
Certified Information Systems Auditor
Domain 1Objective 2
Audit Planning and Risk Assessment CISA Practice Questions (Page 3)
Part of the Information Systems Auditing Process domain, which accounts for 18% of the CISA exam.
34questions here
7free pages
10concepts
18%of the exam
Questions 11–15
- 11
What is a control gap?
Select an answer first - 12
During the planning phase of an audit of a new customer relationship management (CRM) system, the auditor reviews the control design documentation. The documentation indicates that the system has a control to restrict access to customer data based on job role. However, the auditor discovers that the control is not configured to enforce segregation of duties for sales representatives who can both create and approve discounts. What should the auditor do NEXT?
Select an answer first - 13
Which factor is most important when prioritizing audit engagements?
Select an answer first - 14
To whom should audit project status be reported during the audit?
Select an answer first - 15
During an audit of a major system implementation, the audit team discovers that the project is behind schedule due to unexpected technical issues. The audit manager needs to communicate this to stakeholders. Which of the following is the MOST appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.