ISACA CISA — Certified Information Systems Auditor · Domain 1 · 18% of exam

Information System Auditing Process

Drill 20 practice questions focused entirely on Information System Auditing Process for the ISACA CISA exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A newly appointed IS audit manager discovers that the internal audit function has been operating without a formally approved audit charter for the past two years. The manager wants to establish the charter's authority appropriately. To BEST ensure the audit function's independence and organizational authority, who should approve the audit charter?

Reviewed for accuracy · Report an issue
Question 2 of 20

During a review of an organization's purchase-to-pay process, an IS auditor gains read-only access to the complete general ledger and accounts payable transaction files for the fiscal year. Rather than selecting a statistical sample, the auditor decides to use data analytics software to test 100% of the transactions for duplicate payments, split purchase orders below approval thresholds, and payments to vendors not in the approved master file. What is the PRIMARY advantage of this approach compared to traditional sampling?

Reviewed for accuracy · Report an issue
Question 3 of 20

During a fraud investigation, an IS auditor collects log files and a copy of a suspect employee's hard drive as potential evidence for possible legal proceedings. To ensure the evidence will be admissible and defensible, which action is MOST important for the auditor to perform?

Reviewed for accuracy · Report an issue
Question 4 of 20

During an audit of a data center's physical access controls, an IS auditor observes badge-reader operation for one hour on the day of the visit and notes that all entries required a valid badge. The auditor plans to conclude that access controls operated effectively throughout the entire audit period. What is the MOST significant limitation of relying on this observation as audit evidence?

Reviewed for accuracy · Report an issue
Question 5 of 20

During a review of a company's procurement process, an IS auditor is evaluating several pieces of evidence to support a finding about unauthorized purchase orders. The auditor has collected: (1) a system-generated exception report produced by the auditor using the ERP database, (2) a verbal confirmation from the procurement manager, (3) a screenshot of the approval screen emailed by an accounts payable clerk, and (4) a signed policy document provided by the vendor. Which piece of evidence should the auditor consider MOST reliable?

Reviewed for accuracy · Report an issue
Question 6 of 20

During an information systems audit, a senior auditor completes the fieldwork and drafts preliminary conclusions on the effectiveness of change management controls. Before the findings are consolidated into the report, what should the audit manager do FIRST to comply with ISACA's audit and assurance standards regarding supervision?

Reviewed for accuracy · Report an issue
Question 7 of 20

Six months after issuing a report on weaknesses in the change management process, an IS auditor is preparing to conduct follow-up activities. Management previously committed to implementing a formal change approval workflow and provided a memo stating the workflow is now 'fully operational.' What is the auditor's MOST appropriate next step?

Reviewed for accuracy · Report an issue
Question 8 of 20

An IS auditor is assigned to audit the change management process for a core banking application. Two years ago, before joining the internal audit department, this same auditor served as the lead administrator responsible for configuring and approving changes to that exact application. What is the MOST appropriate action for the audit manager to take?

Reviewed for accuracy · Report an issue
Question 9 of 20

During an audit of the change management process, an IS auditor interviews the change manager, who states that all emergency changes are reviewed and approved by the Change Advisory Board (CAB) within 48 hours after implementation. What should the auditor do NEXT to support a conclusion on this control?

Reviewed for accuracy · Report an issue
Question 10 of 20

During the planning phase of an audit of a payroll application, an IS auditor must decide how much emphasis to place on various control areas. Several minor configuration weaknesses exist, but the auditor is concerned about errors that could significantly affect the accuracy of reported payroll expense. Which concept should MOST guide the auditor in deciding where to focus audit effort?

Reviewed for accuracy · Report an issue
Question 11 of 20

An IS auditor has been assigned to audit a newly implemented procurement application that the audit team has never reviewed before. Before defining the detailed audit scope and objectives, which activity should the auditor perform FIRST?

Reviewed for accuracy · Report an issue
Question 12 of 20

Midway through an IS audit of a payroll application, the auditor discovers that the business has quietly added a new self-service module that was not part of the approved audit scope. Testing this module would require significant additional hours that were not budgeted, and management is now pressing for the module to be included because of recent errors it produced. What is the auditor's BEST course of action?

Reviewed for accuracy · Report an issue
Question 13 of 20

An IS audit department has completed several engagements over the past year. Management wants to establish a quality assurance and improvement program (QAIP) to ensure the audit function conforms to professional standards and continuously improves. Which of the following would BEST provide independent assurance about the overall quality of the audit function?

Reviewed for accuracy · Report an issue
Question 14 of 20

An IS auditor has completed fieldwork on a review of the organization's identity and access management processes. Several control weaknesses were identified, some highly technical (e.g., misconfigured LDAP bind accounts) and some governance-related (e.g., no periodic access recertification). The auditor is preparing to communicate the results to the audit committee, which is composed primarily of non-technical board members. What should the auditor do FIRST when structuring the report for this audience?

Reviewed for accuracy · Report an issue
Question 15 of 20

An IS auditor is testing whether user access requests are properly approved before provisioning. Using attribute sampling, the auditor sets a tolerable deviation rate of 5% and tests 60 access requests. The auditor finds 4 requests that were provisioned without documented approval, yielding a sample deviation rate of 6.67%. What is the auditor's MOST appropriate next step?

Reviewed for accuracy · Report an issue
Question 16 of 20

During execution of a purchasing controls audit, an IS auditor decides not to use statistical sampling. Instead, the auditor deliberately selects the 30 highest-dollar purchase orders plus all transactions processed during the year-end weekend when a temporary employee had elevated access. Which statement BEST describes a key limitation the auditor must acknowledge when using this approach?

Reviewed for accuracy · Report an issue
Question 17 of 20

An IS auditor is testing the accuracy of dollar amounts recorded in a company's accounts payable subledger. The auditor wants to estimate the total monetary error present in the population balance rather than simply count how many transactions deviate from a control. Which sampling approach is MOST appropriate for this objective?

Reviewed for accuracy · Report an issue
Question 18 of 20

During an engagement, a junior IS auditor argues that an ISACA IT Audit Guideline should be applied exactly as written because 'it is required.' The audit manager reviews the situation and finds that following the guideline as written would not fit the specific technical environment being audited. According to ISACA's framework for IT audit and assurance, how should the manager characterize the applicability of ISACA Guidelines versus Standards?

Reviewed for accuracy · Report an issue
Question 19 of 20

During a quality review of a completed IT operations audit, a reviewer notices that one of the audit conclusions states the change management process is 'operating effectively,' but the associated workpaper contains only the auditor's narrative summary of an interview with the change manager. No test results, samples, or supporting artifacts are referenced. What is the reviewer's MOST significant concern regarding this workpaper?

Reviewed for accuracy · Report an issue
Question 20 of 20

During the planning phase, an IS auditor is asked to recommend an approach that will allow management to identify control breakdowns in the accounts payable system as transactions are processed, rather than waiting for a scheduled annual audit. Which approach should the auditor recommend?

Reviewed for accuracy · Report an issue

More CISA practice

Keep going with the other ISACA CISA — Certified Information Systems Auditor domains, or take a full timed mock exam.

← Back to CISA overview