Sunday, October 11, 2026

🎯 Cracking the MCQ Challenge — CIA Part 1

🎯 Cracking the MCQ Challenge — CIA Part 1

🎯 Cracking the MCQ Challenge — CIA Part 1


Dear Students,


Today I want to talk to you about the one thing that stands between you and your success in the CIA Part 1 Exam — the MCQ section.


Let me be very clear: your challenge is MCQ questions.


But here's what makes it even harder — it's not just what the questions ask. It's how they ask it.


---


⚠️ The Real Problem: Understanding & Interpreting the Question


Most CIA Part 1 students don't fail because they don't know the topic.


They struggle because:


· The question wording doesn't register on the first reading

· All 4 options look misleading — sometimes more than one seems correct

· The English terms and sentence arrangement used by the IIA Examination Committee are unusual, indirect, and often confusing

· You read a question twice, three times — and still aren't sure what's being asked


This is the most difficult task in the exam. And it's exactly what we need to crack.


---


🔍 First, Understand How the IIA Compiles MCQs


To beat the IIA, you must think like the IIA.


The IIA Examination Committee designs questions to test understanding and application — not memorization. That's why:


· Questions are framed in indirect language

· Distractors (wrong options) are deliberately close to the correct answer

· The correct option often depends on one or two key words in the question stem


Once you understand this, you stop being surprised — and start being prepared.


---


✅ The Solution: 3 Practical Steps


1️⃣ Understand Each Topic & Subtopic — Concept First


Don't just read. Understand.


For every subtopic, ask yourself:


· What is this concept really saying?

· How would the IIA test this?


2️⃣ Solve Simple, Basic-Concept MCQs — With a Timer


Start with basic questions. Build your interpretation speed.


Then add a timer. This trains your brain to read, interpret, and decide — fast.


3️⃣ Focus, Write & Memorize Key Terms From Every Subtopic


This is the game-changer.


For example, in the Control Environment topic from COSO, key words you must instantly recognize — whether they appear in the question or in the options:


· Mission

· Vision

· Goals

· Structure

· Tone at the Top

· Overriding Principles

· Strategy


When you see these words, your brain should immediately connect them to Control Environment — and eliminate options that don't fit.


This is how you decode misleading options.


---


💡 Point 1: Smart Students Take Risks — With High Confidence


Smart students always take risks — but with high confidence. Whatever type of MCQs appear, face them boldly.


The IIA always compiles questions that look tricky — absurd, unmatched with any MCQ from Gleim, Hock, or Wiley. But somehow, they match the IIA Support Package.


So my strong suggestion: solve the IIA GMSISUCCESS Support Package at least TWO times.


Get familiar with the language of the IIA. Do you agree with me?


Even if a few topics are weak — don't worry. There is no need to have mastery or full control over all topics. You must simply be:


· ✅ Familiar with the terms and words

· ✅ Clear on the concept of that topic and subtopic


Taking risk is another prerequisite for passing and cracking this MCQ section.


---


🚫 Point 2: Never Use Blind Guessing


Don't use blind guessing.


Agreed?


Even average students score 550+ (passing criteria: 600 out of 700) on the scale. The only condition is:


· 🔥 A fighting spirit

· ⏳ Patience

· 🎲 Risk-taking skill

· 🧠 Common sense and logic

· ⚡ Keeping momentum — MCQ reading, interpreting, and speed during the exam

· ⏱️ Never get stuck on one MCQ for more than 3 minutes


Agreed?


---


🏆 Point 3: The Three Things You Must Keep in Mind


The Three Golden Rules


1. Master the IIA Language

Solve the GMSISUCCESS Support Package at least twice. Know the terms, words, and concepts — even if every topic isn't your strongest.


2. Take Calculated Risks With Confidence

Never blind guess. Use logic, common sense, and reasoning on every MCQ.


3. Maintain Momentum and Patience

Don't get stuck on any single MCQ beyond 3 minutes. Keep your reading and interpreting speed high throughout the exam.


---


🌟 Final Words


You don't need to be a master of everything.


You need fighting spirit, patience, risk-taking skill, common sense, logic, and speed.


Even average students score 400+. So can you.


My best wishes 🍀 to all students.


Go crack it!


— Prof. Mahaley

Head, GMSISuccess Mumbai

Saturday, October 10, 2026

Risk Management MCQ – CIA Part 1

  


Risk Management MCQ – CIA Part 1

Risk Management MCQ  – CIA Part 1


SECTION A: DIRECT KNOWLEDGE QUESTIONS


### *MCQ 1: Risk Appetite / Tolerance + Residual Risk (Most Tested Concept)*


*CASE:* 

ABC Ltd is a manufacturing company. The Board has set Risk Appetite for operational loss as $5 Million per year. Management has set Risk Tolerance at $4 Million.


The company has a key supplier in a politically unstable country. The risk assessment is done:

- Inherent Risk = $8 Million loss if supplier fails (High Likelihood)

- Company implemented a control: Dual sourcing – Secondary supplier ready – Cost $500,000

- After control, Residual Risk = $3 Million


The Internal Auditor reviews this. The secondary supplier audit reveals the secondary supplier has no capacity to supply in next 3 months due to financial issues.


*Question: What should Internal Auditor conclude and report?*


A) Residual risk is $3 Million which is within both appetite ($5M) and tolerance ($4M), so risk is effectively managed, no reporting needed.


B) Inherent risk of $8M exceeds appetite, so management should terminate the supplier relationship immediately.


C) The control is ineffective, actual residual risk is still close to inherent risk of $8M, which exceeds both risk appetite and tolerance, so this is a material risk exposure that must be reported to Board/Audit Committee.


D) Risk tolerance should be increased to $8M to accommodate inherent risk.


*CORRECT ANSWER:

---


### *MCQ 2: Risk Response + Three Lines Model (Case on GITC + Risk Management)*


*CASE:*

You are the Chief Audit Executive (CAE) of a bank. The bank launched a new mobile payment app quickly to compete in market without conducting a formal Risk Assessment (RCSA). The IT Department (1st Line) developed and launched the app.


After 2 months, customers report fraud due to weak authentication. Loss is $2M.


The Chief Risk Officer (CRO) – 2nd Line says: "We were not involved in app launch, IT did not consult us. Also Internal Audit (3rd Line) did not audit the app before launch, so IA is also responsible."


The CIO says: "Internal Audit should take ownership of Risk Management for all new products to prevent such failures in future."


*Question: As CAE, what is the MOST appropriate response as per IIA Standards and Three Lines Model?*


A) Accept responsibility as 3rd Line should have audited before launch, and agree to take ownership of Risk Management for new products to ensure independence.


B) Agree with CRO – 1st Line (IT) is responsible for managing risk, 2nd Line should have been consulted, 3rd Line provides independent assurance AFTER launch, not before. IA should not own risk management as it impairs independence. Recommend strengthening Risk Management process: mandatory RCSA and 2nd Line review for all new products before launch.


C) Recommend that all risk management responsibility should be transferred to Internal Audit as 3rd Line is most competent to manage risk.


D) Conclude that since fraud occurred, the only correct risk response is Terminate/Avoid – Shut down the mobile app permanently.


*CORRECT ANSWER: 


*LEARNING POINT FOR EXAM:*

- 1st Line = Owns Risk, 2nd Line = Oversight/Challenge, 3rd Line = Assurance – Never own.

- IA role in Risk Management = Assess effectiveness, NOT own or manage.

- If question says "Management wants IA to own ERM" – Answer is ALWAYS – Refuse, impairs independence, recommend safeguards.


Q3. Who owns the risk in an organization?


A) Board of Directors

B) Internal Audit

C) Management

D) External Auditors


Answer: .


---


Q4. What is the role of the Board in risk management?


A) Day-to-day risk management

B) Designing and operating controls

C) Providing oversight and determining if the RM process is adequate and effective

D) Independent assurance


Answer: 

---


Q5. Internal Audit's role in risk management is to:


A) Design and implement the RM framework

B) Own and manage risk

C) Provide independent assurance on the effectiveness of RM processes

D) Approve the risk appetite


---


Q6. Risk Appetite is best defined as:


A) The maximum risk the organization can absorb

B) The acceptable variation around a specific objective

C) The broad amount of risk the organization is willing to accept in pursuit of value

D) Risk remaining after controls are applied


---


Q7. Risk Tolerance is:


A) The broad willingness to accept risk

B) The narrower acceptable variation around a specific objective

C) The absolute maximum risk the organization can assume

D) The same as risk appetite

---


Q8. Risk Capacity refers to:


A) The organization's ability to design controls

B) The maximum amount of risk the organization can assume (the "outer limit")

C) The acceptable variation around objectives

D) The risk appetite minus tolerance



Q9. Inherent Risk is:


A) Risk remaining after controls

B) Risk before any management actions or controls

C) The same as residual risk

D) Risk that cannot be managed



Q10. Residual Risk is:


A) Risk before controls

B) The maximum risk the organization can absorb

C) Risk remaining after controls and responses have been applied

D) The board's preferred risk level




Q11. How many interrelated components does COSO ERM (2017) have?


A) 3

B) 5

C) 8

D) 17



Q12. Which COSO ERM component addresses "tone at the top"?


A) Strategy & Objective Setting

B) Performance

C) Governance & Culture

D) Review & Revision



Q13. Risk appetite is established under which COSO ERM component?


A) Governance & Culture

B) Strategy & Objective Setting

C) Performance

D) Information, Communication & Reporting


Q14. Risk identification and assessment falls under which COSO ERM component?


A) Governance & Culture

B) Strategy & Objective Setting

C) Performance

D) Review & Revision


Q15. Monitoring changes in the risk landscape falls under which COSO ERM component?


A) Performance

B) Review & Revision

C) Information, Communication & Reporting

D) Governance & Culture



Q16. "Right information to right people" is the focus of which COSO ERM component?


A) Performance

B) Review & Revision

C) Information, Communication & Reporting

D) Governance & Culture



Q17. The IIA Three Lines Model (2020) replaced:


A) COSO ERM (2004)

B) The Three Lines of Defense model

C) The COSO Internal Control Framework

D) The Risk Management Framework



Q18. Which line owns and manages risk directly?


A) First Line

B) Second Line

C) Third Line

D) Board


Q19. Which line provides expertise and monitors risks?


A) First Line

B) Second Line

C) Third Line

D) External Audit


Q20. Which line provides independent assurance to the governing body?


A) First Line

B) Second Line

C) Third Line

D) Management


Q21. How many risk response methods are identified in the notes?


A) 3

B) 4

C) 5

D) 6



Q22. Which risk response involves eliminating the activity?


A) Accept

B) Avoid

C) Reduce

D) Share


Q23. Which risk response involves taking on more risk for performance?


A) Accept

B) Avoid

C) Pursue/Exploit

D) Reduce


Q24. Insurance and hedging are examples of which risk response?


A) Avoid

B) Reduce/Mitigate

C) Share/Transfer

D) Accept


Q25. M&A risk is classified as which type of risk?


A) Operational

B) Financial

C) Strategic

D) Compliance


Q26. IT failure risk is classified as which type of risk?


A) Strategic

B) Operational

C) Financial

D) Reputational


Q27. Liquidity risk is classified as which type of risk?


A) Strategic

B) Operational

C) Financial

D) Compliance


Q28. A preventive control:


A) Finds loss after it occurs

B) Stops loss before it happens

C) Fixes issues after detection

D) Transfers risk to a third party


Q29. A detective control:


A) Stops loss before it happens

B) Finds loss after it occurs

C) Fixes issues after detection

D) Eliminates risk entirely


Q30. A corrective control:


A) Stops loss before it happens

B) Finds loss after it occurs

C) Fixes issues after detection

D) Prevents fraud


SECTION B: NEGATIVE-TYPE QUESTIONS


---

Q31. Which of the following is NOT a role of Internal Audit in risk management?


A) Providing independent assurance

B) Evaluating the effectiveness of RM processes

C) Designing and implementing the RM system

D) Reporting on RM effectiveness to the Board



Q32. Which of the following is NOT a component of COSO ERM (2017)?


A) Governance & Culture

B) Performance

C) Risk Transfer & Insurance

D) Review & Revision



Q33. Which of the following is NOT a risk response method?


A) Avoid

B) Accept

C) Ignore

D) Share/Transfer


Q34. Which of the following is NOT a type of risk mentioned in the notes?


A) Strategic

B) Operational

C) Technical

D) Reputational


Q35. Which statement about the Board is INCORRECT?


A) The Board provides oversight

B) The Board sets the tone

C) The Board owns and manages day-to-day risk

D) The Board determines if the RM process is adequate and effective


Q36. Which statement about Risk Tolerance is INCORRECT?


A) It is narrower than risk appetite

B) It relates to a specific objective

C) It represents the maximum risk the organization can assume

D) It defines acceptable variation



Q37. Which is NOT a characteristic of the Three Lines Model (2020)?


A) Uses principles rather than rigid structures

B) First Line owns and manages risk

C) Third Line designs controls to ensure effectiveness

D) Second Line provides expertise and monitoring


Q38. Which of the following is NOT an example of a preventive control?


A) Passwords on systems

B) Segregation of duties

C) Monthly bank reconciliations

D) Physical access restrictions


Q39. Which statement about Inherent Risk is INCORRECT?


A) It exists before management actions

B) It exists before controls are applied

C) It is the same as residual risk

D) It represents raw risk exposure


Q40. Which is NOT a valid reason for Internal Audit to decline designing an ERM system?


A) It impairs objectivity

B) It creates a self-review threat

C) It is a management responsibility

D) It would reduce IA's budget


SECTION C: TRICKY LOGICAL REASONING QUESTIONS


--

Q41. A CRO identifies risks, designs controls, and monitors them. Internal Audit is asked to verify the CRO's work. What is the PRIMARY concern?


A) The CRO lacks technical expertise

B) The CRO's self-review threat weakens independence and the control environment

C) The CRO is not part of the Three Lines Model

D) The CRO should report to the Board instead

---


Q42. A bank's policy states: "We accept moderate credit risk." A loan portfolio allows 5% default variance. Capital can absorb $500M in losses. A portfolio shows 6% default. What is the MOST appropriate interpretation?


A) The bank has exceeded its risk capacity

B) The bank has exceeded its risk appetite but is within tolerance

C) The bank has exceeded its risk tolerance but may still be within capacity

D) The bank has exceeded both tolerance and capacity


Q43. A manufacturing plant has a fire risk rated High (inherent). After installing sprinklers and fire alarms, the risk is rated Low (residual). The CEO says, "Since residual risk is low, we don't need to worry." Is the CEO correct?


A) Yes, because residual risk is low

B) No, because residual risk must always be zero

C) Partially — residual risk being low means controls are working, but IA must assess alignment with appetite and monitoring is still needed

D) Yes, because the controls have eliminated the risk


Q44. A company faces a risk from a competitor launching a superior product. Management decides to do nothing. Is this valid?


A) No, management must always respond to competitive threats

B) Yes, if it's within risk appetite — "Accept" is a legitimate response

C) No, this is a strategic risk that must be avoided

D) Yes, but only if the Board approves it


Q45. A company buys insurance for a factory in a flood zone. What risk response is this, and what limitation exists?


A) Avoid; no limitation

B) Share/Transfer; insurance transfers financial impact but not all risk (reputation, business interruption may remain)

C) Reduce; insurance eliminates all risk

D) Accept; insurance is not a risk response



Q46. A retail chain's ERM process includes: (a) Board approves risk appetite, (b) Management identifies risks quarterly, (c) Results are reported to the Audit Committee, (d) No process exists to monitor changing regulations. Which COSO component is MISSING?


A) Governance & Culture

B) Performance

C) Review & Revision

D) Information, Communication & Reporting



Q47. The CFO asks Internal Audit to design and implement a new ERM system. The CFO argues IA "knows risk best." What should IA do?


A) Accept, since IA has the expertise

B) Decline, because designing/implementing RM systems impairs objectivity and is a management responsibility

C) Accept, but only if the Board approves

D) Accept, but disclose it in the audit report



Q48. If Internal Audit already designed an ERM system, can it still audit it?


A) No, never

B) Yes, without any disclosure

C) Yes, but must disclose the impairment and ensure independent oversight (e.g., external reviewer) for that engagement

D) Yes, because IA is always independent



Q49. A hospital uses brainstorming, SWOT analysis, and process mapping to identify risks. It does NOT use scenario analysis or interviews with frontline staff. What risks might be missed?


A) Only financial risks

B) Low-probability, high-impact events and operational/frontline risks

C) Only compliance risks

D) No risks would be missed



Q50. A detective control finds fraud after a $1M loss. What is the PRIMARY weakness?


A) Detective controls are useless

B) Detective controls don't prevent loss — they only identify it; preventive controls should be considered to reduce impact

C) The control was not designed properly

D) Fraud cannot be prevented


Q51. A portfolio shows 6% default when tolerance is 5%. IA should report this as:


A) An acceptable variation

B) A deviation requiring management to reduce/mitigate risk to return within tolerance

C) A risk capacity breach

D) A strategic risk



Q52. Management proposes a new product with potential $600M loss when risk capacity is $500M. What should IA do?


A) Approve the product

B) Flag that it exceeds risk capacity; the Board must either reject it or increase capital before proceeding

C) Ignore it since it's a management decision

D) Recommend insurance


Q53. A sprinkler system fails inspection. What happens to the risk level?


A) It remains low

B) It becomes zero

C) Residual risk rises back toward inherent until the control is restored

D) It becomes a strategic risk




Q54. Which risk does IA evaluate when concluding on adequacy?


A) Inherent risk

B) Residual risk

C) Risk capacity

D) Risk appetite



Q55. Without an objective, "risk" is:


A) Still meaningful

B) Meaningless — risk is always the effect of uncertainty on objectives

C) The same as inherent risk

D) The same as residual risk



Q56. A unit that designs and monitors its own controls is:


A) Independent

B) Not independent; IA cannot rely blindly on its testing without evaluating objectivity

C) Following best practices

D) Exempt from IA review


Q57. Can Internal Audit rely on the CRO's monitoring?


A) Yes, always

B) No, never

C) Only after evaluating the CRO's competence and objectivity

D) Only if the Board approves



Q58. Who ultimately determines if the RM process is effective?


A) The CRO

B) Internal Audit

C) The Board provides oversight and determines adequacy/effectiveness; IA provides independent assurance to support that judgment

D) External auditors



Q59. Match each risk to the best response: (1) Factory in flood zone, (2) Currency fluctuation, (3) New regulation, (4) Competitor launching superior product.


A) 1-Avoid/Reduce, 2-Share/Transfer, 3-Reduce/Mitigate, 4-Accept or Pursue

B) 1-Accept, 2-Avoid, 3-Share, 4-Reduce

C) 1-Share, 2-Reduce, 3-Accept, 4-Avoid

D) 1-Reduce, 2-Accept, 3-Avoid, 4-Share


Q60. Which technique best addresses emerging risks?


A) Brainstorming

B) SWOT analysis

C) Scenario analysis and environmental scanning

D) Process mapping



SECTION D: EXAM TRIGGER QUICK QUESTIONS


Q61. If the question says "Who owns risk?" the answer is likely:


A) Internal Audit

B) Management (First Line)

C) Board

D) External Auditors


Q62. If the question says "Who provides assurance?" the answer is likely:


A) Management

B) Internal Audit (Third Line)

C) Risk Committee

D) CEO



Q63. If the question says "Risk after controls?" the answer is likely:


A) Inherent risk

B) Residual risk

C) Risk capacity

D) Risk appetite



Q64. If the question says "Maximum risk absorbable?" the answer is likely:


A) Risk appetite

B) Risk tolerance

C) Risk capacity

D) Residual risk


Q65. If the question says "Acceptable variation?" the answer is likely:


A) Risk appetite

B) Risk tolerance

C) Risk capacity

D) Inherent risk



Q66. If the question says "Broad risk willingness?" the answer is likely:


A) Risk tolerance

B) Risk capacity

C) Risk appetite

D) Residual risk


Q67. If the question says "IA asked to design controls?" the answer is likely:


A) Accept the engagement

B) Decline — impairs objectivity

C) Accept with Board approval

D) Accept but disclose


Q68. If the question says "Risk within appetite but not reduced?" the answer is likely:


A) Avoid

B) Accept (valid response)

C) Reduce

D) Share


Q69. If the question says "Missing monitoring of changes?" the answer is likely:


A) Governance & Culture gap

B) Performance gap

C) Review & Revision (COSO gap)

D) Information & Communication gap


Q70. On the CIA exam, which three lenses solve 80% of scenario questions?


A) Cost, benefit, risk


B) Who owns this? Is IA's independence preserved? Is the risk within appetite/tolerance/capacity?

C) Plan, do, check

D) Identify, assess, respond


SUMMARY TABLE: KEY DISTINCTIONS


Concept Definition Key Point

Risk Appetite Broad amount of risk willing to accept "Preferred level"

Risk Tolerance Narrower acceptable variation Around a specific objective

Risk Capacity Maximum risk absorbable "Outer limit"

Inherent Risk Before controls Raw exposure

Residual Risk After controls IA focuses here

First Line Operational Management Owns and manages risk

Second Line Risk & Compliance Expertise and monitoring

Third Line Internal Audit Independent assurance

Avoid Eliminate activity Response method

Accept Within appetite Valid response

Pursue/Exploit Take on more risk For performance

Reduce/Mitigate Bring within tolerance Response method

Share/Transfer Insurance, hedging Transfers financial impact


Thursday, October 8, 2026

100 MCQs – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based


100 MCQs – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based First solve & then check ✔️ yourself..Answers provided at the end.

As per ISACA New Syllabus – All keywords covered: Audit Charter, Standards, Risk Assessment, Planning, Evidence, Materiality, Control, Sampling.


*1.* What is the PRIMARY purpose of IS Audit Charter?

*A) Define authority, responsibility of audit function*

B) Define audit plan

C) List audit findings

D) Define IT policy

*Ans: 

*2.* Who should approve IS Audit Charter?

*A) Board / Audit Committee*

B) CIO

C) IT Manager

D) External Auditor

*Ans:

*3.* ISACA IS Auditing Standards are mandatory for?

*A) All IS audits*

B) Only external audits

C) Only internal audits

D) Optional

*Ans:


*4.* What is Risk-Based Auditing?

*A) Audit based on risk assessment*

B) Audit all systems equally

C) Audit only financial systems

D) Audit only when fraud occurs

*Ans: 


*5.* Inherent Risk is?

*A) Risk before controls*

B) Risk after controls

C) Risk of auditor not detecting

D) Risk of control failure

*Ans: 


*6.* Residual Risk = ?

*A) Inherent Risk – Control effectiveness*

B) Inherent + Control Risk

C) Audit Risk

D) Detection Risk

*Ans: 


*7.* Which risk does auditor control directly?

*A) Detection Risk*

B) Inherent Risk

C) Control Risk

D) Business Risk

*Ans: 

*8.* Audit Risk = Inherent Risk x Control Risk x ?

*A) Detection Risk*

B) Residual Risk

C) Business Risk

D) Audit Risk

*Ans:


*9.* Materiality in IS Audit means?

*A) Significance of finding to business*

B) Amount in financial statement

C) Number of records

D) Audit fee

*Ans:

*10.* First step in IS Audit Planning?

*A) Understand business, its risks and processes*

B) Start testing controls

C) Issue report

D) Collect evidence

*Ans:


*11.* Which document defines scope, objective, timing of audit?

*A) Audit Plan / Engagement Letter*

B) Audit Charter

C) Audit Report

D) Risk Register

*Ans:


*12.* What is Audit Program?

*A) Detailed steps to achieve audit objectives*

B) Software program

C) Audit charter

D) Audit report

*Ans:.


*13.* Evidence is MOST reliable when?

*A) Directly obtained by auditor, from independent source, original*

B) From client copy

C) Oral evidence only

D) Internal evidence only

*Ans: 

*14.* Which is MOST reliable audit evidence?

*A) Auditor's direct observation*

B) Client's internal memo

C) Photocopy of document

D) Oral statement by client

*Ans:.


*15.* Sampling Risk is?

*A) Conclusion from sample differs from population*

B) All records are wrong

C) Auditor fails to sample

D) No risk

*Ans:

*16.* Alpha Risk (Type I) means?

*A) Auditor says control works when it does not*

B) Auditor says control does not work when it actually works – False negative

C) No risk

D) Inherent risk

*Ans: .


*17.* Beta Risk (Type II) in IS Audit is?

*A) Auditor concludes control effective when it is ineffective – More dangerous*

B) Auditor concludes ineffective when effective

C) No risk

D) Sampling correct

*Ans:

*18.* Best sampling method for fraud detection?

*A) Discovery / Directed Sampling*

B) Statistical sampling

C) Random sampling

D) Haphazard sampling

*Ans: 

*19.* When population has high variance, which sampling?

*A) Stratified Sampling*

B) Simple Random

C) Systematic

D) Judgmental

*Ans: 

*20.* CAATs stands for?

*A) Computer Assisted Audit Techniques*

B) Computer Audit Tools

C) Control Audit Techniques

D) Compliance Audit Tools

*Ans: 

*21.* Which CAAT is used to test calculation without affecting live data?

*A) Test Data / Base Case System Evaluation*

B) Parallel Simulation

C) Embedded Audit Module

D) GAS

*Ans: 


*22.* Continuous Auditing uses?

*A) Embedded Audit Module / SCARF*

B) Manual auditing

C) Year-end audit only

D) No technology

*Ans: 


*23.* What is SCARF?

*A) System Control Audit Review File – Embedded module that collects suspicious transactions*

B) Audit software

C) Risk file

D) Report file

*Ans


*24.* Audit Hook is?

*A) Code that triggers when specific condition met – Red flag*

B) Fishing technique

C) Audit report

D) Audit plan

*Ans:


*25.* Which controls to test FIRST in risk-based audit?

*A) Entity-level / General Controls (GITC)*

B) Application controls

C) No controls

D) Only manual controls

*Ans:

*26.* Which is Preventive Control?

*A) Segregation of Duties, Access Control, Authorization*

B) Reconciliation

C) Log review

D) Backup review

*Ans: 


*27.* Detective Control is?

*A) Log monitoring, Reconciliation, Review*

B) Access control

C) Firewalls

D) Encryption

*Ans:


*28.* Corrective Control is?

*A) Backup restore, Contingency plan, Patching*

B) Access control

C) Authorization

D) Reconciliation

*Ans:


*29.* Compensating Control is used when?

*A) Primary control fails or not cost-effective – Alternative control*

B) No control needed

C) All controls fail

D) Only preventive needed

*Ans:


*30.* Segregation of Duties violation is?

*A) One person can commit and conceal fraud – Developer in Production*

B) Two persons share password

C) Manager reviews report

D) No violation

*Ans:

*31.* What should auditor do if Inherent Risk is High?

*A) Increase substantive testing, reduce detection risk*

B) Reduce testing

C) Do nothing

D) Issue clean report

*Ans: .


*32.* Control Risk is high when?

*A) Controls are weak / not designed properly*

B) Controls are strong

C) Auditor is weak

D) No risk

*Ans:

*33.* Evidence collection method for compliance?

*A) Observation, Inquiry, Inspection, Re-performance*

B) Only inquiry

C) Only observation

D) No method

*Ans: 

*34.* Inquiry as audit evidence is?

*A) Weakest – Needs corroboration*

B) Strongest

C) Sufficient alone

D) Not evidence

*Ans:


*35.* Which is substantive test?

*A) Test of details of transactions, balances, analytical procedures*

B) Test of control design

C) Test of control operating effectiveness

D) No test

*Ans.


*36.* What is Compliance Test?

*A) Test if control is operating effectively – Test of Controls*

B) Test of balances

C) Test of details

D) Analytical test

*Ans:


*37.* Tolerable Error in sampling means?

*A) Max error auditor can accept and still say control effective / balance correct*

B) No error allowed

C) All errors allowed

D) Sampling error

*Ans: 

*38.* Confidence Level 95% means?

*A) 95% chance sample represents population – 5% sampling risk*

B) 100% correct

C) 5% correct

D) No confidence

*Ans:

*39.* Which sampling does NOT use statistics?

*A) Judgmental / Non-statistical sampling*

B) Variable sampling

C) Attribute sampling

D) Stratified sampling

*Ans

*40.* When to use 100% examination instead of sampling?

*A) Population small, High risk, Forensic audit*

B) Always sampling

C) Never 100%

D) Only for low risk

*Ans: 


*41.* What is Audit Trail?

*A) Chronological record to trace transaction from source to final – For reconstruction*

B) Audit report

C) Audit plan

D) No trail

*Ans: 


*42.* Which ISACA guideline says auditor must be independent?

*A) Independence and Objectivity – 2nd Standard*

B) No guideline

C) Audit Charter only

D) Management guideline

*Ans: 

*43.* Internal Audit reporting to CIO violates?

*A) Independence – Should report to Board/Audit Committee*

B) No violation

C) Good practice

D) Required

*Ans:

*44.* Follow-up audit is done to?

*A) Verify management implemented audit recommendations*

B) Do new audit

C) Close audit file

D) No follow-up needed

*Ans: 

*45.* Audit Documentation should contain?

*A) Plan, Program, Evidence, Findings, Report – Enough for another auditor to understand*

B) Only report

C) Only plan

D) No documentation needed

*Ans: 

*46.* What is Snapshot?

*A) Record of system at point in time for audit – Before/After image*

B) Photo

C) Audit report

D) No meaning

*Ans

*47.* Integrated Auditing means?

*A) Combined financial, operational and IS audit*

B) Only IS audit

C) Only financial audit

D) No integration

*Ans: 


*48.* Control Self-Assessment (CSA) is?

*A) Management self-assesses controls – Auditor facilitates*

B) Auditor assesses controls

C) No self-assessment

D) External audit

*Ans:

*49.* What is Benchmarking in audit?

*A) Compare control/process with best practice or industry standard*

B) No comparison

C) Only internal compare

D) Audit fee compare

*Ans:.


*50.* Maturity Model used in audit to?

*A) Assess maturity of process – 0-5 levels – e.g., COBIT, CMM*

B) Assess audit fee

C) No use

D) Only for software

*Ans:

*51.* COBIT is used for?

*A) IT Governance and Management framework – For audit planning*

B) Only for coding

C) Only for hardware

D) No use

*Ans:

*52.* What is Risk Appetite vs Risk Tolerance already covered – Which is broader?

*A) Risk Appetite broader – Tolerance specific limit*

B) Tolerance broader

C) Same

D) No relation

*Ans:

*53.* Business Impact Analysis (BIA) is used for?

*A) Identify critical processes and impact of disruption – For audit prioritization*

B) Audit fee

C) No use

D) Only for BCP

*Ans: 


*54.* Which is MOST important for audit planning?

*A) Risk Assessment and Business Understanding*

B) Audit software

C) Audit fee

D) Auditor name

*Ans:


*55.* Analytical Procedures in IS Audit?

*A) Compare trends, ratios, reasonableness – e.g., Log review trends, CPU usage trends*

B) No analytics

C) Only financial analytics

D) No need

*Ans:

*56.* What is KRI?

*A) Key Risk Indicator – Early warning of increasing risk*

B) Key Result Indicator

C) No indicator

D) Audit indicator

*Ans: 

*57.* What is KPI?

*A) Key Performance Indicator – Past performance achieved*

B) Risk indicator

C) No indicator

D) Control indicator

*Ans: 


*58.* Auditing BYOD policy – What is first step?

*A) Understand BYOD policy, risks, MDM controls*

B) Test MDM directly

C) Ignore BYOD

D) Issue report

*Ans:


*59.* Cloud audit – Who is responsible for data?

*A) Client ultimately responsible even if data in cloud – Cannot outsource accountability*

B) Cloud provider fully responsible

C) No one responsible

D) Auditor responsible

*Ans:


*60.* Continuous Auditing vs Continuous Monitoring – Difference?

*A) Auditing = Done by Auditor – Monitoring = Done by Management*

B) Same

C) No difference

D) Both by management

*Ans: 

*61.* What is Forensic Audit objective?

*A) Collect evidence acceptable in court – Chain of custody critical*

B) Regular audit

C) Financial audit only

D) No objective

*Ans:.


*62.* Chain of Custody means?

*A) Document who handled evidence, when, where – To prove integrity in court*

B) No chain

C) Audit chain

D) Supply chain

*Ans:

*63.* What is Due Diligence audit?

*A) Pre-merger/acquisition audit to assess risks and controls of target*

B) No diligence

C) Regular audit

D) Only financial

*Ans:

*64.* Which audit technique uses dummy entity?

*A) Integrated Test Facility (ITF) – Dummy master file record – e.g., Dummy vendor*

B) Test data

C) No technique

D) Parallel simulation

*Ans: 



*65.* Parallel Simulation means?

*A) Auditor's program re-processes client's data and compares results*

B) Client's program re-processes

C) No simulation

D) Only manual

*Ans:

*66.* White Box vs Black Box testing – White Box?

*A) Auditor knows internal logic/code – Tests logic*

B) Does not know internal logic – Tests input/output

C) No testing

D) Only black box used

*Ans:


*67.* When to use Black Box audit?

*A) When auditor does not have access to code – Tests functionality*

B) Always white box

C) Never black box

D) Only for code review

*Ans:


*68.* What is Material weakness vs Significant deficiency?

*A) Material weakness = Reasonable possibility of material misstatement not prevented – More severe – Must report to Board*

B) Same

C) Significant more severe

D) No difference

*Ans:


*69.* Audit Report should be?

*A) Clear, Concise, Objective, Timely, Supported by evidence – With risk and recommendation*

B) Long and confusing

C) No recommendation

D) Only findings

*Ans:

*70.* Finding should include?

*A) Criteria, Condition, Cause, Effect, Recommendation (CC CER)*

B) Only condition

C) Only criteria

D) No structure

*Ans:


*71.* What is Criteria?

*A) What SHOULD be – Standard, Policy, Best practice*

B) What is

C) No criteria

D) Audit report

*Ans:


*72.* Effect in audit finding means?

*A) Impact/Risk of finding – Financial, Reputational, Compliance*

B) No effect

C) Only cause

D) Audit fee

*Ans:


*73.* Which evidence collection has observer bias risk?

*A) Observation – Hawthorne effect – People behave differently when watched*

B) Inspection

C) Re-performance

D) Document review

*Ans: 


*74.* What is GAS?

*A) Generalized Audit Software – ACL, IDEA – For data analysis*

B) Gas audit

C) No software

D) Audit gas

*Ans:


*75.* Benford's Law used for?

*A) Detect fraud in numbers – Natural numbers follow Benford pattern – Anomaly indicates fraud*

B) No fraud detection

C) Only for math

D) Audit planning

*Ans:.


*76.* What is Code Review audit?

*A) Auditor reviews source code for vulnerabilities, backdoors, logic bombs*

B) No review

C) Only execution

D) Only output review

*Ans: 


*77.* Logic Bomb is?

*A) Malicious code triggered by specific condition – e.g., date, event*

B) No bomb

C) Audit bomb

D) Only hardware

*Ans:


*78.* Who should have access to audit working papers?

*A) Only audit team and authorized reviewers – Confidential*

B) Everyone

C) Client's staff

D) Public

*Ans: 


*79.* Retention of audit working papers – As per ISACA?

*A) As per legal and organizational policy – Typically 5-7 years*

B) 1 day

C) No retention

D) Forever 1 month

*Ans:


*80.* What is Professional Skepticism?

*A) Questioning mind, critical assessment – Don't trust blindly, corroborate*

B) Trust everything client says

C) No skepticism

D) Only trust management

*Ans:

*81.* What is Independence in fact vs appearance?

*A) In fact = Actually independent – In appearance = Others perceive you independent – Both needed*

B) Only fact needed

C) Only appearance needed

D) No independence needed

*Ans:.


*82.* Can internal auditor audit area where he previously worked?

*A) Not within 12 months – Impairs independence – Cooling period needed*

B) Can audit immediately

C) Never can audit

D) No restriction

*Ans: 


*83.* What is Co-sourcing vs Outsourcing of audit?

*A) Co-sourcing = Internal + External together – Outsourcing = Fully external firm does audit*

B) Same

C) No difference

D) Only co-sourcing used

*Ans


*84.* What is Audit Universe?

*A) All auditable areas in organization – For annual audit planning*

B) One audit area

C) No universe

D) Only IT areas

*Ans:.


*85.* Annual audit plan based on?

*A) Risk assessment of audit universe + Management request + Regulatory requirement*

B) Random

C) Only management request

D) Only regulatory

*Ans: 


*86.* What is Engagement Letter?

*A) Formal agreement with auditee – Scope, objective, responsibilities, timelines*

B) No letter needed

C) Only oral agreement

D) Audit report

*Ans:


*87.* Expectation Gap means?

*A) Difference between what auditee expects and what auditor delivers – Managed by engagement letter*

B) No gap

C) Audit fee gap

D) No meaning

*Ans:

*88.* What is Walkthrough?

*A) Tracing one transaction from start to end to understand process and controls – First step before detailed testing*

B) Walking in office

C) No walkthrough

D) Audit report walk

*Ans:


*89.* Which is better – Preventive or Detective control?

*A) Preventive is better and cheaper – Prevents loss – But both needed – Defense in depth*

B) Detective better

C) No control better

D) Only corrective needed

*Ans: 


*90.* Defense in Depth means?

*A) Multiple layers of controls – If one fails, other catches – e.g., Firewall + IDS + Access control*

B) One control enough

C) No defense

D) Only preventive

*Ans:


*91.* What is Compensating control for lack of SoD in small company?

*A) Manager review, Audit trail review, Independent reconciliation*

B) No control

C) Ignore SoD

D) Only one person does all

*Ans:

*92.* What is Audit Evidence sufficiency vs appropriateness?

*A) Sufficiency = Quantity – Enough evidence – Appropriateness = Quality – Relevant and Reliable*

B) Same

C) No difference

D) Only quantity matters

*Ans


*93.* When auditor finds fraud, what should do FIRST?

*A) Inform appropriate level – Audit Committee / Board – Not necessarily management if management involved – Preserve evidence*

B) Tell everyone

C) Ignore

D) Delete evidence

*Ans

*94.* What is Whistleblower mechanism?

*A) Anonymous reporting channel for fraud/ethics violations – Auditor should test its existence and effectiveness*

B) No mechanism

C) Only for HR

D) Not for audit

*Ans: 


*95.* What is Fraud Triangle?

*A) Pressure, Opportunity, Rationalization – All three needed for fraud – Auditor looks for these*

B) No triangle

C) Only pressure

D) Only opportunity

*Ans:

*96.* What is Fraud Diamond adds 4th element?

*A) Capability – Person must have skill to commit fraud*

B) No diamond

C) Only triangle needed

D) Pressure only

*Ans:

*97.* What is Continuous Auditing benefit?

*A) Real-time assurance, Early detection, Reduced audit cost over time, 100% population testing*

B) No benefit

C) Only manual benefit

D) Yearly audit benefit

*Ans:


*98.* What is Risk Assessment Matrix used for?

*A) Prioritize risks based on Likelihood x Impact – Heat map*

B) No matrix

C) Only for audit fee

D) Only for planning

*Ans: 


*99.* What is Control Matrix?

*A) Maps risks to controls – Shows which control mitigates which risk – Identifies gaps*

B) No matrix

C) Only risk matrix

D) Audit matrix

*Ans


*100.* What is FINAL step in IS Audit Process (Domain 1)?

*A) Follow-up and Issue closure – Verify remediation – Then close audit*

B) Start new audit without follow-up

C) No final step

D) Only report

*Ans:


ANSWERS:

100 MCQs with Answers + Explanation – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based*


As per ISACA New Syllabus – All keywords covered: Audit Charter, Standards, Risk Assessment, Planning, Evidence, Materiality, Control, Sampling.


*1.* What is the PRIMARY purpose of IS Audit Charter?

*A) Define authority, responsibility of audit function*

B) Define audit plan

C) List audit findings

D) Define IT policy

*Ans: A* – Charter gives mandate from Board/Audit Committee – Without charter, audit has no authority.


*2.* Who should approve IS Audit Charter?

*A) Board / Audit Committee*

B) CIO

C) IT Manager

D) External Auditor

*Ans: A* – Independence – Board/Audit Committee approves.


*3.* ISACA IS Auditing Standards are mandatory for?

*A) All IS audits*

B) Only external audits

C) Only internal audits

D) Optional

*Ans: A* – ISACA Standards mandatory for all CISA holders.


*4.* What is Risk-Based Auditing?

*A) Audit based on risk assessment*

B) Audit all systems equally

C) Audit only financial systems

D) Audit only when fraud occurs

*Ans: A* – Focus on high-risk areas – Efficient audit.


*5.* Inherent Risk is?

*A) Risk before controls*

B) Risk after controls

C) Risk of auditor not detecting

D) Risk of control failure

*Ans: A* – Gross risk – Before any controls.


*6.* Residual Risk = ?

*A) Inherent Risk – Control effectiveness*

B) Inherent + Control Risk

C) Audit Risk

D) Detection Risk

*Ans: A* – Net risk after controls – What audit tests.


*7.* Which risk does auditor control directly?

*A) Detection Risk*

B) Inherent Risk

C) Control Risk

D) Business Risk

*Ans: A* – Auditor can reduce detection risk by more substantive testing.


*8.* Audit Risk = Inherent Risk x Control Risk x ?

*A) Detection Risk*

B) Residual Risk

C) Business Risk

D) Audit Risk

*Ans: A* – Classic audit risk model.


*9.* Materiality in IS Audit means?

*A) Significance of finding to business*

B) Amount in financial statement

C) Number of records

D) Audit fee

*Ans: A* – Impact on business objectives, not just amount.


*10.* First step in IS Audit Planning?

*A) Understand business, its risks and processes*

B) Start testing controls

C) Issue report

D) Collect evidence

*Ans: A* – Understand business is always first.


*11.* Which document defines scope, objective, timing of audit?

*A) Audit Plan / Engagement Letter*

B) Audit Charter

C) Audit Report

D) Risk Register

*Ans: A* – Audit Plan defines scope, objective, resources.


*12.* What is Audit Program?

*A) Detailed steps to achieve audit objectives*

B) Software program

C) Audit charter

D) Audit report

*Ans: A* – Step-by-step procedures – Prepared after planning.


*13.* Evidence is MOST reliable when?

*A) Directly obtained by auditor, from independent source, original*

B) From client copy

C) Oral evidence only

D) Internal evidence only

*Ans: A* – External + Direct + Original = Most reliable.


*14.* Which is MOST reliable audit evidence?

*A) Auditor's direct observation*

B) Client's internal memo

C) Photocopy of document

D) Oral statement by client

*Ans: A* – Direct observation > External doc > Internal doc > Oral.


*15.* Sampling Risk is?

*A) Conclusion from sample differs from population*

B) All records are wrong

C) Auditor fails to sample

D) No risk

*Ans: A* – Sample not representative – 2 types: Alpha and Beta risk.


*16.* Alpha Risk (Type I) means?

*A) Auditor says control works when it does not*

B) Auditor says control does not work when it actually works – False negative

C) No risk

D) Inherent risk

*Ans: B* – In audit, Beta risk (False assurance) is more dangerous than Alpha.


*17.* Beta Risk (Type II) in IS Audit is?

*A) Auditor concludes control effective when it is ineffective – More dangerous*

B) Auditor concludes ineffective when effective

C) No risk

D) Sampling correct

*Ans: A* – Beta = Wrong assurance – Leads to audit failure.


*18.* Best sampling method for fraud detection?

*A) Discovery / Directed Sampling*

B) Statistical sampling

C) Random sampling

D) Haphazard sampling

*Ans: A* – Discovery sampling for fraud – Look for one occurrence.


*19.* When population has high variance, which sampling?

*A) Stratified Sampling*

B) Simple Random

C) Systematic

D) Judgmental

*Ans: A* – Divide population into strata (high value, low value) – Reduces variance.


*20.* CAATs stands for?

*A) Computer Assisted Audit Techniques*

B) Computer Audit Tools

C) Control Audit Techniques

D) Compliance Audit Tools

*Ans: A* – Tools like ACL, IDEA, Excel – Used for data analysis.


*21.* Which CAAT is used to test calculation without affecting live data?

*A) Test Data / Base Case System Evaluation*

B) Parallel Simulation

C) Embedded Audit Module

D) GAS

*Ans: A* – Test data into copy of production – Does not affect live.


*22.* Continuous Auditing uses?

*A) Embedded Audit Module / SCARF*

B) Manual auditing

C) Year-end audit only

D) No technology

*Ans: A* – Continuous monitoring – SCARF, EAM, Audit Hooks.


*23.* What is SCARF?

*A) System Control Audit Review File – Embedded module that collects suspicious transactions*

B) Audit software

C) Risk file

D) Report file

*Ans: A* – EAM + SCARF = Collects transactions for audit.


*24.* Audit Hook is?

*A) Code that triggers when specific condition met – Red flag*

B) Fishing technique

C) Audit report

D) Audit plan

*Ans: A* – Example: Trigger when salary > $10,000.


*25.* Which controls to test FIRST in risk-based audit?

*A) Entity-level / General Controls (GITC)*

B) Application controls

C) No controls

D) Only manual controls

*Ans: A* – If GITC fails, all application controls unreliable – Test GITC first.


*26.* Which is Preventive Control?

*A) Segregation of Duties, Access Control, Authorization*

B) Reconciliation

C) Log review

D) Backup review

*Ans: A* – Prevents error – Detective = Reconciliation, Log review.


*27.* Detective Control is?

*A) Log monitoring, Reconciliation, Review*

B) Access control

C) Firewalls

D) Encryption

*Ans: A* – Detects after occurrence.


*28.* Corrective Control is?

*A) Backup restore, Contingency plan, Patching*

B) Access control

C) Authorization

D) Reconciliation

*Ans: A* – Corrects after detection.


*29.* Compensating Control is used when?

*A) Primary control fails or not cost-effective – Alternative control*

B) No control needed

C) All controls fail

D) Only preventive needed

*Ans: A* – Example: If SoD not possible in small company, manager review = compensating.


*30.* Segregation of Duties violation is?

*A) One person can commit and conceal fraud – Developer in Production*

B) Two persons share password

C) Manager reviews report

D) No violation

*Ans: A* – Core SoD failure – Most common audit finding.


*31.* What should auditor do if Inherent Risk is High?

*A) Increase substantive testing, reduce detection risk*

B) Reduce testing

C) Do nothing

D) Issue clean report

*Ans: A* – High inherent = More audit work.


*32.* Control Risk is high when?

*A) Controls are weak / not designed properly*

B) Controls are strong

C) Auditor is weak

D) No risk

*Ans: A* – High control risk = Cannot rely on controls – Do substantive testing.


*33.* Evidence collection method for compliance?

*A) Observation, Inquiry, Inspection, Re-performance*

B) Only inquiry

C) Only observation

D) No method

*Ans: A* – Four methods – Re-performance most reliable.


*34.* Inquiry as audit evidence is?

*A) Weakest – Needs corroboration*

B) Strongest

C) Sufficient alone

D) Not evidence

*Ans: A* – Oral evidence alone insufficient – Must corroborate.


*35.* Which is substantive test?

*A) Test of details of transactions, balances, analytical procedures*

B) Test of control design

C) Test of control operating effectiveness

D) No test

*Ans: A* – Substantive proves dollar amount correct – Control test proves control works.


*36.* What is Compliance Test?

*A) Test if control is operating effectively – Test of Controls*

B) Test of balances

C) Test of details

D) Analytical test

*Ans: A* – Compliance = Control testing.


*37.* Tolerable Error in sampling means?

*A) Max error auditor can accept and still say control effective / balance correct*

B) No error allowed

C) All errors allowed

D) Sampling error

*Ans: A* – If error > tolerable, control ineffective.


*38.* Confidence Level 95% means?

*A) 95% chance sample represents population – 5% sampling risk*

B) 100% correct

C) 5% correct

D) No confidence

*Ans: A* – Higher confidence = Larger sample.


*39.* Which sampling does NOT use statistics?

*A) Judgmental / Non-statistical sampling*

B) Variable sampling

C) Attribute sampling

D) Stratified sampling

*Ans: A* – Auditor judgment – Cannot measure sampling risk – But allowed.


*40.* When to use 100% examination instead of sampling?

*A) Population small, High risk, Forensic audit*

B) Always sampling

C) Never 100%

D) Only for low risk

*Ans: A* – For small high-risk populations, examine all.


*41.* What is Audit Trail?

*A) Chronological record to trace transaction from source to final – For reconstruction*

B) Audit report

C) Audit plan

D) No trail

*Ans: A* – Must be enabled – If no audit trail = Control failure.


*42.* Which ISACA guideline says auditor must be independent?

*A) Independence and Objectivity – 2nd Standard*

B) No guideline

C) Audit Charter only

D) Management guideline

*Ans: A* – Organizational independence – Report to Audit Committee, not to CIO.


*43.* Internal Audit reporting to CIO violates?

*A) Independence – Should report to Board/Audit Committee*

B) No violation

C) Good practice

D) Required

*Ans: A* – Reporting to CIO impairs independence – Major finding.


*44.* Follow-up audit is done to?

*A) Verify management implemented audit recommendations*

B) Do new audit

C) Close audit file

D) No follow-up needed

*Ans: A* – Required by ISACA – Auditor must follow up.


*45.* Audit Documentation should contain?

*A) Plan, Program, Evidence, Findings, Report – Enough for another auditor to understand*

B) Only report

C) Only plan

D) No documentation needed

*Ans: A* – Working papers – Retention as per policy.


*46.* What is Snapshot?

*A) Record of system at point in time for audit – Before/After image*

B) Photo

C) Audit report

D) No meaning

*Ans: A* – Used to verify processing – Before and after processing image.


*47.* Integrated Auditing means?

*A) Combined financial, operational and IS audit*

B) Only IS audit

C) Only financial audit

D) No integration

*Ans: A* – Team with financial + IT auditors – Best for application controls.


*48.* Control Self-Assessment (CSA) is?

*A) Management self-assesses controls – Auditor facilitates*

B) Auditor assesses controls

C) No self-assessment

D) External audit

*Ans: A* – CSA workshop – But auditor must not own controls – Independence risk.


*49.* What is Benchmarking in audit?

*A) Compare control/process with best practice or industry standard*

B) No comparison

C) Only internal compare

D) Audit fee compare

*Ans: A* – Example: Compare password policy with ISO 27001.


*50.* Maturity Model used in audit to?

*A) Assess maturity of process – 0-5 levels – e.g., COBIT, CMM*

B) Assess audit fee

C) No use

D) Only for software

*Ans: A* – 0 Non-existent to 5 Optimized – Shows gap.


*51.* COBIT is used for?

*A) IT Governance and Management framework – For audit planning*

B) Only for coding

C) Only for hardware

D) No use

*Ans: A* – COBIT 2019 – Main framework for IS Audit.


*52.* What is Risk Appetite vs Risk Tolerance already covered – Which is broader?

*A) Risk Appetite broader – Tolerance specific limit*

B) Tolerance broader

C) Same

D) No relation

*Ans: A* – Appetite = Board level broad, Tolerance = Management specific.


*53.* Business Impact Analysis (BIA) is used for?

*A) Identify critical processes and impact of disruption – For audit prioritization*

B) Audit fee

C) No use

D) Only for BCP

*Ans: A* – Auditor uses BIA to prioritize critical systems for audit.


*54.* Which is MOST important for audit planning?

*A) Risk Assessment and Business Understanding*

B) Audit software

C) Audit fee

D) Auditor name

*Ans: A* – Risk assessment drives audit plan.


*55.* Analytical Procedures in IS Audit?

*A) Compare trends, ratios, reasonableness – e.g., Log review trends, CPU usage trends*

B) No analytics

C) Only financial analytics

D) No need

*Ans: A* – Example: Login failures suddenly increased – Indicates attack.


*56.* What is KRI?

*A) Key Risk Indicator – Early warning of increasing risk*

B) Key Result Indicator

C) No indicator

D) Audit indicator

*Ans: A* – Example: Failed logins > 10 = KRI for brute force risk.


*57.* What is KPI?

*A) Key Performance Indicator – Past performance achieved*

B) Risk indicator

C) No indicator

D) Control indicator

*Ans: A* – KRI = Future risk, KPI = Past performance.


*58.* Auditing BYOD policy – What is first step?

*A) Understand BYOD policy, risks, MDM controls*

B) Test MDM directly

C) Ignore BYOD

D) Issue report

*Ans: A* – Always understand policy and risk first.


*59.* Cloud audit – Who is responsible for data?

*A) Client ultimately responsible even if data in cloud – Cannot outsource accountability*

B) Cloud provider fully responsible

C) No one responsible

D) Auditor responsible

*Ans: A* – Outsourcing responsibility but not accountability – Key CISA concept.


*60.* Continuous Auditing vs Continuous Monitoring – Difference?

*A) Auditing = Done by Auditor – Monitoring = Done by Management*

B) Same

C) No difference

D) Both by management

*Ans: A* – Auditor does auditing, Management does monitoring.


*61.* What is Forensic Audit objective?

*A) Collect evidence acceptable in court – Chain of custody critical*

B) Regular audit

C) Financial audit only

D) No objective

*Ans: A* – Preserve evidence, chain of custody, no tampering.


*62.* Chain of Custody means?

*A) Document who handled evidence, when, where – To prove integrity in court*

B) No chain

C) Audit chain

D) Supply chain

*Ans: A* – If chain broken, evidence not admissible.


*63.* What is Due Diligence audit?

*A) Pre-merger/acquisition audit to assess risks and controls of target*

B) No diligence

C) Regular audit

D) Only financial

*Ans: A* – Important for M&A – Check IT controls, licenses, security.


*64.* Which audit technique uses dummy entity?

*A) Integrated Test Facility (ITF) – Dummy master file record – e.g., Dummy vendor*

B) Test data

C) No technique

D) Parallel simulation

*Ans: A* – ITF tests live processing with dummy records – Must be removed.


*65.* Parallel Simulation means?

*A) Auditor's program re-processes client's data and compares results*

B) Client's program re-processes

C) No simulation

D) Only manual

*Ans: A* – Detects unauthorized logic in client's program.


*66.* White Box vs Black Box testing – White Box?

*A) Auditor knows internal logic/code – Tests logic*

B) Does not know internal logic – Tests input/output

C) No testing

D) Only black box used

*Ans: A* – White = With code knowledge, Black = Without code – Just input/output.


*67.* When to use Black Box audit?

*A) When auditor does not have access to code – Tests functionality*

B) Always white box

C) Never black box

D) Only for code review

*Ans: A* – Most IS audits are black box – Test controls, not code.


*68.* What is Material weakness vs Significant deficiency?

*A) Material weakness = Reasonable possibility of material misstatement not prevented – More severe – Must report to Board*

B) Same

C) Significant more severe

D) No difference

*Ans: A* – Material weakness > Significant deficiency > Deficiency.


*69.* Audit Report should be?

*A) Clear, Concise, Objective, Timely, Supported by evidence – With risk and recommendation*

B) Long and confusing

C) No recommendation

D) Only findings

*Ans: A* – Report structure: Executive summary, Findings, Risk, Recommendation, Response.


*70.* Finding should include?

*A) Criteria, Condition, Cause, Effect, Recommendation (CC CER)*

B) Only condition

C) Only criteria

D) No structure

*Ans: A* – 5 Cs for good finding.


*71.* What is Criteria?

*A) What SHOULD be – Standard, Policy, Best practice*

B) What is

C) No criteria

D) Audit report

*Ans: A* – Criteria = Standard – Condition = What is (actual).


*72.* Effect in audit finding means?

*A) Impact/Risk of finding – Financial, Reputational, Compliance*

B) No effect

C) Only cause

D) Audit fee

*Ans: A* – Effect shows materiality – Why management should fix.


*73.* Which evidence collection has observer bias risk?

*A) Observation – Hawthorne effect – People behave differently when watched*

B) Inspection

C) Re-performance

D) Document review

*Ans: A* – People change behavior when observed – So observation alone weak.


*74.* What is GAS?

*A) Generalized Audit Software – ACL, IDEA – For data analysis*

B) Gas audit

C) No software

D) Audit gas

*Ans: A* – GAS can read different file formats, do sampling, stratification.


*75.* Benford's Law used for?

*A) Detect fraud in numbers – Natural numbers follow Benford pattern – Anomaly indicates fraud*

B) No fraud detection

C) Only for math

D) Audit planning

*Ans: A* – Used in forensic analytics – Example: Expense claims fraud.


*76.* What is Code Review audit?

*A) Auditor reviews source code for vulnerabilities, backdoors, logic bombs*

B) No review

C) Only execution

D) Only output review

*Ans: A* – White box technique – Needs expertise.


*77.* Logic Bomb is?

*A) Malicious code triggered by specific condition – e.g., date, event*

B) No bomb

C) Audit bomb

D) Only hardware

*Ans: A* – Example: Code deletes data if employee terminated.


*78.* Who should have access to audit working papers?

*A) Only audit team and authorized reviewers – Confidential*

B) Everyone

C) Client's staff

D) Public

*Ans: A* – Working papers confidential – Protected.


*79.* Retention of audit working papers – As per ISACA?

*A) As per legal and organizational policy – Typically 5-7 years*

B) 1 day

C) No retention

D) Forever 1 month

*Ans: A* – Must comply with regulations.


*80.* What is Professional Skepticism?

*A) Questioning mind, critical assessment – Don't trust blindly, corroborate*

B) Trust everything client says

C) No skepticism

D) Only trust management

*Ans: A* – Core auditor mindset – Required by ISACA.


*81.* What is Independence in fact vs appearance?

*A) In fact = Actually independent – In appearance = Others perceive you independent – Both needed*

B) Only fact needed

C) Only appearance needed

D) No independence needed

*Ans: A* – If auditor appears non-independent (e.g., auditing own work), violates even if actually independent.


*82.* Can internal auditor audit area where he previously worked?

*A) Not within 12 months – Impairs independence – Cooling period needed*

B) Can audit immediately

C) Never can audit

D) No restriction

*Ans: A* – 12-month cooling – ISACA standard.


*83.* What is Co-sourcing vs Outsourcing of audit?

*A) Co-sourcing = Internal + External together – Outsourcing = Fully external firm does audit*

B) Same

C) No difference

D) Only co-sourcing used

*Ans: A* – Co-sourcing retains knowledge – Better.


*84.* What is Audit Universe?

*A) All auditable areas in organization – For annual audit planning*

B) One audit area

C) No universe

D) Only IT areas

*Ans: A* – List of all processes, systems, locations – Risk-ranked for annual plan.


*85.* Annual audit plan based on?

*A) Risk assessment of audit universe + Management request + Regulatory requirement*

B) Random

C) Only management request

D) Only regulatory

*Ans: A* – Risk-based annual plan – High-risk areas audited annually.


*86.* What is Engagement Letter?

*A) Formal agreement with auditee – Scope, objective, responsibilities, timelines*

B) No letter needed

C) Only oral agreement

D) Audit report

*Ans: A* – Protects both auditor and auditee – Prevents expectation gap.


*87.* Expectation Gap means?

*A) Difference between what auditee expects and what auditor delivers – Managed by engagement letter*

B) No gap

C) Audit fee gap

D) No meaning

*Ans: A* – Common gap – Auditee expects auditor to find all frauds – Not possible.


*88.* What is Walkthrough?

*A) Tracing one transaction from start to end to understand process and controls – First step before detailed testing*

B) Walking in office

C) No walkthrough

D) Audit report walk

*Ans: A* – One transaction walkthrough – Confirms process understanding.


*89.* Which is better – Preventive or Detective control?

*A) Preventive is better and cheaper – Prevents loss – But both needed – Defense in depth*

B) Detective better

C) No control better

D) Only corrective needed

*Ans: A* – Prevent > Detect > Correct – But need all layers.


*90.* Defense in Depth means?

*A) Multiple layers of controls – If one fails, other catches – e.g., Firewall + IDS + Access control*

B) One control enough

C) No defense

D) Only preventive

*Ans: A* – Layered controls – Core security principle.


*91.* What is Compensating control for lack of SoD in small company?

*A) Manager review, Audit trail review, Independent reconciliation*

B) No control

C) Ignore SoD

D) Only one person does all

*Ans: A* – Small company cannot segregate – Compensating = Supervisory review.


*92.* What is Audit Evidence sufficiency vs appropriateness?

*A) Sufficiency = Quantity – Enough evidence – Appropriateness = Quality – Relevant and Reliable*

B) Same

C) No difference

D) Only quantity matters

*Ans: A* – Need both sufficient AND appropriate – More quantity cannot compensate poor quality.


*93.* When auditor finds fraud, what should do FIRST?

*A) Inform appropriate level – Audit Committee / Board – Not necessarily management if management involved – Preserve evidence*

B) Tell everyone

C) Ignore

D) Delete evidence

*Ans: A* – If fraud by management, inform Board/Audit Committee – Not management – Also preserve chain of custody.


*94.* What is Whistleblower mechanism?

*A) Anonymous reporting channel for fraud/ethics violations – Auditor should test its existence and effectiveness*

B) No mechanism

C) Only for HR

D) Not for audit

*Ans: A* – SOX requires whistleblower hotline – Auditor tests it.


*95.* What is Fraud Triangle?

*A) Pressure, Opportunity, Rationalization – All three needed for fraud – Auditor looks for these*

B) No triangle

C) Only pressure

D) Only opportunity

*Ans: A* – CISA/CIA important – Opportunity = Weak controls – What auditor can reduce.


*96.* What is Fraud Diamond adds 4th element?

*A) Capability – Person must have skill to commit fraud*

B) No diamond

C) Only triangle needed

D) Pressure only

*Ans: A* – Triangle + Capability = Diamond – High capability person (e.g., IT admin) more risk.


*97.* What is Continuous Auditing benefit?

*A) Real-time assurance, Early detection, Reduced audit cost over time, 100% population testing*

B) No benefit

C) Only manual benefit

D) Yearly audit benefit

*Ans: A* – Enables 100% testing vs sampling – Future of audit.


*98.* What is Risk Assessment Matrix used for?

*A) Prioritize risks based on Likelihood x Impact – Heat map*

B) No matrix

C) Only for audit fee

D) Only for planning

*Ans: A* – High likelihood high impact = Red – Audit first.


*99.* What is Control Matrix?

*A) Maps risks to controls – Shows which control mitigates which risk – Identifies gaps*

B) No matrix

C) Only risk matrix

D) Audit matrix

*Ans: A* – If risk has no control = Gap – If control has no risk = Redundant.


*100.* What is FINAL step in IS Audit Process (Domain 1)?

*A) Follow-up and Issue closure – Verify remediation – Then close audit*

B) Start new audit without follow-up

C) No final step

D) Only report

*Ans: A* – Audit not complete until follow-up – ISACA requires follow-up.


www.gmsisuccess.in