Certified Information Systems Auditor (CISA) | Domain 1 Audit Planning and Risk Assessment 01
Problem 1 ・ Question 1 / 9
Which reporting relationship best secures the independence of the IS audit function?
View explanation
Reporting functionally to a governing body such as the audit committee strengthens independence from executive management.
Problem 1 ・ Question 2 / 9
What is the most appropriate basis for prioritising audit subjects in the annual audit plan?
View explanation
Risk-based auditing prioritises on the basis of the impact on enterprise objectives and the likelihood of occurrence.
Problem 1 ・ Question 3 / 9
When starting a new audit engagement, what should the IS auditor clarify first?
View explanation
Once the objectives and scope are clear, the procedures, resources and schedule can be worked out.
Problem 1 ・ Question 4 / 9
An IS auditor is asked to audit a system whose design they were responsible for until recently. What is the most appropriate response?
View explanation
Disclose the self-review threat and protect objectivity, for example by moving the work to an independent auditor.
Problem 1 ・ Question 5 / 9
What is the main purpose of considering materiality in audit planning?
View explanation
Materiality is used to identify matters that would affect users' judgement and to allocate audit resources appropriately.
Problem 1 ・ Question 6 / 9
Which risk exists where there are no controls and nothing is done about it?
View explanation
Inherent risk is the risk an activity or asset carries in itself, before controls are taken into account.
Problem 1 ・ Question 7 / 9
Which control stops errors arising in the first place?
View explanation
Preventive controls such as input checks and segregation of duties reduce the likelihood of error and fraud.
Problem 1 ・ Question 8 / 9
The department being audited has no formal approval control, but an independent after-the-event review reduces the risk to a comparable degree. What is that review?
View explanation
A control that makes up for the absence of the intended control to a comparable degree is a compensating control.
Problem 1 ・ Question 9 / 9
An IS auditor has judged the risk of fraud to be high. What should they do next?
View explanation
Design audit procedures that respond to the risk assessed and gather sufficient evidence.
Result
More sets in this exam
- Certified Information Systems Auditor (CISA) | IS Audit Fundamentals
- Certified Information Systems Auditor (CISA) | Domain 2 IT Governance and Strategy 01
- Certified Information Systems Auditor (CISA) | Domain 2 Resources, Data and Third Parties 02
- Certified Information Systems Auditor (CISA) | Domain 3 Acquisition and Development Governance 01
- Certified Information Systems Auditor (CISA) | Domain 3 Testing, Conversion and Implementation 02
- Certified Information Systems Auditor (CISA) | Domain 4 IT Operations and Service Management 01