ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 17 )

Updated On: 24-Feb-2026

An IS auditor is following up on prior period items and finds management did not address an audit finding. Which of the following should be the IS auditor's NEXT course of action?

  1. Note the exception in a new report as the item was not addressed by management.
  2. Interview management to determine why the finding was not addressed.
  3. Recommend alternative solutions to address the repeat finding.
  4. Conduct a risk assessment of the repeat finding.

Answer(s): B



The PRIMARY focus of a post-implementation review is to verify that:

  1. enterprise architecture (EA) has been complied with.
  2. user requirements have been met.
  3. acceptance testing has been properly executed.
  4. user access controls have been adequately designed.

Answer(s): B



Which of the following BEST protects an organization's proprietary code during a joint-development activity involving a third party?

  1. Privacy agreement
  2. Statement of work (SOW)
  3. Nondisclosure agreement (NDA)
  4. Service level agreement (SLA)

Answer(s): C



During which process is regression testing MOST commonly used?

  1. Unit testing
  2. System modification
  3. Stress testing
  4. Program development

Answer(s): B



Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?

  1. Business units are allowed to dispose printers directly to authorized vendors.
  2. Inoperable printers are stored in an unsecured area.
  3. Disposal policies and procedures are not consistently implemented.
  4. Evidence is not available to verify printer hard drives have been sanitized prior to disposal.

Answer(s): D






Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

Join the CISA Discussion