CISA DOMAIN 1 PRACTICE
EXAM 150 QUESTIONS
Question 1: An IS auditor is assigned to review a cloud migration project after having approved several key design decisions as a project manager six months earlier.What is the auditor's BEST course of action?
Choices:
1) Proceed because the project manager role has ended 2) Disclose the prior involvement and have audit management assess independence 3) Limit testing to areas the auditor did not design 4) Rely only on management representations
Correct Answer: Disclose the prior involvement and have audit management assess
independence Explanation: Prior responsibility for key design decisions can impair objectivity. The auditor should disclose the conict so audit management can determine whether reassignment or safeguards are needed before the engagement proceeds.Page 1
Question 2: What is the PRIMARY purpose of an IS audit charter?
Choices:
1) To set annual security objectives for management 2) To document every control owned by IT 3) To dene the audit function's authority responsibility and accountability 4) To list detailed test steps for each engagement Correct Answer: To dene the audit function's authority responsibility and accountability Explanation: An audit charter formally establishes the purpose, authority, responsibility, and organizational position of the audit function. Detailed procedures belong in engagement work programs rather than the charter.Question 3: An IS auditor discovers a signicant control weakness outside the approved scope that could materially aect nancial reporting. What should the auditor do FIRST?
Choices:
1) Ignore it because it is outside scope 2) Immediately issue a nal audit report 3) Evaluate its signicance and communicate it through appropriate audit channels 4) Expand the audit without informing management Correct Answer: Evaluate its signicance and communicate it through appropriate audit channels Explanation: A potentially material issue should not be ignored. The auditor should rst assess signicance and communicate it to audit management or the appropriate governance level so any scope change or separate work can be authorized.Page 2
Question 4: Which action MOST directly supports an IS auditor's professional
competence requirement?
Choices:
1) Using only automated audit tools 2) Accepting every assignment oered by management 3) Delegating all technical testing to IT sta 4) Maintaining relevant knowledge and skills through continuing professional education Correct Answer: Maintaining relevant knowledge and skills through continuing professional education Explanation: Professional competence requires maintaining knowledge and skills appropriate to assigned work. Continuing professional education helps the auditor remain capable of performing audits using current practices and technologies.Question 5: Management asks an IS auditor to remove a valid high-risk nding because remediation is already planned. What should the auditor do?
Choices:
1) Remove the nding if management promises to x it 2) Retain the nding and accurately describe management's planned corrective action 3) Delay the report until remediation is complete 4) Change the rating to low risk Correct Answer: Retain the nding and accurately describe management's planned corrective action Explanation: An audit report should accurately reect conditions identied during the audit.Planned remediation can be included in management's response, but it does not erase the underlying nding or justify changing its risk rating without evidence.Page 3