_Domain 1 Weight: 17% | Focus: IS Audit Standards, Risk Assessment, Audit Planning_
Section A...
*CASE STUDY: FinBank Digital Transformation*
FinBank is rolling out a new mobile banking app and migrating customer data to a public cloud. The CIO hired an external vendor for development. The Board asked the Internal Audit department to conduct an IS audit before go-live. The CISA auditor has 3 weeks to complete the audit.
*Q1. Audit Planning & Risk Assessment*
*Q*: During audit planning, what should the CISA auditor do FIRST to determine audit scope?
A. Begin testing application controls in the mobile app
B. *Perform a risk assessment to identify high-risk areas*
C. Send an engagement letter to the external vendor
D. Review last year’s financial audit report
*Answer:
*Q2. Audit Charter & Independence*
*Q*: To ensure independence, which document must the auditor review before starting the audit?
A. SDLC Documentation
B. *IS Audit Charter approved by the Board/Audit Committee*
C. Vendor SLA
D. Business Continuity Plan
*Answer:
*Q3. Materiality & Audit Objective*
*Q*: The primary objective of this pre-go-live IS audit should be to:
A. Identify all coding bugs in the mobile app
B. *Provide reasonable assurance that risks related to confidentiality, integrity, and availability are managed*
C. Recommend a cheaper cloud vendor
D. Test user password complexity only
*Answer:
*Q4. Evidence & Sampling*
*Q*: Due to the 3-week timeline, the auditor decides to test 50 out of 10,000 cloud access logs. This approach is called:
A. 100% Testing
B. *Audit Sampling*
C. Continuous Auditing
D. Walkthrough
*Answer:
*Q5. Third-Party Risk & Audit Standards*
*Q*: The vendor is managing the cloud infrastructure. Which ISACA standard requires the auditor to assess the vendor’s controls?
A. 1201 Audit Evidence
B. *1401 Third-Party Management*
C. 1207 Irregularities and Illegal Acts
D. 1001 Audit Charter
*Answer:
*Q6. Audit Finding & Reporting*
*Q*: The auditor finds "No encryption for customer PII in cloud storage". What is the MOST appropriate next step?
A. Immediately shut down the mobile app
B. *Discuss the finding with management to confirm facts and get management response*
C. Report directly to regulators
D. Ignore it as it is the vendor’s responsibility
*Answer:
*Q7. Follow-up*
*Q*: 6 months after the audit, what is the auditor’s responsibility regarding the encryption finding?
A. No responsibility after report is issued
B. *Perform follow-up to determine if management implemented corrective action*
C. Wait for external audit to check
D. Re-audit the entire application
*Answer:
*DOMAIN 1 KEY CONCEPTS TO REMEMBER FOR CISA*
**Topic** **Key Point**
**Audit Process** Plan → Risk Assessment → Objectives → Evidence → Reporting → Follow-up
**Risk-Based Audit** Scope is driven by risk, not by checklist
**Independence** Charter + Reporting to Audit Committee
**Evidence** Sufficient, Reliable, Relevant, Useful
**3rd Party** You are still responsible. Get SOC report or audit them
*Exam Tip*: CISA Domain 1 is not about technical testing. It’s about "How do you plan, execute, and report an audit professionally as per ISACA Standards."
Section B...
Here are *10 more Case-Based MCQs for CISA Domain 1: Information System Auditing Process*
Format: Case → Question → Answer + Explanation. Exam style.
*CISA DOMAIN 1 MOCK TEST - 10 CASE BASED MCQs*
*CASE 1: E-Commerce Company Audit*
ShopFast is launching a new payment gateway. The IS auditor is assigned 2 weeks before launch.
*Q1. What is the BEST approach to define audit scope?*
A. Audit all IT systems in the company
B. *Focus on risks related to payment processing, data security, and PCI-DSS compliance*
C. Copy scope from last year’s audit
D. Ask developers what to audit
*Answer:
*Q2. Who should APPROVE the audit charter?*
A. CIO
B. *Audit Committee / Board of Directors*
C. External Auditor
D. CISO
*Answer:
---
*CASE 2: Evidence & Documentation*
The auditor is testing change management controls.
*Q3. Which is the MOST reliable audit evidence?*
A. Interview with developer
B. *System-generated change log with user ID and timestamp*
C. Email from manager
D. Screenshot from developer
*Answer:
*Q4. Auditor finds 2 exceptions in 40 samples. What should be done?*
A. Conclude controls are effective
B. *Expand sample size and evaluate impact*
C. Ignore minor exceptions
D. Report immediately to regulators
*Answer:
---
*CASE 3: Audit Reporting*
Audit found "Lack of segregation of duties: 1 admin has prod access + code deploy rights".
*Q5. In the audit report, what should come FIRST?*
A. Recommendation
B. *Finding + Risk*
C. Management Response
D. Root Cause
*Answer:
*Q6. Management says "We accept the risk". Auditor should:*
A. Force them to fix it
B. *Document management’s acceptance and escalate to Audit Committee if risk is high*
C. Close the finding
D. Do nothing
*Answer: .
--
*CASE 4: Audit Planning & Standards*
*Q7. Which ISACA Standard requires the auditor to maintain professional competence?*
A. 1002 Organizational Independence
B. *1003 Professional Competence*
C. 1203 Audit Documentation
D. 1402 Compliance
*Answer:
*Q8. During audit planning, what is the purpose of a walkthrough?*
A. To test controls
B. *To understand business process and identify risks*
C. To collect evidence
D. To train staff
*Answer:
---
*CASE 5: Follow-up & Quality*
*Q9. 90 days after audit, what should the auditor do?*
A. Start new audit
B. *Follow-up to verify status of corrective actions*
C. Ask management to self-assess
D. Wait 1 year
*Answer
*Q10. Which activity BEST demonstrates audit quality assurance?*
A. Using audit software
B. *Internal peer review of audit working papers*
C. Completing audit on time
D. Having CISA certification
*Answer:
---
*DOMAIN 1 EXAM FORMULAS*
1. *Risk = Likelihood × Impact*
2. *Audit Phases*: Plan → Fieldwork → Reporting → Follow-up
3. *4 Cs of Finding*: Criteria, Condition, Cause, Effect
4. *Evidence Hierarchy*: Observation > System Generated > External > Internal > Oral
*CISA Tip*: 17% of exam is Domain 1. GARP/ISACA loves "What should auditor do FIRST/NEXT/BEST" questions.
ANSWERS.....
Section A....
CISA Exam | Domain 1: Information System Auditing Process
*Case-Based MCQs with Answers & Explanation*
_Domain 1 Weight: 17% | Focus: IS Audit Standards, Risk Assessment, Audit Planning_
*CASE STUDY: FinBank Digital Transformation*
FinBank is rolling out a new mobile banking app and migrating customer data to a public cloud. The CIO hired an external vendor for development. The Board asked the Internal Audit department to conduct an IS audit before go-live. The CISA auditor has 3 weeks to complete the audit.
*MCQs with Answers*
*Q1. Audit Planning & Risk Assessment*
*Q*: During audit planning, what should the CISA auditor do FIRST to determine audit scope?
A. Begin testing application controls in the mobile app
B. *Perform a risk assessment to identify high-risk areas*
C. Send an engagement letter to the external vendor
D. Review last year’s financial audit report
*Answer: B*
*Explanation - CISA Domain 1.2*: Per ISACA IS Auditing Standards, the auditor must conduct a risk-based audit. Before any testing, identify risks from the cloud migration, new app, and 3rd party vendor. Risk assessment drives scope, objectives, and resources.
*Q2. Audit Charter & Independence*
*Q*: To ensure independence, which document must the auditor review before starting the audit?
A. SDLC Documentation
B. *IS Audit Charter approved by the Board/Audit Committee*
C. Vendor SLA
D. Business Continuity Plan
*Answer: B*
*Explanation - CISA Domain 1.1*: The IS Audit Charter defines authority, independence, scope, and reporting lines. Without Board-approved charter, the auditor cannot access data or report findings objectively.
*Q3. Materiality & Audit Objective*
*Q*: The primary objective of this pre-go-live IS audit should be to:
A. Identify all coding bugs in the mobile app
B. *Provide reasonable assurance that risks related to confidentiality, integrity, and availability are managed*
C. Recommend a cheaper cloud vendor
D. Test user password complexity only
*Answer: B*
*Explanation - CISA Domain 1.3*: Audit objectives must align with business goals. For a new customer-facing app, the objective is assurance over CIA triad and compliance, not just bug hunting.
*Q4. Evidence & Sampling*
*Q*: Due to the 3-week timeline, the auditor decides to test 50 out of 10,000 cloud access logs. This approach is called:
A. 100% Testing
B. *Audit Sampling*
C. Continuous Auditing
D. Walkthrough
*Answer: B*
*Explanation - CISA Domain 1.4*: When population is large and time is limited, ISACA allows statistical or non-statistical sampling. Results are projected to the population. Must document sampling method.
*Q5. Third-Party Risk & Audit Standards*
*Q*: The vendor is managing the cloud infrastructure. Which ISACA standard requires the auditor to assess the vendor’s controls?
A. 1201 Audit Evidence
B. *1401 Third-Party Management*
C. 1207 Irregularities and Illegal Acts
D. 1001 Audit Charter
*Answer: B*
*Explanation - CISA Domain 1.1*: ISACA Standard 1401 states the IS auditor should consider third-party relationships and obtain assurance over controls at service providers. Options: review SOC2 report, right-to-audit clause.
*Q6. Audit Finding & Reporting*
*Q*: The auditor finds "No encryption for customer PII in cloud storage". What is the MOST appropriate next step?
A. Immediately shut down the mobile app
B. *Discuss the finding with management to confirm facts and get management response*
C. Report directly to regulators
D. Ignore it as it is the vendor’s responsibility
*Answer: B*
*Explanation - CISA Domain 1.5*: Per ISACA Standards, findings must be discussed with relevant management first for factual accuracy and to obtain action plan, owner, and timeline before final report.
*Q7. Follow-up*
*Q*: 6 months after the audit, what is the auditor’s responsibility regarding the encryption finding?
A. No responsibility after report is issued
B. *Perform follow-up to determine if management implemented corrective action*
C. Wait for external audit to check
D. Re-audit the entire application
*Answer: B*
*Explanation - CISA Domain 1.6*: ISACA requires IS auditors to monitor and follow-up on management’s remediation of audit findings to ensure risks are addressed.
SECTION B....
Here are *10 more Case-Based MCQs for CISA Domain 1: Information System Auditing Process*
Format: Case → Question → Answer + Explanation. Exam style.
*CISA DOMAIN 1 MOCK TEST - 10 CASE BASED MCQs*
*CASE 1: E-Commerce Company Audit*
ShopFast is launching a new payment gateway. The IS auditor is assigned 2 weeks before launch.
*Q1. What is the BEST approach to define audit scope?*
A. Audit all IT systems in the company
B. *Focus on risks related to payment processing, data security, and PCI-DSS compliance*
C. Copy scope from last year’s audit
D. Ask developers what to audit
*Answer: B*
*Why*: Domain 1.2 - Risk-based scoping. High risk = payment + PII + compliance.
*Q2. Who should APPROVE the audit charter?*
A. CIO
B. *Audit Committee / Board of Directors*
C. External Auditor
D. CISO
*Answer: B*
*Why*: Domain 1.1 - Independence requires Board/Audit Committee approval.
---
*CASE 2: Evidence & Documentation*
The auditor is testing change management controls.
*Q3. Which is the MOST reliable audit evidence?*
A. Interview with developer
B. *System-generated change log with user ID and timestamp*
C. Email from manager
D. Screenshot from developer
*Answer: B*
*Why*: Domain 1.4 - System-generated evidence > Oral > Document. Less bias.
*Q4. Auditor finds 2 exceptions in 40 samples. What should be done?*
A. Conclude controls are effective
B. *Expand sample size and evaluate impact*
C. Ignore minor exceptions
D. Report immediately to regulators
*Answer: B*
*Why*: Domain 1.4 - Exceptions may indicate control failure. Need to assess if it’s isolated.
---
*CASE 3: Audit Reporting*
Audit found "Lack of segregation of duties: 1 admin has prod access + code deploy rights".
*Q5. In the audit report, what should come FIRST?*
A. Recommendation
B. *Finding + Risk*
C. Management Response
D. Root Cause
*Answer: B*
*Why*: Domain 1.5 - ISACA report structure: Criteria, Condition, Cause, Effect, Recommendation. Risk/Effect must be clear first.
*Q6. Management says "We accept the risk". Auditor should:*
A. Force them to fix it
B. *Document management’s acceptance and escalate to Audit Committee if risk is high*
C. Close the finding
D. Do nothing
*Answer: B*
*Why*: Domain 1.5 - Auditor cannot force. Must document and escalate material risks.
---
*CASE 4: Audit Planning & Standards*
*Q7. Which ISACA Standard requires the auditor to maintain professional competence?*
A. 1002 Organizational Independence
B. *1003 Professional Competence*
C. 1203 Audit Documentation
D. 1402 Compliance
*Answer: B*
*Why*: Domain 1.1 - Standard 1003. Must have CISA, CPE, and relevant skills.
*Q8. During audit planning, what is the purpose of a walkthrough?*
A. To test controls
B. *To understand business process and identify risks*
C. To collect evidence
D. To train staff
*Answer: B*
*Why*: Domain 1.2 - Walkthrough = understand process flow before testing.
---
*CASE 5: Follow-up & Quality*
*Q9. 90 days after audit, what should the auditor do?*
A. Start new audit
B. *Follow-up to verify status of corrective actions*
C. Ask management to self-assess
D. Wait 1 year
*Answer: B*
*Why*: Domain 1.6 - Follow-up is mandatory per ISACA.
*Q10. Which activity BEST demonstrates audit quality assurance?*
A. Using audit software
B. *Internal peer review of audit working papers*
C. Completing audit on time
D. Having CISA certification
*Answer: B*
*Why*: Domain 1.1 - QA program includes supervision, review, and independent internal QA.
No comments:
Post a Comment