TechNuggets Academy

Information Systems Auditing Process

Free Certified Information Systems Auditor practice — 6 questions on Information Systems Auditing Process, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 1: Information Systems Auditing Process
An IS auditor is testing controls over the purchase order approval process to determine the rate at which control deviations occur in a large population of transactions. Which sampling method is BEST suited for this objective?
Attribute sampling is designed to estimate the rate or percentage of occurrence of a specific attribute (a control deviation) in a population, making it the standard technique for compliance testing of internal controls.
Question 2 of 6 · Domain 1: Information Systems Auditing Process
During a review of accounts payable, an IS auditor obtains four pieces of evidence. Which is generally considered the MOST reliable form of audit evidence?
Evidence the auditor generates directly and independently, such as reperforming a control, is the most reliable because it does not depend on the honesty, competence, or intermediary handling of the auditee or a third party.
Question 3 of 6 · Domain 1: Information Systems Auditing Process
A financial institution wants an IS auditor to continuously monitor high-value wire transfers as they are processed, flagging any transaction exceeding a defined threshold in real time for follow-up review. Which CAAT technique BEST supports this requirement?
An embedded audit module consists of audit code built into the application that continuously monitors live transactions and flags those meeting predefined criteria in real time, directly supporting continuous auditing of high-value transfers.
Question 4 of 6 · Domain 1: Information Systems Auditing Process
During a follow-up review, the IS auditor finds that management has not implemented an agreed-upon corrective action for a high-risk finding and now disagrees with the original recommendation. What should the IS auditor do NEXT?
When a high-risk finding remains unresolved and management disagrees, the auditor must communicate the status, including management's position and the associated risk, to senior management or the audit committee so those charged with governance can decide on further action.
Question 5 of 6 · Domain 1: Information Systems Auditing Process
An IS auditor is planning a compliance-focused audit of a hospital's patient record access controls, where there is no direct monetary measure of loss from a control failure. How should the auditor BEST determine materiality for this engagement?
When no direct financial measure exists, IS audit materiality is determined using qualitative criteria such as criticality of the process, regulatory/compliance impact, safety, and reputational consequences, combined with any relevant quantitative data available.
Question 6 of 6 · Domain 1: Information Systems Auditing Process
An IS auditor was, six months ago, employed as a network administrator responsible for configuring the firewall rules in the department now being audited. The auditor has been assigned to lead an audit of that department's network security controls. What is the MOST appropriate action?
ISACA's Code of Professional Ethics and IS audit standards require disclosure of any actual or potential impairment to independence; if independence is impaired, the auditor should be reassigned or documented compensating safeguards should be applied before the engagement proceeds.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →