ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 40 )

Updated On: 27-Feb-2026

During an audit of an organization's financial statements, an IS auditor finds that the IT general controls are deficient. What should the IS auditor recommend?

  1. Increase the compliance testing of the application controls.
  2. Place greater reliance on the application controls.
  3. Increase the substantive testing of the financial balances.
  4. Place greater reliance on the framework of control.

Answer(s): C



An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?

  1. Configure users on the mobile device management (MDM) solution.
  2. Create inventory records of personal devices.
  3. Implement an acceptable use policy.
  4. Conduct security awareness training.

Answer(s): C



During an incident management audit, an IS auditor finds that several similar incidents were logged during the audit period. Which of the following is the auditor's
MOST important course of action?

  1. Document the finding and present it to management.
  2. Determine if a root cause analysis was conducted.
  3. Validate whether all incidents have been actioned.
  4. Confirm the resolution time of the incidents.

Answer(s): B



Stress testing should ideally be carried out under a:

  1. test environment with test data.
  2. production environment with test data.
  3. test environment with production workloads.
  4. production environment with production workloads.

Answer(s): C



An audit of environmental controls at a data center could include a review of the:

  1. local alarms on emergency exits.
  2. logs recording visitors to the data center.
  3. list of employees authorized to enter the data center.
  4. ceiling space to ensure that there are no wet pipes.

Answer(s): D






Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

Join the CISA Discussion