
Certified Information Systems Auditor
Domain 1Objective 1
Audit Frameworks and Standards CISA Practice Questions (Page 2)
Part of the Information Systems Auditing Process domain, which accounts for 18% of the CISA exam.
28questions here
6free pages
6concepts
18%of the exam
Questions 6–10
- 6
An IS auditor is planning a compliance audit of a healthcare organization's patient data handling practices. The organization uses a third-party cloud provider for data storage. The auditor must ensure the audit meets ISACA IS Audit Standards. Which approach best addresses the standards' requirements while considering the third-party environment?
Select an answer first - 7
During an audit of a software development company, an IS auditor discovers that the lead developer is a close personal friend. The auditor is concerned that this relationship could impair objectivity. According to the ISACA Code of Professional Ethics, what is the most appropriate course of action?
Select an answer first - 8
What is the primary purpose of a risk assessment in an IS audit context?
Select an answer first - 9
An IS auditor is planning an operational audit of a manufacturing company's inventory management process. The audit committee has asked the auditor to ensure the engagement is conducted with the same rigor as a financial statement audit. Which action best aligns the operational audit with ISACA IS Audit Standards?
Select an answer first - 10
An IS auditor is engaged to evaluate whether a hospital's patient record system complies with the Health Insurance Portability and Accountability Act (HIPAA) and also to assess the operational efficiency of the system's backup procedures. Which type of audit is the auditor performing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.