a sample deviation rate of 6.67%. What is the auditor's MOST appropriate next step?

Reviewed for accuracy · Report an issue
Question 2 of 11

During a review of a high-volume transaction processing system, an IS auditor notes that users frequently report intermittent transaction timeouts during peak business hours. The DBA team confirms that database CPU and memory utilization remain well within thresholds during these periods. Which of the following is the MOST likely cause the auditor should recommend investigating first?

Reviewed for accuracy · Report an issue
Question 3 of 11

An organization wants to protect the confidentiality of sensitive emails sent to external business partners. IT proposes encrypting all outbound messages using the sender's own private key so recipients can verify the origin. As the IS auditor, what is your PRIMARY concern with this proposed approach?

Reviewed for accuracy · Report an issue
Question 4 of 11

An IS auditor reviewing the IT service desk notes that the team has recently improved its first-call resolution (FCR) rate from 62% to 91% over one quarter, which management presents as a major service improvement. However, the auditor observes that repeat incident volume and the number of tickets reopened within 48 hours have both increased during the same period. What should the auditor conclude?

Reviewed for accuracy · Report an issue
Question 5 of 11

During a review of an enterprise single sign-on deployment that uses Kerberos, an IS auditor wants to determine which control most directly prevents an attacker who has captured a valid authentication ticket from re-submitting it later to gain access. Which control should the auditor verify is functioning correctly?

Reviewed for accuracy · Report an issue
Question 6 of 11

A critical zero-day vulnerability affecting an internet-facing application server has been publicly disclosed, and an active exploit is circulating. The vendor has released an emergency patch. During a review of the organization's response, an IS auditor notes that the operations team deployed the patch directly to production within hours, bypassing the normal test cycle, but did complete a documented emergency change request approved by the change advisory board on-call authority. What should the auditor conclude?

Reviewed for accuracy · Report an issue
Question 7 of 11

An IS auditor is testing a population of 8,000 accounts payable transactions to detect whether the total dollar value of the balance is materially overstated. Larger-value transactions carry greater potential for material misstatement, and the auditor wants transactions with higher monetary amounts to have a proportionally greater chance of selection. Which sampling method is MOST appropriate?

Reviewed for accuracy · Report an issue
Question 8 of 11

During the development of a new customer portal, the project team decides to integrate with a 20-year-old core banking system using screen-scraping because the legacy system has no documented APIs. An IS auditor reviewing the design should be MOST concerned that this approach:

Reviewed for accuracy · Report an issue
Question 9 of 11

An IS auditor is reviewing an outsourcing arrangement in which a cloud provider hosts a critical customer-facing application. The signed contract specifies a 99.9% monthly availability target and defines financial service credits payable to the organization if the target is missed. During the review, the auditor notes that the organization relies entirely on the provider's self-reported availability figures and receives only a quarterly summary report. Which of the following is the auditor's GREATEST concern?

Reviewed for accuracy · Report an issue
Question 10 of 11

An IS auditor is reviewing an SLA between an organization and its primary cloud hosting provider. The SLA commits the provider to 99.9% availability. During the review, the auditor learns that the provider relies on a third-party network carrier for connectivity but has no formal underpinning agreement with that carrier guaranteeing comparable service levels. Which of the following is the auditor's GREATEST concern?

Reviewed for accuracy · Report an issue
Question 11 of 11

An IS auditor is reviewing a backup storage environment that uses data deduplication to reduce storage consumption across multiple daily backups. During the review, the auditor notes that all backup jobs write to a single deduplication appliance located in the primary data center, and no copies are replicated elsewhere. Which of the following represents the GREATEST concern with this configuration?

Reviewed for accuracy · Report an issue