
Certified Information Systems Auditor
Domain 1Objective 1
Audit Frameworks and Standards CISA Practice Questions (Page 6)
Part of the Information Systems Auditing Process domain, which accounts for 18% of the CISA exam.
28questions here
6free pages
6concepts
18%of the exam
Questions 26–28
- 26
An IS auditor is asked to identify and prioritize potential threats to a company's new e-commerce application. The auditor uses a structured approach to evaluate the likelihood and impact of various threats and vulnerabilities. Which type of assessment is the auditor performing?
Select an answer first - 27
An IS auditor is asked to determine whether the existing access control measures in a payroll system are sufficient to prevent unauthorized changes to salary data. The auditor evaluates the design of the controls and tests whether they are working as intended. Which type of assessment is the auditor performing?
Select an answer first - 28
An audit that evaluates both the accuracy of financial statements and the effectiveness of internal controls over financial reporting is best described as:
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.