Isaca

CISA practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 1371-question bank.

Provider
Isaca
Question bank
1371
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CISA, a certification listed under Isaca. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isaca. The certification credential is issued by Isaca, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?

    Choose one answer.

    • The BCP has not been tested since it was first issued.
    • The BCP is not version-controlled.
    • The BCP's contact information needs to be updated.
    • The BCP has not been approved by senior management.
  2. Question 2 · 1

    Which of the following is the BEST way to ensure that an application is performing according to its specifications?

    Choose one answer.

    • Pilot testing
    • System testing
    • Integration testing
    • Unit testing
  3. Question 3 · 1

    While auditing a small organization's data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?

    Choose one answer.

    • Conduct awareness presentations and seminars for information classification policies.
    • Use automatic document classification based on content.
    • Have IT security staff conduct targeted training for data owners.
    • Publish the data classification policy on the corporate web portal.
  4. Question 4 · 1

    Which of the following should be the GREATEST concern for an IS auditor performing a post-implementation review for a major system upgrade?

    Choose one answer.

    • Changes are promoted to production by the development group.
    • Developers have access to the testing environment.
    • Object code can be accessed by the development group.
    • Change approvals are not formally documented.
  5. Question 5 · 1

    Which of the following observations noted by an IS auditor reviewing internal IT standards is MOST important to address?

    Choose one answer.

    • The standards have no reference to an industry-recognized framework.
    • The standards are not detailed in policies and procedures.
    • The standards are not readily available to organization-wide users.
    • The standards have not been revised within the last year.
  6. Question 6 · 1

    Which of the following is MOST important for an organization to consider when planning to outsource data storage to a third-party provider?

    Choose one answer.

    • The cost of delivering the service
    • The country in which the provider operates
    • The classification levels of the stored data
    • The skill set and experience of the provider
  7. Question 7 · 1

    An IS auditor has been tasked with analyzing an organization's capital expenditures against its repair and maintenance costs. Which of the following is the BEST reason to use a data analytics tool for this purpose?

    Choose one answer.

    • It reduces the sample size required to perform the audit.
    • It improves the reliability of the data.
    • It reduces the error rate.
    • It enables the auditor to work with 100% of the transactions.
  8. Question 8 · 1

    An IS auditor should look for which of the following to ensure the risk associated with scope creep has been mitigated during software development?

    Choose one answer.

    • Source code version control
    • Project change management controls
    • Existence of an architecture review board
    • Configuration management
  9. Question 9 · 1

    Which of the following is MOST important to consider when defining disaster recovery strategies?

    Choose one answer.

    • Mean time to restore (MTTR)
    • Maximum time between failures (MTBF)
    • Maximum tolerable downtime (MTD)
    • Mean time to acknowledge (MTTA)
  10. Question 10 · 1

    Which of the following is the GREATEST advantage of agile development over waterfall development?

    Choose one answer.

    • Agile development values working software over static documentation.
    • Agile development values processes and tools over individuals and interactions.
    • Agile development values contract negotiation over customer collaboration.
    • Agile development values following a plan over responding to change.
  11. Question 11 · 1

    Which of the following controls provides the MOST protection against ransomware attacks?

    Choose one answer.

    • Education and awareness training
    • Tested and reliable backups
    • A tested incident response plan
    • Signature based anti-malware tools
  12. Question 12 · 1

    Which of the following is the BEST control to help ensure that security requirements are considered throughout the life cycle of an agile software development project?

    Choose one answer.

    • Including project team members who can provide security expertise
    • Reverting to traditional waterfall software development life cycle (SDLC) techniques
    • Documenting security control requirements and obtaining internal audit sign off
    • Requiring the project to go through accreditation before release into production
  13. Question 13 · 1

    An IS auditor finds that a key Internet-facing system is vulnerable to attack and that patches are not available. What should the auditor recommend be done FIRST?

    Choose one answer.

    • Implement additional firewalls to protect the system.
    • Decommission the server.
    • Implement a new system that can be patched.
    • Evaluate the associated risk.
  14. Question 14 · 1

    Which of the following is the BEST control to help ensure that security requirements are considered throughout the life cycle of an agile software development project?

    Choose one answer.

    • Including project team members who can provide security expertise
    • Reverting to traditional waterfall software development life cycle (SDLC) techniques
    • Documenting security control requirements and obtaining internal audit sign off
    • Requiring the project to go through accreditation before release into production
  15. Question 15 · 1

    Which of the following is the BEST control to help ensure that security requirements are considered throughout the life cycle of an agile software development project?

    Choose one answer.

    • Including project team members who can provide security expertise
    • Reverting to traditional waterfall software development life cycle (SDLC) techniques
    • Documenting security control requirements and obtaining internal audit sign off
    • Requiring the project to go through accreditation before release into production

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free