Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 1Objective 2

Audit Planning and Risk Assessment CISA Practice Questions (Page 4)

Part of the Information Systems Auditing Process domain, which accounts for 18% of the CISA exam.

34questions here
7free pages
10concepts
18%of the exam

Questions 16–20

  1. 16foundation · easy

    What is the primary purpose of risk-based audit planning?

    Select an answer first
  2. 17expert · hard

    An IT audit manager is developing the annual audit plan. The organization has a high-risk legacy system that is scheduled for decommissioning in six months, but it still processes financial transactions. The audit committee has requested that the audit plan focus on emerging risks, including a new cloud migration project. The audit team has limited resources. Which of the following is the BEST approach to balance these priorities?

    Select an answer first
  3. 18expert · hard

    An auditor is developing an audit program for a review of a new customer relationship management (CRM) system. The audit objective is to ensure that customer data is protected from unauthorized access. The system has role-based access control, but the auditor is concerned about segregation of duties for users who can both create and approve discounts. Which of the following is the MOST appropriate procedure to include in the audit program?

    Select an answer first
  4. 19foundation · easy

    Which of the following is a key component of audit project management?

    Select an answer first
  5. 20foundation · easy

    Which control classification is most likely to be tested by inspecting configuration settings?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.