Study sets
English

Certified Information Systems Auditor (CISA) | Domain 1 Audit Execution and Reporting 02

1 / 90.0s

Problem 1 ・ Question 1 / 9

When selecting a sample to confirm that a control operated consistently, what should be checked about the population first?

View explanation

If the sample is drawn from an incomplete population, its results cannot properly be projected onto the population.

Problem 1 ・ Question 2 / 9

What is the best way to detect duplicate payments efficiently in a large volume of transaction data?

View explanation

Data analytics can extract from the whole population the transactions that meet the duplication criteria.

Problem 1 ・ Question 3 / 9

Which is generally the most reliable form of audit evidence?

View explanation

Evidence the auditor obtains directly from an independent external source is generally the most reliable.

Problem 1 ・ Question 4 / 9

Which procedure gives the strongest support that the procedure for removing user access actually works?

View explanation

Tracing from HR records and re-performing the check lets the auditor confirm operating effectiveness directly.

Problem 1 ・ Question 5 / 9

When an IS auditor uses an explanation obtained in an interview as evidence, what matters most?

View explanation

Oral explanations need to be checked against other objective evidence to make them more reliable.

Problem 1 ・ Question 6 / 9

What is the main advantage of statistical sampling?

View explanation

Statistical methods allow the precision of the result and the sampling risk to be evaluated in probabilistic terms.

Problem 1 ・ Question 7 / 9

What is the main purpose of audit working papers?

View explanation

Working papers record the basis for the audit work and judgements, making review and quality control possible.

Problem 1 ・ Question 8 / 9

What is the greatest benefit of identifying the cause of an audit finding?

View explanation

Addressing the cause rather than the surface exception leads to lasting improvement.

Problem 1 ・ Question 9 / 9

For a significant finding, management has decided to accept the risk and not remediate. What should the auditor do next?

View explanation

Risk acceptance should be made by someone with the appropriate authority, and anything beyond the tolerance should be escalated.