Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 1Objective 2

Audit Planning and Risk Assessment CISA Practice Questions (Page 5)

Part of the Information Systems Auditing Process domain, which accounts for 18% of the CISA exam.

34questions here
7free pages
10concepts
18%of the exam

Questions 21–25

  1. 21foundation · easy

    Which risk assessment technique uses a matrix to plot the likelihood and impact of risks?

    Select an answer first
  2. 22foundation · easy

    Which step is typically the first in the risk-based audit planning process?

    Select an answer first
  3. 23foundation · easy

    What is the primary purpose of an audit program?

    Select an answer first
  4. 24application · medium

    A multinational company is building its annual IT audit plan. The audit committee wants to ensure that limited audit resources are directed to the areas of greatest potential impact. The company has a new cloud-based customer relationship management (CRM) system that processes credit card payments, a legacy on-premises payroll system scheduled for decommissioning next year, and a recently implemented network segmentation project. Which of the following is the BEST approach for prioritizing these audit areas?

    Select an answer first
  5. 25application · medium

    An auditor is developing an audit program for a review of the change management process for a critical application. The audit objective is to determine whether changes are authorized, tested, and approved before implementation. Which of the following procedures should be included in the audit program?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.