100 MCQs – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based First solve & then check ✔️ yourself..Answers provided at the end.
As per ISACA New Syllabus – All keywords covered: Audit Charter, Standards, Risk Assessment, Planning, Evidence, Materiality, Control, Sampling.
*1.* What is the PRIMARY purpose of IS Audit Charter?
*A) Define authority, responsibility of audit function*
B) Define audit plan
C) List audit findings
D) Define IT policy
*Ans:
*2.* Who should approve IS Audit Charter?
*A) Board / Audit Committee*
B) CIO
C) IT Manager
D) External Auditor
*Ans:
*3.* ISACA IS Auditing Standards are mandatory for?
*A) All IS audits*
B) Only external audits
C) Only internal audits
D) Optional
*Ans:
*4.* What is Risk-Based Auditing?
*A) Audit based on risk assessment*
B) Audit all systems equally
C) Audit only financial systems
D) Audit only when fraud occurs
*Ans:
*5.* Inherent Risk is?
*A) Risk before controls*
B) Risk after controls
C) Risk of auditor not detecting
D) Risk of control failure
*Ans:
*6.* Residual Risk = ?
*A) Inherent Risk – Control effectiveness*
B) Inherent + Control Risk
C) Audit Risk
D) Detection Risk
*Ans:
*7.* Which risk does auditor control directly?
*A) Detection Risk*
B) Inherent Risk
C) Control Risk
D) Business Risk
*Ans:
*8.* Audit Risk = Inherent Risk x Control Risk x ?
*A) Detection Risk*
B) Residual Risk
C) Business Risk
D) Audit Risk
*Ans:
*9.* Materiality in IS Audit means?
*A) Significance of finding to business*
B) Amount in financial statement
C) Number of records
D) Audit fee
*Ans:
*10.* First step in IS Audit Planning?
*A) Understand business, its risks and processes*
B) Start testing controls
C) Issue report
D) Collect evidence
*Ans:
*11.* Which document defines scope, objective, timing of audit?
*A) Audit Plan / Engagement Letter*
B) Audit Charter
C) Audit Report
D) Risk Register
*Ans:
*12.* What is Audit Program?
*A) Detailed steps to achieve audit objectives*
B) Software program
C) Audit charter
D) Audit report
*Ans:.
*13.* Evidence is MOST reliable when?
*A) Directly obtained by auditor, from independent source, original*
B) From client copy
C) Oral evidence only
D) Internal evidence only
*Ans:
*14.* Which is MOST reliable audit evidence?
*A) Auditor's direct observation*
B) Client's internal memo
C) Photocopy of document
D) Oral statement by client
*Ans:.
*15.* Sampling Risk is?
*A) Conclusion from sample differs from population*
B) All records are wrong
C) Auditor fails to sample
D) No risk
*Ans:
*16.* Alpha Risk (Type I) means?
*A) Auditor says control works when it does not*
B) Auditor says control does not work when it actually works – False negative
C) No risk
D) Inherent risk
*Ans: .
*17.* Beta Risk (Type II) in IS Audit is?
*A) Auditor concludes control effective when it is ineffective – More dangerous*
B) Auditor concludes ineffective when effective
C) No risk
D) Sampling correct
*Ans:
*18.* Best sampling method for fraud detection?
*A) Discovery / Directed Sampling*
B) Statistical sampling
C) Random sampling
D) Haphazard sampling
*Ans:
*19.* When population has high variance, which sampling?
*A) Stratified Sampling*
B) Simple Random
C) Systematic
D) Judgmental
*Ans:
*20.* CAATs stands for?
*A) Computer Assisted Audit Techniques*
B) Computer Audit Tools
C) Control Audit Techniques
D) Compliance Audit Tools
*Ans:
*21.* Which CAAT is used to test calculation without affecting live data?
*A) Test Data / Base Case System Evaluation*
B) Parallel Simulation
C) Embedded Audit Module
D) GAS
*Ans:
*22.* Continuous Auditing uses?
*A) Embedded Audit Module / SCARF*
B) Manual auditing
C) Year-end audit only
D) No technology
*Ans:
*23.* What is SCARF?
*A) System Control Audit Review File – Embedded module that collects suspicious transactions*
B) Audit software
C) Risk file
D) Report file
*Ans
*24.* Audit Hook is?
*A) Code that triggers when specific condition met – Red flag*
B) Fishing technique
C) Audit report
D) Audit plan
*Ans:
*25.* Which controls to test FIRST in risk-based audit?
*A) Entity-level / General Controls (GITC)*
B) Application controls
C) No controls
D) Only manual controls
*Ans:
*26.* Which is Preventive Control?
*A) Segregation of Duties, Access Control, Authorization*
B) Reconciliation
C) Log review
D) Backup review
*Ans:
*27.* Detective Control is?
*A) Log monitoring, Reconciliation, Review*
B) Access control
C) Firewalls
D) Encryption
*Ans:
*28.* Corrective Control is?
*A) Backup restore, Contingency plan, Patching*
B) Access control
C) Authorization
D) Reconciliation
*Ans:
*29.* Compensating Control is used when?
*A) Primary control fails or not cost-effective – Alternative control*
B) No control needed
C) All controls fail
D) Only preventive needed
*Ans:
*30.* Segregation of Duties violation is?
*A) One person can commit and conceal fraud – Developer in Production*
B) Two persons share password
C) Manager reviews report
D) No violation
*Ans:
*31.* What should auditor do if Inherent Risk is High?
*A) Increase substantive testing, reduce detection risk*
B) Reduce testing
C) Do nothing
D) Issue clean report
*Ans: .
*32.* Control Risk is high when?
*A) Controls are weak / not designed properly*
B) Controls are strong
C) Auditor is weak
D) No risk
*Ans:
*33.* Evidence collection method for compliance?
*A) Observation, Inquiry, Inspection, Re-performance*
B) Only inquiry
C) Only observation
D) No method
*Ans:
*34.* Inquiry as audit evidence is?
*A) Weakest – Needs corroboration*
B) Strongest
C) Sufficient alone
D) Not evidence
*Ans:
*35.* Which is substantive test?
*A) Test of details of transactions, balances, analytical procedures*
B) Test of control design
C) Test of control operating effectiveness
D) No test
*Ans.
*36.* What is Compliance Test?
*A) Test if control is operating effectively – Test of Controls*
B) Test of balances
C) Test of details
D) Analytical test
*Ans:
*37.* Tolerable Error in sampling means?
*A) Max error auditor can accept and still say control effective / balance correct*
B) No error allowed
C) All errors allowed
D) Sampling error
*Ans:
*38.* Confidence Level 95% means?
*A) 95% chance sample represents population – 5% sampling risk*
B) 100% correct
C) 5% correct
D) No confidence
*Ans:
*39.* Which sampling does NOT use statistics?
*A) Judgmental / Non-statistical sampling*
B) Variable sampling
C) Attribute sampling
D) Stratified sampling
*Ans
*40.* When to use 100% examination instead of sampling?
*A) Population small, High risk, Forensic audit*
B) Always sampling
C) Never 100%
D) Only for low risk
*Ans:
*41.* What is Audit Trail?
*A) Chronological record to trace transaction from source to final – For reconstruction*
B) Audit report
C) Audit plan
D) No trail
*Ans:
*42.* Which ISACA guideline says auditor must be independent?
*A) Independence and Objectivity – 2nd Standard*
B) No guideline
C) Audit Charter only
D) Management guideline
*Ans:
*43.* Internal Audit reporting to CIO violates?
*A) Independence – Should report to Board/Audit Committee*
B) No violation
C) Good practice
D) Required
*Ans:
*44.* Follow-up audit is done to?
*A) Verify management implemented audit recommendations*
B) Do new audit
C) Close audit file
D) No follow-up needed
*Ans:
*45.* Audit Documentation should contain?
*A) Plan, Program, Evidence, Findings, Report – Enough for another auditor to understand*
B) Only report
C) Only plan
D) No documentation needed
*Ans:
*46.* What is Snapshot?
*A) Record of system at point in time for audit – Before/After image*
B) Photo
C) Audit report
D) No meaning
*Ans
*47.* Integrated Auditing means?
*A) Combined financial, operational and IS audit*
B) Only IS audit
C) Only financial audit
D) No integration
*Ans:
*48.* Control Self-Assessment (CSA) is?
*A) Management self-assesses controls – Auditor facilitates*
B) Auditor assesses controls
C) No self-assessment
D) External audit
*Ans:
*49.* What is Benchmarking in audit?
*A) Compare control/process with best practice or industry standard*
B) No comparison
C) Only internal compare
D) Audit fee compare
*Ans:.
*50.* Maturity Model used in audit to?
*A) Assess maturity of process – 0-5 levels – e.g., COBIT, CMM*
B) Assess audit fee
C) No use
D) Only for software
*Ans:
*51.* COBIT is used for?
*A) IT Governance and Management framework – For audit planning*
B) Only for coding
C) Only for hardware
D) No use
*Ans:
*52.* What is Risk Appetite vs Risk Tolerance already covered – Which is broader?
*A) Risk Appetite broader – Tolerance specific limit*
B) Tolerance broader
C) Same
D) No relation
*Ans:
*53.* Business Impact Analysis (BIA) is used for?
*A) Identify critical processes and impact of disruption – For audit prioritization*
B) Audit fee
C) No use
D) Only for BCP
*Ans:
*54.* Which is MOST important for audit planning?
*A) Risk Assessment and Business Understanding*
B) Audit software
C) Audit fee
D) Auditor name
*Ans:
*55.* Analytical Procedures in IS Audit?
*A) Compare trends, ratios, reasonableness – e.g., Log review trends, CPU usage trends*
B) No analytics
C) Only financial analytics
D) No need
*Ans:
*56.* What is KRI?
*A) Key Risk Indicator – Early warning of increasing risk*
B) Key Result Indicator
C) No indicator
D) Audit indicator
*Ans:
*57.* What is KPI?
*A) Key Performance Indicator – Past performance achieved*
B) Risk indicator
C) No indicator
D) Control indicator
*Ans:
*58.* Auditing BYOD policy – What is first step?
*A) Understand BYOD policy, risks, MDM controls*
B) Test MDM directly
C) Ignore BYOD
D) Issue report
*Ans:
*59.* Cloud audit – Who is responsible for data?
*A) Client ultimately responsible even if data in cloud – Cannot outsource accountability*
B) Cloud provider fully responsible
C) No one responsible
D) Auditor responsible
*Ans:
*60.* Continuous Auditing vs Continuous Monitoring – Difference?
*A) Auditing = Done by Auditor – Monitoring = Done by Management*
B) Same
C) No difference
D) Both by management
*Ans:
*61.* What is Forensic Audit objective?
*A) Collect evidence acceptable in court – Chain of custody critical*
B) Regular audit
C) Financial audit only
D) No objective
*Ans:.
*62.* Chain of Custody means?
*A) Document who handled evidence, when, where – To prove integrity in court*
B) No chain
C) Audit chain
D) Supply chain
*Ans:
*63.* What is Due Diligence audit?
*A) Pre-merger/acquisition audit to assess risks and controls of target*
B) No diligence
C) Regular audit
D) Only financial
*Ans:
*64.* Which audit technique uses dummy entity?
*A) Integrated Test Facility (ITF) – Dummy master file record – e.g., Dummy vendor*
B) Test data
C) No technique
D) Parallel simulation
*Ans:
*65.* Parallel Simulation means?
*A) Auditor's program re-processes client's data and compares results*
B) Client's program re-processes
C) No simulation
D) Only manual
*Ans:
*66.* White Box vs Black Box testing – White Box?
*A) Auditor knows internal logic/code – Tests logic*
B) Does not know internal logic – Tests input/output
C) No testing
D) Only black box used
*Ans:
*67.* When to use Black Box audit?
*A) When auditor does not have access to code – Tests functionality*
B) Always white box
C) Never black box
D) Only for code review
*Ans:
*68.* What is Material weakness vs Significant deficiency?
*A) Material weakness = Reasonable possibility of material misstatement not prevented – More severe – Must report to Board*
B) Same
C) Significant more severe
D) No difference
*Ans:
*69.* Audit Report should be?
*A) Clear, Concise, Objective, Timely, Supported by evidence – With risk and recommendation*
B) Long and confusing
C) No recommendation
D) Only findings
*Ans:
*70.* Finding should include?
*A) Criteria, Condition, Cause, Effect, Recommendation (CC CER)*
B) Only condition
C) Only criteria
D) No structure
*Ans:
*71.* What is Criteria?
*A) What SHOULD be – Standard, Policy, Best practice*
B) What is
C) No criteria
D) Audit report
*Ans:
*72.* Effect in audit finding means?
*A) Impact/Risk of finding – Financial, Reputational, Compliance*
B) No effect
C) Only cause
D) Audit fee
*Ans:
*73.* Which evidence collection has observer bias risk?
*A) Observation – Hawthorne effect – People behave differently when watched*
B) Inspection
C) Re-performance
D) Document review
*Ans:
*74.* What is GAS?
*A) Generalized Audit Software – ACL, IDEA – For data analysis*
B) Gas audit
C) No software
D) Audit gas
*Ans:
*75.* Benford's Law used for?
*A) Detect fraud in numbers – Natural numbers follow Benford pattern – Anomaly indicates fraud*
B) No fraud detection
C) Only for math
D) Audit planning
*Ans:.
*76.* What is Code Review audit?
*A) Auditor reviews source code for vulnerabilities, backdoors, logic bombs*
B) No review
C) Only execution
D) Only output review
*Ans:
*77.* Logic Bomb is?
*A) Malicious code triggered by specific condition – e.g., date, event*
B) No bomb
C) Audit bomb
D) Only hardware
*Ans:
*78.* Who should have access to audit working papers?
*A) Only audit team and authorized reviewers – Confidential*
B) Everyone
C) Client's staff
D) Public
*Ans:
*79.* Retention of audit working papers – As per ISACA?
*A) As per legal and organizational policy – Typically 5-7 years*
B) 1 day
C) No retention
D) Forever 1 month
*Ans:
*80.* What is Professional Skepticism?
*A) Questioning mind, critical assessment – Don't trust blindly, corroborate*
B) Trust everything client says
C) No skepticism
D) Only trust management
*Ans:
*81.* What is Independence in fact vs appearance?
*A) In fact = Actually independent – In appearance = Others perceive you independent – Both needed*
B) Only fact needed
C) Only appearance needed
D) No independence needed
*Ans:.
*82.* Can internal auditor audit area where he previously worked?
*A) Not within 12 months – Impairs independence – Cooling period needed*
B) Can audit immediately
C) Never can audit
D) No restriction
*Ans:
*83.* What is Co-sourcing vs Outsourcing of audit?
*A) Co-sourcing = Internal + External together – Outsourcing = Fully external firm does audit*
B) Same
C) No difference
D) Only co-sourcing used
*Ans
*84.* What is Audit Universe?
*A) All auditable areas in organization – For annual audit planning*
B) One audit area
C) No universe
D) Only IT areas
*Ans:.
*85.* Annual audit plan based on?
*A) Risk assessment of audit universe + Management request + Regulatory requirement*
B) Random
C) Only management request
D) Only regulatory
*Ans:
*86.* What is Engagement Letter?
*A) Formal agreement with auditee – Scope, objective, responsibilities, timelines*
B) No letter needed
C) Only oral agreement
D) Audit report
*Ans:
*87.* Expectation Gap means?
*A) Difference between what auditee expects and what auditor delivers – Managed by engagement letter*
B) No gap
C) Audit fee gap
D) No meaning
*Ans:
*88.* What is Walkthrough?
*A) Tracing one transaction from start to end to understand process and controls – First step before detailed testing*
B) Walking in office
C) No walkthrough
D) Audit report walk
*Ans:
*89.* Which is better – Preventive or Detective control?
*A) Preventive is better and cheaper – Prevents loss – But both needed – Defense in depth*
B) Detective better
C) No control better
D) Only corrective needed
*Ans:
*90.* Defense in Depth means?
*A) Multiple layers of controls – If one fails, other catches – e.g., Firewall + IDS + Access control*
B) One control enough
C) No defense
D) Only preventive
*Ans:
*91.* What is Compensating control for lack of SoD in small company?
*A) Manager review, Audit trail review, Independent reconciliation*
B) No control
C) Ignore SoD
D) Only one person does all
*Ans:
*92.* What is Audit Evidence sufficiency vs appropriateness?
*A) Sufficiency = Quantity – Enough evidence – Appropriateness = Quality – Relevant and Reliable*
B) Same
C) No difference
D) Only quantity matters
*Ans
*93.* When auditor finds fraud, what should do FIRST?
*A) Inform appropriate level – Audit Committee / Board – Not necessarily management if management involved – Preserve evidence*
B) Tell everyone
C) Ignore
D) Delete evidence
*Ans
*94.* What is Whistleblower mechanism?
*A) Anonymous reporting channel for fraud/ethics violations – Auditor should test its existence and effectiveness*
B) No mechanism
C) Only for HR
D) Not for audit
*Ans:
*95.* What is Fraud Triangle?
*A) Pressure, Opportunity, Rationalization – All three needed for fraud – Auditor looks for these*
B) No triangle
C) Only pressure
D) Only opportunity
*Ans:
*96.* What is Fraud Diamond adds 4th element?
*A) Capability – Person must have skill to commit fraud*
B) No diamond
C) Only triangle needed
D) Pressure only
*Ans:
*97.* What is Continuous Auditing benefit?
*A) Real-time assurance, Early detection, Reduced audit cost over time, 100% population testing*
B) No benefit
C) Only manual benefit
D) Yearly audit benefit
*Ans:
*98.* What is Risk Assessment Matrix used for?
*A) Prioritize risks based on Likelihood x Impact – Heat map*
B) No matrix
C) Only for audit fee
D) Only for planning
*Ans:
*99.* What is Control Matrix?
*A) Maps risks to controls – Shows which control mitigates which risk – Identifies gaps*
B) No matrix
C) Only risk matrix
D) Audit matrix
*Ans
*100.* What is FINAL step in IS Audit Process (Domain 1)?
*A) Follow-up and Issue closure – Verify remediation – Then close audit*
B) Start new audit without follow-up
C) No final step
D) Only report
*Ans:
ANSWERS:
100 MCQs with Answers + Explanation – CISA Domain 1: Information Systems Auditing Process – 21% Weightage – Keyword Based*
As per ISACA New Syllabus – All keywords covered: Audit Charter, Standards, Risk Assessment, Planning, Evidence, Materiality, Control, Sampling.
*1.* What is the PRIMARY purpose of IS Audit Charter?
*A) Define authority, responsibility of audit function*
B) Define audit plan
C) List audit findings
D) Define IT policy
*Ans: A* – Charter gives mandate from Board/Audit Committee – Without charter, audit has no authority.
*2.* Who should approve IS Audit Charter?
*A) Board / Audit Committee*
B) CIO
C) IT Manager
D) External Auditor
*Ans: A* – Independence – Board/Audit Committee approves.
*3.* ISACA IS Auditing Standards are mandatory for?
*A) All IS audits*
B) Only external audits
C) Only internal audits
D) Optional
*Ans: A* – ISACA Standards mandatory for all CISA holders.
*4.* What is Risk-Based Auditing?
*A) Audit based on risk assessment*
B) Audit all systems equally
C) Audit only financial systems
D) Audit only when fraud occurs
*Ans: A* – Focus on high-risk areas – Efficient audit.
*5.* Inherent Risk is?
*A) Risk before controls*
B) Risk after controls
C) Risk of auditor not detecting
D) Risk of control failure
*Ans: A* – Gross risk – Before any controls.
*6.* Residual Risk = ?
*A) Inherent Risk – Control effectiveness*
B) Inherent + Control Risk
C) Audit Risk
D) Detection Risk
*Ans: A* – Net risk after controls – What audit tests.
*7.* Which risk does auditor control directly?
*A) Detection Risk*
B) Inherent Risk
C) Control Risk
D) Business Risk
*Ans: A* – Auditor can reduce detection risk by more substantive testing.
*8.* Audit Risk = Inherent Risk x Control Risk x ?
*A) Detection Risk*
B) Residual Risk
C) Business Risk
D) Audit Risk
*Ans: A* – Classic audit risk model.
*9.* Materiality in IS Audit means?
*A) Significance of finding to business*
B) Amount in financial statement
C) Number of records
D) Audit fee
*Ans: A* – Impact on business objectives, not just amount.
*10.* First step in IS Audit Planning?
*A) Understand business, its risks and processes*
B) Start testing controls
C) Issue report
D) Collect evidence
*Ans: A* – Understand business is always first.
*11.* Which document defines scope, objective, timing of audit?
*A) Audit Plan / Engagement Letter*
B) Audit Charter
C) Audit Report
D) Risk Register
*Ans: A* – Audit Plan defines scope, objective, resources.
*12.* What is Audit Program?
*A) Detailed steps to achieve audit objectives*
B) Software program
C) Audit charter
D) Audit report
*Ans: A* – Step-by-step procedures – Prepared after planning.
*13.* Evidence is MOST reliable when?
*A) Directly obtained by auditor, from independent source, original*
B) From client copy
C) Oral evidence only
D) Internal evidence only
*Ans: A* – External + Direct + Original = Most reliable.
*14.* Which is MOST reliable audit evidence?
*A) Auditor's direct observation*
B) Client's internal memo
C) Photocopy of document
D) Oral statement by client
*Ans: A* – Direct observation > External doc > Internal doc > Oral.
*15.* Sampling Risk is?
*A) Conclusion from sample differs from population*
B) All records are wrong
C) Auditor fails to sample
D) No risk
*Ans: A* – Sample not representative – 2 types: Alpha and Beta risk.
*16.* Alpha Risk (Type I) means?
*A) Auditor says control works when it does not*
B) Auditor says control does not work when it actually works – False negative
C) No risk
D) Inherent risk
*Ans: B* – In audit, Beta risk (False assurance) is more dangerous than Alpha.
*17.* Beta Risk (Type II) in IS Audit is?
*A) Auditor concludes control effective when it is ineffective – More dangerous*
B) Auditor concludes ineffective when effective
C) No risk
D) Sampling correct
*Ans: A* – Beta = Wrong assurance – Leads to audit failure.
*18.* Best sampling method for fraud detection?
*A) Discovery / Directed Sampling*
B) Statistical sampling
C) Random sampling
D) Haphazard sampling
*Ans: A* – Discovery sampling for fraud – Look for one occurrence.
*19.* When population has high variance, which sampling?
*A) Stratified Sampling*
B) Simple Random
C) Systematic
D) Judgmental
*Ans: A* – Divide population into strata (high value, low value) – Reduces variance.
*20.* CAATs stands for?
*A) Computer Assisted Audit Techniques*
B) Computer Audit Tools
C) Control Audit Techniques
D) Compliance Audit Tools
*Ans: A* – Tools like ACL, IDEA, Excel – Used for data analysis.
*21.* Which CAAT is used to test calculation without affecting live data?
*A) Test Data / Base Case System Evaluation*
B) Parallel Simulation
C) Embedded Audit Module
D) GAS
*Ans: A* – Test data into copy of production – Does not affect live.
*22.* Continuous Auditing uses?
*A) Embedded Audit Module / SCARF*
B) Manual auditing
C) Year-end audit only
D) No technology
*Ans: A* – Continuous monitoring – SCARF, EAM, Audit Hooks.
*23.* What is SCARF?
*A) System Control Audit Review File – Embedded module that collects suspicious transactions*
B) Audit software
C) Risk file
D) Report file
*Ans: A* – EAM + SCARF = Collects transactions for audit.
*24.* Audit Hook is?
*A) Code that triggers when specific condition met – Red flag*
B) Fishing technique
C) Audit report
D) Audit plan
*Ans: A* – Example: Trigger when salary > $10,000.
*25.* Which controls to test FIRST in risk-based audit?
*A) Entity-level / General Controls (GITC)*
B) Application controls
C) No controls
D) Only manual controls
*Ans: A* – If GITC fails, all application controls unreliable – Test GITC first.
*26.* Which is Preventive Control?
*A) Segregation of Duties, Access Control, Authorization*
B) Reconciliation
C) Log review
D) Backup review
*Ans: A* – Prevents error – Detective = Reconciliation, Log review.
*27.* Detective Control is?
*A) Log monitoring, Reconciliation, Review*
B) Access control
C) Firewalls
D) Encryption
*Ans: A* – Detects after occurrence.
*28.* Corrective Control is?
*A) Backup restore, Contingency plan, Patching*
B) Access control
C) Authorization
D) Reconciliation
*Ans: A* – Corrects after detection.
*29.* Compensating Control is used when?
*A) Primary control fails or not cost-effective – Alternative control*
B) No control needed
C) All controls fail
D) Only preventive needed
*Ans: A* – Example: If SoD not possible in small company, manager review = compensating.
*30.* Segregation of Duties violation is?
*A) One person can commit and conceal fraud – Developer in Production*
B) Two persons share password
C) Manager reviews report
D) No violation
*Ans: A* – Core SoD failure – Most common audit finding.
*31.* What should auditor do if Inherent Risk is High?
*A) Increase substantive testing, reduce detection risk*
B) Reduce testing
C) Do nothing
D) Issue clean report
*Ans: A* – High inherent = More audit work.
*32.* Control Risk is high when?
*A) Controls are weak / not designed properly*
B) Controls are strong
C) Auditor is weak
D) No risk
*Ans: A* – High control risk = Cannot rely on controls – Do substantive testing.
*33.* Evidence collection method for compliance?
*A) Observation, Inquiry, Inspection, Re-performance*
B) Only inquiry
C) Only observation
D) No method
*Ans: A* – Four methods – Re-performance most reliable.
*34.* Inquiry as audit evidence is?
*A) Weakest – Needs corroboration*
B) Strongest
C) Sufficient alone
D) Not evidence
*Ans: A* – Oral evidence alone insufficient – Must corroborate.
*35.* Which is substantive test?
*A) Test of details of transactions, balances, analytical procedures*
B) Test of control design
C) Test of control operating effectiveness
D) No test
*Ans: A* – Substantive proves dollar amount correct – Control test proves control works.
*36.* What is Compliance Test?
*A) Test if control is operating effectively – Test of Controls*
B) Test of balances
C) Test of details
D) Analytical test
*Ans: A* – Compliance = Control testing.
*37.* Tolerable Error in sampling means?
*A) Max error auditor can accept and still say control effective / balance correct*
B) No error allowed
C) All errors allowed
D) Sampling error
*Ans: A* – If error > tolerable, control ineffective.
*38.* Confidence Level 95% means?
*A) 95% chance sample represents population – 5% sampling risk*
B) 100% correct
C) 5% correct
D) No confidence
*Ans: A* – Higher confidence = Larger sample.
*39.* Which sampling does NOT use statistics?
*A) Judgmental / Non-statistical sampling*
B) Variable sampling
C) Attribute sampling
D) Stratified sampling
*Ans: A* – Auditor judgment – Cannot measure sampling risk – But allowed.
*40.* When to use 100% examination instead of sampling?
*A) Population small, High risk, Forensic audit*
B) Always sampling
C) Never 100%
D) Only for low risk
*Ans: A* – For small high-risk populations, examine all.
*41.* What is Audit Trail?
*A) Chronological record to trace transaction from source to final – For reconstruction*
B) Audit report
C) Audit plan
D) No trail
*Ans: A* – Must be enabled – If no audit trail = Control failure.
*42.* Which ISACA guideline says auditor must be independent?
*A) Independence and Objectivity – 2nd Standard*
B) No guideline
C) Audit Charter only
D) Management guideline
*Ans: A* – Organizational independence – Report to Audit Committee, not to CIO.
*43.* Internal Audit reporting to CIO violates?
*A) Independence – Should report to Board/Audit Committee*
B) No violation
C) Good practice
D) Required
*Ans: A* – Reporting to CIO impairs independence – Major finding.
*44.* Follow-up audit is done to?
*A) Verify management implemented audit recommendations*
B) Do new audit
C) Close audit file
D) No follow-up needed
*Ans: A* – Required by ISACA – Auditor must follow up.
*45.* Audit Documentation should contain?
*A) Plan, Program, Evidence, Findings, Report – Enough for another auditor to understand*
B) Only report
C) Only plan
D) No documentation needed
*Ans: A* – Working papers – Retention as per policy.
*46.* What is Snapshot?
*A) Record of system at point in time for audit – Before/After image*
B) Photo
C) Audit report
D) No meaning
*Ans: A* – Used to verify processing – Before and after processing image.
*47.* Integrated Auditing means?
*A) Combined financial, operational and IS audit*
B) Only IS audit
C) Only financial audit
D) No integration
*Ans: A* – Team with financial + IT auditors – Best for application controls.
*48.* Control Self-Assessment (CSA) is?
*A) Management self-assesses controls – Auditor facilitates*
B) Auditor assesses controls
C) No self-assessment
D) External audit
*Ans: A* – CSA workshop – But auditor must not own controls – Independence risk.
*49.* What is Benchmarking in audit?
*A) Compare control/process with best practice or industry standard*
B) No comparison
C) Only internal compare
D) Audit fee compare
*Ans: A* – Example: Compare password policy with ISO 27001.
*50.* Maturity Model used in audit to?
*A) Assess maturity of process – 0-5 levels – e.g., COBIT, CMM*
B) Assess audit fee
C) No use
D) Only for software
*Ans: A* – 0 Non-existent to 5 Optimized – Shows gap.
*51.* COBIT is used for?
*A) IT Governance and Management framework – For audit planning*
B) Only for coding
C) Only for hardware
D) No use
*Ans: A* – COBIT 2019 – Main framework for IS Audit.
*52.* What is Risk Appetite vs Risk Tolerance already covered – Which is broader?
*A) Risk Appetite broader – Tolerance specific limit*
B) Tolerance broader
C) Same
D) No relation
*Ans: A* – Appetite = Board level broad, Tolerance = Management specific.
*53.* Business Impact Analysis (BIA) is used for?
*A) Identify critical processes and impact of disruption – For audit prioritization*
B) Audit fee
C) No use
D) Only for BCP
*Ans: A* – Auditor uses BIA to prioritize critical systems for audit.
*54.* Which is MOST important for audit planning?
*A) Risk Assessment and Business Understanding*
B) Audit software
C) Audit fee
D) Auditor name
*Ans: A* – Risk assessment drives audit plan.
*55.* Analytical Procedures in IS Audit?
*A) Compare trends, ratios, reasonableness – e.g., Log review trends, CPU usage trends*
B) No analytics
C) Only financial analytics
D) No need
*Ans: A* – Example: Login failures suddenly increased – Indicates attack.
*56.* What is KRI?
*A) Key Risk Indicator – Early warning of increasing risk*
B) Key Result Indicator
C) No indicator
D) Audit indicator
*Ans: A* – Example: Failed logins > 10 = KRI for brute force risk.
*57.* What is KPI?
*A) Key Performance Indicator – Past performance achieved*
B) Risk indicator
C) No indicator
D) Control indicator
*Ans: A* – KRI = Future risk, KPI = Past performance.
*58.* Auditing BYOD policy – What is first step?
*A) Understand BYOD policy, risks, MDM controls*
B) Test MDM directly
C) Ignore BYOD
D) Issue report
*Ans: A* – Always understand policy and risk first.
*59.* Cloud audit – Who is responsible for data?
*A) Client ultimately responsible even if data in cloud – Cannot outsource accountability*
B) Cloud provider fully responsible
C) No one responsible
D) Auditor responsible
*Ans: A* – Outsourcing responsibility but not accountability – Key CISA concept.
*60.* Continuous Auditing vs Continuous Monitoring – Difference?
*A) Auditing = Done by Auditor – Monitoring = Done by Management*
B) Same
C) No difference
D) Both by management
*Ans: A* – Auditor does auditing, Management does monitoring.
*61.* What is Forensic Audit objective?
*A) Collect evidence acceptable in court – Chain of custody critical*
B) Regular audit
C) Financial audit only
D) No objective
*Ans: A* – Preserve evidence, chain of custody, no tampering.
*62.* Chain of Custody means?
*A) Document who handled evidence, when, where – To prove integrity in court*
B) No chain
C) Audit chain
D) Supply chain
*Ans: A* – If chain broken, evidence not admissible.
*63.* What is Due Diligence audit?
*A) Pre-merger/acquisition audit to assess risks and controls of target*
B) No diligence
C) Regular audit
D) Only financial
*Ans: A* – Important for M&A – Check IT controls, licenses, security.
*64.* Which audit technique uses dummy entity?
*A) Integrated Test Facility (ITF) – Dummy master file record – e.g., Dummy vendor*
B) Test data
C) No technique
D) Parallel simulation
*Ans: A* – ITF tests live processing with dummy records – Must be removed.
*65.* Parallel Simulation means?
*A) Auditor's program re-processes client's data and compares results*
B) Client's program re-processes
C) No simulation
D) Only manual
*Ans: A* – Detects unauthorized logic in client's program.
*66.* White Box vs Black Box testing – White Box?
*A) Auditor knows internal logic/code – Tests logic*
B) Does not know internal logic – Tests input/output
C) No testing
D) Only black box used
*Ans: A* – White = With code knowledge, Black = Without code – Just input/output.
*67.* When to use Black Box audit?
*A) When auditor does not have access to code – Tests functionality*
B) Always white box
C) Never black box
D) Only for code review
*Ans: A* – Most IS audits are black box – Test controls, not code.
*68.* What is Material weakness vs Significant deficiency?
*A) Material weakness = Reasonable possibility of material misstatement not prevented – More severe – Must report to Board*
B) Same
C) Significant more severe
D) No difference
*Ans: A* – Material weakness > Significant deficiency > Deficiency.
*69.* Audit Report should be?
*A) Clear, Concise, Objective, Timely, Supported by evidence – With risk and recommendation*
B) Long and confusing
C) No recommendation
D) Only findings
*Ans: A* – Report structure: Executive summary, Findings, Risk, Recommendation, Response.
*70.* Finding should include?
*A) Criteria, Condition, Cause, Effect, Recommendation (CC CER)*
B) Only condition
C) Only criteria
D) No structure
*Ans: A* – 5 Cs for good finding.
*71.* What is Criteria?
*A) What SHOULD be – Standard, Policy, Best practice*
B) What is
C) No criteria
D) Audit report
*Ans: A* – Criteria = Standard – Condition = What is (actual).
*72.* Effect in audit finding means?
*A) Impact/Risk of finding – Financial, Reputational, Compliance*
B) No effect
C) Only cause
D) Audit fee
*Ans: A* – Effect shows materiality – Why management should fix.
*73.* Which evidence collection has observer bias risk?
*A) Observation – Hawthorne effect – People behave differently when watched*
B) Inspection
C) Re-performance
D) Document review
*Ans: A* – People change behavior when observed – So observation alone weak.
*74.* What is GAS?
*A) Generalized Audit Software – ACL, IDEA – For data analysis*
B) Gas audit
C) No software
D) Audit gas
*Ans: A* – GAS can read different file formats, do sampling, stratification.
*75.* Benford's Law used for?
*A) Detect fraud in numbers – Natural numbers follow Benford pattern – Anomaly indicates fraud*
B) No fraud detection
C) Only for math
D) Audit planning
*Ans: A* – Used in forensic analytics – Example: Expense claims fraud.
*76.* What is Code Review audit?
*A) Auditor reviews source code for vulnerabilities, backdoors, logic bombs*
B) No review
C) Only execution
D) Only output review
*Ans: A* – White box technique – Needs expertise.
*77.* Logic Bomb is?
*A) Malicious code triggered by specific condition – e.g., date, event*
B) No bomb
C) Audit bomb
D) Only hardware
*Ans: A* – Example: Code deletes data if employee terminated.
*78.* Who should have access to audit working papers?
*A) Only audit team and authorized reviewers – Confidential*
B) Everyone
C) Client's staff
D) Public
*Ans: A* – Working papers confidential – Protected.
*79.* Retention of audit working papers – As per ISACA?
*A) As per legal and organizational policy – Typically 5-7 years*
B) 1 day
C) No retention
D) Forever 1 month
*Ans: A* – Must comply with regulations.
*80.* What is Professional Skepticism?
*A) Questioning mind, critical assessment – Don't trust blindly, corroborate*
B) Trust everything client says
C) No skepticism
D) Only trust management
*Ans: A* – Core auditor mindset – Required by ISACA.
*81.* What is Independence in fact vs appearance?
*A) In fact = Actually independent – In appearance = Others perceive you independent – Both needed*
B) Only fact needed
C) Only appearance needed
D) No independence needed
*Ans: A* – If auditor appears non-independent (e.g., auditing own work), violates even if actually independent.
*82.* Can internal auditor audit area where he previously worked?
*A) Not within 12 months – Impairs independence – Cooling period needed*
B) Can audit immediately
C) Never can audit
D) No restriction
*Ans: A* – 12-month cooling – ISACA standard.
*83.* What is Co-sourcing vs Outsourcing of audit?
*A) Co-sourcing = Internal + External together – Outsourcing = Fully external firm does audit*
B) Same
C) No difference
D) Only co-sourcing used
*Ans: A* – Co-sourcing retains knowledge – Better.
*84.* What is Audit Universe?
*A) All auditable areas in organization – For annual audit planning*
B) One audit area
C) No universe
D) Only IT areas
*Ans: A* – List of all processes, systems, locations – Risk-ranked for annual plan.
*85.* Annual audit plan based on?
*A) Risk assessment of audit universe + Management request + Regulatory requirement*
B) Random
C) Only management request
D) Only regulatory
*Ans: A* – Risk-based annual plan – High-risk areas audited annually.
*86.* What is Engagement Letter?
*A) Formal agreement with auditee – Scope, objective, responsibilities, timelines*
B) No letter needed
C) Only oral agreement
D) Audit report
*Ans: A* – Protects both auditor and auditee – Prevents expectation gap.
*87.* Expectation Gap means?
*A) Difference between what auditee expects and what auditor delivers – Managed by engagement letter*
B) No gap
C) Audit fee gap
D) No meaning
*Ans: A* – Common gap – Auditee expects auditor to find all frauds – Not possible.
*88.* What is Walkthrough?
*A) Tracing one transaction from start to end to understand process and controls – First step before detailed testing*
B) Walking in office
C) No walkthrough
D) Audit report walk
*Ans: A* – One transaction walkthrough – Confirms process understanding.
*89.* Which is better – Preventive or Detective control?
*A) Preventive is better and cheaper – Prevents loss – But both needed – Defense in depth*
B) Detective better
C) No control better
D) Only corrective needed
*Ans: A* – Prevent > Detect > Correct – But need all layers.
*90.* Defense in Depth means?
*A) Multiple layers of controls – If one fails, other catches – e.g., Firewall + IDS + Access control*
B) One control enough
C) No defense
D) Only preventive
*Ans: A* – Layered controls – Core security principle.
*91.* What is Compensating control for lack of SoD in small company?
*A) Manager review, Audit trail review, Independent reconciliation*
B) No control
C) Ignore SoD
D) Only one person does all
*Ans: A* – Small company cannot segregate – Compensating = Supervisory review.
*92.* What is Audit Evidence sufficiency vs appropriateness?
*A) Sufficiency = Quantity – Enough evidence – Appropriateness = Quality – Relevant and Reliable*
B) Same
C) No difference
D) Only quantity matters
*Ans: A* – Need both sufficient AND appropriate – More quantity cannot compensate poor quality.
*93.* When auditor finds fraud, what should do FIRST?
*A) Inform appropriate level – Audit Committee / Board – Not necessarily management if management involved – Preserve evidence*
B) Tell everyone
C) Ignore
D) Delete evidence
*Ans: A* – If fraud by management, inform Board/Audit Committee – Not management – Also preserve chain of custody.
*94.* What is Whistleblower mechanism?
*A) Anonymous reporting channel for fraud/ethics violations – Auditor should test its existence and effectiveness*
B) No mechanism
C) Only for HR
D) Not for audit
*Ans: A* – SOX requires whistleblower hotline – Auditor tests it.
*95.* What is Fraud Triangle?
*A) Pressure, Opportunity, Rationalization – All three needed for fraud – Auditor looks for these*
B) No triangle
C) Only pressure
D) Only opportunity
*Ans: A* – CISA/CIA important – Opportunity = Weak controls – What auditor can reduce.
*96.* What is Fraud Diamond adds 4th element?
*A) Capability – Person must have skill to commit fraud*
B) No diamond
C) Only triangle needed
D) Pressure only
*Ans: A* – Triangle + Capability = Diamond – High capability person (e.g., IT admin) more risk.
*97.* What is Continuous Auditing benefit?
*A) Real-time assurance, Early detection, Reduced audit cost over time, 100% population testing*
B) No benefit
C) Only manual benefit
D) Yearly audit benefit
*Ans: A* – Enables 100% testing vs sampling – Future of audit.
*98.* What is Risk Assessment Matrix used for?
*A) Prioritize risks based on Likelihood x Impact – Heat map*
B) No matrix
C) Only for audit fee
D) Only for planning
*Ans: A* – High likelihood high impact = Red – Audit first.
*99.* What is Control Matrix?
*A) Maps risks to controls – Shows which control mitigates which risk – Identifies gaps*
B) No matrix
C) Only risk matrix
D) Audit matrix
*Ans: A* – If risk has no control = Gap – If control has no risk = Redundant.
*100.* What is FINAL step in IS Audit Process (Domain 1)?
*A) Follow-up and Issue closure – Verify remediation – Then close audit*
B) Start new audit without follow-up
C) No final step
D) Only report
*Ans: A* – Audit not complete until follow-up – ISACA requires follow-up.
www.gmsisuccess.in
