Thursday, October 8, 2026

100 MCQs – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based


100 MCQs – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based First solve & then check ✔️ yourself..Answers provided at the end.

As per ISACA New Syllabus – All keywords covered: Audit Charter, Standards, Risk Assessment, Planning, Evidence, Materiality, Control, Sampling.


*1.* What is the PRIMARY purpose of IS Audit Charter?

*A) Define authority, responsibility of audit function*

B) Define audit plan

C) List audit findings

D) Define IT policy

*Ans: 

*2.* Who should approve IS Audit Charter?

*A) Board / Audit Committee*

B) CIO

C) IT Manager

D) External Auditor

*Ans:

*3.* ISACA IS Auditing Standards are mandatory for?

*A) All IS audits*

B) Only external audits

C) Only internal audits

D) Optional

*Ans:


*4.* What is Risk-Based Auditing?

*A) Audit based on risk assessment*

B) Audit all systems equally

C) Audit only financial systems

D) Audit only when fraud occurs

*Ans: 


*5.* Inherent Risk is?

*A) Risk before controls*

B) Risk after controls

C) Risk of auditor not detecting

D) Risk of control failure

*Ans: 


*6.* Residual Risk = ?

*A) Inherent Risk – Control effectiveness*

B) Inherent + Control Risk

C) Audit Risk

D) Detection Risk

*Ans: 


*7.* Which risk does auditor control directly?

*A) Detection Risk*

B) Inherent Risk

C) Control Risk

D) Business Risk

*Ans: 

*8.* Audit Risk = Inherent Risk x Control Risk x ?

*A) Detection Risk*

B) Residual Risk

C) Business Risk

D) Audit Risk

*Ans:


*9.* Materiality in IS Audit means?

*A) Significance of finding to business*

B) Amount in financial statement

C) Number of records

D) Audit fee

*Ans:

*10.* First step in IS Audit Planning?

*A) Understand business, its risks and processes*

B) Start testing controls

C) Issue report

D) Collect evidence

*Ans:


*11.* Which document defines scope, objective, timing of audit?

*A) Audit Plan / Engagement Letter*

B) Audit Charter

C) Audit Report

D) Risk Register

*Ans:


*12.* What is Audit Program?

*A) Detailed steps to achieve audit objectives*

B) Software program

C) Audit charter

D) Audit report

*Ans:.


*13.* Evidence is MOST reliable when?

*A) Directly obtained by auditor, from independent source, original*

B) From client copy

C) Oral evidence only

D) Internal evidence only

*Ans: 

*14.* Which is MOST reliable audit evidence?

*A) Auditor's direct observation*

B) Client's internal memo

C) Photocopy of document

D) Oral statement by client

*Ans:.


*15.* Sampling Risk is?

*A) Conclusion from sample differs from population*

B) All records are wrong

C) Auditor fails to sample

D) No risk

*Ans:

*16.* Alpha Risk (Type I) means?

*A) Auditor says control works when it does not*

B) Auditor says control does not work when it actually works – False negative

C) No risk

D) Inherent risk

*Ans: .


*17.* Beta Risk (Type II) in IS Audit is?

*A) Auditor concludes control effective when it is ineffective – More dangerous*

B) Auditor concludes ineffective when effective

C) No risk

D) Sampling correct

*Ans:

*18.* Best sampling method for fraud detection?

*A) Discovery / Directed Sampling*

B) Statistical sampling

C) Random sampling

D) Haphazard sampling

*Ans: 

*19.* When population has high variance, which sampling?

*A) Stratified Sampling*

B) Simple Random

C) Systematic

D) Judgmental

*Ans: 

*20.* CAATs stands for?

*A) Computer Assisted Audit Techniques*

B) Computer Audit Tools

C) Control Audit Techniques

D) Compliance Audit Tools

*Ans: 

*21.* Which CAAT is used to test calculation without affecting live data?

*A) Test Data / Base Case System Evaluation*

B) Parallel Simulation

C) Embedded Audit Module

D) GAS

*Ans: 


*22.* Continuous Auditing uses?

*A) Embedded Audit Module / SCARF*

B) Manual auditing

C) Year-end audit only

D) No technology

*Ans: 


*23.* What is SCARF?

*A) System Control Audit Review File – Embedded module that collects suspicious transactions*

B) Audit software

C) Risk file

D) Report file

*Ans


*24.* Audit Hook is?

*A) Code that triggers when specific condition met – Red flag*

B) Fishing technique

C) Audit report

D) Audit plan

*Ans:


*25.* Which controls to test FIRST in risk-based audit?

*A) Entity-level / General Controls (GITC)*

B) Application controls

C) No controls

D) Only manual controls

*Ans:

*26.* Which is Preventive Control?

*A) Segregation of Duties, Access Control, Authorization*

B) Reconciliation

C) Log review

D) Backup review

*Ans: 


*27.* Detective Control is?

*A) Log monitoring, Reconciliation, Review*

B) Access control

C) Firewalls

D) Encryption

*Ans:


*28.* Corrective Control is?

*A) Backup restore, Contingency plan, Patching*

B) Access control

C) Authorization

D) Reconciliation

*Ans:


*29.* Compensating Control is used when?

*A) Primary control fails or not cost-effective – Alternative control*

B) No control needed

C) All controls fail

D) Only preventive needed

*Ans:


*30.* Segregation of Duties violation is?

*A) One person can commit and conceal fraud – Developer in Production*

B) Two persons share password

C) Manager reviews report

D) No violation

*Ans:

*31.* What should auditor do if Inherent Risk is High?

*A) Increase substantive testing, reduce detection risk*

B) Reduce testing

C) Do nothing

D) Issue clean report

*Ans: .


*32.* Control Risk is high when?

*A) Controls are weak / not designed properly*

B) Controls are strong

C) Auditor is weak

D) No risk

*Ans:

*33.* Evidence collection method for compliance?

*A) Observation, Inquiry, Inspection, Re-performance*

B) Only inquiry

C) Only observation

D) No method

*Ans: 

*34.* Inquiry as audit evidence is?

*A) Weakest – Needs corroboration*

B) Strongest

C) Sufficient alone

D) Not evidence

*Ans:


*35.* Which is substantive test?

*A) Test of details of transactions, balances, analytical procedures*

B) Test of control design

C) Test of control operating effectiveness

D) No test

*Ans.


*36.* What is Compliance Test?

*A) Test if control is operating effectively – Test of Controls*

B) Test of balances

C) Test of details

D) Analytical test

*Ans:


*37.* Tolerable Error in sampling means?

*A) Max error auditor can accept and still say control effective / balance correct*

B) No error allowed

C) All errors allowed

D) Sampling error

*Ans: 

*38.* Confidence Level 95% means?

*A) 95% chance sample represents population – 5% sampling risk*

B) 100% correct

C) 5% correct

D) No confidence

*Ans:

*39.* Which sampling does NOT use statistics?

*A) Judgmental / Non-statistical sampling*

B) Variable sampling

C) Attribute sampling

D) Stratified sampling

*Ans

*40.* When to use 100% examination instead of sampling?

*A) Population small, High risk, Forensic audit*

B) Always sampling

C) Never 100%

D) Only for low risk

*Ans: 


*41.* What is Audit Trail?

*A) Chronological record to trace transaction from source to final – For reconstruction*

B) Audit report

C) Audit plan

D) No trail

*Ans: 


*42.* Which ISACA guideline says auditor must be independent?

*A) Independence and Objectivity – 2nd Standard*

B) No guideline

C) Audit Charter only

D) Management guideline

*Ans: 

*43.* Internal Audit reporting to CIO violates?

*A) Independence – Should report to Board/Audit Committee*

B) No violation

C) Good practice

D) Required

*Ans:

*44.* Follow-up audit is done to?

*A) Verify management implemented audit recommendations*

B) Do new audit

C) Close audit file

D) No follow-up needed

*Ans: 

*45.* Audit Documentation should contain?

*A) Plan, Program, Evidence, Findings, Report – Enough for another auditor to understand*

B) Only report

C) Only plan

D) No documentation needed

*Ans: 

*46.* What is Snapshot?

*A) Record of system at point in time for audit – Before/After image*

B) Photo

C) Audit report

D) No meaning

*Ans

*47.* Integrated Auditing means?

*A) Combined financial, operational and IS audit*

B) Only IS audit

C) Only financial audit

D) No integration

*Ans: 


*48.* Control Self-Assessment (CSA) is?

*A) Management self-assesses controls – Auditor facilitates*

B) Auditor assesses controls

C) No self-assessment

D) External audit

*Ans:

*49.* What is Benchmarking in audit?

*A) Compare control/process with best practice or industry standard*

B) No comparison

C) Only internal compare

D) Audit fee compare

*Ans:.


*50.* Maturity Model used in audit to?

*A) Assess maturity of process – 0-5 levels – e.g., COBIT, CMM*

B) Assess audit fee

C) No use

D) Only for software

*Ans:

*51.* COBIT is used for?

*A) IT Governance and Management framework – For audit planning*

B) Only for coding

C) Only for hardware

D) No use

*Ans:

*52.* What is Risk Appetite vs Risk Tolerance already covered – Which is broader?

*A) Risk Appetite broader – Tolerance specific limit*

B) Tolerance broader

C) Same

D) No relation

*Ans:

*53.* Business Impact Analysis (BIA) is used for?

*A) Identify critical processes and impact of disruption – For audit prioritization*

B) Audit fee

C) No use

D) Only for BCP

*Ans: 


*54.* Which is MOST important for audit planning?

*A) Risk Assessment and Business Understanding*

B) Audit software

C) Audit fee

D) Auditor name

*Ans:


*55.* Analytical Procedures in IS Audit?

*A) Compare trends, ratios, reasonableness – e.g., Log review trends, CPU usage trends*

B) No analytics

C) Only financial analytics

D) No need

*Ans:

*56.* What is KRI?

*A) Key Risk Indicator – Early warning of increasing risk*

B) Key Result Indicator

C) No indicator

D) Audit indicator

*Ans: 

*57.* What is KPI?

*A) Key Performance Indicator – Past performance achieved*

B) Risk indicator

C) No indicator

D) Control indicator

*Ans: 


*58.* Auditing BYOD policy – What is first step?

*A) Understand BYOD policy, risks, MDM controls*

B) Test MDM directly

C) Ignore BYOD

D) Issue report

*Ans:


*59.* Cloud audit – Who is responsible for data?

*A) Client ultimately responsible even if data in cloud – Cannot outsource accountability*

B) Cloud provider fully responsible

C) No one responsible

D) Auditor responsible

*Ans:


*60.* Continuous Auditing vs Continuous Monitoring – Difference?

*A) Auditing = Done by Auditor – Monitoring = Done by Management*

B) Same

C) No difference

D) Both by management

*Ans: 

*61.* What is Forensic Audit objective?

*A) Collect evidence acceptable in court – Chain of custody critical*

B) Regular audit

C) Financial audit only

D) No objective

*Ans:.


*62.* Chain of Custody means?

*A) Document who handled evidence, when, where – To prove integrity in court*

B) No chain

C) Audit chain

D) Supply chain

*Ans:

*63.* What is Due Diligence audit?

*A) Pre-merger/acquisition audit to assess risks and controls of target*

B) No diligence

C) Regular audit

D) Only financial

*Ans:

*64.* Which audit technique uses dummy entity?

*A) Integrated Test Facility (ITF) – Dummy master file record – e.g., Dummy vendor*

B) Test data

C) No technique

D) Parallel simulation

*Ans: 



*65.* Parallel Simulation means?

*A) Auditor's program re-processes client's data and compares results*

B) Client's program re-processes

C) No simulation

D) Only manual

*Ans:

*66.* White Box vs Black Box testing – White Box?

*A) Auditor knows internal logic/code – Tests logic*

B) Does not know internal logic – Tests input/output

C) No testing

D) Only black box used

*Ans:


*67.* When to use Black Box audit?

*A) When auditor does not have access to code – Tests functionality*

B) Always white box

C) Never black box

D) Only for code review

*Ans:


*68.* What is Material weakness vs Significant deficiency?

*A) Material weakness = Reasonable possibility of material misstatement not prevented – More severe – Must report to Board*

B) Same

C) Significant more severe

D) No difference

*Ans:


*69.* Audit Report should be?

*A) Clear, Concise, Objective, Timely, Supported by evidence – With risk and recommendation*

B) Long and confusing

C) No recommendation

D) Only findings

*Ans:

*70.* Finding should include?

*A) Criteria, Condition, Cause, Effect, Recommendation (CC CER)*

B) Only condition

C) Only criteria

D) No structure

*Ans:


*71.* What is Criteria?

*A) What SHOULD be – Standard, Policy, Best practice*

B) What is

C) No criteria

D) Audit report

*Ans:


*72.* Effect in audit finding means?

*A) Impact/Risk of finding – Financial, Reputational, Compliance*

B) No effect

C) Only cause

D) Audit fee

*Ans:


*73.* Which evidence collection has observer bias risk?

*A) Observation – Hawthorne effect – People behave differently when watched*

B) Inspection

C) Re-performance

D) Document review

*Ans: 


*74.* What is GAS?

*A) Generalized Audit Software – ACL, IDEA – For data analysis*

B) Gas audit

C) No software

D) Audit gas

*Ans:


*75.* Benford's Law used for?

*A) Detect fraud in numbers – Natural numbers follow Benford pattern – Anomaly indicates fraud*

B) No fraud detection

C) Only for math

D) Audit planning

*Ans:.


*76.* What is Code Review audit?

*A) Auditor reviews source code for vulnerabilities, backdoors, logic bombs*

B) No review

C) Only execution

D) Only output review

*Ans: 


*77.* Logic Bomb is?

*A) Malicious code triggered by specific condition – e.g., date, event*

B) No bomb

C) Audit bomb

D) Only hardware

*Ans:


*78.* Who should have access to audit working papers?

*A) Only audit team and authorized reviewers – Confidential*

B) Everyone

C) Client's staff

D) Public

*Ans: 


*79.* Retention of audit working papers – As per ISACA?

*A) As per legal and organizational policy – Typically 5-7 years*

B) 1 day

C) No retention

D) Forever 1 month

*Ans:


*80.* What is Professional Skepticism?

*A) Questioning mind, critical assessment – Don't trust blindly, corroborate*

B) Trust everything client says

C) No skepticism

D) Only trust management

*Ans:

*81.* What is Independence in fact vs appearance?

*A) In fact = Actually independent – In appearance = Others perceive you independent – Both needed*

B) Only fact needed

C) Only appearance needed

D) No independence needed

*Ans:.


*82.* Can internal auditor audit area where he previously worked?

*A) Not within 12 months – Impairs independence – Cooling period needed*

B) Can audit immediately

C) Never can audit

D) No restriction

*Ans: 


*83.* What is Co-sourcing vs Outsourcing of audit?

*A) Co-sourcing = Internal + External together – Outsourcing = Fully external firm does audit*

B) Same

C) No difference

D) Only co-sourcing used

*Ans


*84.* What is Audit Universe?

*A) All auditable areas in organization – For annual audit planning*

B) One audit area

C) No universe

D) Only IT areas

*Ans:.


*85.* Annual audit plan based on?

*A) Risk assessment of audit universe + Management request + Regulatory requirement*

B) Random

C) Only management request

D) Only regulatory

*Ans: 


*86.* What is Engagement Letter?

*A) Formal agreement with auditee – Scope, objective, responsibilities, timelines*

B) No letter needed

C) Only oral agreement

D) Audit report

*Ans:


*87.* Expectation Gap means?

*A) Difference between what auditee expects and what auditor delivers – Managed by engagement letter*

B) No gap

C) Audit fee gap

D) No meaning

*Ans:

*88.* What is Walkthrough?

*A) Tracing one transaction from start to end to understand process and controls – First step before detailed testing*

B) Walking in office

C) No walkthrough

D) Audit report walk

*Ans:


*89.* Which is better – Preventive or Detective control?

*A) Preventive is better and cheaper – Prevents loss – But both needed – Defense in depth*

B) Detective better

C) No control better

D) Only corrective needed

*Ans: 


*90.* Defense in Depth means?

*A) Multiple layers of controls – If one fails, other catches – e.g., Firewall + IDS + Access control*

B) One control enough

C) No defense

D) Only preventive

*Ans:


*91.* What is Compensating control for lack of SoD in small company?

*A) Manager review, Audit trail review, Independent reconciliation*

B) No control

C) Ignore SoD

D) Only one person does all

*Ans:

*92.* What is Audit Evidence sufficiency vs appropriateness?

*A) Sufficiency = Quantity – Enough evidence – Appropriateness = Quality – Relevant and Reliable*

B) Same

C) No difference

D) Only quantity matters

*Ans


*93.* When auditor finds fraud, what should do FIRST?

*A) Inform appropriate level – Audit Committee / Board – Not necessarily management if management involved – Preserve evidence*

B) Tell everyone

C) Ignore

D) Delete evidence

*Ans

*94.* What is Whistleblower mechanism?

*A) Anonymous reporting channel for fraud/ethics violations – Auditor should test its existence and effectiveness*

B) No mechanism

C) Only for HR

D) Not for audit

*Ans: 


*95.* What is Fraud Triangle?

*A) Pressure, Opportunity, Rationalization – All three needed for fraud – Auditor looks for these*

B) No triangle

C) Only pressure

D) Only opportunity

*Ans:

*96.* What is Fraud Diamond adds 4th element?

*A) Capability – Person must have skill to commit fraud*

B) No diamond

C) Only triangle needed

D) Pressure only

*Ans:

*97.* What is Continuous Auditing benefit?

*A) Real-time assurance, Early detection, Reduced audit cost over time, 100% population testing*

B) No benefit

C) Only manual benefit

D) Yearly audit benefit

*Ans:


*98.* What is Risk Assessment Matrix used for?

*A) Prioritize risks based on Likelihood x Impact – Heat map*

B) No matrix

C) Only for audit fee

D) Only for planning

*Ans: 


*99.* What is Control Matrix?

*A) Maps risks to controls – Shows which control mitigates which risk – Identifies gaps*

B) No matrix

C) Only risk matrix

D) Audit matrix

*Ans


*100.* What is FINAL step in IS Audit Process (Domain 1)?

*A) Follow-up and Issue closure – Verify remediation – Then close audit*

B) Start new audit without follow-up

C) No final step

D) Only report

*Ans:


ANSWERS:

100 MCQs with Answers + Explanation – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based*


As per ISACA New Syllabus – All keywords covered: Audit Charter, Standards, Risk Assessment, Planning, Evidence, Materiality, Control, Sampling.


*1.* What is the PRIMARY purpose of IS Audit Charter?

*A) Define authority, responsibility of audit function*

B) Define audit plan

C) List audit findings

D) Define IT policy

*Ans: A* – Charter gives mandate from Board/Audit Committee – Without charter, audit has no authority.


*2.* Who should approve IS Audit Charter?

*A) Board / Audit Committee*

B) CIO

C) IT Manager

D) External Auditor

*Ans: A* – Independence – Board/Audit Committee approves.


*3.* ISACA IS Auditing Standards are mandatory for?

*A) All IS audits*

B) Only external audits

C) Only internal audits

D) Optional

*Ans: A* – ISACA Standards mandatory for all CISA holders.


*4.* What is Risk-Based Auditing?

*A) Audit based on risk assessment*

B) Audit all systems equally

C) Audit only financial systems

D) Audit only when fraud occurs

*Ans: A* – Focus on high-risk areas – Efficient audit.


*5.* Inherent Risk is?

*A) Risk before controls*

B) Risk after controls

C) Risk of auditor not detecting

D) Risk of control failure

*Ans: A* – Gross risk – Before any controls.


*6.* Residual Risk = ?

*A) Inherent Risk – Control effectiveness*

B) Inherent + Control Risk

C) Audit Risk

D) Detection Risk

*Ans: A* – Net risk after controls – What audit tests.


*7.* Which risk does auditor control directly?

*A) Detection Risk*

B) Inherent Risk

C) Control Risk

D) Business Risk

*Ans: A* – Auditor can reduce detection risk by more substantive testing.


*8.* Audit Risk = Inherent Risk x Control Risk x ?

*A) Detection Risk*

B) Residual Risk

C) Business Risk

D) Audit Risk

*Ans: A* – Classic audit risk model.


*9.* Materiality in IS Audit means?

*A) Significance of finding to business*

B) Amount in financial statement

C) Number of records

D) Audit fee

*Ans: A* – Impact on business objectives, not just amount.


*10.* First step in IS Audit Planning?

*A) Understand business, its risks and processes*

B) Start testing controls

C) Issue report

D) Collect evidence

*Ans: A* – Understand business is always first.


*11.* Which document defines scope, objective, timing of audit?

*A) Audit Plan / Engagement Letter*

B) Audit Charter

C) Audit Report

D) Risk Register

*Ans: A* – Audit Plan defines scope, objective, resources.


*12.* What is Audit Program?

*A) Detailed steps to achieve audit objectives*

B) Software program

C) Audit charter

D) Audit report

*Ans: A* – Step-by-step procedures – Prepared after planning.


*13.* Evidence is MOST reliable when?

*A) Directly obtained by auditor, from independent source, original*

B) From client copy

C) Oral evidence only

D) Internal evidence only

*Ans: A* – External + Direct + Original = Most reliable.


*14.* Which is MOST reliable audit evidence?

*A) Auditor's direct observation*

B) Client's internal memo

C) Photocopy of document

D) Oral statement by client

*Ans: A* – Direct observation > External doc > Internal doc > Oral.


*15.* Sampling Risk is?

*A) Conclusion from sample differs from population*

B) All records are wrong

C) Auditor fails to sample

D) No risk

*Ans: A* – Sample not representative – 2 types: Alpha and Beta risk.


*16.* Alpha Risk (Type I) means?

*A) Auditor says control works when it does not*

B) Auditor says control does not work when it actually works – False negative

C) No risk

D) Inherent risk

*Ans: B* – In audit, Beta risk (False assurance) is more dangerous than Alpha.


*17.* Beta Risk (Type II) in IS Audit is?

*A) Auditor concludes control effective when it is ineffective – More dangerous*

B) Auditor concludes ineffective when effective

C) No risk

D) Sampling correct

*Ans: A* – Beta = Wrong assurance – Leads to audit failure.


*18.* Best sampling method for fraud detection?

*A) Discovery / Directed Sampling*

B) Statistical sampling

C) Random sampling

D) Haphazard sampling

*Ans: A* – Discovery sampling for fraud – Look for one occurrence.


*19.* When population has high variance, which sampling?

*A) Stratified Sampling*

B) Simple Random

C) Systematic

D) Judgmental

*Ans: A* – Divide population into strata (high value, low value) – Reduces variance.


*20.* CAATs stands for?

*A) Computer Assisted Audit Techniques*

B) Computer Audit Tools

C) Control Audit Techniques

D) Compliance Audit Tools

*Ans: A* – Tools like ACL, IDEA, Excel – Used for data analysis.


*21.* Which CAAT is used to test calculation without affecting live data?

*A) Test Data / Base Case System Evaluation*

B) Parallel Simulation

C) Embedded Audit Module

D) GAS

*Ans: A* – Test data into copy of production – Does not affect live.


*22.* Continuous Auditing uses?

*A) Embedded Audit Module / SCARF*

B) Manual auditing

C) Year-end audit only

D) No technology

*Ans: A* – Continuous monitoring – SCARF, EAM, Audit Hooks.


*23.* What is SCARF?

*A) System Control Audit Review File – Embedded module that collects suspicious transactions*

B) Audit software

C) Risk file

D) Report file

*Ans: A* – EAM + SCARF = Collects transactions for audit.


*24.* Audit Hook is?

*A) Code that triggers when specific condition met – Red flag*

B) Fishing technique

C) Audit report

D) Audit plan

*Ans: A* – Example: Trigger when salary > $10,000.


*25.* Which controls to test FIRST in risk-based audit?

*A) Entity-level / General Controls (GITC)*

B) Application controls

C) No controls

D) Only manual controls

*Ans: A* – If GITC fails, all application controls unreliable – Test GITC first.


*26.* Which is Preventive Control?

*A) Segregation of Duties, Access Control, Authorization*

B) Reconciliation

C) Log review

D) Backup review

*Ans: A* – Prevents error – Detective = Reconciliation, Log review.


*27.* Detective Control is?

*A) Log monitoring, Reconciliation, Review*

B) Access control

C) Firewalls

D) Encryption

*Ans: A* – Detects after occurrence.


*28.* Corrective Control is?

*A) Backup restore, Contingency plan, Patching*

B) Access control

C) Authorization

D) Reconciliation

*Ans: A* – Corrects after detection.


*29.* Compensating Control is used when?

*A) Primary control fails or not cost-effective – Alternative control*

B) No control needed

C) All controls fail

D) Only preventive needed

*Ans: A* – Example: If SoD not possible in small company, manager review = compensating.


*30.* Segregation of Duties violation is?

*A) One person can commit and conceal fraud – Developer in Production*

B) Two persons share password

C) Manager reviews report

D) No violation

*Ans: A* – Core SoD failure – Most common audit finding.


*31.* What should auditor do if Inherent Risk is High?

*A) Increase substantive testing, reduce detection risk*

B) Reduce testing

C) Do nothing

D) Issue clean report

*Ans: A* – High inherent = More audit work.


*32.* Control Risk is high when?

*A) Controls are weak / not designed properly*

B) Controls are strong

C) Auditor is weak

D) No risk

*Ans: A* – High control risk = Cannot rely on controls – Do substantive testing.


*33.* Evidence collection method for compliance?

*A) Observation, Inquiry, Inspection, Re-performance*

B) Only inquiry

C) Only observation

D) No method

*Ans: A* – Four methods – Re-performance most reliable.


*34.* Inquiry as audit evidence is?

*A) Weakest – Needs corroboration*

B) Strongest

C) Sufficient alone

D) Not evidence

*Ans: A* – Oral evidence alone insufficient – Must corroborate.


*35.* Which is substantive test?

*A) Test of details of transactions, balances, analytical procedures*

B) Test of control design

C) Test of control operating effectiveness

D) No test

*Ans: A* – Substantive proves dollar amount correct – Control test proves control works.


*36.* What is Compliance Test?

*A) Test if control is operating effectively – Test of Controls*

B) Test of balances

C) Test of details

D) Analytical test

*Ans: A* – Compliance = Control testing.


*37.* Tolerable Error in sampling means?

*A) Max error auditor can accept and still say control effective / balance correct*

B) No error allowed

C) All errors allowed

D) Sampling error

*Ans: A* – If error > tolerable, control ineffective.


*38.* Confidence Level 95% means?

*A) 95% chance sample represents population – 5% sampling risk*

B) 100% correct

C) 5% correct

D) No confidence

*Ans: A* – Higher confidence = Larger sample.


*39.* Which sampling does NOT use statistics?

*A) Judgmental / Non-statistical sampling*

B) Variable sampling

C) Attribute sampling

D) Stratified sampling

*Ans: A* – Auditor judgment – Cannot measure sampling risk – But allowed.


*40.* When to use 100% examination instead of sampling?

*A) Population small, High risk, Forensic audit*

B) Always sampling

C) Never 100%

D) Only for low risk

*Ans: A* – For small high-risk populations, examine all.


*41.* What is Audit Trail?

*A) Chronological record to trace transaction from source to final – For reconstruction*

B) Audit report

C) Audit plan

D) No trail

*Ans: A* – Must be enabled – If no audit trail = Control failure.


*42.* Which ISACA guideline says auditor must be independent?

*A) Independence and Objectivity – 2nd Standard*

B) No guideline

C) Audit Charter only

D) Management guideline

*Ans: A* – Organizational independence – Report to Audit Committee, not to CIO.


*43.* Internal Audit reporting to CIO violates?

*A) Independence – Should report to Board/Audit Committee*

B) No violation

C) Good practice

D) Required

*Ans: A* – Reporting to CIO impairs independence – Major finding.


*44.* Follow-up audit is done to?

*A) Verify management implemented audit recommendations*

B) Do new audit

C) Close audit file

D) No follow-up needed

*Ans: A* – Required by ISACA – Auditor must follow up.


*45.* Audit Documentation should contain?

*A) Plan, Program, Evidence, Findings, Report – Enough for another auditor to understand*

B) Only report

C) Only plan

D) No documentation needed

*Ans: A* – Working papers – Retention as per policy.


*46.* What is Snapshot?

*A) Record of system at point in time for audit – Before/After image*

B) Photo

C) Audit report

D) No meaning

*Ans: A* – Used to verify processing – Before and after processing image.


*47.* Integrated Auditing means?

*A) Combined financial, operational and IS audit*

B) Only IS audit

C) Only financial audit

D) No integration

*Ans: A* – Team with financial + IT auditors – Best for application controls.


*48.* Control Self-Assessment (CSA) is?

*A) Management self-assesses controls – Auditor facilitates*

B) Auditor assesses controls

C) No self-assessment

D) External audit

*Ans: A* – CSA workshop – But auditor must not own controls – Independence risk.


*49.* What is Benchmarking in audit?

*A) Compare control/process with best practice or industry standard*

B) No comparison

C) Only internal compare

D) Audit fee compare

*Ans: A* – Example: Compare password policy with ISO 27001.


*50.* Maturity Model used in audit to?

*A) Assess maturity of process – 0-5 levels – e.g., COBIT, CMM*

B) Assess audit fee

C) No use

D) Only for software

*Ans: A* – 0 Non-existent to 5 Optimized – Shows gap.


*51.* COBIT is used for?

*A) IT Governance and Management framework – For audit planning*

B) Only for coding

C) Only for hardware

D) No use

*Ans: A* – COBIT 2019 – Main framework for IS Audit.


*52.* What is Risk Appetite vs Risk Tolerance already covered – Which is broader?

*A) Risk Appetite broader – Tolerance specific limit*

B) Tolerance broader

C) Same

D) No relation

*Ans: A* – Appetite = Board level broad, Tolerance = Management specific.


*53.* Business Impact Analysis (BIA) is used for?

*A) Identify critical processes and impact of disruption – For audit prioritization*

B) Audit fee

C) No use

D) Only for BCP

*Ans: A* – Auditor uses BIA to prioritize critical systems for audit.


*54.* Which is MOST important for audit planning?

*A) Risk Assessment and Business Understanding*

B) Audit software

C) Audit fee

D) Auditor name

*Ans: A* – Risk assessment drives audit plan.


*55.* Analytical Procedures in IS Audit?

*A) Compare trends, ratios, reasonableness – e.g., Log review trends, CPU usage trends*

B) No analytics

C) Only financial analytics

D) No need

*Ans: A* – Example: Login failures suddenly increased – Indicates attack.


*56.* What is KRI?

*A) Key Risk Indicator – Early warning of increasing risk*

B) Key Result Indicator

C) No indicator

D) Audit indicator

*Ans: A* – Example: Failed logins > 10 = KRI for brute force risk.


*57.* What is KPI?

*A) Key Performance Indicator – Past performance achieved*

B) Risk indicator

C) No indicator

D) Control indicator

*Ans: A* – KRI = Future risk, KPI = Past performance.


*58.* Auditing BYOD policy – What is first step?

*A) Understand BYOD policy, risks, MDM controls*

B) Test MDM directly

C) Ignore BYOD

D) Issue report

*Ans: A* – Always understand policy and risk first.


*59.* Cloud audit – Who is responsible for data?

*A) Client ultimately responsible even if data in cloud – Cannot outsource accountability*

B) Cloud provider fully responsible

C) No one responsible

D) Auditor responsible

*Ans: A* – Outsourcing responsibility but not accountability – Key CISA concept.


*60.* Continuous Auditing vs Continuous Monitoring – Difference?

*A) Auditing = Done by Auditor – Monitoring = Done by Management*

B) Same

C) No difference

D) Both by management

*Ans: A* – Auditor does auditing, Management does monitoring.


*61.* What is Forensic Audit objective?

*A) Collect evidence acceptable in court – Chain of custody critical*

B) Regular audit

C) Financial audit only

D) No objective

*Ans: A* – Preserve evidence, chain of custody, no tampering.


*62.* Chain of Custody means?

*A) Document who handled evidence, when, where – To prove integrity in court*

B) No chain

C) Audit chain

D) Supply chain

*Ans: A* – If chain broken, evidence not admissible.


*63.* What is Due Diligence audit?

*A) Pre-merger/acquisition audit to assess risks and controls of target*

B) No diligence

C) Regular audit

D) Only financial

*Ans: A* – Important for M&A – Check IT controls, licenses, security.


*64.* Which audit technique uses dummy entity?

*A) Integrated Test Facility (ITF) – Dummy master file record – e.g., Dummy vendor*

B) Test data

C) No technique

D) Parallel simulation

*Ans: A* – ITF tests live processing with dummy records – Must be removed.


*65.* Parallel Simulation means?

*A) Auditor's program re-processes client's data and compares results*

B) Client's program re-processes

C) No simulation

D) Only manual

*Ans: A* – Detects unauthorized logic in client's program.


*66.* White Box vs Black Box testing – White Box?

*A) Auditor knows internal logic/code – Tests logic*

B) Does not know internal logic – Tests input/output

C) No testing

D) Only black box used

*Ans: A* – White = With code knowledge, Black = Without code – Just input/output.


*67.* When to use Black Box audit?

*A) When auditor does not have access to code – Tests functionality*

B) Always white box

C) Never black box

D) Only for code review

*Ans: A* – Most IS audits are black box – Test controls, not code.


*68.* What is Material weakness vs Significant deficiency?

*A) Material weakness = Reasonable possibility of material misstatement not prevented – More severe – Must report to Board*

B) Same

C) Significant more severe

D) No difference

*Ans: A* – Material weakness > Significant deficiency > Deficiency.


*69.* Audit Report should be?

*A) Clear, Concise, Objective, Timely, Supported by evidence – With risk and recommendation*

B) Long and confusing

C) No recommendation

D) Only findings

*Ans: A* – Report structure: Executive summary, Findings, Risk, Recommendation, Response.


*70.* Finding should include?

*A) Criteria, Condition, Cause, Effect, Recommendation (CC CER)*

B) Only condition

C) Only criteria

D) No structure

*Ans: A* – 5 Cs for good finding.


*71.* What is Criteria?

*A) What SHOULD be – Standard, Policy, Best practice*

B) What is

C) No criteria

D) Audit report

*Ans: A* – Criteria = Standard – Condition = What is (actual).


*72.* Effect in audit finding means?

*A) Impact/Risk of finding – Financial, Reputational, Compliance*

B) No effect

C) Only cause

D) Audit fee

*Ans: A* – Effect shows materiality – Why management should fix.


*73.* Which evidence collection has observer bias risk?

*A) Observation – Hawthorne effect – People behave differently when watched*

B) Inspection

C) Re-performance

D) Document review

*Ans: A* – People change behavior when observed – So observation alone weak.


*74.* What is GAS?

*A) Generalized Audit Software – ACL, IDEA – For data analysis*

B) Gas audit

C) No software

D) Audit gas

*Ans: A* – GAS can read different file formats, do sampling, stratification.


*75.* Benford's Law used for?

*A) Detect fraud in numbers – Natural numbers follow Benford pattern – Anomaly indicates fraud*

B) No fraud detection

C) Only for math

D) Audit planning

*Ans: A* – Used in forensic analytics – Example: Expense claims fraud.


*76.* What is Code Review audit?

*A) Auditor reviews source code for vulnerabilities, backdoors, logic bombs*

B) No review

C) Only execution

D) Only output review

*Ans: A* – White box technique – Needs expertise.


*77.* Logic Bomb is?

*A) Malicious code triggered by specific condition – e.g., date, event*

B) No bomb

C) Audit bomb

D) Only hardware

*Ans: A* – Example: Code deletes data if employee terminated.


*78.* Who should have access to audit working papers?

*A) Only audit team and authorized reviewers – Confidential*

B) Everyone

C) Client's staff

D) Public

*Ans: A* – Working papers confidential – Protected.


*79.* Retention of audit working papers – As per ISACA?

*A) As per legal and organizational policy – Typically 5-7 years*

B) 1 day

C) No retention

D) Forever 1 month

*Ans: A* – Must comply with regulations.


*80.* What is Professional Skepticism?

*A) Questioning mind, critical assessment – Don't trust blindly, corroborate*

B) Trust everything client says

C) No skepticism

D) Only trust management

*Ans: A* – Core auditor mindset – Required by ISACA.


*81.* What is Independence in fact vs appearance?

*A) In fact = Actually independent – In appearance = Others perceive you independent – Both needed*

B) Only fact needed

C) Only appearance needed

D) No independence needed

*Ans: A* – If auditor appears non-independent (e.g., auditing own work), violates even if actually independent.


*82.* Can internal auditor audit area where he previously worked?

*A) Not within 12 months – Impairs independence – Cooling period needed*

B) Can audit immediately

C) Never can audit

D) No restriction

*Ans: A* – 12-month cooling – ISACA standard.


*83.* What is Co-sourcing vs Outsourcing of audit?

*A) Co-sourcing = Internal + External together – Outsourcing = Fully external firm does audit*

B) Same

C) No difference

D) Only co-sourcing used

*Ans: A* – Co-sourcing retains knowledge – Better.


*84.* What is Audit Universe?

*A) All auditable areas in organization – For annual audit planning*

B) One audit area

C) No universe

D) Only IT areas

*Ans: A* – List of all processes, systems, locations – Risk-ranked for annual plan.


*85.* Annual audit plan based on?

*A) Risk assessment of audit universe + Management request + Regulatory requirement*

B) Random

C) Only management request

D) Only regulatory

*Ans: A* – Risk-based annual plan – High-risk areas audited annually.


*86.* What is Engagement Letter?

*A) Formal agreement with auditee – Scope, objective, responsibilities, timelines*

B) No letter needed

C) Only oral agreement

D) Audit report

*Ans: A* – Protects both auditor and auditee – Prevents expectation gap.


*87.* Expectation Gap means?

*A) Difference between what auditee expects and what auditor delivers – Managed by engagement letter*

B) No gap

C) Audit fee gap

D) No meaning

*Ans: A* – Common gap – Auditee expects auditor to find all frauds – Not possible.


*88.* What is Walkthrough?

*A) Tracing one transaction from start to end to understand process and controls – First step before detailed testing*

B) Walking in office

C) No walkthrough

D) Audit report walk

*Ans: A* – One transaction walkthrough – Confirms process understanding.


*89.* Which is better – Preventive or Detective control?

*A) Preventive is better and cheaper – Prevents loss – But both needed – Defense in depth*

B) Detective better

C) No control better

D) Only corrective needed

*Ans: A* – Prevent > Detect > Correct – But need all layers.


*90.* Defense in Depth means?

*A) Multiple layers of controls – If one fails, other catches – e.g., Firewall + IDS + Access control*

B) One control enough

C) No defense

D) Only preventive

*Ans: A* – Layered controls – Core security principle.


*91.* What is Compensating control for lack of SoD in small company?

*A) Manager review, Audit trail review, Independent reconciliation*

B) No control

C) Ignore SoD

D) Only one person does all

*Ans: A* – Small company cannot segregate – Compensating = Supervisory review.


*92.* What is Audit Evidence sufficiency vs appropriateness?

*A) Sufficiency = Quantity – Enough evidence – Appropriateness = Quality – Relevant and Reliable*

B) Same

C) No difference

D) Only quantity matters

*Ans: A* – Need both sufficient AND appropriate – More quantity cannot compensate poor quality.


*93.* When auditor finds fraud, what should do FIRST?

*A) Inform appropriate level – Audit Committee / Board – Not necessarily management if management involved – Preserve evidence*

B) Tell everyone

C) Ignore

D) Delete evidence

*Ans: A* – If fraud by management, inform Board/Audit Committee – Not management – Also preserve chain of custody.


*94.* What is Whistleblower mechanism?

*A) Anonymous reporting channel for fraud/ethics violations – Auditor should test its existence and effectiveness*

B) No mechanism

C) Only for HR

D) Not for audit

*Ans: A* – SOX requires whistleblower hotline – Auditor tests it.


*95.* What is Fraud Triangle?

*A) Pressure, Opportunity, Rationalization – All three needed for fraud – Auditor looks for these*

B) No triangle

C) Only pressure

D) Only opportunity

*Ans: A* – CISA/CIA important – Opportunity = Weak controls – What auditor can reduce.


*96.* What is Fraud Diamond adds 4th element?

*A) Capability – Person must have skill to commit fraud*

B) No diamond

C) Only triangle needed

D) Pressure only

*Ans: A* – Triangle + Capability = Diamond – High capability person (e.g., IT admin) more risk.


*97.* What is Continuous Auditing benefit?

*A) Real-time assurance, Early detection, Reduced audit cost over time, 100% population testing*

B) No benefit

C) Only manual benefit

D) Yearly audit benefit

*Ans: A* – Enables 100% testing vs sampling – Future of audit.


*98.* What is Risk Assessment Matrix used for?

*A) Prioritize risks based on Likelihood x Impact – Heat map*

B) No matrix

C) Only for audit fee

D) Only for planning

*Ans: A* – High likelihood high impact = Red – Audit first.


*99.* What is Control Matrix?

*A) Maps risks to controls – Shows which control mitigates which risk – Identifies gaps*

B) No matrix

C) Only risk matrix

D) Audit matrix

*Ans: A* – If risk has no control = Gap – If control has no risk = Redundant.


*100.* What is FINAL step in IS Audit Process (Domain 1)?

*A) Follow-up and Issue closure – Verify remediation – Then close audit*

B) Start new audit without follow-up

C) No final step

D) Only report

*Ans: A* – Audit not complete until follow-up – ISACA requires follow-up.


www.gmsisuccess.in