Certified Information Systems Auditor · every answer carries the reasoning, and why each
other option fails.
2,604 questions
9 chapters of notes
EN + ZH languages
Tap an option to see the answer, the reasoning, and why the other three fail.
Question 1 of 10
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
AThe BCP has not been tested since it was first issued.
BThe BCP is not version-controlled.Lack of version control can lead to the wrong version being used, but the plan itself may still be valid—this is a document management issue that can be corrected quickly.
CThe BCP's contact information needs to be updated.Outdated contact information is a maintenance deficiency that can simply be updated; it does not affect whether the overall design of the plan is workable.
DThe BCP has not been approved by senior management.Missing senior management approval affects the plan's authority and resource commitment—a governance flaw. A plan that has been approved but never tested is equally unreliable.
Why A is correct
The value of a BCP can only be proven through testing. A plan that has never been rehearsed has all of its assumptions—staff arrival times, alternate site capacity, recovery sequencing—unverified, and it will most likely fail when an actual disaster occurs. This is a case of "a control exists but its effectiveness is unknown," which is exactly what an auditor should be most concerned about. Lack of version control, outdated contact information, and missing senior management approval are all documentation governance deficiencies that can be corrected, but none of them reduce the plan's overall reliability to zero the way "never tested" does.
Question 2 of 10
Which of the following would be of GREATEST concern to an IS auditor conducting an audit of an organization's network security with the focus of preventing system breaches?
AComputer names are available to the Internet.Computer names being visible to the internet constitutes information disclosure, useful to attackers for asset mapping, but it does not itself constitute a means of breach.
BThe data loss prevention (DLP) system does not monitor malicious incoming traffic.
CHelp desk personnel are able to remote into other external systems.Help desk personnel remoting into external systems is an outbound access control issue, a different risk direction from preventing system breaches.
DThe guest wireless system does not have content filtering.Lack of content filtering on the guest wireless affects the guest network, which is typically segregated from the internal core network.
Why B is correct
The focus of this audit is preventing system breaches, and a breach necessarily originates from incoming malicious traffic. That the organization's data loss prevention (DLP) system does not monitor incoming malicious traffic means the most critical path lacks detection and blocking capability, allowing an attack to proceed unimpeded and unnoticed. Exposed computer names constitute information disclosure, while help desk personnel remoting into external systems and the guest wireless lacking content filtering do not directly constitute a breach path into core systems.
Question 3 of 10
An IS auditor is reviewing documentation from a change that was applied to an application. Which of the following findings would be the GREATEST concern?
ATesting documentation is approved prior to completion of user acceptance testing (UAT).
BTesting documentation does not show manager approval.Testing documentation lacking manager approval is a missing sign-off record that needs to be remedied, but the testing itself may already be fully complete.
CTesting documentation is kept in hard copy format.Keeping testing documentation in hard-copy format is merely a choice of medium and does not affect the evidence's validity.
DTesting documentation is dated three weeks before the system implementation date.Testing documentation dated three weeks before implementation is a normal scheduling arrangement, since testing should be completed before go-live anyway.
Why A is correct
Testing documentation being approved before user acceptance testing is complete means the person signing off did so without complete test results — the "pass" evidence is logically unfounded, and the entire testing gatekeeping process becomes a formality. This is the most substantive deficiency at the documentation level. Missing manager sign-off, hard-copy storage, and documentation dated three weeks before implementation are all formatting or scheduling matters.
Question 4 of 10
What is the MOST critical finding when reviewing an organization's information security management?
ANo official charter for the information security management system
BNo employee awareness training and education programLack of employee awareness training and education is a deficiency in a specific activity, one that needs to be carried out under the authorization of the management system.
CNo dedicated security officerNo dedicated security officer is an organizational staffing issue; the responsibility may be assigned to someone else.
DNo periodic assessments to identify threats and vulnerabilitiesNot periodically assessing threats and vulnerabilities is a process deficiency, which likewise depends on the management system already being formally established.
Why A is correct
A formal charter for the information security management system defines its objectives, scope, authorization, responsibilities, and the governance layer's commitment. Without a charter, the security function has no formal authorization — it cannot govern business units, obtain budget, or set rules, and everything else it does lacks a foundation. This is therefore the most fundamental deficiency. Awareness training, a dedicated security officer, and periodic threat assessments are all specific activities carried out under the authorization of the charter.
Question 5 of 10
During an ongoing audit, management requests a briefing on the findings to date. Which of the following is the IS auditor's BEST course of action?
ARequest management wait until a final report is ready for discussion.Refusing any interim communication is both unnecessary and could miss the opportunity to correct misunderstandings in a timely manner.
BRequest the auditee provide management responses.Requiring the auditee to provide a formal management response before the observations have been confirmed is premature.
CReview working papers with the auditee.Working papers are the audit's internal work records and should not be shared with the auditee for review.
DPresent observations for discussion only.
Why D is correct
With the audit still in progress, the observations have not yet been fully corroborated and evaluated, so briefing management at this point requires careful judgment: it is appropriate to discuss the observations formed so far and hear the other party's explanations and additional input, but not to draw conclusions or present them as formal findings. This satisfies management's need to be informed while avoiding misleading decisions due to insufficient evidence. Refusing to communicate is unnecessary, requiring management to respond at this point is premature, and working papers are internal audit documents not meant to be shared externally.
Question 6 of 10
Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?
AAverage the business units' IT risk levels.Averaging risk levels that were rated on inconsistent criteria produces a meaningless number.
BIdentify the highest-rated IT risk level among the business units.Taking the highest rating across units skews the picture and is likewise affected by the inconsistent criteria.
CEstablish a global IT risk scoring criteria.
DPrioritize the organization's IT risk scenarios.Prioritizing risk scenarios is a subsequent step that presumes the scenarios have already been scored against a unified standard.
Why C is correct
When business units use different methods to manage IT risk, the "high, medium, low" ratings they report mean different things, so they cannot be aggregated or compared, and the organization's overall risk appetite cannot be determined. The first step must be to establish global, unified IT risk scoring criteria — only numbers produced against the same yardstick can be meaningfully summed or weighed. Averaging, taking the highest rating, or prioritizing scenarios all assume the scoring basis is already unified.
Question 7 of 10
What is an effective countermeasure for the vulnerability of data entry operators potentially leaving their computers without logging off? Choose the BEST answer.
AAdministrator alertsAdministrator alerts are an after-the-fact notification and cannot prevent unauthorized operations that occur while the session remains open.
BClose supervisionClose supervision depends on continuous human oversight, is costly, and is harder to guarantee without gaps, making it less reliable than an automatic screen lock.
CScreensaver passwords
DEmployee security awareness trainingSecurity awareness training can only raise vigilance; it still depends on the operator remembering to log off every time, and cannot take effect automatically.
Why C is correct
The specific form of the vulnerability is "the person has left, but the session is still open," so the countermeasure must take effect automatically without requiring human intervention. A password-protected screensaver automatically locks the screen once idle time reaches a set threshold, requiring the password to be re-entered upon return — regardless of whether the operator remembers to log off, the window of risk is automatically closed, making it the most direct and effective technical control. Security awareness training and close supervision both depend on the person doing the right thing every single time — a single lapse causes the control to fail. Administrator alerts are merely an after-the-fact notification and cannot stop unauthorized access that has already occurred during that window.
Question 8 of 10
A top-down approach to the development of operational policies will help ensure:
Acompliance with all policies.Whether policies are complied with depends on execution, oversight, and accountability mechanisms; the direction of derivation itself cannot guarantee compliance.
Bthat they are consistent across the organization.
Cthat they are reviewed periodically.Periodic review is a maintenance arrangement after policy publication, governed by the policy management process, and is unrelated to the top-down method of derivation.
Dthat they are implemented as a part of risk assessment.Policies originating from a risk assessment and being implemented accordingly is a feature of the bottom-up approach, not an effect brought about by top-down derivation.
Why B is correct
A top-down approach to developing operational policies derives lower-level policies from the organization's overarching policy step by step: every lower-level policy can be traced back to a higher-level requirement, so the whole organization stays consistent in principles, wording, and terminology, and conflicting rules between departments do not arise — this is the approach's main advantage. Having policies implemented as part of a risk assessment is a feature of the bottom-up approach; whether policies are complied with and periodically reviewed are matters of execution and maintenance after publication, relying on oversight mechanisms rather than being guaranteed by the direction of derivation.
Question 9 of 10
In a client-server architecture, a domain name service (DNS) is MOST important because it provides the:
AIP addresses for the Internet.Vaguely stating that DNS "provides IP addresses for the internet" does not describe the act of resolution, and address allocation is instead handled by DHCP or a registration authority.
BResolution service for the name/address.
CDomain name system.Simply restating the term from the question is a tautology and does not explain what function it provides.
DAddress of the domain server.The address of the domain server is a parameter that must be configured before using DNS in the first place; it is not a service that DNS provides.
Why B is correct
The core function of DNS (Domain Name System) is to translate human-readable domain names into the IP addresses needed for machine routing — in other words, to provide a resolution service between names and addresses. Before a client can access a server, it must first query DNS for the address corresponding to the target name, and only after obtaining that address can it establish a connection; this is exactly why DNS's importance in a client/server architecture lies in this resolution service. Among the other options, "the address of the domain server" is a prerequisite configuration for using DNS, not something DNS itself provides; "IP addresses for the internet" is too vague to describe a specific service; and "the domain name system" merely restates the term given in the question rather than describing what it provides.
Question 10 of 10
Which of the following is the BEST way to satisfy a two-factor user authentication?
AUser ID along with passwordA user ID together with a password both fall under "something you know"; the ID is not even secret, so overall this remains single-factor authentication.
BIris scanning plus fingerprint scanningIris and fingerprint both belong to the same category of biometric factor; stacking two of them still does not span categories, so it does not constitute two-factor authentication.
CA smart card requiring the user's PIN
DA magnetic card requiring the user's PINA magnetic card is easy to duplicate; although the combination is also formally "have plus know," the strength of the credential is clearly weaker than that of a smart card.
Why C is correct
Two-factor authentication requires two factors drawn from different categories: something you know (a password, a PIN), something you have (a card, a token), and something you are (a biometric trait). A smart card paired with a PIN combines "have" and "know," spanning two categories, so it qualifies. Iris scanning plus fingerprint scanning uses two items, but both fall under "something you are," so they remain a single category and do not constitute two factors. The difference between a smart card and a magnetic card is that the smart card contains an embedded chip capable of encryption and is difficult to duplicate, whereas a magnetic card can be easily copied — so although both fall under the "have" category, the smart card solution is superior.
These 10 are a sample
✓2,604 questions, each with the full reasoning
✓Every wrong option explained, not just the right one
✓9 chapters of syllabus notes, written from a cold start
✓Full-length mock exam with per-domain scoring
✓Printable PDF included — one purchase, no renewal