Sign In
Home/ISACA/CISA/Free questions

CISA — Free Practice Questions

10 free sample questions from a bank of 2264, with the correct answers and explanations. No signup required — start practising right now.

1Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
  • The BCP has not been tested since it was first issued.
  • The BCP is not version-controlled.
  • The BCP's contact information needs to be updated.
  • The BCP has not been approved by senior management.
Answer: A
2Which of the following is the BEST way to ensure that an application is performing according to its specifications?
  • Pilot testing
  • System testing
  • Integration testing
  • Unit testing
Answer: B
3While auditing a small organization's data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?
  • Conduct awareness presentations and seminars for information classification policies.
  • Use automatic document classification based on content.
  • Have IT security staff conduct targeted training for data owners.
  • Publish the data classification policy on the corporate web portal.
Answer: C
4Which of the following should be the GREATEST concern for an IS auditor performing a post-implementation review for a major system upgrade?
  • Changes are promoted to production by the development group.
  • Developers have access to the testing environment.
  • Object code can be accessed by the development group.
  • Change approvals are not formally documented.
Answer: D
5Which of the following observations noted by an IS auditor reviewing internal IT standards is MOST important to address?
  • The standards have no reference to an industry-recognized framework.
  • The standards are not detailed in policies and procedures.
  • The standards are not readily available to organization-wide users.
  • The standards have not been revised within the last year.
Answer: A
6Which of the following is MOST important for an organization to consider when planning to outsource data storage to a third-party provider?
  • The cost of delivering the service
  • The country in which the provider operates
  • The classification levels of the stored data
  • The skill set and experience of the provider
Answer: B
7An IS auditor has been tasked with analyzing an organization's capital expenditures against its repair and maintenance costs. Which of the following is the BEST reason to use a data analytics tool for this purpose?
  • It reduces the sample size required to perform the audit.
  • It improves the reliability of the data.
  • It reduces the error rate.
  • It enables the auditor to work with 100% of the transactions.
Answer: D
8Which of the following presents the GREATEST risk associated with end-user computing (EUC) applications over financial reporting?
  • Lack of portability for users
  • Calculation errors in spreadsheets B. Inability to quickly modify and deploy a solution
  • Loss of time due to manual processes
Answer: B
9An IS auditor should look for which of the following to ensure the risk associated with scope creep has been mitigated during software development?
  • Source code version control
  • Project change management controls
  • Existence of an architecture review board
  • Configuration management
Answer: B
10Which of the following is MOST important to consider when defining disaster recovery strategies?
  • Mean time to restore (MTTR)
  • Maximum time between failures (MTBF)
  • Maximum tolerable downtime (MTD)
  • Mean time to acknowledge (MTTA)
Answer: C

Want the full bank of 2264 questions for CISA? See all practice exams.