Medium CISA practice questions
Applied — put a concept to work in a realistic situation. 137 medium questions available — no sign-up, always free.
An organization is replacing its core inventory management system. Project management has selected an abrupt (direct) changeover on a weekend, decommissioning the legacy system immediately once the new system goes live. As the IS auditor reviewing the implementation plan, which aspect should raise the GREATEST concern?
During a review of a perimeter firewall, an IS auditor finds that the rule base ends with an explicit 'permit any any' statement placed after several specific deny rules. Which of the following is the auditor's GREATEST concern?
An IS auditor is reviewing an agile software development project. The development team completes sprints every two weeks and demonstrates working features to stakeholders. However, the auditor notices that several completed user stories lacked documented acceptance criteria before development began, and defects related to these stories are frequently found only after release to production. Which of the following is the auditor's BEST recommendation to address the root cause?
A financial analyst needs to send a confidential report to an external business partner and wants to ensure that only that partner can read the message. Both parties have valid PKI certificates. Which key should the analyst use to encrypt the report so that confidentiality is preserved?
A newly appointed IS audit manager discovers that the internal audit function has been operating without a formally approved audit charter for the past two years. The manager wants to establish the charter's authority appropriately. To BEST ensure the audit function's independence and organizational authority, who should approve the audit charter?
During a review of an organization's purchase-to-pay process, an IS auditor gains read-only access to the complete general ledger and accounts payable transaction files for the fiscal year. Rather than selecting a statistical sample, the auditor decides to use data analytics software to test 100% of the transactions for duplicate payments, split purchase orders below approval thresholds, and payments to vendors not in the approved master file. What is the PRIMARY advantage of this approach compared to traditional sampling?
During a fraud investigation, an IS auditor collects log files and a copy of a suspect employee's hard drive as potential evidence for possible legal proceedings. To ensure the evidence will be admissible and defensible, which action is MOST important for the auditor to perform?
During an audit of a data center's physical access controls, an IS auditor observes badge-reader operation for one hour on the day of the visit and notes that all entries required a valid badge. The auditor plans to conclude that access controls operated effectively throughout the entire audit period. What is the MOST significant limitation of relying on this observation as audit evidence?
During a review of a company's procurement process, an IS auditor is evaluating several pieces of evidence to support a finding about unauthorized purchase orders. The auditor has collected: (1) a system-generated exception report produced by the auditor using the ERP database, (2) a verbal confirmation from the procurement manager, (3) a screenshot of the approval screen emailed by an accounts payable clerk, and (4) a signed policy document provided by the vendor. Which piece of evidence should the auditor consider MOST reliable?
During an information systems audit, a senior auditor completes the fieldwork and drafts preliminary conclusions on the effectiveness of change management controls. Before the findings are consolidated into the report, what should the audit manager do FIRST to comply with ISACA's audit and assurance standards regarding supervision?
Six months after issuing a report on weaknesses in the change management process, an IS auditor is preparing to conduct follow-up activities. Management previously committed to implementing a formal change approval workflow and provided a memo stating the workflow is now 'fully operational.' What is the auditor's MOST appropriate next step?
An IS auditor is assigned to audit the change management process for a core banking application. Two years ago, before joining the internal audit department, this same auditor served as the lead administrator responsible for configuring and approving changes to that exact application. What is the MOST appropriate action for the audit manager to take?
During an audit of the change management process, an IS auditor interviews the change manager, who states that all emergency changes are reviewed and approved by the Change Advisory Board (CAB) within 48 hours after implementation. What should the auditor do NEXT to support a conclusion on this control?
During the planning phase of an audit of a payroll application, an IS auditor must decide how much emphasis to place on various control areas. Several minor configuration weaknesses exist, but the auditor is concerned about errors that could significantly affect the accuracy of reported payroll expense. Which concept should MOST guide the auditor in deciding where to focus audit effort?
An IS auditor has been assigned to audit a newly implemented procurement application that the audit team has never reviewed before. Before defining the detailed audit scope and objectives, which activity should the auditor perform FIRST?
Midway through an IS audit of a payroll application, the auditor discovers that the business has quietly added a new self-service module that was not part of the approved audit scope. Testing this module would require significant additional hours that were not budgeted, and management is now pressing for the module to be included because of recent errors it produced. What is the auditor's BEST course of action?
An IS audit department has completed several engagements over the past year. Management wants to establish a quality assurance and improvement program (QAIP) to ensure the audit function conforms to professional standards and continuously improves. Which of the following would BEST provide independent assurance about the overall quality of the audit function?
An IS auditor has completed fieldwork on a review of the organization's identity and access management processes. Several control weaknesses were identified, some highly technical (e.g., misconfigured LDAP bind accounts) and some governance-related (e.g., no periodic access recertification). The auditor is preparing to communicate the results to the audit committee, which is composed primarily of non-technical board members. What should the auditor do FIRST when structuring the report for this audience?
During execution of a purchasing controls audit, an IS auditor decides not to use statistical sampling. Instead, the auditor deliberately selects the 30 highest-dollar purchase orders plus all transactions processed during the year-end weekend when a temporary employee had elevated access. Which statement BEST describes a key limitation the auditor must acknowledge when using this approach?
An IS auditor is testing the accuracy of dollar amounts recorded in a company's accounts payable subledger. The auditor wants to estimate the total monetary error present in the population balance rather than simply count how many transactions deviate from a control. Which sampling approach is MOST appropriate for this objective?
During an engagement, a junior IS auditor argues that an ISACA IT Audit Guideline should be applied exactly as written because 'it is required.' The audit manager reviews the situation and finds that following the guideline as written would not fit the specific technical environment being audited. According to ISACA's framework for IT audit and assurance, how should the manager characterize the applicability of ISACA Guidelines versus Standards?
During a quality review of a completed IT operations audit, a reviewer notices that one of the audit conclusions states the change management process is 'operating effectively,' but the associated workpaper contains only the auditor's narrative summary of an interview with the change manager. No test results, samples, or supporting artifacts are referenced. What is the reviewer's MOST significant concern regarding this workpaper?
During an audit of a company's disaster recovery arrangements, the IS auditor confirms that full backups are performed nightly and encrypted copies are shipped to an offsite vault daily. Backup completion logs show no failures for the past 12 months. Which of the following should be the auditor's GREATEST concern?
During a review of nightly batch operations, an IS auditor notes that the overnight processing window has begun to overrun into online business hours, delaying transaction availability for morning users. Data volumes have grown 40% over the past year, but the job schedule and hardware have not changed. What should the auditor recommend as the MOST appropriate first action?
An IS auditor reviewing an enterprise's IT performance monitoring program notes that management measures internal metrics such as help desk ticket resolution time and server uptime, and reports steady year-over-year improvement. However, business units continue to complain that IT service quality lags behind competitors. Which action would BEST enable management to determine whether IT performance is genuinely competitive?