
Certified Information Systems Auditor
Domain 3Objective 4
Control Identification and Design CISA Practice Questions (Page 5)
Part of the Information Systems Acquisition, Development and Implementation domain, which accounts for 12% of the CISA exam.
28questions here
6free pages
5concepts
12%of the exam
Questions 21–25
- 21
A project team is implementing a new payroll system. They have identified a risk that a payroll administrator could accidentally overpay an employee. The team has implemented a control that requires a second administrator to approve any payroll run before it is processed. How should this control be classified?
Select an answer first - 22
A multinational corporation is implementing a new HR system that will store employee data for all regions. The project team has identified the following risks: (1) unauthorized access to sensitive employee data, (2) data loss due to a natural disaster in one region, and (3) non-compliance with GDPR for EU employees. The team has a limited budget and must choose a set of controls. Which set of controls provides the most comprehensive risk coverage?
Select an answer first - 23
When designing a control to mitigate the risk of unauthorized changes to program code during development, which control design is most effective?
Select an answer first - 24
An organization implements a control that requires two signatures before a purchase order is released. How should this control be classified?
Select an answer first - 25
Which of the following is the primary objective of designing controls for an information systems development project?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.