Certified Information Systems Auditor (CISA) | Domain 1 Audit Execution and Reporting 02
Problem 1 ・ Question 1 / 9
When selecting a sample to confirm that a control operated consistently, what should be checked about the population first?
View explanation
If the sample is drawn from an incomplete population, its results cannot properly be projected onto the population.
Problem 1 ・ Question 2 / 9
What is the best way to detect duplicate payments efficiently in a large volume of transaction data?
View explanation
Data analytics can extract from the whole population the transactions that meet the duplication criteria.
Problem 1 ・ Question 3 / 9
Which is generally the most reliable form of audit evidence?
View explanation
Evidence the auditor obtains directly from an independent external source is generally the most reliable.
Problem 1 ・ Question 4 / 9
Which procedure gives the strongest support that the procedure for removing user access actually works?
View explanation
Tracing from HR records and re-performing the check lets the auditor confirm operating effectiveness directly.
Problem 1 ・ Question 5 / 9
When an IS auditor uses an explanation obtained in an interview as evidence, what matters most?
View explanation
Oral explanations need to be checked against other objective evidence to make them more reliable.
Problem 1 ・ Question 6 / 9
What is the main advantage of statistical sampling?
View explanation
Statistical methods allow the precision of the result and the sampling risk to be evaluated in probabilistic terms.
Problem 1 ・ Question 7 / 9
What is the main purpose of audit working papers?
View explanation
Working papers record the basis for the audit work and judgements, making review and quality control possible.
Problem 1 ・ Question 8 / 9
What is the greatest benefit of identifying the cause of an audit finding?
View explanation
Addressing the cause rather than the surface exception leads to lasting improvement.
Problem 1 ・ Question 9 / 9
For a significant finding, management has decided to accept the risk and not remediate. What should the auditor do next?
View explanation
Risk acceptance should be made by someone with the appropriate authority, and anything beyond the tolerance should be escalated.
Result
More sets in this exam
- Certified Information Systems Auditor (CISA) | IS Audit Fundamentals
- Certified Information Systems Auditor (CISA) | Domain 1 Audit Planning and Risk Assessment 01
- Certified Information Systems Auditor (CISA) | Domain 2 Resources, Data and Third Parties 02
- Certified Information Systems Auditor (CISA) | Domain 3 Acquisition and Development Governance 01
- Certified Information Systems Auditor (CISA) | Domain 3 Testing, Conversion and Implementation 02
- Certified Information Systems Auditor (CISA) | Domain 4 IT Operations and Service Management 01