PassFish

CISA practice questions — 10 free

Certified Information Systems Auditor · every answer carries the reasoning, and why each other option fails.
2,604 questions
9 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?

Why A is correct

The value of a BCP can only be proven through testing. A plan that has never been rehearsed has all of its assumptions—staff arrival times, alternate site capacity, recovery sequencing—unverified, and it will most likely fail when an actual disaster occurs. This is a case of "a control exists but its effectiveness is unknown," which is exactly what an auditor should be most concerned about. Lack of version control, outdated contact information, and missing senior management approval are all documentation governance deficiencies that can be corrected, but none of them reduce the plan's overall reliability to zero the way "never tested" does.

Question 2 of 10

Which of the following would be of GREATEST concern to an IS auditor conducting an audit of an organization's network security with the focus of preventing system breaches?

Why B is correct

The focus of this audit is preventing system breaches, and a breach necessarily originates from incoming malicious traffic. That the organization's data loss prevention (DLP) system does not monitor incoming malicious traffic means the most critical path lacks detection and blocking capability, allowing an attack to proceed unimpeded and unnoticed. Exposed computer names constitute information disclosure, while help desk personnel remoting into external systems and the guest wireless lacking content filtering do not directly constitute a breach path into core systems.

Question 3 of 10

An IS auditor is reviewing documentation from a change that was applied to an application. Which of the following findings would be the GREATEST concern?

Why A is correct

Testing documentation being approved before user acceptance testing is complete means the person signing off did so without complete test results — the "pass" evidence is logically unfounded, and the entire testing gatekeeping process becomes a formality. This is the most substantive deficiency at the documentation level. Missing manager sign-off, hard-copy storage, and documentation dated three weeks before implementation are all formatting or scheduling matters.

Question 4 of 10

What is the MOST critical finding when reviewing an organization's information security management?

Why A is correct

A formal charter for the information security management system defines its objectives, scope, authorization, responsibilities, and the governance layer's commitment. Without a charter, the security function has no formal authorization — it cannot govern business units, obtain budget, or set rules, and everything else it does lacks a foundation. This is therefore the most fundamental deficiency. Awareness training, a dedicated security officer, and periodic threat assessments are all specific activities carried out under the authorization of the charter.

Question 5 of 10

During an ongoing audit, management requests a briefing on the findings to date. Which of the following is the IS auditor's BEST course of action?

Why D is correct

With the audit still in progress, the observations have not yet been fully corroborated and evaluated, so briefing management at this point requires careful judgment: it is appropriate to discuss the observations formed so far and hear the other party's explanations and additional input, but not to draw conclusions or present them as formal findings. This satisfies management's need to be informed while avoiding misleading decisions due to insufficient evidence. Refusing to communicate is unnecessary, requiring management to respond at this point is premature, and working papers are internal audit documents not meant to be shared externally.

Question 6 of 10

Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?

Why C is correct

When business units use different methods to manage IT risk, the "high, medium, low" ratings they report mean different things, so they cannot be aggregated or compared, and the organization's overall risk appetite cannot be determined. The first step must be to establish global, unified IT risk scoring criteria — only numbers produced against the same yardstick can be meaningfully summed or weighed. Averaging, taking the highest rating, or prioritizing scenarios all assume the scoring basis is already unified.

Question 7 of 10

What is an effective countermeasure for the vulnerability of data entry operators potentially leaving their computers without logging off? Choose the BEST answer.

Why C is correct

The specific form of the vulnerability is "the person has left, but the session is still open," so the countermeasure must take effect automatically without requiring human intervention. A password-protected screensaver automatically locks the screen once idle time reaches a set threshold, requiring the password to be re-entered upon return — regardless of whether the operator remembers to log off, the window of risk is automatically closed, making it the most direct and effective technical control. Security awareness training and close supervision both depend on the person doing the right thing every single time — a single lapse causes the control to fail. Administrator alerts are merely an after-the-fact notification and cannot stop unauthorized access that has already occurred during that window.

Question 8 of 10

A top-down approach to the development of operational policies will help ensure:

Why B is correct

A top-down approach to developing operational policies derives lower-level policies from the organization's overarching policy step by step: every lower-level policy can be traced back to a higher-level requirement, so the whole organization stays consistent in principles, wording, and terminology, and conflicting rules between departments do not arise — this is the approach's main advantage. Having policies implemented as part of a risk assessment is a feature of the bottom-up approach; whether policies are complied with and periodically reviewed are matters of execution and maintenance after publication, relying on oversight mechanisms rather than being guaranteed by the direction of derivation.

Question 9 of 10

In a client-server architecture, a domain name service (DNS) is MOST important because it provides the:

Why B is correct

The core function of DNS (Domain Name System) is to translate human-readable domain names into the IP addresses needed for machine routing — in other words, to provide a resolution service between names and addresses. Before a client can access a server, it must first query DNS for the address corresponding to the target name, and only after obtaining that address can it establish a connection; this is exactly why DNS's importance in a client/server architecture lies in this resolution service. Among the other options, "the address of the domain server" is a prerequisite configuration for using DNS, not something DNS itself provides; "IP addresses for the internet" is too vague to describe a specific service; and "the domain name system" merely restates the term given in the question rather than describing what it provides.

Question 10 of 10

Which of the following is the BEST way to satisfy a two-factor user authentication?

Why C is correct

Two-factor authentication requires two factors drawn from different categories: something you know (a password, a PIN), something you have (a card, a token), and something you are (a biometric trait). A smart card paired with a PIN combines "have" and "know," spanning two categories, so it qualifies. Iris scanning plus fingerprint scanning uses two items, but both fall under "something you are," so they remain a single category and do not constitute two factors. The difference between a smart card and a magnetic card is that the smart card contains an embedded chip capable of encryption and is difficult to duplicate, whereas a magnetic card can be easily copied — so although both fall under the "have" category, the smart card solution is superior.

These 10 are a sample

See the full bank