CISA DOMAIN 2 PRACTICE
27 QUESTIONS
Question 1: An IS auditor is reviewing a multinational organization's IT compliance framework. Which action should management take FIRST when establishing control requirements?
Choices:
1) Adopt the strictest control from every jurisdiction 2) Identify applicable legal, regulatory, contractual, and industry obligations 3) Implement a single global control framework without exceptions 4) Require each business unit to create its own independent control set Correct Answer: Identify applicable legal, regulatory, contractual, and industry obligations Explanation: Control requirements should be based rst on the obligations that actually apply to the organization. Once legal, regulatory, contractual, and industry requirements are identied, management can map them to a consistent control framework and address jurisdiction-specic dierences.Page 1
Question 2: A company plans to move customer records to a cloud provider in
another country. What should be the IS auditor's GREATEST concern during governance review?
Choices:
1) Whether the provider uses the same project methodology as the company 2) Whether cross-border transfer and data residency requirements have been evaluated 3) Whether the provider's data center is newer than the internal facility 4) Whether the provider oers volume discounts for long-term storage Correct Answer: Whether cross-border transfer and data residency requirements have been evaluated Explanation: Cross-border processing can be restricted by privacy, data residency, or sector- specic requirements. Governance should conrm that the transfer is legally permitted and that required safeguards are in place before operational or cost considerations are accepted.Question 3: Who should be ultimately accountable for ensuring that enterprise IT governance supports organizational objectives?
Choices:
1) The chief information ocer 2) The internal audit director 3) The board and executive leadership acting through the enterprise governance structure 4) The external audit rm Correct Answer: The board and executive leadership acting through the enterprise governance structure Explanation: IT governance is an enterprise responsibility. The board and executive leadership retain ultimate accountability for direction, oversight, value delivery, and risk, even though day- to-day responsibilities may be delegated to IT management.Page 2
Question 4: An IT steering committee receives funding requests for ve major technology initiatives, but resources are insucient to approve all of them. What is the BEST basis for prioritization?
Choices:
1) The order in which project managers submitted requests 2) The technical preferences of the infrastructure team 3) Alignment with business objectives, expected value, risk, and resource constraints 4) Equal funding for every business unit Correct Answer: Alignment with business objectives, expected value, risk, and resource constraints Explanation: A governance body should prioritize investments according to enterprise strategy, expected benets, risk, and available resources. This creates an objective portfolio view rather than allowing timing, politics, or technical preference to drive investment decisions.
Question 5: During an audit, the IT strategic plan contains numerous technology
initiatives but does not identify the business outcomes they are intended to support.What is the MOST signicant concern?
Choices:
1) The plan may not demonstrate alignment between IT investments and enterprise objectives 2) The plan may contain too few technical architecture diagrams 3) The plan may prevent IT from using agile development methods 4) The plan may cause duplicate user accounts Correct Answer: The plan may not demonstrate alignment between IT investments and enterprise objectives Page 3