ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 51 )

Updated On: 28-Feb-2026

While planning a review of IT governance, the IS auditor is MOST likely to:

  1. obtain information about the framework of control adopted by management.
  2. examine audit committee minutes for IS-related matters and their control.
  3. assess whether business process owner responsibilities are consistent across the organization.
  4. review compliance with policies and procedures issued by the board of directors.

Answer(s): A



Many departments of an organization have not implemented audit recommendations by their agreed upon target dates. Who should address this situation?

  1. Head of internal audit
  2. External auditor
  3. Department managers
  4. Senior management

Answer(s): D



An advantage of object-oriented system development is that it:

  1. is easier to code than procedural languages.
  2. partitions systems into a client/server architecture.
  3. decreases the need for system documentation.
  4. is suited to data with complex relationships.

Answer(s): D



Which of the following MUST be completed as part of the annual audit planning process?

  1. Fieldwork
  2. Risk control matrix
  3. Risk assessment
  4. Business impact analysis (BIA)

Answer(s): C



Code changes are compiled and placed in a change folder by the developer. An implementation team migrates changes to production from the change folder.
Which of the following BEST indicates separation of duties is in place during the migration process?

  1. A second individual performs code review before the change is released to production.
  2. The implementation team does not have access to change the source code.
  3. The implementation team does not have experience writing code.
  4. The developer approves changes prior to moving them to the change folder.

Answer(s): B






Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

Join the CISA Discussion