
Certified Information Systems Auditor
Domain 1Objective 2
Audit Planning and Risk Assessment CISA Practice Questions (Page 2)
Part of the Information Systems Auditing Process domain, which accounts for 18% of the CISA exam.
34questions here
7free pages
10concepts
18%of the exam
Questions 6–10
- 6
An internal audit department is defining its audit universe for the first time. The organization is a mid-sized manufacturing company with multiple business units, including production, sales, and finance. The audit committee has requested that the audit plan focus on areas that could significantly impact the achievement of organizational objectives. Which of the following is the MOST appropriate first step in defining the audit universe?
Select an answer first - 7
In risk assessment, what does 'likelihood' refer to?
Select an answer first - 8
What is the primary factor in allocating audit resources effectively?
Select an answer first - 9
When allocating audit resources, which team skill is most critical for an audit of a complex IT system?
Select an answer first - 10
An IT audit manager is conducting a risk assessment to prioritize audit engagements for the upcoming year. The organization has recently experienced a ransomware attack that encrypted critical file servers, and management has expressed concern about the effectiveness of backup and recovery procedures. The audit manager needs to evaluate the likelihood and impact of a similar attack recurring. Which technique would be MOST appropriate for this assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.