CISA DOMAIN 2 PRACTICE
EXAM 27 QUESTIONS
Question 1: An IS auditor is reviewing a proposed cloud service that will store
customer information in several countries. What should the auditor recommend
FIRST?
Choices:
1) Conrm that the provider has an annual penetration test 2) Identify applicable legal and regulatory requirements for the planned data ows 3) Require the provider to use the same security tools as the organization 4) Compare the provider's fees with domestic hosting costs Correct Answer: Identify applicable legal and regulatory requirements for the planned data ows Explanation: The rst step is to identify which laws, regulations, contractual obligations, and data-transfer restrictions apply to the proposed processing locations and data ows. Control design and vendor requirements should then be evaluated against those obligations.Page 1
Question 2: A company policy permits a practice that is prohibited by an applicable regulation. Which requirement should govern the activity?
Choices:
1) The company policy because it was approved by management 2) The practice commonly followed by peer organizations 3) The applicable regulation 4) The least costly control alternative
Correct Answer: The applicable regulation
Explanation: External legal and regulatory requirements take precedence over internal policy.Management should revise the policy and related procedures so they do not authorize activity that violates a binding requirement.
Question 3: Which approach BEST helps management demonstrate that IT controls
address multiple overlapping regulatory and industry requirements?
Choices:
1) Maintain separate technical environments for each requirement 2) Map each obligation to common control objectives and evidence 3) Allow each business unit to dene its own compliance terminology 4) Test only the controls associated with the strictest requirement
Correct Answer: Map each obligation to common control objectives and evidence
Explanation: A control-mapping or compliance-mapping approach links laws, regulations, standards, and contractual obligations to common controls and evidence. This reduces duplication while showing how each requirement is addressed.Page 2
Question 4: Who is ultimately accountable for ensuring that enterprise IT
governance supports organizational objectives?
Choices:
1) The chief information ocer 2) The internal audit director 3) The board of directors 4) The IT operations manager
Correct Answer: The board of directors
Explanation: The board has ultimate accountability for governance and oversight, including ensuring that information and technology support enterprise objectives and that related risk and value are appropriately governed. Management executes the direction established by governance.Question 5: An IS auditor is evaluating whether the IT strategy is aligned with the business strategy. Which evidence would be MOST persuasive?
Choices:
1) The IT department has a three-year technology roadmap 2) IT objectives are explicitly mapped to business objectives with approved measures and investment priorities 3) The CIO attends monthly technology vendor briengs 4) The IT budget increased at the same rate as corporate revenue Correct Answer: IT objectives are explicitly mapped to business objectives with approved measures and investment priorities Explanation: Alignment is best demonstrated when IT objectives, investments, and measures can be traced directly to business objectives and priorities. A roadmap or budget alone does not prove that technology activities support enterprise strategy.Page 3