Free CISA Practice Exam: Information Systems Auditing
Answer 150 original CISA practice questions with explanations, audit exhibits and diagrams across all five domains.
These are original IT Mastery practice questions, independently selected from the published app question bank. They are not official ISACA questions, copied live-exam content or exam dumps. IT Mastery is independent of ISACA.
How to use this practice set
Answer all 150 questions before opening explanations for a timed attempt. Every question has four choices and one best answer. Use four hours if rehearsing the official time allowance; the page does not run a timer, save responses or reproduce an official exam form. Record your choices separately.
Questions cover the five domains in proportions 27 / 27 / 18 / 39 / 39. Both concise scenarios and document-based questions are included. Read each exhibit and any diagram description as part of the evidence.
Answer options were shuffled during page generation. Displayed answer letters are derived from that order; refreshing the page retains the same static order.
Practice-set coverage
| Domain | Official range | Questions in this set |
|---|---|---|
| Information System Auditing Process | 18% | 27 |
| Governance and Management of IT | 18% | 27 |
| Information Systems Acquisition, Development, and Implementation | 12% | 18 |
| Information Systems Operations and Business Resilience | 26% | 39 |
| Protection of Information Assets | 26% | 39 |
Practice questions
Questions 1-25
Question 1
Topic: Information Asset Protection
An IS auditor is assessing the operating effectiveness of a SOC control designed to detect unauthorized privileged access. The control requires continuous ingestion from every designated critical source and daily heartbeat review. The SOC cites falling alerts as evidence of improved security.
Review-period evidence:
| Evidence | June 1-14 | June 15-28 |
|---|---|---|
| Identity-provider feed | Healthy | Heartbeat failed; zero events |
| Authentication volume | 10,000/day | 10,200/day |
| Other required feeds | Healthy | Healthy |
| Privileged-access alerts | 100/day | 58/day |
The identity-provider feed is designated critical and historically generated 40% of privileged-access alerts. What should the auditor do next?
Options:
A. Generate a current identity-provider alert end to end before rating review-period effectiveness.
B. Assess the outage and compensating telemetry for omitted events before rating review-period effectiveness.
C. Rebaseline expected alert volume around healthy feeds before rating review-period effectiveness.
D. Compare confirmed-incident rates across both periods before rating review-period effectiveness.
Best answer: B
Explanation: Alert volume supports a security trend only when the underlying detection population remains complete and comparable. Authentication activity stayed essentially constant, but the critical identity-provider feed failed and produced no events. The 42% alert decline also closely matches that source’s historical 40% contribution, indicating lost visibility rather than demonstrated risk reduction. The auditor should establish the outage’s duration and scope, identify potentially omitted privileged events, and evaluate whether independent telemetry provided equivalent coverage during the gap. A successful restoration test can confirm current ingestion but cannot prove the control operated throughout June 15-28.
Rebaselining or analyzing detected incidents would preserve the same incomplete population and cannot validate the SOC’s conclusion.
- Rebaselining around healthy feeds normalizes the missing required source instead of assessing its effect on detection coverage.
- Confirmed-incident rates include only detected activity and cannot reveal privileged events that were never ingested.
- A current end-to-end test verifies restoration, not sustained operation during the affected review period.
Question 2
Topic: Operations and Resilience
An IS auditor is assessing an operations-owned workbook used weekly to authorize inventory transfers of up to $6 million.
- Formula cells are password-locked after preparation.
- An emailed CSV is imported after filename and column-format checks, but source authenticity, record counts, and control totals are not validated.
- Two reorder formulas differ from the approved workbook, with no approval or version record.
- The manager reviews the summary, but no independent reconciliation occurs.
Which recommendation would BEST address the risks before continued reliance on the workbook?
Options:
A. Require automated schema and duplicate checks, sample formula reperformance, and reconciliation to the purchasing budget before each authorization.
B. Require restricted edit access, password rotation, and a documented management reasonableness review before each authorization.
C. Require authorized-source and control-total validation, approved formula versioning, and independent reconciliation of inputs and outputs before authorization.
D. Require archived locked versions, preparer exception sign-off, and forecast-to-actual variance investigation after each authorization.
Best answer: C
Explanation: Workbook protection primarily restricts editing; it does not establish the integrity of imported data or prove that formulas match the approved logic. A material end-user computing process needs controls over three areas: validating external data against an authorized source and control totals, controlling and approving formula versions, and independently reconciling inputs and resulting outputs before authorization. Management review, sample reperformance, and post-transfer variance analysis can supplement these controls, but they do not resolve the identified source, change, and reconciliation gaps before the decision is made.
- Access restrictions and reasonableness review do not validate imported data or detect unapproved formula changes reliably.
- Schema, duplicate, and budget checks do not establish source completeness or reconcile calculations to approved logic.
- Archived versions and post-transfer variance analysis detect issues retrospectively rather than supporting the pending authorization.
Question 3
Topic: Acquisition and Implementation
An IS auditor is performing a post-implementation review of a refund system intended to prevent unauthorized payments.
Approved requirement: Refunds of $10,000 or more require approval by two different employees, one from Customer Service and one from Finance. The requester cannot approve.
Production evidence: A $12,400 refund requested by MChen was approved twice by JLee, who had an approved temporary assignment to both approval roles. The system then released the refund.
Which conclusion is BEST supported?
Options:
A. The workflow cannot be assessed until more high-value refund records are sampled.
B. The workflow fails the requirement because it validates roles rather than distinct employee identities.
C. The workflow satisfies the requirement because both required approval roles acted before release.
D. The workflow satisfies the requirement because management authorized the temporary dual-role assignment.
Best answer: B
Explanation: Approved functional and control requirements are acceptance criteria for assessing an implemented system. Here, the workflow must enforce both required roles and two different employee identities. The production record directly demonstrates that the deployed control accepted one identity for both approvals and released the refund. Recording two role approvals and excluding the requester do not satisfy the distinct-employee condition.
A single confirmed counterexample is sufficient to establish that the implementation permits a prohibited state. A larger sample may help estimate how often the issue occurred, but it is not necessary to identify the implementation deficiency. Management’s approval of dual-role access also does not override the transaction requirement unless that requirement was formally changed.
- Role approvals recorded fails because role validation does not establish that two different employees approved the refund.
- Authorized dual access fails because access authorization does not waive the approved transaction-level separation requirement.
- Larger sample needed fails because the observed exception already proves the workflow can violate the requirement.
Question 4
Topic: Operations and Resilience
An IS auditor reviews the following resilience record:
Exhibit: Approved standard and test record
Requirement: Customer processing must continue after failure
of any one compute or power component.
Power map:
UPS-1 -> PDU-1 -> Node A
UPS-1 -> PDU-2 -> Node B
Test action: Powered off Node A at its chassis.
Observation: Node B processed transactions for 30 minutes.
Power components disconnected: None
Recorded result: Pass
Which assessment should the auditor make?
Options:
A. Conclude no resilience evidence exists until a facility-wide power-loss test is completed.
B. Conclude resilience was demonstrated because separate PDUs isolate the nodes during a component failure.
C. Conclude the design is adequate, but repeat the node failover test for a longer period.
D. Conclude compute failover worked, but the shared UPS prevents meeting the power-component requirement.
Best answer: D
Explanation: The record demonstrates compute failover: Node B continued processing when Node A was shut down. However, the power map shows that both PDUs depend on UPS-1. Separate downstream PDUs protect against failure of one PDU, but they do not protect against failure of their common upstream UPS. Because the requirement covers failure of any one power component, the architecture does not satisfy the requirement for an UPS-1 failure. Extending the node test would provide more evidence about failover duration, not eliminate the common power dependency. The recorded pass therefore applies only to the compute failure tested, not to the complete resilience requirement.
- Separate PDUs cannot isolate the nodes from failure of their shared upstream UPS.
- A longer node test evaluates sustained operation but does not correct the common power dependency.
- A facility-wide outage test is unnecessary to identify the gap and would disregard valid compute failover evidence.
Question 5
Topic: Information Asset Protection
An IS auditor is assessing a Kubernetes platform that hosts workloads for separate customers.
Privileged cross-tenant access must be individually attributable, approved, and time-limited to an emergency session.
Evidence:
- Tenant namespaces use default-deny network policies and namespace-scoped RBAC.
- A shared support service account has a non-expiring credential and cluster-wide
getandlistpermissions for pods and secrets. - During 90 days, the account queried pod health daily, but logs show no secret requests or cross-tenant incidents.
Which assessment is BEST supported?
Options:
A. Conclude network-isolation design is inadequate because network policies do not constrain management-plane RBAC permissions.
B. Conclude tenant isolation is operating effectively because logs show no secret access or cross-tenant security incident.
C. Conclude tenant-isolation design is inadequate because standing cluster-wide privilege bypasses the required emergency-access model.
D. Conclude tenant-isolation design is adequate but operating effectiveness is deficient because the account supports routine monitoring.
Best answer: C
Explanation: Isolation must cover both workload traffic and privileged management-plane access. Namespace RBAC and network policies reduce ordinary cross-tenant access, but the shared service account retains standing cluster-wide authority to read secrets. Its non-expiring credential and routine use conflict with the required emergency-access model, making this a control design deficiency. The absence of observed secret requests may reduce evidence of exploitation, but it does not remove the unauthorized capability or establish effective isolation.
Network policies govern workload communications, while RBAC governs management-plane authorization. The decisive issue is therefore excessive privileged access, not a failure of network segmentation.
- Treating design as adequate overlooks that the permanent cluster-wide role directly conflicts with the approved control model.
- Relying on clean logs confuses absence of detected misuse with adequate control design.
- Blaming network policies misclassifies an RBAC privilege issue as a network-segmentation failure.
Question 6
Topic: Information Asset Protection
An IS auditor is evaluating a quarterly payroll access recertification. Which recommendation BEST addresses the assurance deficiencies in the record?
Access Recertification Standard and campaign record:
Population: Reconcile all active application accounts
to the campaign population.
Decision owner: Each user's business manager.
IAM role: Administer the campaign; do not approve access.
Active payroll accounts: 1,284
Campaign records: 1,247
Population reconciliation: Not performed
Decision actor: IAM operations analyst
Result: Retain all 1,247 accounts
Attachment: Payroll owner email stating "No concerns."
Options:
A. Reperform the review with a reconciled population and record-level business manager decisions.
B. Reconcile the population totals and obtain payroll owner approval of the campaign summary.
C. Reperform the review using the IAM export and obtain approval from the IAM operations manager.
D. Retain the completed review and have business managers certify only the omitted accounts.
Best answer: A
Explanation: Reliable access recertification requires both a complete review population and approval by accountable business reviewers. The campaign omitted 37 active payroll accounts, and no reconciliation established why they were excluded. Therefore, the population cannot support a completeness assertion. For the included accounts, an IAM analyst made the decisions even though IAM was authorized only to administer the campaign. The payroll owner’s general email does not demonstrate review of individual users’ business needs.
The review should be repeated using a population reconciled to the active application accounts, with each decision attributable to the designated business manager. Technical administration and broad acknowledgment cannot replace accountable, record-level certification.
- Reviewing only the 37 omitted accounts leaves the original 1,247 IAM analyst decisions unsupported by authorized business review.
- IAM management approval remains a technical-function review rather than the required assessment of each user’s business need.
- A campaign-summary approval does not demonstrate record-level decisions by designated managers, even after totals are reconciled.
Question 7
Topic: Operations and Resilience
An IS auditor reviews a patch record against the following procedure.
PATCH PROCEDURE
Risk rating: exploit activity, exposure, business impact
Critical target: production deployment within 72 hours
Emergency testing: approved business-function and rollback tests
Closure: production version check succeeds AND authenticated scan reports not detected
PATCH RECORD
Asset: Internet-facing payment gateway
Risk: Critical; active exploitation; high business impact
Opened: July 8, 09:00 Deployed: July 9, 16:00
Staging: payment, login, rollback tests passed and approved
Production version check: Passed
Authenticated scan: Vulnerability detected
Status: Closed; scanner considered stale; no follow-up recorded
What should the auditor recommend?
Options:
A. Recommend management retain closure and investigate the scan during routine scanner maintenance.
B. Recommend management reopen the record and repeat staging tests before confirming remediation.
C. Recommend management retain closure and perform another production version check to confirm remediation.
D. Recommend management reopen the record and resolve the positive scan before confirming remediation.
Best answer: D
Explanation: Patch assurance distinguishes prioritization, testing, deployment and remediation verification. The critical classification reflects active exploitation, external exposure and high business impact, while deployment occurred within 72 hours. The approved staging tests also satisfy the stated emergency-testing requirement. However, closure requires both a successful production version check and an authenticated scan reporting that the vulnerability is not detected. The scan remains positive, and the unsupported assumption that it is stale does not resolve this contradictory evidence. Management should investigate the result, correct any deployment or scanning issue, and obtain a satisfactory rescan before confirming remediation. Successful installation evidence alone does not establish that the vulnerability was effectively removed.
- Deferring the positive result to routine maintenance leaves the mandatory closure criterion unmet.
- Repeating staging tests does not resolve contradictory evidence from the production environment.
- Another version check duplicates evidence that already passed and cannot replace the required vulnerability scan result.
Question 8
Topic: Acquisition and Implementation
An IS auditor is evaluating go-live readiness for an online ordering platform. Release policy requires production-like evidence that support, security, and recovery criteria are met before approval.
Readiness evidence:
- Service desk staff passed a support simulation.
- High-severity security findings were retested and closed.
- A recovery exercise restored service in 3 hours 40 minutes, meeting the 4-hour RTO.
- Restored transactions were 55 minutes old, exceeding the 30-minute RPO.
- Replication intended to reduce data loss was enabled afterward but has not been recovery-tested.
Which recommendation should the auditor make?
Options:
A. Approve go-live based on the met RTO and the enabled replication setting.
B. Defer go-live pending a production-like recovery test that meets the 30-minute RPO.
C. Defer go-live pending another security test confirming closure of high-severity findings.
D. Approve go-live with a post-release recovery exercise validating the 30-minute RPO.
Best answer: B
Explanation: Recovery time objective (RTO) measures how quickly service must be restored, while recovery point objective (RPO) limits acceptable data loss. The exercise restored service within four hours, so it met the RTO. However, the recovered transactions were 55 minutes old, exceeding the 30-minute RPO. Enabling replication may improve recovery capability, but configuration alone does not demonstrate operating effectiveness or recoverability. Because release policy requires production-like evidence before approval, recovery must be tested again with the replication change in place. Post-release validation would not satisfy the stated readiness requirement.
- Relying on replication fails because an enabled but untested mechanism does not demonstrate that the required recovery point can be achieved.
- Testing after release fails because policy requires recovery evidence before go-live approval.
- Repeating security testing does not address the remaining deficiency because high-severity findings were already retested and closed.
Question 9
Topic: IT Governance and Management
An IS auditor is reviewing emergency change management intended to prevent unauthorized production changes.
- Policy: Production changes must be authorized, tested and traceable.
- Mandatory standard: Create a ticket before deployment, obtain owner approval within one business day and complete retrospective review within five business days.
- Procedure: Record the incident, link test evidence, deploy and route the ticket for review.
- Discretionary guidance: Teams should consider an independent peer walkthrough for high-impact changes.
A sampled high-impact change met the policy, standard and procedure, but had no peer walkthrough. Which audit judgment is best supported?
Options:
A. Conclude policy requirements were breached and seek formal acceptance of the walkthrough exception.
B. Conclude procedure requirements were breached and require walkthrough evidence in each emergency ticket.
C. Conclude standard requirements were breached and expand testing for omitted peer walkthroughs.
D. Conclude mandatory requirements were met and evaluate the walkthrough as an improvement opportunity.
Best answer: D
Explanation: Policies provide management direction, standards establish mandatory and measurable requirements, procedures prescribe how activities are performed, and guidance recommends discretionary practices. The sampled change satisfied the stated policy, mandatory standard and procedure. Because the peer walkthrough appears only in explicitly discretionary guidance, its absence does not establish a control violation or require a formal exception. The auditor may still assess whether high-impact changes create enough residual risk to justify recommending peer walkthroughs as a control enhancement. A recommendation based on risk should not be misreported as noncompliance with requirements that do not mandate the practice.
- A policy breach is unsupported because the change was authorized, tested and traceable as required.
- A standard breach is unsupported because every stated timing and documentation requirement was satisfied.
- A procedure failure is unsupported because the prescribed operational steps were completed; the walkthrough was separate guidance.
Question 10
Topic: Operations and Resilience
An IS auditor reviews the disposal of a laptop containing confidential data.
Policy excerpt:
Before confidential media leaves organizational custody, IT must document approved sanitization or cryptographic erasure with key-destruction evidence. The asset register must retain approval, signed handoffs, and final destruction evidence.
Disposal record:
| Field | Entry |
|---|---|
| Approval | ITAM-731, approved June 4 |
| Sanitization | Full-disk encryption enabled |
| Key destruction evidence | None attached |
| Handoff | Both parties signed June 6 |
| Destruction certificate | EC-908, attached June 8 |
Which control deficiency is BEST supported by this record?
Options:
A. Final disposition was not demonstrated after the external handoff.
B. Transfer authorization was not demonstrated before external release.
C. Information protection was not demonstrated before external release.
D. Custody accountability was not demonstrated through the external handoff.
Best answer: C
Explanation: Media disposal controls must protect information before an asset leaves organizational custody. Full-disk encryption protects stored data while valid encryption keys exist, but merely recording that encryption was enabled does not demonstrate sanitization or cryptographic erasure. The record contains no key-destruction evidence, so it does not satisfy the policy’s pre-release requirement.
The approved ticket supports authorization, both handoff signatures preserve custody accountability, and the vendor certificate supports final physical destruction. However, later destruction does not compensate for missing evidence that confidential data was protected as required when custody transferred.
- Transfer authorization: The approved IT asset management ticket predates the external handoff.
- Custody accountability: The record identifies the transfer and contains signatures from both parties.
- Final disposition: The attached vendor certificate documents destruction after the handoff.
Question 11
Topic: Information Asset Protection
An IS auditor is reviewing a monitoring rule after a change in business operations.
Approved monitoring record:
MONITORING CHANGE RECORD R-17
Rule: Alert on >500 customer records outside 07:00-19:00
Owner: Security Monitoring
Production tuning: Data owner approval required
Validation: Test candidate logic against authorized activity and confirmed cases
Business change: Customer support moved to 24-hour operations
Previous two-month alert average: 180
Current two-month alerts: 1,240
Closed as expected activity: 1,180
Closures linked to investigation evidence: 42
Confirmed cases expected to trigger R-17: 3; detected: 1
Candidate-rule validation performed: None
Which action should the auditor recommend?
Options:
A. Raise the bulk-access threshold using prior alert volumes, obtain approval, and require evidence for future closures.
B. Exclude the new operating hours and approved service accounts, obtain approval, and compare subsequent alert volumes.
C. Validate candidate logic against authorized activity and confirmed cases, obtain approval, and track subsequent outcomes.
D. Retain the current logic, require evidence for future closures, and reconsider tuning after three months.
Best answer: C
Explanation: Monitoring rules must be reassessed when business behavior changes because previous thresholds and schedules may no longer distinguish normal from suspicious activity. The record shows substantial apparent noise, weak evidence supporting most closures, and two missed confirmed cases. Alert volume or closure rate alone cannot demonstrate effective detection.
Security Monitoring should test candidate logic against authorized 24-hour activity and the confirmed cases, document the results, and obtain the required data-owner approval before production tuning. Subsequent investigation outcomes should then be monitored to confirm sustained effectiveness. The objective is improved detection quality, not merely restoration of the previous alert count.
- Blanket time or account exclusions could conceal malicious activity occurring through newly authorized channels.
- Raising the threshold to match historical volume optimizes alert quantity without demonstrating detection effectiveness.
- Delaying tuning leaves known noise and missed detections unresolved despite available cases for validation.
Question 12
Topic: Information Asset Protection
An IS auditor is assessing a payroll archive encryption control. The business requirement states that no key administrator may independently access protected salary information.
Current access:
- Key custodians can read encrypted payroll archives for restoration support.
- They can modify key policies, including granting their own accounts decryption rights.
- Policy changes and decryption events are logged and reviewed the next business day.
- No unauthorized decryption has been detected.
Which conclusion is best supported?
Options:
A. Conclude the separation failed operationally because custodians’ archive access demonstrates they viewed decrypted salary information.
B. Conclude the preventive separation is inadequately designed because custodians can combine archive access with self-granted decryption.
C. Conclude the separation is adequately designed because custodians lack standing decryption and all changes are independently reviewed.
D. Conclude the separation is designed effectively, but defer operating-effectiveness judgment until a sample of decryption events is tested.
Best answer: B
Explanation: Separation of duties is assessed from effective capabilities, not merely current standing permissions. A custodian who can obtain encrypted archives and modify the key policy to grant personal decryption rights can independently reach the protected information. This violates the stated preventive requirement.
Next-business-day log review is a detective control. It may identify policy changes or decryption after they occur, but it does not prevent the incompatible access. However, the absence of unauthorized events also means the auditor cannot conclude that salary information was actually decrypted. The evidence supports a control design deficiency, not a proven operating failure or confidentiality breach.
- Standing access only: The ability to self-grant decryption defeats separation even when decryption is not permanently assigned.
- Defer for testing: Operating tests are unnecessary to identify the incompatible capabilities already present in the design.
- Assume actual disclosure: Access to encrypted archives does not prove that custodians viewed decrypted salary information.
Question 13
Topic: Information Asset Protection
An IS auditor is performing real-time assurance over a service provider’s incident notification control. The notification workflow has not been initiated.
Contract requirement:
Notify the customer within 24 clock hours after the provider’s incident response manager confirms unauthorized disclosure of customer personal data. Preliminary alerts do not start the period, and an initial notice may be supplemented.
Timeline:
- May 8, 08:00: A DLP alert is generated.
- May 8, 11:00: An analyst validates that customer records were disclosed.
- May 8, 13:00: The incident response manager confirms the incident.
- May 9, 10:00: Management plans notification for May 10, 16:00 after forensic scoping.
What should the auditor recommend?
Options:
A. Advise initial notification by May 9 at 13:00, based on manager confirmation.
B. Advise initial notification immediately as overdue, based on the original DLP alert.
C. Advise initial notification by May 9 at 11:00, based on analyst validation.
D. Advise initial notification on May 10 at 16:00, based on completed scoping.
Best answer: A
Explanation: The reporting trigger is the event specified in the contract, not necessarily initial detection or completion of the investigation. The DLP alert was preliminary, and the analyst was not the designated confirmation authority. The incident response manager confirmed the disclosure on May 8 at 13:00, so the 24-clock-hour deadline is May 9 at 13:00. At the review time, the deadline has not passed, but only three hours remain. Because the contract permits supplemental information, incomplete forensic scoping does not justify delaying the initial notice. The auditor should advise responsible management promptly while leaving notification execution to management.
- Analyst validation does not start the contractual period because confirmation is assigned to the incident response manager.
- DLP alert timing does not make the notice overdue because preliminary alerts are expressly excluded as triggers.
- Completed scoping is not required before initial notice, and waiting until May 10 would exceed the supplied deadline.
Question 14
Topic: Auditing Process
An IS auditor is assessing whether the maker-checker control operated for all production supplier payments in June. Policy requires different users to initiate and approve each payment.
- The reconciled immutable ledger covers all 8,420 posted payments.
- For 37 payment IDs, the ledger records the same account for initiation and approval.
- Ledger timestamps represent database commit time, not user action time.
- The operations manager attributes the records to an outage replay that committed earlier approvals under a service account. The incident ticket confirms the replay window but contains no payment IDs or user actions.
Which audit procedure would BEST support a conclusion about the 37 payments?
Options:
A. Test random unaffected payments and use the resulting exception rate to classify the 37 anomalous payments.
B. Classify the 37 records as control exceptions and assess their effect on June operating effectiveness.
C. Correlate the 37 IDs with source approvals, identity logs, and replay records, then classify each payment.
D. Correlate replay-window entries with the recovery procedure and incident ticket, then exclude the replayed payments.
Best answer: C
Explanation: Immutability establishes that ledger records have not been altered, but it does not prove that commit timestamps and replay accounts represent the original user actions. The reconciled population supports completeness, while the 37 identified records require transaction-level investigation. Correlating each payment with source approval history, identity evidence, and replay records tests management’s explanation across the relevant IDs and time periods. This evidence can distinguish an actual maker-checker failure from a replay-related audit-trail issue. A recovery ticket or unaffected sample does not resolve who initiated and approved the disputed payments.
- Recovery documentation confirms authorized processing and timing, but not separate initiators and approvers for each disputed payment.
- Immediate exception classification treats record integrity as proof that the replay account represents the original approving user.
- Testing unaffected payments may assess broader operation but cannot resolve the contradictory evidence for the known anomalies.
Question 15
Topic: Operations and Resilience
An IS auditor is observing a disaster recovery exercise to assess whether order processing can safely return from the recovery site to the primary site. The primary site has passed technical recovery tests.
Failback procedure:
- Freeze transaction processing.
- Reconcile all order IDs, statuses, and amounts through the freeze cutoff.
- Obtain process-owner authorization after review of the final reconciliation.
A reconciliation completed at 13:45 covers transactions through 13:40. Before the scheduled 14:05 freeze, the recovery site records 36 new orders and 14 status corrections. At 14:00, the process owner approves failback using the 13:45 report.
What should the auditor recommend?
Options:
A. Freeze processing, rerun full-population reconciliation, and rely on the existing process-owner authorization for failback.
B. Freeze processing, rerun full-population reconciliation, and obtain infrastructure-manager authorization before failback.
C. Freeze processing, reconcile only post-report changes, and obtain renewed process-owner authorization before failback.
D. Freeze processing, rerun full-population reconciliation, and obtain renewed process-owner authorization before failback.
Best answer: D
Explanation: Failback requires assurance over both data integrity and business authorization, not merely technical readiness. The existing report and approval are stale because 50 changes occurred after the report’s cutoff. Once processing is frozen, a full-population reconciliation must confirm that identifiers, statuses, and amounts reflect the final recovery-site state. The designated process owner must then review that evidence and authorize the return to normal processing.
Successful technical tests demonstrate that the primary environment can operate, but they do not establish that its data is complete and accurate. Similarly, authorization issued before the final reconciliation does not satisfy the required control sequence.
- Reconciling only recent changes does not satisfy the stated requirement for a full-population reconciliation through the freeze cutoff.
- Existing authorization predates the final data state and therefore is not based on the required final reconciliation.
- Infrastructure-management approval confirms technical readiness but does not replace authorization from the designated business process owner.
Question 16
Topic: IT Governance and Management
An IS auditor is reviewing privacy controls before management approves a fraud analytics service. The organization requires transfer approval for every country receiving personal data and contracts that impose equivalent privacy obligations on subprocessors.
Evidence:
- The approved, minimum dataset is processed by the primary provider in Country B.
- The privacy office approved the transfer mechanism for Country B.
- A subprocessor in Country C receives the same data for support.
- Country C has not been assessed, and the contract lacks subprocessor flow-down obligations.
- An assurance report covers both providers with no relevant security exceptions.
Which recommendation should the IS auditor provide?
Options:
A. Recommend release only after Country C transfer approval and contractual flow-down obligations are completed.
B. Recommend release after the vendor confirms equivalent safeguards for Country C in a written attestation.
C. Recommend release after Country C is added to inventory under the approved Country B mechanism.
D. Recommend release based on the assurance report, with relevant exceptions monitored in later periods.
Best answer: A
Explanation: Privacy assurance must follow the complete data flow, including onward transfers to subprocessors. The stated standard requires separate transfer approval for every receiving country and contractual flow-down of equivalent privacy obligations. Country B’s approved mechanism therefore does not establish approval for Country C, and the existing contract does not satisfy the subprocessor requirement.
The assurance report supports security-control assessment but does not replace country-specific transfer approval or required contractual terms. Similarly, an inventory entry or vendor attestation documents the arrangement without correcting its design deficiencies. The auditor should identify these gaps and recommend their resolution while management retains release authority.
- Adding Country C to inventory records the transfer but does not approve its mechanism or establish contractual obligations.
- Security assurance with no exceptions does not demonstrate compliance with the separate privacy transfer and contracting requirements.
- A vendor attestation is weaker than the explicitly required contractual flow-down and does not provide Country C transfer approval.
Question 17
Topic: Acquisition and Implementation
An IS auditor is reviewing a packaged application before production deployment and final payment. The cited SOC report covers the supplier’s general controls, not the configured application’s logging behavior.
Acceptance record:
AP-4 Final Product Acceptance
Every mandatory requirement must reference an executed test.
Failed or untested requirements require risk-owner disposition.
AC-118
M-14 Invoice matching UAT-23 Pass
M-22 Privileged-action log -- Supplier SOC report
M-31 Recovery within 24 h DR-2 Pass
Exceptions: None
Final acceptance: Business owner approved
Which recommendation BEST addresses the acceptance-control deficiency?
Options:
A. Reopen AC-118, assess the SOC report scope and customer controls, and map its assurance to M-22.
B. Reopen AC-118, test M-22, and obtain risk-owner disposition if it does not pass.
C. Reopen AC-118, reperform UAT-23 with independent invoice data, and update the evidence for M-14.
D. Reopen AC-118, repeat DR-2 under peak transaction volume, and update the evidence for M-31.
Best answer: B
Explanation: Product acceptance requires evidence that each mandatory requirement was tested in the configured product or handled through the authorized exception process. AC-118 provides neither for M-22: the test identifier is blank, the supplier report addresses general controls, and the record lists no exception. The business owner’s approval does not compensate for missing test evidence or the required risk-owner disposition.
Because deployment and final payment are pending, management can reopen the record, perform the product-specific logging test, and document either a passing result or an approved disposition. Supplier assurance may support due diligence, but it does not establish that the configured logging requirement operates as required.
- Expanded SOC review does not demonstrate privileged-action logging in the configured product or satisfy the executed-test requirement.
- Invoice retesting addresses M-14, which already has a recorded passing test, rather than the untested logging requirement.
- Recovery stress testing adds an unstated peak-volume criterion and does not resolve the missing evidence for M-22.
Question 18
Topic: IT Governance and Management
An IS auditor has reconciled a monthly service-quality record to the source monitoring and incident data.
Service quality agreement and record:
Availability target: >= 99.90% monthly
Availability formula: (service minutes - applicable downtime) / service minutes
Maintenance exclusion: allowed only with customer notice >= 7 days
P1 target: restore within 4 hours for >= 95% of monthly P1 incidents
Service minutes: 43,200
Downtime counted: 20 minutes
Downtime excluded: 45 minutes emergency maintenance; notice given 2 hours before
Reported availability: 99.95%
P1 incidents restored within 4 hours: 19 of 20
Status: Conforming
Which conclusion is BEST supported?
Options:
A. The service does not conform because one P1 incident exceeded four hours, although reported availability met target.
B. The service does not conform because applicable downtime makes availability about 99.85%, although the P1 target was met.
C. The service conforms because emergency maintenance is excludable downtime and the P1 restoration rate reached 95%.
D. The service conforms because reported availability exceeded 99.90% and exactly 95% of P1 incidents met target.
Best answer: B
Explanation: Conformance must be assessed against the agreed measurement rules, not the reported status. The emergency maintenance received only two hours of notice, so it does not qualify for exclusion. Applicable downtime is therefore 65 minutes, producing availability of \((43,200-65)/43,200 \times 100\), or approximately 99.85%. This is below the 99.90% requirement. Separately, 19 of 20 P1 incidents equals 95%, so that requirement was met.
Failing either agreed quality requirement prevents the service from being classified as conforming for the month.
- Relying on reported availability overlooks whether the excluded downtime satisfied the agreement’s notice condition.
- Treating one late P1 restoration as nonconformance ignores that the requirement permits up to 5% to exceed four hours.
- Classifying all emergency maintenance as excludable disregards the explicit seven-day customer-notice requirement.
Question 19
Topic: Auditing Process
A small application team cannot segregate code development from production deployment. The business risk owner accepts detection by the next business day.
An operations manager outside the team:
- Has read-only log access and authority to require rollback and escalation.
- Reconciles every deployment ID, hash, and timestamp to an approved change ticket.
- Retains source exports, ticket evidence, exception dispositions, and signed review records.
For the quarter, the auditor verified all 62 reviews were timely. Two unmatched deployments were identified, escalated, and rolled back according to policy. Log completeness was reconciled to platform sequence counters.
How should the auditor assess this review?
Options:
A. Assess the review as insufficiently evidenced, because direct observation of each deployment is still required.
B. Assess the review as ineffective compensation, because it occurs after production deployment rather than before it.
C. Assess the review as design-adequate only, because incompatible staff still perform both development and deployment.
D. Assess the review as effective detective compensation for the quarter, within the accepted next-day detection window.
Best answer: D
Explanation: A compensating control can reduce segregation-of-duties risk when full separation is impractical. Here, the reviewer is independent of development and deployment, has authority to investigate and require corrective action, examines precise attributes for every deployment, and retains reliable evidence. Complete and timely records for the quarter, including detected exceptions and documented rollbacks, support both suitable design and sustained operating effectiveness. The control is detective rather than preventive, so exposure remains until the next-business-day review, but that interval was explicitly accepted by the business risk owner.
Continued incompatible access does not invalidate a compensating review when the review meaningfully addresses the resulting risk.
- Design only overlooks the quarter of complete review records and demonstrated exception handling.
- Post-deployment timing is consistent with a detective control and meets the accepted detection window.
- Direct observation is unnecessary because reconciled system logs, tickets, and retained dispositions provide appropriate evidence.
Question 20
Topic: Acquisition and Implementation
An IS auditor is reviewing the final customer-balance conversion rehearsal before go-live. Management requires reconciled totals and data-owner approval for every manually corrected exception.
Evidence:
- Source and destination: 120,000 records totaling $37.5 million
- Rejected and manually corrected records: 64
- Exceptions closed by migration lead: 64
- Corrections with data-owner approval: 41
Which conclusion is best supported?
Options:
A. Totals reconcile, but resolution remains unsupported for 23 manually corrected records.
B. Totals reconcile, but the conversion mapping is ineffective because manual corrections occurred.
C. Totals reconcile, and all exceptions are resolved because destination totals match.
D. Totals reconcile, and exception resolution is effective because most corrections were approved.
Best answer: A
Explanation: Conversion assurance requires separate evaluation of aggregate reconciliation and exception resolution. Equal source and destination counts and values support completeness and agreement at the control-total level, but they do not prove that individual corrections were accurate or authorized. Of the 64 manually corrected records, only 41 have the approval required by management. Therefore, resolution of the remaining 23 exceptions is unsupported, even though the migration lead closed them and the aggregate totals match.
Manual exceptions do not automatically demonstrate a defective mapping; their cause and handling must be evaluated separately.
- Matching totals cannot replace the required data-owner approval for manually corrected records.
- Approval of a majority does not establish that a control requiring approval for every exception operated effectively.
- The existence of manual corrections alone does not prove that the underlying conversion mapping is ineffective.
Question 21
Topic: Auditing Process
A bank uses a production service to approve customer credit-limit increases. An IS auditor is planning a review to determine whether decisions use authorized, accurate data, apply approved logic, control exceptions, and produce accurate customer and account outcomes.
Process facts:
- Applications and credit-bureau data feed a transformation pipeline.
- Versioned models and rules generate recommendations.
- Service agents override 8% of recommendations with supervisor approval.
- Final decisions generate notices and update limits in the core account system.
Which audit boundary BEST supports the assurance objective?
Options:
A. Trace samples from original sources through transformations, logic versions, and overrides to customer notices and decision logs.
B. Trace samples from original sources through transformations and logic versions to notices and posted account-limit changes.
C. Trace samples from transformed features through logic versions and overrides to notices and posted account-limit changes.
D. Trace samples from original sources through transformations, logic versions, overrides, notices, and posted account-limit changes.
Best answer: D
Explanation: An end-to-end boundary for an automated decision follows selected transactions from authoritative source data to their operational effects. It should cover source ingestion and transformation, the deployed model and rule versions, manual overrides and approvals, and both downstream outputs: customer notices and actual account-limit updates. Each stage can fail even when model validation results are satisfactory. Including automated and overridden cases also recognizes that overrides are a material production decision path, representing 8% of recommendations here. Stopping at transformed data, automated processing, or decision logs would leave part of the stated assurance objective unsupported.
- Starting with transformed features cannot establish whether source data was authorized, complete, and accurately ingested.
- Following only automated logic omits the material manual-override path and its supervisory controls.
- Ending with notices and decision logs does not verify that approved limits were accurately posted to customer accounts.
Question 22
Topic: Acquisition and Implementation
An IS auditor is reviewing pre-production results for a new accounts payable application. Management requires every approved invoice to reconcile by count and value to either the bank payment file or the exception queue before release. Only Treasury may receive the file, and AP supervisors manage exceptions.
| Test result | Count | Value (USD) |
|---|---|---|
| Approved invoices | 2,400 | $1,260,000 |
| Payment file | 2,370 | $1,248,000 |
| Exception queue | 25 | $9,500 |
Access testing confirmed Treasury-only distribution. The application marked reconciliation as passed because the payment file matched its accepted-record table. What should the auditor recommend?
Options:
A. Recommend deferring production authorization until reconciliation accounts for five invoices and the $2,500 difference.
B. Recommend production authorization after verifying the 25 queued exceptions are assigned and resolved by AP supervisors.
C. Recommend production authorization after documenting the accepted-table match and Treasury-only output access.
D. Recommend deferring production authorization until Treasury reconciles the bank acknowledgment to the generated payment file.
Best answer: A
Explanation: An effective output reconciliation accounts for the complete authorized input population by both count and value. The payment file and exception queue total 2,395 invoices worth $1,257,500, leaving five invoices and $2,500 unexplained. Comparing the payment file with a downstream accepted-record table does not detect records omitted before or during validation. Treasury-only access supports authorized distribution, and the queue supports handling of identified exceptions, but neither control resolves the completeness failure. Production authorization should therefore await investigation of the discrepancy and successful end-to-end reconciliation.
- The accepted-table match begins after validation and cannot identify source invoices omitted from both outputs.
- Supervising 25 visible exceptions does not account for the five invoices missing from the exception queue.
- A bank acknowledgment confirms file transmission, not completeness against the original approved invoice population.
Question 23
Topic: Auditing Process
An IS auditor is preparing the final report. Which audit conclusion is BEST supported by the completion record?
Audit completion record
Objective: Assess timely revocation of privileged access.
Period: January 1-December 31
Coverage: ERP and finance database; 88% of privileged IDs
Excluded: Cloud console; access export was unavailable
Test criterion: No more than 1 late revocation in 46 samples
Test result: 3 late revocations, ranging from 9 to 18 days
Finding rating: High
Management response: Remediation is planned next quarter
Closure evidence: None received by the report date
Options:
A. Conclude controls were ineffective in the tested systems, retain the high finding as unresolved, and state no conclusion on the cloud console.
B. Conclude controls were effective in the tested systems, report the three delays as isolated exceptions, and state no conclusion on the cloud console.
C. Conclude controls were ineffective across all three systems, retain the high finding as unresolved, and extend the tested results to the cloud console.
D. Conclude controls were ineffective in the tested systems, close the high finding based on planned remediation, and state no conclusion on the cloud console.
Best answer: A
Explanation: An audit conclusion must reflect the evidence obtained, the boundaries of coverage, and the status of significant findings. Three late revocations exceeded the stated acceptance criterion, supporting a conclusion that the control did not operate effectively in the tested ERP and finance database populations. Because cloud console records were unavailable, the auditor lacks sufficient evidence to extend that conclusion to the excluded system. The high-rated finding also remains unresolved because a management remediation plan indicates intent, not completed and verified corrective action. Reporting 88% coverage does not support an enterprise-wide conclusion when a material system was not tested.
- Enterprise-wide conclusion improperly extends tested results to the cloud console despite the documented lack of evidence.
- Effective-controls conclusion conflicts with three deviations when the acceptance criterion allowed no more than one.
- Planned remediation as closure treats management intent as verified correction even though no closure evidence was received.
Question 24
Topic: Information Asset Protection
An IS auditor is evaluating confidential benefit applications routed through a managed web application firewall (WAF) for attack filtering.
Policy: The WAF may decrypt data for in-memory inspection, but request bodies must not be persisted, and plaintext access must remain limited to the inspection service.
Evidence: Valid TLS protects both network links. The provider assurance report covers TLS and key management but excludes tenant logging configurations.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
Customer data travels over one TLS session to a cloud WAF, which decrypts and inspects it, writes full request bodies to debug logs, and forwards data over a second TLS session to the application. A provider support group of 24 users can read the logs.
Which assessment is best supported?
Options:
A. Transit protection is achieved, with logging representing only a separate retention exception.
B. The WAF design is unacceptable because intermediary decryption precludes protection of confidential data.
C. Link encryption operates, but plaintext protection fails at the WAF processing boundary.
D. Plaintext protection is established because the assurance report covers TLS termination and key management.
Best answer: C
Explanation: TLS on consecutive links provides hop-by-hop encryption, not continuous protection while an intermediary processes the data. TLS termination at the WAF creates a plaintext boundary where access, storage, and logging controls must be evaluated. Here, in-memory inspection is permitted, but writing complete request bodies to logs creates prohibited persistence. Access by 24 support users also extends plaintext exposure beyond the authorized inspection service. Valid TLS configurations establish protection on the network links, while the provider report does not address the excluded tenant logging configuration.
The issue is not permitted WAF decryption itself, but inadequate protection of the resulting plaintext.
- Treating logging only as retention overlooks that the logs create an unauthorized plaintext copy.
- Relying on the assurance report ignores its explicit exclusion of tenant logging configurations.
- Rejecting all intermediary decryption conflicts with the policy permitting controlled in-memory inspection.
Question 25
Topic: Auditing Process
An IS auditor is reassessing the audit plan after a merger. The prior plan ranked areas partly by application count.
Audit universe change record:
| Area | Merger-related change | Current assurance record |
|---|---|---|
| Identity | 12 Tier 1 services now use one identity platform; acquired directory supplies automated role mappings | Neither prior audit covered the federated flow |
| Finance | 24 applications; no new interfaces | Open findings receive quarterly follow-up |
| Endpoints | 6,000 devices added using the standard managed build | Monitoring report covers both device populations |
| Customer data | One new batch interface | Privacy assessment completed; first reconciliation pending |
Which area should be elevated most in the risk-based audit plan?
Options:
A. Common identity federation and automated role mapping
B. Financial application controls and remediation follow-up
C. Acquired endpoint configuration and security monitoring
D. Customer data interface and reconciliation controls
Best answer: A
Explanation: Risk-based audit priorities should be reassessed when a merger changes business dependencies, integration paths, or assurance coverage. The common identity platform is now a control dependency for 12 Tier 1 services, while automated role mappings cross the merged organizations’ directories. Neither prior audit assessed this federated flow, creating substantial uncertainty about access provisioning and authentication controls.
Application or device counts alone do not establish priority. The finance area has ongoing findings, but no merger-related interface change and an established follow-up process. Endpoint monitoring covers both populations, while the customer data exposure is limited to one interface. The strongest priority signal is the combination of broad business impact, new integration risk, and missing assurance.
- Finance application count is less decisive because the merger added no interfaces and open findings already have structured follow-up.
- Endpoint volume does not outweigh evidence that the standard build and monitoring cover both device populations.
- Customer data interface warrants attention, but its exposure is narrower and already has privacy assessment coverage.
Questions 26-50
Question 26
Topic: Auditing Process
An audit manager is planning independent pre-go-live assurance for a new ERP system. The business needs a report by the end of week 2 to determine whether go-live risk is acceptable.
- Audit committee-approved scope: access, change, and recovery controls
- Control state: newly implemented, with no prior operating-effectiveness evidence
- Each workstream requires one week and can run concurrently within available hours
- Team: an ERP audit senior, a junior auditor with limited experience, and IAM and recovery specialists
Which staffing and supervision plan is BEST?
Options:
A. Run workstreams concurrently; the senior leads each stream, specialists review access and recovery results at completion, and the junior supports testing.
B. Run workstreams concurrently; specialists lead access and recovery, the junior leads change, and the senior reviews only the draft report.
C. Run workstreams concurrently; specialists lead access and recovery, the senior leads change and conducts milestone reviews, and the junior supports testing.
D. Run workstreams sequentially; specialists lead access and recovery, the senior leads change and conducts milestone reviews, and the junior supports testing.
Best answer: C
Explanation: Engagement planning should align scheduling, competence, and supervision with the approved scope and reporting deadline. Concurrent workstreams satisfy the two-week constraint. IAM and recovery specialists should participate while testing is designed and performed, rather than reviewing completed work after deficiencies may already be embedded. The senior can lead the change-control work and supervise through planned milestone reviews, while the junior performs supporting procedures appropriate to experience.
End-stage review alone is not timely supervision, and sequential execution would miss the required reporting date.
- Having specialists review completed results is too late to ensure that access and recovery procedures were properly designed and executed.
- Allowing the junior to lead change testing with only final report review does not provide supervision during fieldwork.
- Sequential execution uses appropriate skills but cannot complete three one-week workstreams within the two-week deadline.
Question 27
Topic: Information Asset Protection
An IS auditor is assessing controls protecting a data center that hosts a critical payment system. The security standard requires every door-held-open alarm to generate a console alert, guard dispatch within five minutes, and a case containing CCTV review.
Quarterly evidence:
- All 24 controller alarms generated console alerts.
- Twenty alerts had timely dispatch and completed cases.
- Four alerts had no dispatch or case.
- CCTV confirms unbadged entry during two of those four alerts.
Which conclusion is BEST supported?
Options:
A. Detection operated effectively, but response did not operate effectively throughout the quarter.
B. Defer both conclusions until every unbadged entrant has been identified.
C. Both detection and response operated effectively, with four isolated documentation exceptions.
D. Detection did not operate effectively, while response effectiveness remains undetermined.
Best answer: A
Explanation: Operating effectiveness must be evaluated separately for detection and response. Detection worked because every controller alarm generated a console alert. Response did not operate effectively throughout the quarter because 4 of 24 alerts, or 16.7%, received neither required guard dispatch nor a completed case. The recorded absence of dispatch establishes the response failure. CCTV separately confirms actual unbadged-entry exposure during two events. Identifying the entrants may support incident investigation, but it is unnecessary to conclude that the required response control failed. A high success rate does not override significant exceptions when the standard requires action for every alarm.
- Treating the failures as documentation exceptions conflicts with the stated no-dispatch events; CCTV separately shows unbadged entry.
- Classifying the condition as a detection failure ignores that every controller alarm reached the security console.
- Waiting for entrant identification adds an unnecessary condition to evidence already sufficient for assessing control performance.
Question 28
Topic: IT Governance and Management
An IS auditor reviews the following approved strategy records. Which assessment should the auditor make?
Strategy record excerpt:
Business objective B-4
Raise repeat online purchases from 31% to 40% by FY2027
Maintain gross margin at or above 24%
IT initiative I-12
Purpose: Replace the e-commerce platform
Strategic linkage: B-4
Expected benefit: Better customer experience
Success measures: Availability >=99.9%; response time <=2 seconds
Benefits review: Quarterly for 12 months
No further contribution assumptions or business-benefit measures are documented.
Options:
A. Alignment cannot yet be assessed because repeat-purchase and margin results will exist only after implementation.
B. Alignment is adequately demonstrated because service targets are measurable leading indicators for repeat purchases and margin.
C. Alignment is inadequately demonstrated because measures do not connect platform performance to repeat purchases and margin.
D. Alignment is inadequately demonstrated because repeat-purchase improvement is not converted into a projected financial return.
Best answer: C
Explanation: Strategic alignment requires more than mapping an IT initiative to a business objective. The business objective has measurable targets, but the initiative records only technical service measures. Availability and response time may influence customer experience, yet the record does not define how achieving those measures is expected to improve repeat purchases while preserving margin. A benefits realization measure or documented contribution assumption is needed before approval so subsequent reviews can compare expected and actual business outcomes.
Actual results validate benefit realization after implementation, but measurable expected benefits should be defined beforehand. A separate financial-return calculation may be useful, but it is not a substitute for linking the initiative to the stated business targets.
- Technical leading indicators measure platform performance but do not establish the expected change in the cited business outcomes.
- Deferred assessment overlooks that expected benefits and contribution measures should be evaluated before implementation.
- Projected financial return is not the missing requirement because repeat purchases and gross margin already provide measurable business outcomes.
Question 29
Topic: IT Governance and Management
An IS auditor reviews a shared monthly reporting pipeline. Teams repeatedly reassign data defects, and reports are published using manual adjustments.
Approved procedure and issue record:
Source owner: Certify source extract before handoff.
Report custodian: Transform certified extract and publish.
Exceptions: Send discrepancies to the responsible team.
Issue assignment and closure verification: Not specified.
Issue DQ-214: Certified total changed after mapping.
Source owner status: Reassigned to report custodian.
Custodian status: Reassigned to source owner.
Closure evidence: Blank.
Which recommendation would BEST address the underlying governance weakness?
Options:
A. Escalate unresolved discrepancies to the governance council, document acceptance, and retain meeting approvals.
B. Assign all discrepancies to source owners, require extract recertification, and retain correction evidence.
C. Assign all discrepancies to report custodians, require report republication, and retain reconciliation evidence.
D. Define stage-based defect ownership, assign one accountable resolver, and require verified closure evidence.
Best answer: D
Explanation: Data-quality governance should assign clear accountability throughout the reporting pipeline. Source owners may be responsible for source accuracy, while report custodians may be responsible for transformations and publication. The procedure does not define who determines a defect’s origin, owns resolution, or verifies closure. Consequently, both teams can satisfy their narrowly stated duties while defects remain unresolved.
Stage-based ownership links each processing activity to an accountable role. Each issue should also have one named resolver, defined acceptance criteria, and retained evidence that an authorized party verified the correction. Escalation remains appropriate for disputes, but it does not replace routine operational accountability.
- Assigning every discrepancy to source owners ignores defects introduced during transformation after a certified handoff.
- Assigning every discrepancy to report custodians ignores defects already present in source data.
- Governance council escalation may resolve disputes, but it does not establish routine ownership and closure verification.
Question 30
Topic: IT Governance and Management
An IS auditor samples a closed deletion request during a privacy program audit.
Approved procedure and case record:
Procedure P-17
1. Delete in-scope data from primary stores and active replicas.
2. Obtain processor completion attestation; receipt is insufficient.
3. Retention exceptions require a legal basis and destruction date.
4. Isolated backups expire after 90 days and are suppressed if restored.
Case DR-184
Primary profile: deletion successful
Read replica: deletion queued; completion: [blank]
CRM processor: request accepted; attestation: [blank]
Tax invoices: retained; basis: statutory tax duty; destruction date: [blank]
Backup: expires in 86 days; restore suppression: enabled
Which action should the auditor recommend before accepting the case as complete?
Options:
A. Request replica completion evidence and the invoice date; treat processor acceptance as completion.
B. Request replica completion evidence, processor attestation, and immediate invoice and backup deletion.
C. Request replica completion evidence, processor attestation, and the invoice destruction date.
D. Request processor attestation and the invoice date; treat the replica queue as completion.
Best answer: C
Explanation: Deletion assurance requires tracing a request through every responsible location and distinguishing initiation from completion. The primary deletion log covers only the primary store. A queued replica deletion and an accepted processor request do not demonstrate completed erasure. Statutory retention supports an exception for the invoices, but the missing destruction date leaves that exception incomplete. The isolated backup does not require immediate record-level deletion because the approved procedure permits 90-day expiry and requires suppression if restoration occurs. The auditor therefore needs evidence of replica completion, external processor completion, and complete retention documentation before accepting closure.
- Processor acceptance shows receipt of the request, not completion as required by P-17.
- Immediate deletion would disregard the valid invoice retention duty and approved backup-expiry process.
- A queued replica operation shows initiation, not successful deletion from the replica.
Question 31
Topic: Information Asset Protection
A hospital uses IoT sensors to send minute-by-minute vaccine-refrigerator readings to a staffed central monitoring service. Storage rooms are unstaffed overnight, so central alarms must remain continuously available.
The supplier ended all firmware and security updates eight months ago. Firewall rules restrict each sensor to its message broker, SIEM monitoring is active, and quarterly rule reviews show no exceptions. The risk owner has declined long-term acceptance, but no replacement plan exists.
Which recommendation would BEST address this condition?
Options:
A. Accelerate fleetwide replacement after safety testing, using local alarms during one planned central-monitoring outage.
B. Deploy an inline filtering gateway with monthly rule validation, treating gateway controls as the long-term substitute for firmware updates.
C. Implement an owner-approved, staged replacement with safety testing, retaining validated isolation and monitoring through each cutover.
D. Continue operation until normal refresh under a documented exception, with monthly segmentation tests and enhanced anomaly monitoring.
Best answer: C
Explanation: Supplier end of support eliminates the preventive control provided by reliable security updates. Network isolation, firewall validation, and anomaly monitoring reduce exposure and may serve as interim compensating controls, but they cannot correct vulnerabilities within the sensors. Because centralized alarms support vaccine safety and must remain continuously available, management should use a governed, staged replacement process with safety and integration testing before each cutover. The existing safeguards should remain validated until every unsupported device is retired.
Neither permanent compensating controls nor a disruptive fleetwide change adequately addresses both security risk and service continuity.
- Continuing until normal refresh prolongs an unsupported state despite the risk owner’s decision not to accept it long term.
- An inline gateway can restrict or detect traffic but cannot correct every vulnerability within unsupported device firmware.
- A fleetwide cutover creates a central-monitoring outage that conflicts with the continuous safety requirement.
Question 32
Topic: Acquisition and Implementation
An IS auditor reviews oversight of an implementation carrying a material residual access-control risk.
Governance record excerpt:
Corporate risk policy
- Enterprise Risk independently challenges material residual risk.
- Technology Risk Committee accepts material residual risk before release.
Project charter
- Sponsor chairs the Project Steering Committee.
- Sponsor approves all control exceptions.
- Security architect and project QA report to the project manager.
Exception E-17
Risk rating: Material
Approved by: Sponsor
Enterprise Risk review: None
Technology Risk Committee referral: None
Which recommendation would BEST address the governance weakness?
Options:
A. Route material exceptions through Enterprise Risk challenge and Technology Risk Committee acceptance before release.
B. Route material exceptions through project QA challenge and Technology Risk Committee acceptance before release.
C. Route material exceptions through Enterprise Risk challenge and sponsor acceptance before release.
D. Route material exceptions through security architect challenge and Project Steering Committee acceptance before release.
Best answer: A
Explanation: Material residual risk requires both independent challenge and acceptance by the designated authority. The charter improperly concentrates exception approval with the sponsor, while the record shows that neither required governance step occurred. Enterprise Risk is independent of project delivery and therefore provides the required challenge. The Technology Risk Committee has explicit authority to accept the material residual risk before release.
The auditor should recommend correcting the charter and exception workflow rather than personally approving risks or relying on project personnel. Using the authorized functions also preserves management accountability while ensuring that implementation pressures receive independent scrutiny.
- Security architecture reports to the project manager, and the Project Steering Committee lacks the stated acceptance authority.
- Enterprise Risk challenge alone is insufficient because the sponsor is not the designated authority for material residual risk.
- Project QA is not independent of delivery, even though committee acceptance would satisfy the authority requirement.
Question 33
Topic: IT Governance and Management
An IS auditor is assessing risk governance for an online ordering service that supports critical sales operations. Management previously accepted $120,000 of annual residual outage exposure while automated failover was effective. The latest recovery test shows that failover failed and remains unavailable.
The approved risk model now estimates:
- Annual outage probability: 12%
- Single-event impact: $3,000,000
- Maximum tolerated annual exposure: $250,000
The risk owner may accept exposure up to the tolerance; higher exposure requires immediate enterprise risk committee review. What should the auditor recommend?
Options:
A. Reassess exposure at $360,000 and recommend immediate enterprise risk committee review.
B. Reassess exposure at $360,000 and recommend temporary acceptance by the service risk owner.
C. Retain exposure at $120,000 and recommend remediation before the scheduled risk review.
D. Classify $360,000 as inherent risk and defer residual assessment until failover restoration.
Best answer: A
Explanation: Residual risk acceptance applies to the conditions and control effectiveness supporting the accepted estimate; it is not permanent. With failover unavailable, the current annual residual exposure is 12% multiplied by $3,000,000, or $360,000. This exceeds the $250,000 tolerance, so the stated governance rule requires immediate enterprise risk committee review. The auditor should report the changed exposure and recommend escalation while management retains responsibility for risk treatment or acceptance. Remediation may reduce future exposure, but it does not remove the need to evaluate and escalate the current risk state.
- Retaining $120,000 relies on the prior control state and postpones required escalation despite the unresolved failure.
- Temporary risk-owner acceptance exceeds the owner’s delegated authority because the revised exposure is above tolerance.
- Deferring residual assessment misclassifies the risk team’s current residual estimate and leaves the changed exposure unevaluated.
Question 34
Topic: Information Asset Protection
An internal auditor is assessing whether a forensic disk image is sufficiently reliable to support an employee disciplinary decision.
Required procedure: Every evidence transfer must record the custodian, date and time, purpose, and authorization.
Evidence reviewed: The acquisition and laboratory intake records contain matching SHA-256 hashes. However, no record identifies who possessed the drive during the six hours between those events or who authorized its transfer.
Which assessment should the auditor make?
Options:
A. Assess byte integrity as unsupported because the custody gap invalidates both recorded hash results.
B. Assess custody as supported by endpoint records, but authority as unsupported pending management confirmation.
C. Assess integrity and custody as supported because matching hashes demonstrate continuous evidence control.
D. Assess byte integrity as supported, but custody and authority as unsupported pending corroborating evidence.
Best answer: D
Explanation: A cryptographic hash supports the integrity of forensic evidence by showing that the bytes matched when measured at acquisition and intake. It does not identify who possessed the evidence, whether each transfer was authorized, or whether handling requirements were followed. The unexplained six-hour interval therefore represents a chain-of-custody control deficiency even though the matching SHA-256 values support unchanged bytes. The auditor should distinguish these assertions and limit reliance until appropriate corroborating custody and authority evidence is obtained.
Endpoint hash records cannot replace the required documentation for possession between those endpoints.
- Matching hashes do not demonstrate continuous control because they contain no custodian or authorization information.
- A custody gap does not itself invalidate properly calculated matching hashes or negate their integrity evidence.
- Endpoint records document two custody events, not possession throughout the unexplained interval.
Question 35
Topic: IT Governance and Management
An IS auditor is evaluating how a licensed payment company monitors and implements external requirements. The company retains archived transaction exports.
Procedure and record excerpt:
Procedure:
- Log every new or amended regulator item within 5 business days.
- Assess applicability and impact.
- Complete required changes before the effective date.
Regulator index, complete for the review period:
PR-18 | Issued May 6 | Effective Aug 1 | Retain records 3 years
PR-18A | Issued Jun 14 | Effective Aug 1 | Amendment includes archived exports
CY-7 | Issued Jul 2 | Effective Oct 1 | Revised incident report format
Internal obligation register as of Aug 20:
PR-18 | Logged May 8 | Applicable | Ticket closed Jul 25
CY-7 | Logged Jul 3 | Applicable | Ticket open, due Sep 15
Weekly review attestations exist for May through August.
Which audit procedure would BEST determine whether the omission reflects a broader weakness in monitoring and downstream change processing?
Options:
A. Sample closed implementation tickets to obligation-register entries, then inspect change approvals and effective dates.
B. Sample obligation-register entries to the regulator index, then inspect their impact assessments and implementation tickets.
C. Sample weekly review attestations to assigned analysts, then inspect their completion dates and supervisory approvals.
D. Reconcile the regulator index to the obligation register, then trace applicable items through impact assessments and implementation tickets.
Best answer: D
Explanation: The relevant assertion is completeness of regulatory-change capture followed by end-to-end processing. The complete regulator index contains PR-18A, but the internal register does not. Reconciliation from the authoritative external population to the register can identify other omitted requirements. Applicable items should then be traced through impact assessment, ownership, implementation, and completion before their effective dates.
Weekly attestations show that reviews were documented, not that every publication was captured. Testing from register entries or implementation tickets also starts with internal records and may overlook external amendments that never entered the process.
- Register-to-source sampling validates recorded entries but may miss omitted publications such as PR-18A.
- Attestation inspection verifies documented performance but not the completeness of publications reviewed and processed.
- Ticket-to-register tracing evaluates initiated changes, but an omitted external amendment may never generate a ticket.
Question 36
Topic: Information Asset Protection
An IS auditor reviews a personally owned device pilot. The approved standard and pilot record state:
APPROVED BYOD STANDARD
Management scope: Corporate workspace only
Permitted inventory: Device ID, ownership, OS version, compliance result
Prohibited collection: Personal content, installed-app list, precise location
Access conditions: Encryption, supported OS, screen lock, managed-data copy restriction
Separation action: Revoke access and remove corporate data only
PILOT RECORD
Mode: Full-device management
Checks: Screen lock
Collected: Permitted inventory plus installed-app list
Separation action: Full-device wipe
Which recommendation would BEST align the pilot with the approved standard?
Options:
A. Enroll the corporate workspace, collect permitted inventory, enforce app-level controls, and remove corporate data.
B. Enroll the full device, collect permitted inventory, enforce all access conditions, and remove corporate data.
C. Enroll the corporate workspace, collect permitted inventory, enforce all access conditions, and remove corporate data.
D. Enroll the corporate workspace, collect installed-app inventory, enforce all access conditions, and remove corporate data.
Best answer: C
Explanation: Proportionate BYOD management must provide the required business safeguards without exceeding the stated authority over a personally owned device. Corporate-workspace enrollment supports separation of business and personal data while allowing compliance checks for encryption, OS support, screen lock, and copy restrictions. Collection remains limited to approved inventory, and separation triggers access revocation and selective removal of corporate data.
The pilot is deficient in both directions: full-device authority, installed-app collection, and full-device wiping exceed the privacy boundary, while checking only screen lock does not satisfy all access conditions. Privacy minimization does not eliminate device assurance; it limits management authority and data collection to what the approved business controls require.
- Full-device enrollment exceeds the approved corporate-workspace management scope, even if collection and removal are otherwise limited.
- Installed-app inventory is explicitly prohibited and is not authorized merely because it may support security screening.
- App-level controls alone do not establish every required device posture condition, including encryption and supported OS status.
Question 37
Topic: Operations and Resilience
An IS auditor is evaluating an online ordering platform.
Approved resilience requirement:
Continue accepting authenticated orders within 15 minutes after complete loss of any company-operated site.
Current evidence:
- An exercise disabled the East application and database; West resumed authenticated ordering in 9 minutes.
- Every order requires a live response from the only production identity service at Corporate Site C.
- The identity service remained available during the exercise.
- The provider’s current assurance report covers multi-zone traffic-service failover with no relevant exceptions.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The provider traffic service routes customer orders to East and West applications. Each application uses its regional database, the databases replicate, and both applications authenticate every order through the only production identity service at Corporate Site C.
Which audit conclusion is BEST supported?
Options:
A. Conclude that the design does not meet the requirement because both processing regions use the same managed traffic service.
B. Conclude that the design does not meet the requirement because Site C loss prevents authentication in both processing regions.
C. Conclude that the design meets the requirement because the application and database tiers are deployed across two regions.
D. Conclude that the design meets the requirement because the East outage exercise restored ordering within 15 minutes.
Best answer: B
Explanation: Dependency tracing must cover the complete business service, not merely redundant application and database tiers. The 9-minute exercise demonstrates recovery from the East-region outage, but it does not address loss of Corporate Site C. Because both regional applications require the only production identity service for every order, Site C is a single point of failure for authenticated ordering.
The managed traffic service is also a common dependency, but the available evidence supports its multi-zone operation, and it is not hosted at a company-operated site. Regional deployment alone therefore does not establish end-to-end resilience when both regions rely on one site-based component.
- The East exercise tested one regional failure scenario, not the required loss of every company-operated site.
- The managed traffic service has relevant multi-zone assurance and is outside the stated company-site failure condition.
- Two-region application and database deployment does not eliminate the shared identity-service dependency.
Question 38
Topic: Information Asset Protection
A distributor permits third-party technicians to use personal laptops only to reach a managed virtual desktop (VDI) gateway. Corporate laptops need direct access to internal warehouse services.
Control state: NAC is the designated device-trust control. Devices lacking a corporate certificate or healthy EDR status must enter a restricted segment that permits only internet and VDI access.
Audit evidence: During a 45-minute posture-service outage, NAC assigned authenticated users to the workforce VLAN when posture was unavailable. Logs show 12 uncertified devices entered that VLAN and four reached a warehouse API after successful MFA. No malicious transactions were detected.
Which recommendation should the IS auditor make first?
Options:
A. Set unavailable posture results to the restricted segment and test outage behavior.
B. Add automated SIEM containment for uncertified sessions and test response timing.
C. Add device-certificate checks to internal APIs and test direct and VDI access.
D. Add identity-aware firewall rules for contractor accounts and test VDI access.
Best answer: A
Explanation: The control failure is fail-open network admission. MFA verifies user identity but does not establish that the connecting endpoint is managed or trustworthy. Because NAC is the designated device-trust control, assigning devices with unavailable posture results to the workforce VLAN defeats the required segmentation and exposes internal services. The absence of malicious transactions does not reduce this demonstrated control deficiency.
NAC should place failed or unavailable posture checks into the restricted segment. Testing should confirm enforcement during both normal operation and posture-service outages. Application controls and monitoring may add defense in depth, but they do not correct the network admission failure across connected services.
- API certificate checks protect selected applications but leave broader workforce network exposure and do not correct the designated NAC control.
- Contractor-account firewall rules evaluate user identity rather than endpoint posture and may miss unmanaged devices using other authorized accounts.
- SIEM containment reacts after a session begins, while the policy requires preventive segmentation during network admission.
Question 39
Topic: Acquisition and Implementation
An internal IS auditor is assessing whether DevOps controls support weekly claims portal releases while preventing unauthorized production changes. Policy requires every deployment to have an approved user story, independent code review, successful regression tests and service-owner approval before release.
For all 120 deployments in the quarter, reconciled records show:
- All had approved stories, reviews and successful tests.
- 111 had prior service-owner approval.
- Nine were approved automatically by a pipeline service account when tests passed, with no service-owner authorization recorded.
Which conclusion is BEST supported?
Options:
A. Conclude approval effectiveness remains undetermined until owners retrospectively confirm the nine releases.
B. Conclude all controls operated effectively because pipeline tests generated approvals for every release.
C. Conclude accountable approval operated effectively because a nondeveloper service account recorded nine approvals.
D. Conclude accountable approval had an operating deficiency, while traceability and testing operated effectively.
Best answer: D
Explanation: DevOps automation does not eliminate accountable authorization. The reconciled population supports effective operation of traceability, peer-review and regression-testing controls. However, the policy specifically requires the service owner to approve each release before deployment. An approval generated automatically by a service account proves that a pipeline condition was met, not that the designated owner made the required authorization decision.
The nine exceptions therefore demonstrate an operating deficiency in release approval, although they do not invalidate the evidence supporting the other controls. Retrospective owner confirmation may help assess business impact, but it cannot recreate a control that was required to operate before deployment.
- Successful testing provides quality evidence but does not satisfy a separate business authorization requirement.
- A service account’s separation from developers does not establish accountable service-owner approval.
- Retrospective confirmation may assess impact, but it cannot demonstrate that predeployment approval operated when required.
Question 40
Topic: Operations and Resilience
An IS auditor is assessing controls over emergency updates to customer credit limits. The business must permit named database administrators (DBAs) to make direct production updates during application outages so order processing can continue.
- Policy requires data-owner approval for every limit change.
- Direct SQL bypasses application authorization and audit trails.
- Database change auditing is disabled.
- Weekly reconciliation compares approved requests only with application audit entries.
Which recommendation would provide the most effective assurance that emergency changes are authorized, traceable, and accurately reflected?
Options:
A. Require data-owner approval, tamper-protected database change logging, and DBA-team reconciliation of direct updates to tickets and customer records.
B. Require data-owner approval, tamper-protected database change logging, and independent reconciliation of direct updates to tickets and customer records.
C. Require operations-manager approval, tamper-protected database change logging, and independent reconciliation of direct updates to tickets and customer records.
D. Require data-owner approval, privileged-session recording, and independent reconciliation of emergency tickets to application audit entries.
Best answer: B
Explanation: Direct database updates bypass application controls, so compensating controls must address authorization, accountability, and data accuracy at the database level. Data-owner approval establishes business authorization. Tamper-protected database change logs provide reliable evidence of the administrator, affected records, and changes made. An independent reconciliation should then match the complete population of direct updates to approved tickets and verify the resulting customer records.
Application audit entries are incomplete evidence because direct SQL does not create them. Reconciliation performed by the DBA team also lacks sufficient independence because that team executes the changes.
- Operations-manager approval does not satisfy the stated policy assigning authorization to the data owner.
- Session recordings do not correct the incomplete reconciliation population when comparison remains limited to application audit entries.
- DBA-team reconciliation allows personnel responsible for direct updates to verify their own work, weakening detective control independence.
Question 41
Topic: Information Asset Protection
An IS auditor is advising management on remediation sequencing after a penetration test. Management’s approved rule prioritizes demonstrated attack paths by business impact, uses technical severity to break ties, and reduces priority when independently tested preventive controls limit exposure. Unauthorized beneficiary changes have critical impact; limited contact-record disclosure has high impact.
| Finding | Rating | Exposure and controls |
|---|---|---|
| Payroll archive | Critical | No route from user networks; admin subnet uses MFA and PAM |
| Supplier upload parser | High | Supplier login reaches beneficiary API; test completed an unauthorized change; no preventive control |
| Public product catalog | Critical | No sensitive data or payment path; retested WAF blocks exploitation |
| Support search | High | Agent VPN reaches endpoint; test exposed records across queues; DLP alerted afterward |
Which finding should the auditor recommend management remediate first?
Options:
A. The payroll archive restricted to the administration subnet
B. The supplier upload parser linked to beneficiary changes
C. The public product catalog protected by the validated WAF rule
D. The support search exposing records across agent queues
Best answer: B
Explanation: Vulnerability priority should reflect contextual business risk rather than technical severity alone. The supplier parser has a demonstrated path from an ordinary supplier login to a critical payment-integrity function, and testing confirmed an unauthorized beneficiary change. No preventive control currently reduces that exposure. The support-search weakness is also reachable and inadequately prevented, but management classifies its limited disclosure impact as high rather than critical. The payroll and catalog findings have critical technical ratings, yet tested access restrictions or a validated WAF materially reduce their current exposure. Technical ratings remain useful, but attack-path reachability, business impact, and effective compensating controls determine remediation urgency.
- The payroll archive contains sensitive data, but network isolation, MFA, and PAM reduce its demonstrated exposure.
- The product catalog is internet-facing, but it lacks a sensitive transaction path and its WAF protection was independently validated.
- The support search permits high-impact disclosure, but its business impact ranks below unauthorized beneficiary changes.
Question 42
Topic: Acquisition and Implementation
An IS auditor is assessing release readiness before a retailer migrates its order API. Accepted orders must reach the fulfillment ERP and return a status within five minutes. The approved release gate requires a successful target-environment test of this critical path and a rehearsed rollback. Approval is pending.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The web store authenticates through the identity provider and submits orders to the target order API. The API writes to the target database and publishes to the target message broker, which delivers orders to the fulfillment ERP. The ERP returns status to the API.
Evidence:
- API, database, and identity-provider tests passed.
- The API published a test order to the target broker.
- The firewall route between the broker and ERP remains unopened; the ERP received no test order.
- The rollback rehearsal passed.
Which conclusion should the auditor present to the change advisory board?
Options:
A. Readiness is not established because the required end-to-end ERP path remains untested.
B. Readiness is established if the firewall route becomes an operational follow-up after cutover.
C. Readiness is not established because rollback testing did not prove target database disaster recovery.
D. Readiness is established because component testing and the rollback rehearsal address the principal risks.
Best answer: A
Explanation: Migration readiness depends on the complete critical business path, including infrastructure and applications outside the migration package. Component tests show that the API can authenticate, write data, and publish a message, but they do not demonstrate that fulfillment can consume and process the order. Because the unopened firewall route blocks the ERP dependency, the required end-to-end test cannot satisfy the release gate or the five-minute business requirement.
A successful rollback rehearsal supports recovery from a failed cutover, but it does not establish that the migrated service can complete its production workflow. The unresolved dependency must be enabled and tested before readiness can be supported.
- Disaster recovery scope confuses target recovery testing with the stated rollback and end-to-end release criteria.
- Component-level assurance cannot establish that the integrated order workflow operates across all required dependencies.
- Post-cutover follow-up conflicts with the approved gate requiring the critical path to be tested before approval.
Question 43
Topic: Auditing Process
An audit finding reported that contractor accounts remained active after termination. Management submits the following follow-up record and requests closure.
Remediation closure record F-17
Exposure: Active contractor accounts after termination
Required closure evidence (30-day period):
- All termination records reach IAM.
- Unmatched records are assigned and resolved within 24 hours.
June 1: Automated HR-to-IAM workflow approved and enabled.
June 1-30 reconciliation:
- Terminations: 27
- Disabled within 24 hours: 24
- Missing contractor ID: 3
- Those 3 accounts remained enabled for 8-11 days.
Exception queue owner: [blank]
Which conclusion should the IS auditor reach?
Options:
A. Replace the finding with a source-data quality finding.
B. Keep the finding open pending effective handling of unmatched records.
C. Close the finding and monitor the delayed accounts as exceptions.
D. Close the finding based on implementation of automated deprovisioning.
Best answer: B
Explanation: Follow-up work determines whether corrective action removed the reported exposure, not merely whether management implemented a control. Closure required every termination record to reach IAM or be assigned and resolved within 24 hours. Although the workflow processed most records, three unmatched terminations left accounts active for 8-11 days, and the exception queue had no owner. The same unauthorized-access exposure therefore persisted, and operating effectiveness was not demonstrated over the review period.
Workflow approval and majority success show remediation progress, but they do not support closure when the agreed exception control failed.
- Workflow approval demonstrates implementation, but the reconciliation shows that deprovisioning was not effective for the complete population.
- Monitoring delayed accounts separately conflicts with the requirement that all exceptions be resolved within 24 hours.
- Source-data quality explains the failures but does not remove the access exposure or replace the required exception handling.
Question 44
Topic: Acquisition and Implementation
An IS auditor reviews the first production release of a claims application. Which conclusion is best supported by the excerpt?
Policy: Approval must identify the release ticket and
an immutable artifact ID before initial production use.
Version/build: rel-1.0 -> commit 7bc91e
Artifact ID: pkg-4f2a91cd; built 13:22
Authorization: R-1042; approved 14:00
Approved artifact ID: [blank]
Deployment: R-1042; pkg-4f2a91cd; deployed 15:20
Options:
A. Conclude that initial-release approval is unsupported because development personnel initiated the release request.
B. Conclude that version-control integrity is unsupported because the CI process created the protected release tag.
C. Conclude that both controls are supported because the ticket links approval to the deployed package.
D. Conclude that build-to-deployment traceability is supported, but artifact-specific initial-release approval is not demonstrated.
Best answer: D
Explanation: Artifact traceability and release authorization require separate evidence. The version tag maps to a specific commit, and the same immutable artifact ID appears in the build and deployment records. This supports traceability from the source version to the deployed package.
However, the policy requires the approval record itself to identify both the ticket and immutable artifact ID. Because that field is blank, the auditor cannot determine whether the release manager approved pkg-4f2a91cd rather than another package associated with the same ticket. A matching ticket does not bind approval to an exact artifact. The evidence therefore supports build-to-deployment traceability but not artifact-specific authorization for initial production use.
- A shared ticket can cover multiple artifact versions and does not satisfy the required artifact-specific approval.
- The excerpt does not show a CI-created tag causing an integrity failure; authorized automated tagging would not inherently undermine version control.
- Development may initiate a request when an independent release authority approves it and operations performs deployment.
Question 45
Topic: IT Governance and Management
An IS auditor reviews an AI service-desk investment before its funding gate. The risk register is used to support the governance decision.
ERM standard excerpt:
Each material uncertainty that may affect an investment objective favorably or adversely must be recorded separately, with an owner and planned response.
Investment record excerpt:
| Record | Content |
|---|---|
| Business-case baseline | $1.2 million annual savings |
| Pilot estimate | $0.8-$1.8 million, mainly dependent on adoption |
| Architecture note | Reuse for HR may add savings; feasibility untested |
| Risk register | Low adoption; integration delay; vendor-fee increase |
Which recommendation should the auditor make?
Options:
A. Net high-adoption and low-adoption effects in one financial-risk entry with a sponsor and response threshold.
B. Keep high-adoption and HR-reuse assumptions in the business case with assigned owners and review dates.
C. Convert high-adoption and HR-reuse estimates into benefit targets with a sponsor and realization milestones.
D. Add high-adoption and HR-reuse uncertainties as separate opportunity entries with assigned owners and responses.
Best answer: D
Explanation: Enterprise risk management considers uncertainty that can produce either adverse outcomes or opportunities. The pilot range shows uncertainty around the baseline savings, while possible HR reuse represents additional uncertain value. Both may materially affect the investment objective favorably and therefore belong in the risk register under the stated standard. Recording them separately enables governance to assign accountability, select responses such as enhancing or accepting an opportunity, and monitor whether assumptions change. A business case or benefits-realization plan can complement the register but does not satisfy an explicit requirement to record favorable uncertainties.
The key distinction is between documenting uncertain opportunities and treating potential benefits as committed results.
- Keeping upside only in the business case fails the standard’s requirement for separate risk-register entries.
- Netting adoption effects can conceal distinct favorable and adverse drivers that require different responses.
- Converting potential upside into targets treats uncertain value as committed performance rather than as an opportunity risk.
Question 46
Topic: Information Asset Protection
An IS auditor reviews this IAM record on July 15. Policy requires access tied only to a prior role to be removed by the role-change date. The SoD matrix prohibits combining VENDOR_MAINTAIN and PAYMENT_APPROVE unless a risk owner approves a documented compensating control.
Mover record:
Old role: AP vendor administrator
New role: Treasury payment approver
Effective date: June 3
PAYMENT_APPROVE: Granted June 3; Treasury manager approved
VENDOR_MAINTAIN: Active; source is old role
Removal request: None
Risk acceptance or compensating control: None
July recertification: Excluded; mover after May 31 snapshot
Which finding is best supported by this record?
Options:
A. New-role approval and role-design controls failed, introducing a segregation conflict within the Treasury role.
B. Compensating-control documentation and risk-acceptance controls failed, leaving an authorized segregation exception unsupported.
C. Transaction-monitoring and access-use controls failed, allowing approved conflicting privileges to be exercised undetected.
D. Mover deprovisioning failed, leaving an unauthorized cross-role segregation conflict that the July review did not detect.
Best answer: D
Explanation: Role changes require prior-role access to be removed or reauthorized according to the employee’s new business responsibilities. Here, PAYMENT_APPROVE was properly approved, but VENDOR_MAINTAIN remained from the old role with no removal request. The combination violates the SoD matrix, and no approved risk acceptance or compensating control exists. Exclusion from the July recertification also shows that the detective review did not cover this mover and therefore could not compensate for failed deprovisioning. Evidence of actual use would affect the exception’s impact, but it would not eliminate the authorization and segregation deficiency.
- New-role approval is documented, and the conflict spans old and new roles rather than residing within the Treasury role.
- Missing compensating-control documentation does not create an authorized exception because risk acceptance is also absent.
- No access-use evidence is provided, so a transaction-monitoring failure cannot be concluded from this record.
Question 47
Topic: Operations and Resilience
An IS auditor reviews a treasury spreadsheet used to determine daily funding transfers. The approved procedure requires controlled versions, restricted write access, protected formulas, and daily input and output reconciliations.
Evidence for 25 sampled days:
- Production file IDs matched approved releases, with complete change histories.
- Write access was limited to the owner and designated developer; releases had owner approval.
- Formula hashes matched the approved baseline; test recalculations found no exceptions.
- Imported balances were reconciled to source totals, but output reconciliations were marked
N/Aafter the independent estimate was retired. No replacement check existed.
Which conclusion is best supported for the sampled days?
Options:
A. Version, formula, and reconciliation controls operated effectively; access control was deficient.
B. Version, access, and reconciliation controls operated effectively; formula control was deficient.
C. Version, access, and formula controls operated effectively; reconciliation control was deficient.
D. Access, formula, and reconciliation controls operated effectively; version control was deficient.
Best answer: C
Explanation: Business-critical user-built tools require controls addressing distinct failure modes. Approved file IDs and complete histories support version control. Restricted repository permissions and owner-approved releases support access control. Formula hashes and test recalculations support formula integrity.
The reconciliation procedure, however, required both source-to-input and output-to-independent-estimate comparisons. Input reconciliation confirmed that source balances were imported accurately, but it did not satisfy the required validation of the final result. After the independent estimate was retired, marking the check N/A without implementing a replacement meant that part of the reconciliation control did not operate. The missing control does not prove that funding calculations were wrong, but it creates a control deficiency requiring assessment and remediation.
- Access concern is unsupported because write access matched designated roles and releases received owner approval.
- Formula concern is unsupported because baseline hashes matched and test recalculations found no exceptions.
- Version concern is unsupported because production file IDs matched approved releases and change histories were complete.
Question 48
Topic: Operations and Resilience
An IS auditor reviews the following records after a terminated employee initiated a payment.
Control standard
Approved access revocations must be reflected in dependent applications within 15 minutes.
Interface runbook
- Synchronization runs at 08:00, 12:00, and 16:00.
- A successful run loads source changes available when the run starts.
- The application authorizes payments from its local entitlement table.
Event record
| Time | Event |
|---|---|
| 08:00 | Synchronization succeeded |
| 09:02 | Revocation approved |
| 09:03 | Source status changed to disabled |
| 10:15 | Application read active; payment approved |
| 12:00 | Synchronization succeeded; status became disabled |
Which audit conclusion is best supported?
Options:
A. Report a source-system operating deficiency because the approved revocation was not reflected in the application within 15 minutes.
B. Report an interface design deficiency because its four-hour schedule cannot meet the 15-minute authorization-status requirement.
C. Report a synchronization operating deficiency because the successful 08:00 run failed to load the 09:03 status change.
D. Report an application design deficiency because authorization uses a local entitlement table instead of a real-time source query.
Best answer: B
Explanation: The control dependency is the timely transfer of authorization status from the source system to the application’s local table. The source disabled access one minute after approval, and both scheduled synchronization jobs operated as documented. However, a four-hour schedule inherently allows changes made after one run to remain absent until the next run. This design cannot consistently satisfy the 15-minute requirement and caused the application to authorize a payment using stale status.
A local entitlement table is not inherently deficient if updates reach it within the required period. The decisive issue is therefore interface timeliness, not job execution or the use of local data itself.
- Source processing was timely because the source status changed to disabled one minute after approval.
- Job operation was not deficient because the 09:03 change did not exist when the 08:00 run started.
- Real-time lookup is unnecessary because the standard permits up to 15 minutes for downstream updates.
Question 49
Topic: IT Governance and Management
An IS auditor reviews the following vendor oversight record for a critical claims platform. Policy requires quarterly evaluation of service performance and relevant control assurance.
Review date: September 30, 2025
Quarterly uptime: 99.96% (target: 99.90%)
Severity 1 incidents: 2 (both resolved within target)
SOC 2 Type II period: January 1-December 31, 2024
SOC opinion: Unmodified
Gap-period coverage: None on file
Hosting provider: Carved out; separate report not reviewed
Customer control: Quarterly vendor-admin access review
Customer evidence: Not attached
Which action should the auditor recommend to the vendor oversight owner?
Options:
A. Obtain gap-period assurance, confirm the carved-out host remains approved, and inspect completed quarterly access reviews.
B. Obtain gap-period assurance, evaluate the host’s relevant controls, and inspect completed quarterly access reviews.
C. Obtain gap-period assurance, evaluate the host’s relevant controls, and inspect the documented access-review procedure.
D. Obtain current Type I assurance, evaluate the host’s relevant controls, and inspect completed quarterly access reviews.
Best answer: B
Explanation: Service-level results demonstrate availability and incident performance, but they do not establish the operating effectiveness of security and processing controls. The Type II report covers only the stated historical period, so additional evidence is needed from its end date through the current review. Because the hosting provider was carved out, its relevant controls require separate evaluation. The customer entity control also requires evidence that quarterly access reviews were performed, not merely documented. Together, these steps provide ongoing assurance across time, outsourced dependencies, and customer responsibilities.
- A current Type I report assesses control design at a point in time, not operating effectiveness throughout the uncovered period.
- Confirming that the host is approved establishes authorization, not assurance over controls excluded from the primary report.
- Inspecting the access-review procedure supports control design but does not demonstrate quarterly operation.
Question 50
Topic: IT Governance and Management
An IS auditor reviews this quality corrective-action record:
Record: Q-17
Control objective: Only independently approved code is deployed.
Issue: Four deployments included commits added after approval.
Root cause: The workflow retains approved status after code changes.
Interim action: Remind release leads to obtain renewed approval.
Follow-up: Of 10 releases, 3 had later commits and deployed under the original approval.
Owner decision: Permanent corrective action pending.
Which recommendation should the auditor make?
Options:
A. Recommend that management invalidate approval after code changes and require renewed independent approval before deployment.
B. Recommend that management repeat release-approval training quarterly and track completion for all release personnel.
C. Recommend that management review post-approval code changes monthly and report release exceptions to the quality committee.
D. Recommend that management rerun regression tests after code changes and retain updated test evidence before deployment.
Best answer: A
Explanation: A corrective action should address the validated root cause and consider follow-up evidence about prior actions. An approval applies to the code version actually reviewed. Because the workflow retains approved status after later commits, it permits unapproved code to reach production. Follow-up testing also shows that reminders did not correct this weakness consistently.
The auditor should recommend invalidating the approval when code changes and requiring renewed independent approval. Management remains responsible for selecting, implementing and owning the control or formally accepting the residual risk. Regression testing may confirm software behavior, but it does not establish that the changed release received the required independent approval.
- Regression testing provides useful quality evidence but does not restore independent authorization for the changed code version.
- Monthly review detects exceptions after deployment rather than preventing unapproved code from entering production.
- Repeated training strengthens the same administrative measure that follow-up evidence shows was ineffective.
Questions 51-75
Question 51
Topic: Information Asset Protection
An IS auditor is assessing whether a data center admitted only authorized workers and controlled visitors during Q3.
Policy:
- The data center owner quarterly certifies every active permanent badge.
- Visitors require sponsor approval, ID verification, sponsor escort and same-day badge expiration.
Evidence:
- The auditor’s July 1 system export shows 91 active permanent badges.
- The signed July 10 review covers 84 badges, omitting seven contractor badges. The owner claims procurement reviews them but provides no evidence.
- A sample of 25 visitor visits satisfies every stated requirement.
Which assessment is best supported?
Options:
A. Access-review control operated effectively, but visitor escort control failed because sponsors rather than security escorted visitors.
B. Visitor controls operated as tested, but access review failed to cover the complete active-badge population.
C. Visitor and access-review controls operated effectively because contractors were subject to a separate procurement review.
D. Visitor controls operated as tested, but badge deprovisioning failed because seven contractor badges remained active.
Best answer: B
Explanation: Operating effectiveness requires evidence that the required control covered its defined population. The system export identified 91 active permanent badges, but the signed review included only 84. Because policy requires the data center owner to certify every active permanent badge, an unsupported claim of separate procurement review does not resolve the seven omissions. The visitor sample independently supports visitor-control operation for the visits tested because approval, identity verification, sponsor escort and expiration requirements were satisfied.
An active contractor badge does not itself prove deprovisioning failed; evidence that the contractor’s authorization had ended would be needed.
- A claimed procurement review cannot support effectiveness when no evidence exists and the owner’s review must cover every permanent badge.
- Seven active contractor badges indicate incomplete review coverage, not necessarily failed deprovisioning or unauthorized access.
- Sponsor escorts comply with the stated visitor policy; security personnel are not required to perform the escort.
Question 52
Topic: Operations and Resilience
An IS auditor is assessing whether a business impact analysis (BIA) remains valid after operational changes. The procedure requires the process owner to validate impact assumptions and priority after dependency changes; technical owners validate recovery estimates.
BIA record excerpt
Process: Digital order fulfillment
Process owner: Director, Sales Operations
Baseline approval: January 12
Priority: Tier 1 | MTPD: 8 hours | RTO: 4 hours
May 14: Payment gateway replaced
Technical recovery estimate: 3 hours | Technical owner: Confirmed
Process-owner validation: [blank] | Priority impact: [blank]
June 2: Warehouse interface changed from real-time to 4-hour batches
Technical recovery estimate: 3 hours | Technical owner: Confirmed
Process-owner validation: [blank] | Priority impact: [blank]
July 1 review: Carried forward by application manager
Comment: No application outage change
Which control deficiency is MOST strongly supported by this record?
Options:
A. Technical-owner validation of revised recovery estimates is ineffective.
B. Scheduling of periodic BIA reviews for the process is ineffective.
C. Validation of RTO alignment with maximum tolerable downtime is ineffective.
D. Process-owner validation of changed dependencies and priority effects is ineffective.
Best answer: D
Explanation: Business owners are accountable for validating how dependency and operating-model changes affect business impact, recovery priorities and continuity requirements. Both changes received technical confirmation, but the process-owner and priority-impact fields remained blank. The application manager’s statement about application outages does not establish that the changed gateway and batching model preserve the business impact assumptions. Carrying the BIA forward therefore bypassed the required business validation.
Technical recoverability evidence supports the BIA, but it does not replace the process owner’s assessment of business consequences.
- Technical recovery estimates were confirmed for both changes, so the record does not indicate missing technical-owner validation.
- The 4-hour RTO remains below the 8-hour MTPD, so their stated relationship is not the demonstrated deficiency.
- A periodic review occurred on July 1; the issue is its unsupported carry-forward, not evidence of an inadequate schedule.
Question 53
Topic: Operations and Resilience
An IS auditor reviews a known error in a refund system. Eligible refunds must be released within one business day, so management authorized a temporary workaround.
- A support analyst identifies affected records, edits the payment file, and uploads it.
- The same analyst checks the batch total; portal approval does not validate line-level edits.
- The workaround is documented, and the application manager owns a permanent fix due in six weeks.
- Refund amounts are material.
Which recommendation BEST addresses the control condition while supporting timely refunds?
Options:
A. Require independent review of line edits against source records before release, retain evidence, and follow up on the fix.
B. Require operations manager reauthorization of each run before release, retain approval evidence, and follow up on the fix.
C. Require independent sampling of line edits after each weekly cycle, retain exception evidence, and follow up on the fix.
D. Require the application problem owner to execute each run before release, retain runbook evidence, and follow up on the fix.
Best answer: A
Explanation: Authorization and documentation do not establish adequate control over the workaround’s operation. The same analyst identifies records, makes material payment-file changes, and uploads the file. Because existing approval checks only the batch total, incorrect or unauthorized line-level edits could pass undetected. Independent comparison of each edit to its source record before release directly addresses this risk, while retained evidence supports auditability. Following up with the assigned application manager ensures that the temporary process does not replace permanent correction.
Reauthorization confirms permission to run the workaround, but it does not validate the accuracy of individual edits.
- Reauthorizing each run addresses execution authority, not the unsupported line-level changes creating the material payment risk.
- Weekly sampling may detect errors only after refunds have been released and is insufficient for material transactions.
- Assigning execution to the problem owner changes personnel but preserves incompatible selection, editing, and release duties.
Question 54
Topic: Operations and Resilience
An IS auditor is evaluating a monthly SLA review control. Management uses the result to determine whether to claim a service credit. The provider reported 99.94% availability, and monitoring logs confirm the incident durations.
Agreement rules:
- Monthly availability target: >= 99.90%.
- Eligible minutes equal calendar minutes minus qualifying exclusions.
- Exclusions include customer-caused disruptions and planned maintenance that is approved, within the maintenance window, and announced at least 72 hours in advance.
30-day month:
| Unavailable event | Minutes | Relevant fact |
|---|---|---|
| Planned maintenance | 60 | All exclusion conditions met |
| Planned maintenance | 35 | Only 24 hours’ notice |
| Provider network failure | 25 | No exclusion applies |
| Customer firewall error | 40 | Customer-caused |
There were no overlapping events. What should the auditor conclude?
Options:
A. Report 99.94% availability and service-level compliance for the month.
B. Report 99.86% availability and a service-level breach for the month.
C. Report 99.63% availability and a service-level breach for the month.
D. Report 99.77% availability and a service-level breach for the month.
Best answer: B
Explanation: Service availability must be calculated using the agreement’s measurement rules. The qualifying exclusions are the 60-minute planned maintenance and the 40-minute customer-caused disruption. The 35-minute maintenance event remains counted because it did not satisfy the 72-hour notice requirement. Therefore, eligible time is 43,100 minutes, with 60 unavailable minutes.
\[ \begin{aligned} A &= \frac{43{,}100-60}{43{,}100}\times 100\\ &= 99.8608\% \approx 99.86\% \end{aligned} \]Because 99.86% is below the 99.90% target, the provider’s compliance result is not supported.
- The 99.94% result improperly excludes the 35-minute maintenance event despite insufficient advance notice.
- The 99.77% result incorrectly counts the 40-minute customer-caused disruption as provider downtime.
- The 99.63% result ignores all contractual exclusions and uses every incident minute as counted downtime.
Question 55
Topic: IT Governance and Management
An IS auditor reviews a cloud architecture decision record before contract signature. Which assessment should the auditor report?
Architecture decision record
P-7 Portability requirement:
Exit within 12 months by transferring data and workloads
to another provider without material application redesign.
Exception conditions:
Document business benefit and dependency/exit analysis.
Obtain business risk owner approval before commitment.
Proposed service:
Provider-specific APIs and proprietary job definitions.
Standard-format data export: 30 days.
Processing jobs must be rebuilt elsewhere: 8 months.
Benefit: launch 4 months earlier; estimated value $1.2 million.
Review status:
Architecture board: Recommended.
Business sponsor: Benefit endorsed.
Business risk owner exception approval: [blank]
Options:
A. Conclude contractual commitment may proceed conditionally, with risk-owner exception approval obtained before production use.
B. Conclude the proposal does not satisfy P-7 and requires risk-owner exception approval before contractual commitment.
C. Conclude the board recommendation satisfies the exception process, with risk-owner acknowledgment recorded after contractual commitment.
D. Conclude the proposal meets P-7 through standard data export, with the job rebuild monitored during migration.
Best answer: B
Explanation: Portability includes both data and workload portability. Standard-format export supports data retrieval, but provider-specific APIs and the required job rebuild mean the service fails P-7’s condition against material application redesign.
The record documents the expected benefit and identifies the dependency and exit effort, so management may consider the policy’s exception route. However, the designated business risk owner’s approval is missing and must be obtained before contractual commitment. Neither architecture board recommendation nor sponsor endorsement substitutes for the required accountable approval.
The auditor should report the current noncompliance and missing exception evidence while leaving the adoption decision to management.
- Standard data export addresses data portability, but P-7 also requires workload transfer without rebuilding the processing jobs.
- The architecture board recommends the design but is not the record’s designated exception approver.
- Conditional contracting reverses the required sequence because approval must precede commitment, not merely production use.
Question 56
Topic: Auditing Process
An IS audit manager reviews a request concerning an automated quarterly loan-covenant calculation.
Exhibit: engagement request excerpt
The company and lender will jointly approve the procedures. The practitioner will reconcile all Q4 billing records to the general ledger, rerun the covenant formula, and report identified differences. The report will describe procedures performed and findings but will not provide an assurance opinion or conclusion.
Which assessment approach best matches the request?
Options:
A. An agreed-upon procedures engagement on the covenant calculation
B. A limited assurance review of the covenant calculation
C. An operational audit of the revenue reporting process
D. A reasonable assurance compliance examination of the covenant
Best answer: A
Explanation: An agreed-upon procedures engagement fits when specified parties agree on exact procedures and the practitioner reports the procedures performed and resulting findings. The intended users evaluate those findings and draw their own conclusions. Here, the request prescribes reconciliation and recalculation procedures while explicitly excluding an assurance opinion or conclusion. Examining the complete Q4 population does not turn the work into an assurance engagement; the reporting objective and engagement terms determine the approach.
A compliance examination or limited assurance review would require an assurance conclusion, while an operational audit would assess broader process effectiveness or efficiency rather than perform only the agreed procedures.
- A reasonable assurance compliance examination would provide a conclusion about covenant compliance, contrary to the requested reporting terms.
- A limited assurance review would still express a limited assurance conclusion rather than report findings alone.
- An operational audit would evaluate broader process performance and controls, exceeding the narrowly prescribed procedures.
Question 57
Topic: IT Governance and Management
During an audit, an IS auditor reviews the following applicable compliance mapping record. Which recommendation would BEST translate the obligation into an accountable, testable control?
Source requirement:
Privileged access to regulated customer records is reviewed
at least quarterly. The business data owner approves continued
access. Unneeded access is removed within 5 business days.
Approvals and removal evidence are retained for 3 years.
Mapped control:
Owner: IAM Operations
Activity: Send a quarterly access list to application managers.
Evidence: Exported access list
Retention: 1 year
Options:
A. Require annual data-owner approval, five-business-day IAM removal, and three-year retention of approval and removal evidence.
B. Require quarterly data-owner approval, five-business-day IAM removal, and three-year retention of exported access lists.
C. Require quarterly IAM-manager approval, five-business-day IAM removal, and three-year retention of approval and removal evidence.
D. Require quarterly data-owner approval, five-business-day IAM removal, and three-year retention of approval and removal evidence.
Best answer: D
Explanation: Compliance mapping should translate each obligation into specific control attributes: accountable roles, required actions, frequency, completion deadlines, and retained evidence. The existing control records quarterly list distribution, but it does not require business data-owner approval, establish the five-business-day removal deadline, or retain evidence for three years.
A testable control should produce dated approvals and removal records that allow an auditor to verify both authorization decisions and timely remediation throughout the retention period. An exported access list identifies a population at one point in time but does not demonstrate approval or removal. The governing requirement, rather than the current operational practice, determines the necessary control design.
- Retaining exported lists does not demonstrate the required data-owner approvals or timely removal of unnecessary access.
- Assigning approval to IAM managers conflicts with the stated accountability of the business data owner.
- Annual approval does not satisfy the requirement to review privileged access at least quarterly.
Question 58
Topic: Information Asset Protection
An IS auditor reviews certificate renewal controls after an expired production certificate causes an outage. Management relies on a central registry and email alerts.
Procedure excerpt
Every production TLS certificate must be registered with an accountable service owner and renewal contact. The registry emails the contact 60, 30, and 15 days before expiration. The service owner authorizes renewal.
Discovery report
| Certificate | Registry and ownership result | Days remaining |
|---|---|---|
payments-api | Match; owner blank; contact departed | 21 |
billing-jobs | No registry match; CMDB owner blank | 34 |
customer-web | Match; owner and contact current | 48 |
Which recommendation would BEST reduce the risk of recurrence?
Options:
A. Enroll discovered certificates in automated renewal, route exceptions to PKI operations, and review renewal failures.
B. Reconcile discovery results to the registry, assign service owners, and escalate unresolved expiry exceptions.
C. Validate registry contacts quarterly, send alerts earlier, and escalate undelivered messages to department managers.
D. Sample completed renewal tickets quarterly, compare closure dates to expirations, and investigate late approvals.
Best answer: B
Explanation: A certificate renewal control depends on a complete inventory and accountable ownership. The report shows both failure types: billing-jobs is absent from the registry, while payments-api has no owner and an unusable contact. Consequently, registry alerts alone cannot provide assurance that all production certificates will be renewed. Management should reconcile independent discovery results to the registry, identify the responsible service owner, and escalate near-expiry records whose ownership or renewal status remains unresolved. This addresses inventory completeness, authorization accountability, and monitoring follow-up. Earlier or better-delivered alerts help only when a certificate and responsible party are already recorded.
- Contact validation improves alerts for registered certificates but does not detect the unregistered certificate or establish its owner.
- Automated renewal may reduce expiration risk but does not resolve missing accountability or the required service-owner authorization.
- Completed-ticket sampling excludes certificates that never generated a registry record or renewal ticket.
Question 59
Topic: Operations and Resilience
An IS auditor is evaluating the capacity-forecasting control for a payment authorization service. The business requires 95% of requests to complete within 2 seconds during every business period. Management forecasts capacity using only mean demand and concluded that no change is needed.
Operational evidence:
| Measure | Result |
|---|---|
| Mean arrival rate | 5,400 requests/minute |
| Service capacity | 8,000 requests/minute |
| Quarter-end peak | 8,600 requests/minute for 10 minutes |
| Latest peak p95 response | 38 seconds |
| Backlog outcome | Cleared within 3 minutes; no losses |
Which recommendation should the auditor make?
Options:
A. Revise the forecast to compare total daily demand, daily capacity, and backlog clearance.
B. Revise the forecast to model peak arrival rates, queue growth, and p95 response performance.
C. Revise the forecast to correlate maximum CPU utilization, incident counts, and annual request growth.
D. Revise the forecast to apply a safety margin to mean utilization and mean response performance.
Best answer: B
Explanation: Capacity forecasting must evaluate when demand occurs, not merely its average. During the quarter-end peak, arrivals exceed processing capacity by 600 requests per minute. Over 10 minutes, this creates a backlog of 6,000 requests and increasing queue delay. The measured p95 response of 38 seconds confirms failure against the 2-second objective.
Mean utilization and eventual backlog clearance show that total throughput may be sufficient over a longer period, but they do not demonstrate acceptable performance during predictable peaks. The forecast should therefore model peak arrival rates, service rates, queue growth, and the applicable response objective. Daily totals can similarly conceal short periods of service failure.
- Mean safety margin still aggregates demand and mean response time, masking the predictable 10-minute service failure.
- Daily capacity comparison tests eventual throughput rather than the required response time during the peak.
- Infrastructure trends may supplement capacity analysis but do not directly evaluate the observed arrival-rate queue and p95 breach.
Question 60
Topic: Acquisition and Implementation
An IS auditor reviews a benefits realization record before investment approval. Which revision would BEST support accountable measurement of the expected benefit?
Record excerpt:
Benefit: Reduce order-to-cash time by 20%
Target date: 12 months after go-live
Metric source: ERP and receivables records
Measurement: Monthly; quarterly review
Baseline: First 90 days after go-live
Benefit owner: Project manager until project closure
Project closure: 30 days after go-live
Process owner: VP, Sales Operations
Executive sponsor: CIO
Options:
A. Assign the CIO through month 12 and use comparable predeployment records as the baseline.
B. Assign the PMO analyst through month 12 and use comparable predeployment records as the baseline.
C. Assign the VP through month 12 and use the first 90 production days as the baseline.
D. Assign the VP through month 12 and use comparable predeployment records as the baseline.
Best answer: D
Explanation: Benefits realization requires an accountable business owner and a valid basis for comparing results. The VP of Sales Operations owns the affected process and should remain accountable through the 12-month realization period, rather than ending accountability at project closure. Comparable data collected before deployment provides a baseline unaffected by the new system. The stated source, monthly measurement, and quarterly review can then track progress against the 20% target.
Executive sponsorship and PMO measurement support governance, but they do not replace accountability by the business owner who can influence the outcome.
- CIO sponsorship provides oversight, but the CIO is not identified as accountable for the affected business process.
- The first production quarter already reflects the system change, so it cannot provide an unaffected baseline.
- A PMO analyst can coordinate measurement but does not own the business process or expected benefit.
Question 61
Topic: Operations and Resilience
An IS auditor is assessing management’s recovery-copy retention plan during a ransomware investigation. The business must restore order processing, preserve evidence and comply with its privacy disposal policy.
- Daily immutable copies have logged access and expire after 35 days.
- The probable compromise window is June 5 through July 1.
- Counsel’s active legal hold covers copies dated June 5 onward.
- May 31 is the latest copy validated as clean and expires July 5.
- The incident owner approved a recovery exception for the May 31 copy.
- Policy permits disposal exceptions only for an approved recovery need or legal hold.
Which recommendation is best supported?
Options:
A. Retain May 31 under the recovery exception and June 5 onward until forensic imaging finishes, then resume scheduled disposal for both scopes.
B. Retain June 5 onward under legal hold, use the first held copy that passes scanning and allow May 31 to expire.
C. Retain May 31 and every later copy under the recovery exception, then resume disposal after the restored system passes validation.
D. Retain May 31 under the recovery exception and June 5 onward under legal hold, releasing each scope upon its authorized release.
Best answer: D
Explanation: Two purposes create distinct retention requirements. The May 31 copy is the latest validated clean recovery point, so its imminent expiration should be suspended under the incident owner’s approved recovery exception. Copies dated June 5 onward fall within counsel’s active legal hold and must remain preserved for the investigation, regardless of restoration or imaging progress.
The incident does not justify retaining every copy indefinitely. Copies outside the approved exception and legal-hold scope remain subject to normal disposal. Each retained set should be released only by the authority responsible for its retention basis. A later malware scan does not justify losing the known clean copy before an equivalent recovery point is validated, while successful restoration does not terminate a legal hold.
- Using a held copy for recovery would discard the only currently validated clean point before an equivalent replacement is established.
- Applying one broad recovery exception exceeds its approved scope and improperly ties legal-hold release to restoration success.
- Completing forensic imaging does not end an active legal hold; counsel must authorize release of the held copies.
Question 62
Topic: Operations and Resilience
An IS auditor is evaluating whether production change controls operated effectively during the quarter to support reliable releases.
Control requirement:
Every production-impacting change, including deployment configuration, must be authorized, tested and traceable to a change record.
Evidence:
- The release register contains approved application deployments.
- An automation account can directly modify production deployment rules.
- Its audit log shows an approval rule was changed for six hours, with no corresponding release-register entry.
- Artifact reconciliation found no unapproved software version in production.
What should the auditor do next to BEST assess this condition?
Options:
A. Expand the access-control review and test the automation account’s ownership, approval and credential restrictions.
B. Expand the change population to pipeline administration logs and test rule changes against required change-control criteria.
C. Expand the registered-release sample and reconcile additional deployed artifacts to approved application release records.
D. Expand the outcome review and inspect builds, deployments and incidents from the six-hour interval.
Best answer: B
Explanation: Completeness of the change population is decisive. Deployment rules determine how software reaches production, so modifying those rules is a production-impacting configuration change even when no unapproved artifact version is found. Because the normal register excludes direct automation-account activity and the administration log identifies such activity, registered releases are not a complete population for testing.
The auditor should obtain pipeline administration logs for the audit period, reconcile relevant activity to change records and test identified rule changes for authorization, testing and traceability. Artifact reconciliation addresses deployed versions, while access and outcome reviews address different control assertions. Neither establishes that the alternate change path complied with the required process.
- Additional registered-release sampling cannot detect pipeline configuration changes omitted from that register.
- Account ownership and credential restrictions address authorized access, not whether a particular rule change followed change procedures.
- Reviewing deployments and incidents assesses outcomes but does not establish authorization, testing or traceability of the rule change.
Question 63
Topic: Acquisition and Implementation
An IS auditor reviews a proposed customer-service automation investment. Finance has confirmed the approved discount rate, and a signed fixed-price proposal supports the implementation cost. No pilot or historical analysis supports the benefit assumptions.
Exhibit: Business-case approval record
Implementation cost: $4.0 million
Annual benefit: $2.4 million
Benefit basis: 30% volume growth; 80% automated resolution
Benefit timing: 100% of annual run rate from go-live
Sensitivity: implementation cost varied by +/-10%
Result: NPV remains positive in both cases
Which additional analysis would BEST assess whether the business case remains reasonable under uncertainty?
Options:
A. Model plausible ranges for growth, resolution, and ramp-up, including a combined downside scenario.
B. Model a wider implementation-cost range while retaining the base benefit assumptions and timing.
C. Recalculate NPV across alternative discount rates while retaining the base operating assumptions and timing.
D. Model benchmark-based annual benefit ranges while retaining full benefits from the go-live date.
Best answer: A
Explanation: Sensitivity analysis should focus on assumptions that are both material and uncertain. Here, the implementation cost and discount rate have supporting evidence, while transaction growth, automated resolution, and immediate benefit realization do not. Testing only implementation-cost changes therefore provides little assurance about the main sources of forecast risk.
Plausible ranges should be developed for the unsupported benefit drivers and applied in combined scenarios. A downside scenario can reveal whether interactions among lower growth, reduced automation performance, and slower benefit realization eliminate the positive NPV. The key is to test the assumptions driving projected value, not merely variables that are easiest to change.
- Widening the cost range concentrates on an amount supported by a fixed-price proposal and leaves the material benefit uncertainty untested.
- Changing the confirmed discount rate does not address the unsupported assumptions about operational performance and benefit timing.
- Benchmark benefit ranges improve the estimate, but immediate full realization remains an untested and potentially material assumption.
Question 64
Topic: Operations and Resilience
An IS auditor reviews the daily customer-settlement service. The business service owner is the designated risk owner.
- A required component is end-of-support and receives no vendor security patches.
- Its risk exception expired three months ago. Policy requires owner approval before continued use.
- Network isolation, application allowlisting, and monthly scanning have operated effectively.
- A replacement is undergoing integration testing, with deployment planned in three months.
- No exception renewal or current risk acceptance exists.
Which action should the auditor take?
Options:
A. Report an unresolved lifecycle control deficiency, assess residual risk using the verified mitigations, and recommend prompt disposition by the risk owner.
B. Recommend immediate component retirement, document the absence of vendor patches, and require operations to suspend the dependent settlement service.
C. Classify the condition as a migration schedule variance, document the verified mitigations, and defer lifecycle reporting until the planned release.
D. Treat the exception as continuing through the migration date, document the verified mitigations, and monitor completion against the approved plan.
Best answer: A
Explanation: An expired exception means the unsupported component is operating without current risk acceptance under the stated policy. Effective compensating controls and credible migration progress can reduce residual risk and affect the finding’s severity, but they do not renew authorization or restore vendor patch support. The auditor should report the lifecycle control deficiency and provide the risk owner with verified evidence about mitigations and transition status. Management, not the auditor, decides whether to renew the exception, accelerate replacement, or suspend the service. Neither implied extension nor mandatory shutdown is supported by the facts.
- Treating the exception as continuing assumes implied approval, although policy expressly requires owner approval before continued use.
- Classifying the issue solely as a schedule variance overlooks the separate lifecycle control failure created when authorization expired.
- Requiring immediate suspension exceeds the auditor’s authority and disregards management’s responsibility to evaluate business impact and residual risk.
Question 65
Topic: Information Asset Protection
An IS auditor is evaluating whether compromise of an approved service broker would be contained. The record lists all effective permits and role memberships.
Segmentation standard excerpt
Approved broker flows do not establish trust in destination zones. Broker runtime identities must not have administrative privileges there.
Access review record
| Source | Destination | Service | Status |
|---|---|---|---|
| User VLAN | broker01 | TCP 443 | Approved |
broker01 | Orders data subnet | TCP 1433 | Approved |
broker01 | Management subnet | TCP 5986 | Temporary; expiration blank |
- Runtime identity:
CORP\svc_broker - Orders database role:
db_owner - Management server role: Local Administrators
Which audit conclusion is best supported?
Options:
A. A
broker01compromise could affect data, while source filtering keeps management isolated.B. A
broker01compromise could affect management, while the database service boundary keeps data isolated.C. A
broker01compromise could create privileged pivots into both restricted destination tiers.D. A
broker01compromise would remain within the application tier because users lack direct restricted-tier routes.
Best answer: C
Explanation: Effective segmentation depends on actual reachability and authority, not zone labels. The rules accept broker01 as a source for both SQL and WinRM traffic, while its runtime identity is a database owner and local administrator. If the broker is compromised, activity originates from the trusted source and carries elevated rights in both destinations. The absence of direct user-to-restricted-zone rules no longer provides containment after the broker becomes the pivot.
Approved rule labels and named ports document intended flows but do not offset excessive privileges. The blank expiration is also a governance concern, but the combined paths and administrative rights are the primary segmentation failure.
- Source filtering trusts the broker itself, so it cannot contain activity originating from a compromised broker.
- Restricting traffic to TCP 1433 does not isolate the data asset when the runtime identity has
db_ownerauthority. - Missing direct user routes does not prevent movement through a compromised intermediary that has downstream permits.
Question 66
Topic: Operations and Resilience
An IS auditor reviews a disaster recovery completion record. Which conclusion is most appropriate based on the record?
Recovery record excerpt:
Service: Order processing
RTO target / achieved: 4 hours / 3 hours 20 minutes
RPO target / achieved: 30 minutes / 18 minutes
Functional test: Passed
Administrator access: Local password; MFA unavailable
Centralized security logging: Not connected
Compensating controls: [blank]
Deviation expiration: [blank]
Approvals: Recovery lead signed; service owner [blank]; information security [blank]
Status: Complete
DR-12: Completion requires approved access and centralized logging.
A temporary deviation requires named compensating controls, an expiration,
and acceptance by the service owner and information security.
Options:
A. Treat completion as supported because RTO and RPO were met, tracking security gaps separately.
B. Treat completion as unsupported until required deviation acceptance and compensating-control evidence are documented.
C. Treat completion as conditionally supported by recovery-lead approval and a short remediation window.
D. Treat completion as unsupported and disregard the recovery results until the legacy image is replaced.
Best answer: B
Explanation: Disaster recovery assurance covers controlled restoration, not merely service availability. The record supports meeting the RTO and RPO and passing functional testing, so those measurements remain useful. However, procedure DR-12 makes approved access and centralized logging part of recovery completion. A temporary deviation requires named compensating controls, an expiration, and acceptance by both the service owner and information security. Those fields are blank, and recovery-lead approval cannot substitute for the designated acceptance. The auditor should report that completion is unsupported rather than personally accepting the risk. Meeting availability targets does not override security-control release criteria.
- Meeting RTO and RPO demonstrates timely restoration but does not satisfy the documented security and deviation requirements.
- Recovery-lead approval cannot replace the service-owner and information-security acceptance specified by the procedure.
- The security deficiency does not invalidate the measured recovery results or necessarily require replacing the recovery image.
Question 67
Topic: Information Asset Protection
An IS auditor reviews this maintenance readiness record for a data center.
Control standard:
Critical load must remain supported after failure of
any one active cooling component during planned work.
Critical cooling load: 420 kW
Train A: 500 kW | dedicated pump P-A | planned offline
Train B: 500 kW | pump P-1 | available
Train C: 500 kW | pump P-1 | available
P-1 standby or bypass: none
Temperature alarms: staffed continuously
Which assessment is best supported by the record?
Options:
A. Assess the window as lacking single-failure tolerance because both available trains depend on P-1.
B. Assess the window as adequately controlled because staffed alarms provide prompt failure detection.
C. Assess the window as compliant subject to successful post-maintenance failover testing of all three trains.
D. Assess the window as N+1 because either available train can carry the full critical load.
Best answer: A
Explanation: End-to-end redundancy requires independent support paths, not merely sufficient component capacity. Trains B and C can each carry the 420 kW load, but both depend on the sole P-1 pump. While Train A and its dedicated pump are offline, failure of P-1 would stop circulation for both available trains. The arrangement therefore cannot tolerate failure of any one active cooling component as required. Staffed alarms improve detection and response but do not maintain cooling after pump failure. Testing after maintenance may confirm restored redundancy, but it cannot establish protection during the maintenance window.
- Full-capacity chillers do not provide independent paths when both require the same sole pump.
- Alarm staffing reduces detection time but cannot sustain circulation after P-1 fails.
- Post-maintenance testing cannot demonstrate compliance during the earlier maintenance window.
Question 68
Topic: Information Asset Protection
An IS auditor is assessing management’s exposure classification for an internet-facing customer portal before a risk committee review. The security patch was not installed, and the affected module remained externally reachable.
Evidence:
- Threat intelligence and gateway logs show exploit attempts targeting the module.
- An authenticated scan confirms the vulnerable configuration; testing of an identical isolated clone permits unauthorized reading of synthetic records.
- Reconciled production application, database, and egress logs show no successful unauthorized access, record change, or data transfer.
Which assessment is best supported?
Options:
A. Threat activity and an exploitable vulnerability are supported; production data impact is not demonstrated.
B. Threat activity is supported; exploitability and production data impact are not demonstrated.
C. An exploitable vulnerability is supported; threat activity and production data impact are not demonstrated.
D. Threat activity, an exploitable vulnerability, and production data impact are all supported.
Best answer: A
Explanation: Threat presence, vulnerability, and impact are separate conditions. Threat intelligence and gateway records show that an attacker attempted to target the portal. The authenticated scan, matching production configuration, and controlled clone test provide evidence that the weakness was exploitable. However, exploit attempts and technical exploitability do not prove that production data was accessed, altered, or transferred. The reconciled production records provide no evidence of such an outcome.
The audit conclusion should therefore distinguish demonstrated exposure from demonstrated business impact rather than treating the existence of attacks and a vulnerability as proof of compromise.
- Treating all three conditions as established incorrectly equates attack attempts and technical exploitability with actual production data impact.
- Treating exploitability as unverified disregards the authenticated scan, configuration evidence, and reproducible controlled test.
- Treating threat activity as absent disregards both the active campaign intelligence and the observed gateway requests.
Question 69
Topic: Operations and Resilience
An IS auditor is reviewing recurring configuration exceptions on payment servers. The control’s business purpose is to retain approved security settings after automated recovery.
Control state: A source-controlled automation template is the authoritative baseline for server builds.
Evidence:
- An emergency change authorized staff to set minimum TLS to 1.2 manually.
- A compliance scan passed immediately after the repair.
- The nightly rebuild from template version 18 restored TLS 1.0.
- Repository history shows no corresponding template update or approval.
Which recommendation should the auditor prioritize to address the control failure?
Options:
A. Deploy a configuration agent to reapply the runtime setting, then verify it after each rebuild.
B. Update the CMDB after each manual repair, then reconcile its records to the deployed servers.
C. Update, test, approve, and version the automation template, then redeploy and verify the servers.
D. Add a post-deployment compliance gate, then quarantine and repair servers that fail the scan.
Best answer: C
Explanation: Automated redeployment applies the template’s desired state, so a manual runtime repair persists only until the server is replaced. The successful initial scan confirms that the repair worked, while the repository and rebuild evidence show that the approved change was never incorporated into the authoritative baseline. Sustainable remediation requires management to update, test, approve, and version the template through change control, followed by verification of newly deployed servers. A post-deployment gate could detect the recurring defect, but it would not correct the defective source configuration.
- A compliance gate detects or contains noncompliant builds but leaves the authoritative template unchanged.
- Updating the CMDB records the condition but does not control settings applied during redeployment.
- A separate configuration agent creates another enforcement source instead of correcting the designated baseline.
Question 70
Topic: IT Governance and Management
An IS auditor reviews a claims automation project intended to reduce average handling time by 15% and rework by 20% within 12 months.
- The project met its approved scope, schedule, and budget.
- Functional tests passed, and availability exceeds its target.
- Nine months after implementation, no benefits owner, measurement method, or benefits review is documented.
- Management has not produced handling-time or rework results.
Which audit conclusion is BEST supported?
Options:
A. Delivery performance is satisfactory, but value-realization governance cannot demonstrate achievement of the intended business benefits.
B. Strategic alignment is satisfactory because approved scope, schedule, budget, and technical acceptance criteria were achieved.
C. Project governance is satisfactory, but operations monitoring should be expanded to measure additional technical service indicators.
D. Strategic outcomes should be rated unsuccessful because no post-implementation evidence quantifies the expected business benefits.
Best answer: A
Explanation: Project delivery performance and strategic value realization are separate governance concerns. Meeting scope, schedule, budget, testing, and availability targets demonstrates successful delivery of technical outputs. It does not demonstrate the intended business outcomes of reduced handling time and rework. Benefits realization requires defined measures, accountable owners, and post-implementation review. Their absence prevents management and the auditor from determining whether the investment supports its strategic purpose.
The evidence supports a limitation in demonstrating benefits, not a conclusion that the benefits definitely failed.
- Delivery equals alignment confuses successful implementation milestones with evidence that business outcomes were achieved.
- Assume benefits failed overstates the evidence because missing measurements establish uncertainty, not unsuccessful outcomes.
- Expand technical monitoring addresses service performance rather than ownership and measurement of the stated business benefits.
Question 71
Topic: Auditing Process
An organization acquired a subsidiary three months ago. Internal audit is asked to provide independent assurance before systems consolidation.
Principal business purpose: Determine whether the subsidiary complied with payment regulations during the 12 months before acquisition.
- High-risk payments required independent approval before release.
- Approval evidence must be retained for seven years.
- Process narratives and control matrices are unavailable.
- Payment populations, approval timestamps, archive inventories, and archive logs are available.
- Efficiency analysis and future-state redesign are outside the engagement purpose.
Which assurance approach should internal audit select?
Options:
A. Conduct compliance assurance by testing payment and archive evidence against the approval and retention requirements.
B. Conduct a control design assessment by reconstructing workflows and evaluating controls against the approval and retention requirements.
C. Conduct an operational audit by analyzing payment cycle times, exception rates, and resource use against integration targets.
D. Conduct an implementation readiness review by testing migration plans, data mappings, and conversion controls against cutover requirements.
Best answer: A
Explanation: The engagement type should follow its principal business purpose, not the maturity of process documentation. The required conclusion concerns actual regulatory adherence during a defined period, so compliance assurance is appropriate. Internal audit can reconcile the available payment population and inspect approval timestamps, archive inventories, and logs against the stated requirements. Missing narratives require auditors to obtain and document a process understanding through walkthroughs and corroboration, but they do not change the engagement into a design assessment. A design review would determine whether controls are suitably conceived, whereas the board needs evidence that required controls actually operated and records were retained.
- A control design assessment would address whether controls are suitably conceived, not whether they operated during the period under review.
- An operational audit would assess efficiency, which is expressly outside the stated business purpose.
- An implementation readiness review would address future consolidation risks rather than historical regulatory adherence.
Question 72
Topic: Operations and Resilience
An IS auditor is reviewing an annual continuity exercise for a critical order-processing service. The business purpose is to sustain order fulfillment and provide timely instructions to business units and the recovery vendor.
Approved plan:
- The incident commander or named alternate may activate the plan.
- Activation is required when primary-site unavailability is expected to exceed 60 minutes.
- Stakeholders must be notified within 30 minutes after activation.
Exercise evidence:
- 09:00: A four-hour site outage is forecast; the commander is unreachable, and the alternate acknowledges the report.
- 09:20: The alternate starts failover but declines activation, believing only the commander may activate.
- 09:50: Processing is restored.
- 11:00: The commander activates the plan; notices are sent at 11:20.
What is the most appropriate audit conclusion?
Options:
A. Report a communication-design deficiency because notification timing begins after formal plan activation.
B. Conclude continuity controls operated effectively based on recovery and post-activation notification timing.
C. Report an activation operating-effectiveness exception with a resulting delay in stakeholder communications.
D. Report a control-design deficiency in delegated activation authority and communication responsibility.
Best answer: C
Explanation: Continuity activation decisions must apply the approved trigger using the authority assigned in the plan. At 09:00, expected site unavailability was four hours, exceeding the 60-minute threshold, and the named alternate was authorized to act. Starting failover did not replace activation because activation started the required stakeholder communication window. Execution therefore failed at activation and delayed communications, even though processing recovered in 50 minutes.
The plan already addressed delegation and communication responsibility, so the evidence indicates an operating-effectiveness issue rather than a design deficiency. Meeting the 30-minute requirement after the late activation does not cure the missed upstream trigger.
- Delegated-authority design is not deficient because the approved plan expressly gives the named alternate activation authority.
- Recovery performance does not establish effective activation because the trigger depends on forecast site unavailability, not eventual processing downtime.
- Changing communication design is unsupported because prompt activation at 09:00 would have started the existing notification clock.
Question 73
Topic: IT Governance and Management
An IS auditor is assessing the design of governance over major digital investments.
Business purpose: Ensure investments support strategy and that business executives own benefits and residual risk.
Approved decision rights:
- Business sponsors are accountable for benefits and residual risk but have no approval, veto, or escalation authority.
- The CIO may authorize investments up to $1,000,000.
- The IT steering committee reviews CIO decisions quarterly but has no preauthorization role.
Observed case: The CIO authorized an $850,000 platform despite sponsor opposition. The committee reviewed it after the contract was signed, as its mandate required.
Which audit conclusion is best supported?
Options:
A. The decision-right design is adequate because the CIO’s delegated authority is subject to scheduled committee review.
B. The decision-right design has an accountability gap because the sponsor and committee lack precommitment authority.
C. The spending mandate makes the CIO accountable for benefits and residual risk on investments below the threshold.
D. The committee mandate is adequate, but operating effectiveness failed because members did not reverse the CIO’s authorization.
Best answer: B
Explanation: Accountable governance requires reasonable alignment between responsibility and decision authority. The sponsor owns benefits and residual business risk but cannot approve, veto, or escalate the investment before commitment. The steering committee also acts only after the CIO has committed the organization. Consequently, the approved structure permits a decision that conflicts with the accountable sponsor’s judgment without timely governance intervention.
This is a control design issue rather than an operating failure: the CIO and committee acted within their approved mandates. Delegated spending authority establishes who may authorize expenditure, but it does not automatically transfer ownership of business outcomes or residual risk.
- Scheduled postcommitment review cannot ensure strategic alignment or business risk acceptance before the organization becomes obligated.
- Operating effectiveness did not fail because the committee followed its mandate and lacked authority to reverse the authorization.
- CIO spending authority does not transfer the sponsor’s assigned accountability for benefits and residual business risk.
Question 74
Topic: Information Asset Protection
An IS auditor reviews an offline root CA key ceremony. No authentication records exist beyond the following excerpt. Which recommendation BEST addresses the most significant control deficiency?
Control standard and ceremony record:
Root key: Offline HSM; key export disabled
Requirement: Two authorized custodians must each use a
unique identity credential and a separate activation share.
Evidence must attribute shares and signing to those custodians.
09:01 Custodian C17 entered vault
09:02 Custodian C24 entered vault
09:05 Shared account PKI-OP authenticated
09:06 Activation share accepted [custodian not recorded]
09:07 Activation share accepted [custodian not recorded]
09:08 Issuing CA certificate signed
09:12 C17 and C24 signed ceremony attestation
Options:
A. Require witness attestation linking each custodian’s share to the signing session.
B. Review vault access records for entries lacking corresponding ceremony records.
C. Configure unique HSM authentication linking each custodian’s share to the signing session.
D. Reconcile each signed certificate serial to its approved ceremony request.
Best answer: C
Explanation: Certification-authority key controls require both protection and accountability. The record supports physical dual presence, use of two activation shares, and key non-exportability. However, the shared HSM account and unidentified share entries do not establish which authenticated custodian supplied each share or performed the signing activity. Signed attestations provide supporting evidence but do not satisfy the stated requirement for unique identity credentials and system-level attribution. Configuring the HSM to associate each custodian’s unique authentication and share with the signing session creates a direct, auditable record.
Physical access, transaction authorization, and witness evidence are useful controls, but they do not replace individual logical accountability.
- Witness attestation provides corroboration but does not meet the requirement for unique identity credentials in the HSM record.
- Certificate reconciliation addresses transaction authorization and completeness, not attribution of key activation to individual custodians.
- Vault log review monitors physical access, which is already individually recorded and does not resolve shared logical access.
Question 75
Topic: Auditing Process
A senior IS auditor has validated a high-rated access-control finding. No remediation has been implemented. Before the report is finalized, the auditor reviews this record:
Engagement record excerpt:
Conflict declaration
Engagement manager: No actual or apparent conflicts
Email from engagement manager
Delete the finding from the committee report. My spouse leads
this business unit, and its financing closes Friday. The evidence
is accurate, but management promises remediation next quarter.
Keep the details only in the workpapers.
Audit charter
Conflicts and attempts to suppress supported findings must be
reported promptly to the CAE. Unresolved matters may be escalated
to the audit committee.
What should the senior IS auditor do next?
Options:
A. Preserve the finding, promptly disclose the matter to the CAE, and seek independent review
B. Reassess the rating after obtaining a remediation commitment, then document the relationship during engagement closeout
C. Obtain formal risk acceptance from the unit executive, then retain the finding only in the workpapers
D. Send the evidence directly to the audit committee, then suspend reporting until the committee provides direction
Best answer: A
Explanation: Professional objectivity requires prompt disclosure of actual or apparent conflicts and reporting conclusions supported by sufficient, appropriate evidence. The manager’s undisclosed spousal relationship creates an apparent conflict, while the request to conceal an accurate finding constitutes pressure on audit reporting. A future remediation promise does not change the present control condition. The auditor should preserve the evidence and follow the charter by notifying the chief audit executive (CAE) for independent review.
Management may accept business risk, but risk acceptance does not authorize suppression of a supported audit finding. Direct audit committee escalation is premature because the charter directs the auditor to the CAE first and permits further escalation only if the matter remains unresolved.
- A remediation commitment does not establish that the control deficiency has been corrected, and delaying conflict disclosure violates the charter.
- Formal risk acceptance assigns accountability for the risk but does not justify removing a supported finding from the report.
- Direct committee reporting bypasses the charter’s initial CAE escalation step when the CAE is not implicated.
Questions 76-100
Question 76
Topic: Operations and Resilience
An IS auditor reviews an inventory reservation incident. Concurrent requests are permitted, but over-reservation must be prevented before order confirmation.
Incident record:
Initial: SKU-7 quantity=12, version=41
T51 BEGIN; reads quantity=12, version=41
T52 BEGIN; reads quantity=12, version=41
T51 reserves 7; UPDATE quantity=5, version=42
WHERE sku='SKU-7'; COMMIT
T52 reserves 6; UPDATE quantity=6, version=42
WHERE sku='SKU-7'; COMMIT
Final: quantity=6; committed reservations=13
Errors or rollbacks: none
Which remediation most directly addresses the control failure shown?
Options:
A. Use expected-version matching and retry reservations rejected as stale.
B. Use post-commit reconciliation and hold reservations producing inventory exceptions.
C. Use read-committed isolation and retry reservations returning database errors.
D. Use atomic transaction boundaries and retry reservations interrupted before commit.
Best answer: A
Explanation: The trace shows a lost update caused by uncontrolled concurrent read-modify-write processing. Both transactions read version 41, but each update uses only the SKU in its condition. The second transaction therefore overwrites the first transaction’s quantity. An optimistic concurrency control would include the expected version in the update condition. After the first commit changes the version to 42, the second update based on version 41 affects no rows and must reread and retry before confirming the order.
Atomic commits protect transaction completeness, but they do not prevent one complete transaction from overwriting another transaction’s update.
- Read-committed isolation prevents dirty reads but does not ensure that an earlier read remains current when its later update executes.
- Atomic transaction boundaries ensure complete commit or rollback; the record shows that both transactions completed successfully.
- Post-commit reconciliation detects the inconsistency after processing, missing the required preventive timing before confirmation.
Question 77
Topic: Auditing Process
An IS auditor plans to use the following record to assess monthly privileged-access reviews. The authoritative identity repository and dashboard query are available for audit.
Dashboard record:
Owner: IAM Operations (control operator)
Period: June
Compliance: 100% (1,842 of 1,842 accounts)
Input: Consolidated privileged-access table
Transformation: Query-based mappings and exclusions
Source reconciliation: Not documented
Transformation validation: Not documented
Control owner certification: Approved
What should the auditor do before relying on the reported compliance rate?
Options:
A. Observe the operator regenerate the dashboard and inspect change approvals for the current query.
B. Reperform selected access reviews from authoritative records and inspect their documented supervisory approvals.
C. Compare dashboard results across recent periods and investigate unusual compliance-rate or volume changes.
D. Reconcile the dashboard population to authoritative records and independently test its transformation and exclusion rules.
Best answer: D
Explanation: System-generated evidence must be tested for completeness and accuracy before an auditor relies on it. The dashboard is maintained by the control operator, and its 100% result depends on an unreconciled input population and unvalidated query logic. The auditor should reconcile dashboard records to the authoritative identity repository and test whether mappings, exclusions, and calculations operate as intended. Control owner certification does not resolve these reliability gaps because it does not independently establish population completeness or transformation accuracy.
Reperformance of selected reviews may test the underlying control, but it cannot support reliance on the dashboard summary until the data and processing logic are validated.
- Reperforming selected reviews tests individual cases but does not establish that all relevant accounts reached the dashboard.
- Trend analysis may identify anomalies but cannot prove that the source population and query logic are reliable.
- Observing regeneration and inspecting approvals confirms process execution and authorization, not transformation accuracy or population completeness.
Question 78
Topic: Information Asset Protection
An IS auditor is evaluating whether security awareness activities incorporate incident lessons and changing threats. Review the following content-change record.
Source IR-27: Employee scanned a malicious benefits QR code
Relevance: All employees
Decision: Add QR destination-verification scenario
Evidence: Deployed June 3; 92% passed the scenario check
Source TB-14: Increased help-desk impersonation attacks
Relevance: Password-reset agents
Decision: Monitor until an internal incident occurs
Audience assignment: Not recorded
Awareness evidence: None
Which conclusion is BEST supported by this record?
Options:
A. Both inputs were incorporated because the emerging threat remains under monitoring.
B. Deferring the emerging threat was appropriate because no internal incident had occurred.
C. Neither input was incorporated because one scenario check cannot establish lasting behavior.
D. The incident lesson was incorporated, but the relevant emerging threat was not.
Best answer: D
Explanation: Incorporation requires relevant incident and threat information to result in an appropriate awareness response, such as revised content, audience targeting, delivery, or behavioral validation. IR-27 was translated into a scenario for the affected workforce, deployed, and followed by a knowledge check. TB-14 was considered relevant to password-reset agents but produced no content change, audience assignment, or other awareness activity. Waiting for an internal incident makes awareness reactive and fails to address a recognized changing threat proactively.
A single scenario check may not prove sustained behavior, but it does provide evidence that the incident lesson was incorporated into the activity.
- Monitoring TB-14 records the threat-management decision but does not incorporate the threat into awareness activities.
- Limited validation affects assurance about sustained effectiveness, not whether IR-27 was incorporated.
- Requiring an internal incident ignores the recorded relevance of the emerging threat to password-reset agents.
Question 79
Topic: Operations and Resilience
An IS auditor reviews the monthly reliability claim for a customer checkout service. The business target requires customers to complete checkout at least 99.9% of the time, including payment authorization.
Operational evidence:
- Web, application, and database servers reported 99.95% or higher uptime.
- Payment-interface TLS failures prevented checkouts for 120 minutes while all servers remained healthy.
- One-minute synthetic checkout tests recorded 99.72% end-to-end availability.
Management reports that the reliability target was achieved. Which assessment is BEST supported?
Options:
A. The claim is supported because healthy servers place payment-interface failures outside the service measure.
B. The claim is unsupported because component uptime must be weighted by each server’s transaction volume.
C. The claim is unsupported because required payment-interface availability is absent from the component measures.
D. The claim is supported because every monitored server independently exceeded the service availability target.
Best answer: C
Explanation: End-to-end service availability includes every dependency required to complete the business transaction. Individual server uptime measures only those components and does not demonstrate that communication paths, interfaces, certificates, gateways, or external integrations were working. Here, payment authorization is explicitly within the checkout objective. Its interface failed for 120 minutes even though the servers remained healthy. The synthetic tests exercised the complete customer process and measured 99.72%, which is below the 99.9% target. Therefore, the server dashboard does not support management’s service-level reliability claim.
A component can be available while the business service that depends on it remains unavailable.
- Individual server results cannot establish service availability when a required interface prevented completed transactions.
- Transaction-volume weighting would not capture whether the components communicated successfully across the payment interface.
- Healthy servers do not exclude payment authorization because the business target explicitly includes that dependency.
Question 80
Topic: Operations and Resilience
An IS auditor is assessing an order interface during its first week after a release. Order priority determines dispatch timing.
Operational evidence:
- The source changed priority from integers
1,2,3to charactersH,M,L. - The target still expects integers; nonnumeric values become
2, and only rejected records are logged. - The same 12,000 unique order IDs appear in both source and target, with no missing or extra IDs.
- Source priorities are 1,800 high, 7,200 medium, and 3,000 low.
- All target priorities are
2, and the exception log is empty.
Which assessment is BEST supported?
Options:
A. Record-level completeness and priority accuracy are supported; exception visibility is not.
B. Priority accuracy and exception visibility are supported; record-level completeness is not.
C. Record-level completeness is supported; priority accuracy and exception visibility are not.
D. Record-level completeness and exception visibility are supported; priority accuracy is not.
Best answer: C
Explanation: Interface controls must separately address completeness, accuracy, and exception visibility. The matching sets of unique order IDs provide evidence that all 12,000 records reached the target, supporting record-level completeness. They do not establish that each field was transferred accurately. The unchanged target parser treated every new character value as invalid and replaced it with the default priority, producing a distribution inconsistent with the source. Because defaulting did not reject records or generate exceptions, operational monitoring also failed to reveal the conversion problem.
A reconciled record count cannot compensate for unverified field transformations or silent defaults.
- Supporting priority accuracy ignores the complete mismatch between source and target priority distributions.
- Rejecting record-level completeness disregards the reconciled unique order IDs showing all 12,000 orders were loaded.
- Treating an empty log as effective visibility overlooks that defaulted values do not trigger the configured exception mechanism.
Question 81
Topic: IT Governance and Management
An IS auditor is evaluating whether a service dashboard supports management’s stated business objective.
Performance report excerpt:
Objective: Fulfill at least 95% of all submitted requests within one day.
Submitted requests: 1,000
Rejected by automated validation: 200
Accepted requests: 800
Completed within one day: 784
Failed after acceptance: 16
Reported fulfillment rate: 98% (784 / 800)
Note: Rejected requests require customer resubmission and are excluded from the rate.
Which recommendation would BEST improve the measure’s completeness and business relevance?
Options:
A. Redefine the primary rate using all submissions, with rejection causes reported separately.
B. Redefine the primary rate using accepted requests plus successfully completed customer resubmissions.
C. Replace the primary rate with validation time, with accepted-request completion reported separately.
D. Retain the accepted-request rate as primary, with rejected volumes reported as supplemental metrics.
Best answer: A
Explanation: A performance indicator’s denominator must represent the population covered by the business objective. The objective concerns all submitted requests, but the dashboard excludes 200 rejected requests that were not fulfilled and required customer action. This creates survivorship bias and raises the reported rate from 78.4% to 98%. The primary rate should therefore use all 1,000 submissions, while separate rejection-cause reporting can help management identify control or data-quality issues. A supplemental rejection count does not correct a primary indicator that remains misaligned with the objective.
- Keeping the accepted-request rate as primary preserves the exclusion that materially overstates business performance.
- Adding successful resubmissions excludes unresolved rejections and may count the same business demand more than once.
- Validation time measures processing speed rather than the percentage of submitted requests fulfilled.
Question 82
Topic: IT Governance and Management
An IS auditor reviews a SaaS exit plan. A test tenant for the planned replacement service is available.
Exit control record:
Business target: Complete, usable data within 30 days
Contract: Provider will return Customer Data at termination
Return format: To be agreed after termination notice
Proprietary ID conversion: Provider services required
Most recent export or migration test: None
Completeness validation: Not defined
Which recommendation would BEST address the assurance gap?
Options:
A. Recommend an end-to-end export and import test that reconciles data and measures completion time.
B. Recommend a replacement-platform import test that uses synthetic records and projected delivery time.
C. Recommend a tabletop exit exercise that validates assigned responsibilities and dependency response time.
D. Recommend a provider readiness attestation that confirms export capability and expected delivery time.
Best answer: A
Explanation: A contractual data-return clause establishes an obligation, not practical exit capability. The format remains undecided, proprietary ID conversion depends on provider services, and no completeness or timing evidence exists. A representative end-to-end exercise can verify extraction, transformation, import usability, reconciliation, and achievement of the 30-day target.
Provider assurance and tabletop review provide indirect evidence. Testing only the replacement platform excludes the provider’s actual export process and source-data completeness. Practical exit feasibility requires evidence that the organization’s data can be returned completely and made usable within the business deadline.
- A provider attestation remains indirect and cannot demonstrate actual format compatibility, data completeness, or elapsed migration time.
- A tabletop exercise validates roles and sequencing but does not demonstrate that proprietary data can be extracted and migrated.
- Synthetic import testing evaluates the replacement platform while leaving the provider’s export and transformation processes untested.
Question 83
Topic: Operations and Resilience
An auditor is reviewing emergency change CHG-447. All records use synchronized UTC clocks.
Emergency production changes require approval before implementation. Implementation and service-restoration times must be recorded separately.
The incident report states: “Approved 22:10; implemented 22:15; service restored 22:15.”
Relevant records:
| Time | Source | Entry |
|---|---|---|
| 22:07 | Privileged access | Session opened by netops7 |
| 22:08 | Firewall audit | Configuration committed; ref CHG-447 |
| 22:10 | Change workflow | Manager approval recorded |
| 22:15 | Service monitor | Health checks returned to normal |
| 22:18 | Privileged access | Session closed |
Which conclusion BEST reconciles the incident report with the records?
Options:
A. Implementation occurred at 22:07 before approval; restoration occurred at 22:18.
B. Implementation occurred at 22:15 after approval; the session closed at 22:18.
C. Implementation and approval occurred at 22:10; restoration occurred at 22:15.
D. Implementation occurred at 22:08 before approval; restoration occurred at 22:15.
Best answer: D
Explanation: Log reconciliation requires interpreting what each source directly records. The firewall audit entry establishes that the production configuration was implemented at 22:08. The workflow establishes approval at 22:10, so implementation preceded the required approval. The service monitor supports restoration at 22:15, explaining why the incident report may have incorrectly used that timestamp for both implementation and restoration.
Privileged-session boundaries show when access was available, but they do not establish when the configuration changed or service recovered. The reconciled evidence therefore identifies both a preapproval control exception and an inaccurate implementation timestamp.
- Session opening and closing times bound privileged access but do not prove implementation or restoration times.
- The 22:15 health check records service recovery, not the earlier configuration commit.
- The 22:10 workflow entry records approval only; it does not establish simultaneous implementation.
Question 84
Topic: Operations and Resilience
An IS auditor is assessing readiness to restore online order processing within four hours.
- The last exercise met the objective 10 months ago.
- Support teams and emergency roles changed six months ago.
- The recovery provider later changed its network carrier and added an external identity provider.
- The plan still names former contacts, lists the old carrier, and omits the identity provider.
- Policy requires review after organizational or provider changes, but no review or exercise followed.
Which conclusion and recommendation are BEST supported?
Options:
A. Conclude documentation is inaccurate and recommend a tabletop review of revised contacts and contracts instead of recovery testing.
B. Conclude provider assurance is insufficient and recommend obtaining current provider reports before determining whether another exercise is needed.
C. Conclude readiness remains supported and recommend reconfirming current contacts during the next scheduled annual exercise.
D. Conclude readiness is unsupported and recommend updating contacts and dependencies, then exercising the revised plan against the four-hour objective.
Best answer: D
Explanation: Continuity readiness requires current plans and evidence that the present organization, technology, and third-party dependencies can meet approved recovery objectives. The earlier exercise tested a different operating environment, so its successful result does not establish readiness after material organizational and provider changes. Those changes also triggered the stated maintenance policy. Management should update response contacts and dependency information and then exercise the revised plan against the four-hour objective. Document review or provider reports may support the assessment, but neither demonstrates that the changed end-to-end recovery arrangement will operate within the required time.
- The prior exercise does not support current readiness because it occurred before material organizational and provider changes.
- Provider reports may address provider controls, but they cannot validate the organization’s complete recovery process and dependencies.
- A tabletop review can assess plan logic, but it cannot replace recovery evidence for meeting the four-hour restoration objective.
Question 85
Topic: Information Asset Protection
An IS auditor reviews a request to return an order-processing system to production after malware eradication.
Recovery policy and record excerpt:
Approval requires current evidence of:
- malware eradication
- component integrity against the approved baseline
- user and service access against the approved matrix
- critical business transactions and interfaces
Recovery record:
- Two EDR scans: no detections
- System and application hashes: matched
- Accounts and roles: reconciled
- Login and customer lookup: passed
- Order entry, payment interface, settlement batch: not tested
Which recommendation should the auditor make?
Options:
A. Recommend deferral until an independent tool repeats the malware scanning.
B. Recommend deferral until the application owner records the required business tests.
C. Recommend approval with enhanced transaction monitoring after release.
D. Recommend approval after the application owner signs the existing recovery record.
Best answer: B
Explanation: Return-to-service evidence must address eradication, integrity, authorized access, and business operation. The clean scans support eradication, hashes support component integrity, and account reconciliation supports access validation. However, login and customer lookup tests do not demonstrate that critical order entry, payment, and settlement processes work correctly. Because those required tests remain incomplete, the record does not support production return.
The incident manager or other designated manager retains approval authority; the auditor assesses the evidence and recommends deferral. A signature or additional malware scan would not resolve the missing evidence about critical business processing.
- Enhanced monitoring: Post-release detection does not replace the required pre-release validation of critical transactions and interfaces.
- Additional scanning: Another scan could strengthen eradication evidence but would leave business operation untested.
- Owner signature: Signing an incomplete record does not establish that the required business processes operate correctly.
Question 86
Topic: Information Asset Protection
An IS auditor is assessing whether a distributor can restore order fulfillment after ransomware.
Targets: RPO of 1 hour; RTO of 8 hours.
Evidence:
- A clean, immutable recovery point from 20 minutes before disruption was restored after the incident, and order records were reconciled.
- The last exercise restored the application in 2 hours while Active Directory, DNS, and the credential vault remained available.
- The attack disabled those three dependencies, and their recovery time has never been tested.
Which audit conclusion is BEST supported?
Options:
A. The evidence substantiates the RPO, but not the full-service RTO.
B. The evidence substantiates the full-service RTO, but not the RPO.
C. The evidence substantiates both the RPO and full-service RTO.
D. The evidence substantiates neither the RPO nor full-service RTO.
Best answer: A
Explanation: RPO addresses the maximum acceptable data loss. The successful post-incident restoration recovered records to 20 minutes before disruption, which is within the one-hour target. RTO addresses how quickly the complete business service becomes operational. The two-hour application test does not establish the full-service RTO because it assumed that Active Directory, DNS, and the credential vault were available. Those dependencies are now unavailable, and their recovery duration and sequence have not been tested.
Clean, immutable backups can preserve data while identity and operational dependencies still prolong business interruption. End-to-end recovery evidence must cover the complete service chain.
- Substantiating both targets treats an application-only exercise as proof of end-to-end service recovery.
- Rejecting both targets ignores the successful restoration and reconciliation of data within the RPO.
- Substantiating only the RTO reverses the evidence: data currency was demonstrated, while complete service recovery was not.
Question 87
Topic: Auditing Process
An IS auditor must select 120 change records based on this workpaper excerpt.
Audit objectives:
- Compare approval exceptions among platforms.
- Estimate the exception rate for all 12,500 changes.
Reconciled population:
Core: 9,000
Cloud: 2,500
Legacy: 1,000
Sampling requirements:
- At least 25 observations per platform.
- Overall results must reflect actual population shares.
Which sample-selection approach BEST meets these requirements?
Options:
A. Allocate 120 random records proportionally by platform and weight the platform rates for the overall estimate.
B. Draw 120 random records from the full population and use the resulting platform counts for comparison and projection.
C. Draw randomly within each platform, take at least 25 per platform, and weight rates by population shares.
D. Draw 40 random records per platform and use the unweighted combined exception rate as the overall estimate.
Best answer: C
Explanation: The dual audit objective requires disproportionate stratified random sampling. Random selection within each platform provides unbiased evidence for platform-level comparisons, and the minimum of 25 observations prevents the smaller platforms from being inadequately represented. Because this minimum produces a sample whose platform proportions differ from the population, the overall exception rate must be weighted using the actual shares: Core 72%, Cloud 20%, and Legacy 8%.
An equal allocation supports comparisons but distorts the overall estimate if results are simply pooled. A purely proportional allocation supports population projection but provides only about 24 Cloud and 10 Legacy records, failing the stated minimum.
- Equal allocation overrepresents Cloud and Legacy in an unweighted overall rate.
- Full-population random selection does not ensure at least 25 observations from each smaller platform.
- Proportional allocation provides approximately 24 Cloud and 10 Legacy records, below the required minimum.
Question 88
Topic: Auditing Process
An IS auditor is assessing whether an automated refund interface supports the business requirement that every approved return be paid within one business day. The daily interface-exception review is designed and implemented, but review evidence is unavailable for two weeks, so the auditor plans a whole-population substantive analytic.
Available extracts:
- Returns system: unique authorization ID, approval timestamp, status, approved amount
- Payment platform: authorization ID, payment timestamp, paid amount
The payment extract extends through the first business day after period-end. Which data-analytic test best addresses the completeness assertion?
Options:
A. Inner-join approved authorizations to payments and flag IDs whose paid amount differs from the approved amount.
B. Left-join payments to approved authorizations and flag IDs lacking an approved source record.
C. Group payments by authorization ID and flag IDs appearing more than once within the period.
D. Left-join approved authorizations to payments and flag IDs lacking a payment within one business day.
Best answer: D
Explanation: Completeness is tested from the expected source population to the recorded target population. Approved authorizations define the items that should have produced payments. A left join using those authorizations as the driving population preserves every expected item and identifies IDs with no timely payment. Extending the payment extract through the next business day prevents valid period-end approvals from appearing missing because of the processing window.
Whole-population analytics directly tests transaction outcomes despite the missing review evidence, but it does not establish that the daily exception review operated throughout the two weeks. Reverse-direction matching evaluates authorization, while duplicate and amount tests address other assertions.
- Matching payments back to approvals identifies unsupported payments, which addresses occurrence or authorization rather than completeness.
- Grouping repeated payment IDs detects duplicate processing rather than approved returns lacking timely payment.
- Comparing amounts among matched records tests accuracy and excludes authorizations with no matching payment.
Question 89
Topic: Information Asset Protection
An IS auditor reviews a forensic collection note for a suspected data upload. Which interpretation is best supported by the record?
Collection note
Incident window: 01:30-02:30 UTC
Acquisition: Logical image at 09:10 UTC; hashes matched
Included: Allocated files, EDR database, NTFS USN journal
Excluded: Volatile memory and unallocated disk sectors
Clock: Host remained 18 minutes ahead of UTC from 01:00-03:00
02:12:04 host time - EDR: archive.exe created C:\Temp\archive.zip
02:12:06 host time - USN: archive.zip FILE_CREATE
Network sensor: No upload recorded; collector offline 01:45-02:20 UTC
At acquisition: archive.zip absent from allocated files
Options:
A. Place creation at 02:12 UTC; leave transmission and deletion undetermined.
B. Place creation near 01:54 UTC; leave transmission undetermined but confirm deletion.
C. Place creation near 01:54 UTC; leave transmission and deletion undetermined.
D. Place creation near 01:54 UTC; confirm transmission but leave deletion undetermined.
Best answer: C
Explanation: Forensic conclusions must reflect normalized timestamps, source reliability and collection coverage. Because the host remained 18 minutes ahead, the events recorded around 02:12 host time correspond to approximately 01:54 UTC. The EDR and USN entries corroborate the creation activity, while matching acquisition hashes support the integrity of the collected image.
The network collector outage overlaps the corrected event time, so the missing upload record neither confirms nor excludes transmission. Similarly, a logical image containing only allocated files cannot establish deletion merely because the archive is absent; it could have been moved, renamed or deleted into uncollected space. The reliable conclusion is therefore limited to the corrected creation time.
- Using 02:12 UTC ignores the documented 18-minute clock offset.
- Confirming transmission treats a monitoring outage as affirmative evidence rather than missing coverage.
- Confirming deletion overinterprets absence from allocated files when unallocated sectors were not collected.
Question 90
Topic: IT Governance and Management
An IS auditor is reviewing data governance controls for a corporate strategy team. The business objective is to protect an acquisition negotiation while preserving access to unrelated strategy work.
Policy:
Classifications are reviewed annually and whenever business context materially changes. The business data owner approves classification changes; the IT custodian applies labels and access controls. Acquisition records are limited to assigned deal personnel.
Evidence:
- Active negotiations began two weeks ago.
- The folder contains the target’s identity and valuation assumptions but remains classified as Internal.
- Its inherited group has 28 members; only seven are assigned to the deal.
- The next annual review is in eight months.
What should the auditor recommend?
Options:
A. Recommend immediate owner reassessment and custodian restriction to the seven assigned deal personnel.
B. Recommend deal-owner reassessment after signing, while monitoring access for the current group.
C. Recommend immediate access restriction, with classification reassessed during the next annual review.
D. Recommend immediate custodian reclassification and restriction, followed by deal-owner ratification.
Best answer: A
Explanation: Data classification must reflect current business context, not merely the age or original purpose of the records. Active acquisition negotiations materially increase the sensitivity of the target identity and valuation assumptions, triggering the policy’s event-driven review requirement. The business data owner must promptly reassess the classification because that role owns the decision. The IT custodian then implements the label and limits dissemination to authorized deal personnel. The inherited group currently exposes the records to 21 people without a transaction-related need to know. Waiting for the annual review or transaction signing would leave the classification and access controls misaligned during the period of greatest sensitivity.
- Custodian-led reclassification reverses the policy’s assigned authority; later ratification does not make the initial decision properly authorized.
- Deferring reassessment until the annual review ignores the explicit material-change trigger, even if access is restricted immediately.
- Waiting until signing treats transaction completion as the trigger and leaves unnecessary access during active negotiations.
Question 91
Topic: IT Governance and Management
An IS audit manager is evaluating regulatory compliance and unauthorized-administration risk for a payment platform. The regulation requires annual certification of every privileged account assigned to an employee. The business objective covers every privileged identity.
Audit evidence:
- All 142 employee accounts were reconciled and certified before the deadline.
- Twelve provider administrator accounts were excluded because they are not employee accounts.
- Two excluded accounts remain enabled four months after their administrators left the contract.
- Logs show no activity from those two accounts after departure.
Which audit conclusion is most appropriate?
Options:
A. The requirement is unmet, and access risk is inadequately managed because provider administrators have equivalent privileges.
B. The requirement is met, but access risk is inadequately managed because stale provider privileges persist.
C. The requirement is met, and access risk is adequately managed because logs show no unauthorized activity.
D. The requirement is met, and access risk is adequately managed because the provider controls administrator staffing.
Best answer: B
Explanation: Compliance is assessed against the precise requirement, while control effectiveness is assessed against the underlying business objective and risk. The regulation covers employee accounts, and the reconciled evidence confirms that every account in that population was certified. However, the business objective covers all privileged identities. Accounts belonging to departed provider administrators remain enabled, preserving the ability to administer the platform improperly. Clean historical logs show no detected use, but they do not eliminate this continuing exposure. Contractual responsibility for provider staffing also does not transfer the organization’s accountability for its information risk.
The audit conclusion should therefore distinguish narrow regulatory compliance from ineffective management of the broader privileged-access risk.
- Treating provider administrators as employees improperly expands the regulation’s explicitly defined population.
- Clean logs provide historical detective evidence but do not remove the access capability of enabled stale accounts.
- Provider staffing responsibility does not transfer organizational risk accountability or compensate for failed access removal.
Question 92
Topic: Operations and Resilience
An IS auditor evaluates recovery for a payment database that failed at 10:00. The approved recovery point objective (RPO) permits no more than 15 minutes of data loss.
Evidence:
- A full backup completed at 02:00 and passed a restoration test.
- Contiguous transaction logs from 02:00 through 07:30 are available.
- All transaction logs after 07:30 are unavailable.
- A recovery test successfully applied the available logs through 07:30.
Which conclusion is BEST supported?
Options:
A. The database is recoverable through 02:00 only, because the later log chain is incomplete.
B. The database is recoverable through 07:30, but the 15-minute RPO is not supported.
C. The database is recoverable through 09:45, because five-minute log archiving meets the RPO.
D. The database is not recoverable, because missing later logs invalidate the full backup.
Best answer: B
Explanation: Point-in-time database recovery requires a valid backup followed by the necessary contiguous transaction logs. The tested backup provides a 02:00 recovery baseline, and the available logs extend demonstrated recovery through 07:30. Missing logs prevent recovery beyond that point.
For a 10:00 failure and a 15-minute RPO, the database must be recoverable to at least 09:45. Recovery only through 07:30 would lose 150 minutes of transactions, so the recovery capability does not meet the business requirement. The missing later logs limit the recovery point but do not invalidate the backup or the earlier contiguous logs.
- Limiting recovery to 02:00 ignores the contiguous logs and successful test extending the demonstrated recovery point to 07:30.
- Relying on the archival schedule confuses intended log frequency with evidence that the required log files are available.
- Treating the database as wholly unrecoverable ignores the valid backup and logs that support restoration through 07:30.
Question 93
Topic: Operations and Resilience
An IS auditor is reviewing a retailer’s checkout platform. The approved business requirement is continued service after total loss of either data center, with a 15-minute recovery time objective and a 5-minute recovery point objective.
Operational evidence:
- Application and database services operate active-passive across Sites A and B.
- A test stopped those services at Site A; Site B processed transactions within 4 minutes with no data loss.
- Site A’s power, WAN edge, traffic manager and authoritative DNS remained operational.
- The traffic manager and DNS have no instances outside Site A.
Which audit conclusion is best supported?
Options:
A. The architecture establishes data-center fault tolerance, but operating effectiveness remains unproven because only one quarterly test was reviewed.
B. The test confirms data-center fault tolerance because recovery time and observed data loss met the approved objectives.
C. The test confirms server-level failover, but data-center fault tolerance is not established because site-local routing dependencies remained available.
D. The test confirms recovery-time compliance, but recovery-point compliance remains unproven because replication was not tested separately.
Best answer: C
Explanation: Fault tolerance must be assessed against the complete failure scenario in the business requirement. The test removed application and database processes but left Site A’s power, network and routing services operational. Because the traffic manager and authoritative DNS exist only at Site A, complete loss of that site could prevent users from reaching Site B even if its application and database services are healthy.
The 4-minute recovery and zero data loss support server-level failover under the tested conditions. They do not establish the recovery objectives for a full data-center outage. End-to-end site-loss testing, or equivalent validated evidence, is needed to assess that requirement.
- Meeting recovery metrics in a limited test does not extend those results to the untested total-site failure scenario.
- Questioning the number of tests overlooks the more fundamental design gap created by single-site routing dependencies.
- Focusing on replication incorrectly treats the measured recovery time as evidence for a site outage that was not simulated.
Question 94
Topic: Information Asset Protection
An IS auditor reviews a pending service-desk record for a supplier that performs monthly maintenance.
Requester: support@northstar.example
Email authentication: DMARC pass
Request: Reset ns_admin MFA to Leo at +1-202-555-0184.
Mira is unavailable; do not use the old directory number.
Supplier registry: Mira Chen, +1-202-555-0142
Application owner approval: [blank]
Policy: Supplier authentication changes require confirmation
through the registry contact and application owner approval.
Which action should the auditor recommend before the service desk proceeds?
Options:
A. Validate DMARC and prior ticket patterns, then obtain application owner approval.
B. Call Mira at the registry number, then obtain application owner approval.
C. Call Leo at the ticket number, then obtain application owner approval.
D. Reply to the supplier mailbox for confirmation, then obtain application owner approval.
Best answer: B
Explanation: Sensitive changes requested through a trusted supplier channel still require independent identity verification and proper authorization. The request changes an MFA destination and directs staff away from the established contact information, both indicators that the trusted channel may be compromised. A DMARC pass verifies domain alignment, not that the authorized supplier representative initiated the request. Calling the registry contact through previously established information provides out-of-band verification, while application owner approval confirms internal authority to modify privileged access.
Replying through the same mailbox does not cross the trust boundary because an attacker controlling that mailbox could provide the confirmation.
- Calling the newly supplied number relies on contact information that may have been provided by the attacker.
- Replying to the supplier mailbox keeps verification within the potentially compromised communication channel.
- DMARC and familiar ticket patterns support message authenticity assessments but do not verify authority for the MFA change.
Question 95
Topic: Information Asset Protection
An IS auditor reviews IoT temperature sensors used to prevent spoilage at 40 stores.
Management asserts that throughout the year:
- Each connected sensor had an accountable owner.
- Default credentials were changed before network access.
- Critical updates were installed within 30 days.
Current evidence consists of an unreconciled procurement spreadsheet and a year-end scan showing current firmware and no default credentials.
Which additional audit procedure would provide the MOST appropriate evidence of operating effectiveness?
Options:
A. Reconcile inventory and incident records; then inspect support assignments, password-reset tickets, and emergency-update approvals.
B. Reconcile procurement, network-discovery, and retirement records; then inspect ownership history, preconnection credential replacement, and update histories.
C. Reconcile network-discovery and firewall records; then inspect segment ownership, blocked login attempts, and vulnerability-scan results.
D. Reconcile procurement and supplier-support records; then inspect purchase approvals, current credential settings, and latest firmware versions.
Best answer: B
Explanation: Evidence of sustained operating effectiveness must address population completeness, each relevant control, and the entire review period. Reconciling procurement, network-discovery, and retirement records helps identify connected devices that may be missing from management’s spreadsheet. Ownership history establishes accountability over time. Provisioning evidence can demonstrate that default credentials were replaced before connection, while update histories can be compared with vendor release dates and the 30-day requirement.
The year-end scan supports only the devices discovered at that point and cannot establish that credentials and updates were controlled throughout the year.
- Purchase approvals and current configurations do not establish the deployed population or demonstrate timely control operation throughout the year.
- Firewall and vulnerability evidence evaluates network protection but does not directly test device ownership, credential replacement, or update timeliness.
- Incident and support records emphasize reactive activity and may omit devices that experienced no reported incident or emergency update.
Question 96
Topic: Auditing Process
An IS audit manager is finalizing a work program for a January-December review. No additional access or resources can be approved before fieldwork.
Work program excerpt:
OBJECTIVES
O1: Determine whether privileged-access reviews operated quarterly.
O2: Determine whether emergency changes were approved within 2 business days.
AUTHORIZED RESOURCES
Maya: IAM testing; access-review repository access
Leo: Change analytics; change-log query access
DRAFT PROCEDURES
WP-1 Objective: [blank]
Procedure: Inspect the access-review policy and interview the IAM owner.
Resource: Maya, 8 hours
WP-2 Objective: [blank]
Procedure: Query the emergency-change log and test approval timestamps.
Resource: Leo, 16 hours
Which revision BEST makes the work program executable and aligned with the engagement objectives?
Options:
A. Link WP-1 to O1 and test a year-end access reconciliation; link WP-2 to O2 and retain assignments.
B. Link WP-1 to O1 and retain policy inspection and inquiry; link WP-2 to O2 and retain assignments.
C. Link WP-1 to O1 and test review records from each quarter; link WP-2 to O2 and retain assignments.
D. Link WP-1 to O1 and test review records from each quarter; link WP-2 to O2 and swap assignments.
Best answer: C
Explanation: An audit work program should translate each engagement objective into procedures that produce relevant evidence and assign resources with suitable competence and access. O1 concerns operating effectiveness throughout a year, so policy inspection and inquiry address only control design and understanding. Testing completed review records from each quarter provides evidence covering the required frequency and period. Maya has the necessary repository access. WP-2 already addresses O2 through timestamp testing, and Leo has the required analytics capability and query access. Adding objective references improves traceability, but the references alone cannot correct an inadequate procedure.
- Policy and inquiry only does not establish that quarterly reviews operated during the engagement period.
- Year-end reconciliation provides point-in-time evidence rather than evidence of quarterly performance.
- Swapped assignments conflicts with the stated system access and resource capabilities.
Question 97
Topic: Information Asset Protection
An IS auditor is assessing whether security awareness controls cover nonemployee users. Which conclusion is best supported by the exhibit?
Security awareness standard (excerpt)
Baseline: Every workforce member with an organization account, annually.
Privileged module: Any person administering production systems, before access and annually.
Reporting guidance: Every account holder receives internal incident-reporting instructions before access.
Completion record
| Group | Duties | Recorded coverage |
|---|---|---|
| Employee administrators | Production administration | All requirements completed |
| Contractor administrators | Production administration | Vendor baseline current; privileged module not completed; reporting guidance not issued |
| Contractor analysts | Read-only access | Baseline current; reporting guidance issued |
Options:
A. The program is operating effectively because current vendor baseline training covers contractor administrators.
B. The program has a design deficiency because it lacks a separate nonemployee administrator curriculum.
C. The program is appropriately scoped but not operating effectively for privileged contractor administrators.
D. The program has a contract-management deficiency rather than an awareness-control deficiency for contractor administrators.
Best answer: C
Explanation: Awareness coverage should follow access and responsibility rather than employment status. The standard uses “any person” and “every account holder,” so contractor administrators are within scope for privileged-role training and internal reporting guidance. Although they completed general vendor training, the record shows that both access-triggered requirements were omitted. The standard is therefore appropriately designed around risk, but it is not operating effectively for this high-risk group.
A separate contractor curriculum is unnecessary if the existing role-based requirements are applied consistently. Vendor involvement also does not transfer the organization’s accountability for ensuring required awareness coverage.
- Vendor baseline coverage does not satisfy the distinct privileged-role and organization-specific reporting requirements.
- Separate contractor curriculum is unnecessary because the existing standard already applies according to access and duties.
- Contract-management classification does not eliminate the awareness-control failure or transfer organizational accountability to the vendor.
Question 98
Topic: Information Asset Protection
A ransomware incident exploited a known critical vulnerability that had remained unpatched on an internet-facing gateway for 11 days. The post-incident review identified monthly scanning as the root cause.
Management implemented daily scanning and a 48-hour remediation target three months ago. The success criterion requires every critical finding on all 12 gateways to meet the target for three consecutive months.
Which evidence provides the IS auditor with the strongest basis for concluding that the corrective action is operating effectively?
Options:
A. Incident and security-alert records for all 12 gateways across three months, confirming no successful gateway exploitation recurred after corrective action deployment.
B. Independent month-end scan reports for all 12 gateways across three months, confirming no critical findings remained open on each reporting date.
C. Reconciled daily scan results and patch timestamps for all 12 gateways across three months, confirming every critical finding met the 48-hour target.
D. Approved post-incident review and implementation records for all 12 gateways, confirming the daily scanning and 48-hour remediation workflow was formally deployed.
Best answer: C
Explanation: Sustained operating effectiveness requires evidence that the corrective control functioned throughout the review period and achieved its defined criterion across the complete scope. Reconciling daily scan results and patch timestamps for all 12 gateways establishes both coverage and timely remediation for every critical finding during the three months.
Implementation documents establish design and deployment, but not continued operation. Month-end scans show conditions only on reporting dates and may miss violations of the 48-hour target. An absence of recurring incidents may simply reflect a lack of exploitation attempts rather than effective control operation. Period-wide evidence tied directly to the root cause provides the strongest support for sustained risk reduction.
- Month-end scans cannot demonstrate that each critical finding was remediated within 48 hours between reporting dates.
- Review and implementation records establish deployment but do not prove sustained operation over three months.
- No recurring exploitation is outcome evidence, but it does not establish that the corrective control consistently operated.
Question 99
Topic: Operations and Resilience
An IS auditor reviews evidence from a claims-system restoration test. Which conclusion is BEST supported by the record?
Restoration test record:
Objective: Restore the claims database to the 02:00 cutoff;
demonstrate complete committed data and usable claim processing.
Baseline: Production row count, reserve total, and digest of
ordered claim IDs and versions captured at 02:00 and retained read-only.
Restored data: All three baseline values matched exactly.
Integrity check: No database errors.
Business validation: Supervisor opened claims, recalculated a reserve,
saved a test status change, and generated the exception report.
Results: Expected results achieved; no unresolved exceptions.
Environment: Isolated recovery network.
Options:
A. Usability is supported, but completeness remains unverified because only aggregate totals were reconciled.
B. Completeness is supported, but usability remains unverified because validation was not in production.
C. Technical restoration is supported, but both business assertions require another full restoration test.
D. Both completeness and usability are supported for the stated database recovery objective.
Best answer: D
Explanation: Restoration evidence should address data completeness separately from business usability. Completeness is supported by reconciling the restored database to a read-only production baseline captured at the required cutoff. The matching row count, reserve total, and digest of ordered claim IDs and versions provide complementary evidence that committed records were restored. Usability is supported by the supervisor successfully performing representative claim-processing activities and generating the expected report.
A restoration test does not need to occur in production to provide useful evidence. An isolated recovery environment reduces operational risk while allowing realistic validation. The conclusion remains limited to the stated database objective and does not establish recovery of systems or dependencies outside that scope.
- Requiring production validation overlooks that representative workflows can demonstrate usability safely in an isolated recovery environment.
- Describing the reconciliation as aggregate-only ignores the matching claim ID and version digest.
- Requiring another full test disregards the existing reconciliation and successful business validation, which address both stated assertions.
Question 100
Topic: Information Asset Protection
An IS auditor is evaluating whether data-loss prevention (DLP) exceptions conform to authorized business use. The following records relate to one outbound transfer.
Control records:
DLP standard: Exceptions must match all approved destination,
channel, and data parameters; unmatched transfers must be blocked.
Authorization BA-204 (active):
Purpose: Quarterly customer reconciliation
Destination: files.vendor.example
Channel: Managed SFTP
Data: customer_id, email
DLP event E-778:
Destination: uploads.vendor.example
Channel: HTTPS browser upload
Data: customer_id, email
Outcome: Allowed by DEST-VENDOR-ALL; alert created
Exception DEST-VENDOR-ALL:
Scope: *.vendor.example; HTTPS uploads and SFTP
Approval reference: BA-204
Which audit response best follows from this evidence?
Options:
A. Document a content-detection failure and retest identifier matching across HTTPS and SFTP transfers.
B. Document an overbroad exception and assess other transfers allowed under its expanded scope.
C. Treat BA-204 as incomplete and determine whether approval covered all vendor subdomains and channels.
D. Accept the transfer as authorized and verify that approved vendor activity continues generating alerts.
Best answer: B
Explanation: DLP authorization depends on every parameter required by the control standard, not merely the recipient organization or data fields. BA-204 permits the specified data to reach one host through managed SFTP. The event instead used another host and an HTTPS browser upload. The wildcard exception exceeded both authorized dimensions and caused an unapproved transfer to be allowed.
The alert shows that content detection occurred, but detection alone does not establish effective prevention. The auditor should identify the exception-scope deficiency and examine other events allowed by the same exception to determine its impact. A configuration reference to an approval does not expand the approval’s documented scope.
- Matching the vendor organization and data fields is insufficient because the approved destination and channel must also match.
- Content detection succeeded by identifying the data and creating an alert; the failure concerned the allow exception.
- The active authorization cannot be presumed incomplete merely because the implemented exception has broader coverage.
Questions 101-125
Question 101
Topic: IT Governance and Management
An IS auditor reviews Q3 portfolio governance after a resource reallocation has begun. The change record is the designated approval evidence.
Exhibit: Policy and change record
Policy: IT Steering Committee approval must be recorded before
any reallocation that changes a board-approved milestone.
The record must state hours displaced, milestone impact, and business impact.
Usable Q3 delivery capacity: 6,000 hours
Core operations: 2,000 hours; cannot defer
Customer platform: 4,000 hours; board milestone September 30
Privacy remediation: 1,500 hours; mandatory deadline September 30
Decision: Move 1,500 hours from customer platform to privacy remediation.
Impact: Platform milestone moves to November 15;
expected benefit realization is delayed.
Decision entered by: Applications director
Steering Committee approval:
Which audit assessment is most appropriate?
Options:
A. Report an authorization exception because the documented trade-off changed a board-approved milestone without steering committee approval.
B. Report an impact-analysis exception because the delayed platform benefit was not assigned a monetary value.
C. Report no exception because a mandatory deadline authorizes the delivery director to change strategic milestones.
D. Report a capacity-management exception because mandatory work should use added resources rather than hours from strategic projects.
Best answer: A
Explanation: Mandatory work can justifiably displace strategic work when capacity is limited and a fixed deadline applies. The record transparently identifies the 1,500-hour shortfall, the displaced project, the revised milestone and the business impact. However, a sound rationale does not replace accountable authorization. The policy assigns approval of changes to board-approved milestones to the IT Steering Committee, while the designated approval field is blank after work has begun. This supports an authorization control exception, not a conclusion that the resource priority itself was necessarily inappropriate.
- Monetary valuation is not required because the policy asks for business impact, which the delayed benefit statement documents.
- Additional resources are a possible management response, but the evidence does not require them instead of portfolio reprioritization.
- Director authority does not expand merely because work is mandatory; the policy retains milestone-change authority with the steering committee.
Question 102
Topic: Auditing Process
An IS auditor is assessing whether an ERP duplicate-payment control operated effectively throughout the fiscal year. The audit team uses a newly developed script to identify potential control failures.
Evidence:
- The extract contains 240,000 payments totaling $418.2 million.
- An ERP control report for the same scope shows 252,500 payments totaling $423.7 million.
- Two script reruns produce the same 186 candidates.
- The development workpaper contains no tests using cases with known outcomes.
Before relying on the results, which action would provide the strongest support for the automated analysis?
Options:
A. Resolve the count variance with process owners, then inspect sampled candidates against source invoices.
B. Confirm every flagged candidate against payment records, then quantify the resulting duplicate-payment exposure.
C. Reconcile extract counts and values to ERP totals, then test the script with known-result cases.
D. Rerun the extraction and version-controlled script, then compare dataset hashes and candidate counts.
Best answer: C
Explanation: Reproducibility means that the same inputs and code produce consistent results; it does not establish validity. The matching rerun results demonstrate consistency, but the ERP control totals reveal an unresolved population gap. In addition, no known-outcome cases have been used to verify that the script correctly distinguishes duplicate from nonduplicate payments. The auditor should reconcile record counts and monetary totals to establish extraction completeness, then validate the detection logic against cases with expected results. Testing an entire extract reduces sampling risk only for the records actually extracted; it does not correct missing records or flawed matching logic.
- Resolving the variance and sampling flagged cases may confirm some positive classifications but does not test whether the script misses duplicates.
- Confirming all flagged payments measures detected exceptions but leaves population completeness and unflagged transactions untested.
- Matching hashes and candidate counts supports repeatability, not the completeness of the source data or correctness of the detection logic.
Question 103
Topic: Operations and Resilience
An IS auditor reviews the following recovery record. All entries are for the same day.
Recovery requirement
Maximum permitted data loss for the billing database: 30 minutes.
Operations record
08:00 Full backup completed; restore test passed.
12:00 Differential backup completed; checksum validation failed.
08:15-14:00 Log archives completed every 15 minutes;
sequence continuous from the full backup.
14:15 Log archive failed; no usable file created.
14:20 Storage failure stopped database processing.
The recovery procedure permits continuous log archives to be applied to the last usable full backup. What conclusion should the auditor reach?
Options:
A. The requirement was met; the recoverable point is 14:15, limiting loss to 5 minutes.
B. The requirement was not met; the recoverable point is 13:45, resulting in 35 minutes of loss.
C. The requirement was not met; the recoverable point is 08:00, resulting in 6 hours 20 minutes of loss.
D. The requirement was met; the recoverable point is 14:00, limiting loss to 20 minutes.
Best answer: D
Explanation: The data-loss requirement is evaluated by comparing the failure time with the latest point supported by usable recovery evidence. The 08:00 full backup passed its restore test, and the continuous log sequence extends recovery through 14:00. The failed differential backup does not break that log sequence, while the failed 14:15 archive cannot support recovery. Therefore, the potential loss is 20 minutes, from 14:00 to the 14:20 failure, which is within the permitted 30-minute window.
Backup completion times alone are insufficient; recoverability depends on the usable backup and all required logs.
- Using 13:45 disregards the successfully completed 14:00 log archive.
- Using 14:15 incorrectly treats a failed archive with no usable file as recoverable evidence.
- Using 08:00 ignores the continuous logs that can be applied to the usable full backup.
Question 104
Topic: Auditing Process
During follow-up, an IS auditor confirms that no remediation has occurred and reviews this record.
Risk governance record
Finding: F-27, privileged-access reviews not performed
Residual risk: High
Workflow status: Closed - risk accepted
Finding owner: Chief Information Officer (CIO)
CIO entry: "I acknowledge F-27 and accept the residual risk."
Acceptance approval ID: [blank]
Policy:
- Business Risk Committee approves High risk acceptance.
- Finding owners acknowledge findings and propose treatment.
- High risks lacking valid acceptance remain open and are
referred to the Business Risk Committee.
Which action should the IS auditor take?
Options:
A. Reopen F-27 and refer it to the Business Risk Committee.
B. Reopen F-27 and obtain a revised risk acceptance from the CIO.
C. Retain F-27’s closure and separately report the missing approval identifier.
D. Reopen F-27 and refer it to the audit committee for acceptance.
Best answer: A
Explanation: Risk acknowledgment and risk acceptance are distinct governance actions. The CIO’s entry demonstrates awareness of the finding, but the policy assigns authority to accept High residual risk to the Business Risk Committee. The blank approval identifier provides no evidence that this committee approved acceptance. Because remediation has not occurred and valid acceptance is absent, the closed status is unsupported.
The auditor should keep the finding active and follow the stated escalation path. The Business Risk Committee, not the auditor or finding owner, must decide whether management will accept or treat the residual risk. Stronger wording or another CIO signature would not correct the authority deficiency.
- Retaining closure incorrectly treats the CIO’s statement as sufficient despite the missing approval from the designated authority.
- Obtaining revised CIO acceptance changes the documentation but does not give the CIO the required authority.
- Referring acceptance to the audit committee bypasses the management body explicitly assigned the risk decision.
Question 105
Topic: Auditing Process
An IS auditor is assessing an automated daily reconciliation used to confirm the completeness and accuracy of sales postings from the order system to the general ledger.
Six-month control evidence:
- Every report was signed by the accounting supervisor, and no differences were reported.
- The supervisor sees only matched and unmatched totals, not the matching or exclusion rules.
- Finance application administrators can change those rules without approval or audit logging.
- The current rules match the approved baseline.
Which audit response BEST addresses whether reliance on the reconciliation is justified?
Options:
A. Reperform selected days and rely if the current results agree.
B. Test report sign-offs and rely if the reviews were timely.
C. Evaluate rule stability and reduce reliance if period-wide support is unavailable.
D. Compare current rules to the baseline and rely if they match.
Best answer: C
Explanation: Reliance on an automated application control depends on the integrity of its underlying configuration and the controls over changes. Daily signatures confirm that reports were reviewed, but summary totals do not enable the supervisor to validate the matching and exclusion rules. Because administrators can change those rules without approval or logging, clean reports could have been produced using altered logic. Matching the current baseline or reperforming current rules provides point-in-time evidence, not evidence of stability throughout six months. The auditor should seek reliable period-wide evidence and reduce planned reliance if rule stability cannot be established. Consistently signed output does not establish sustained operating effectiveness when an unmonitored configuration determines the result.
- Timely signatures establish performance of the supervisory review, not the integrity of rules hidden from the reviewer.
- Reperformance using current rules provides point-in-time evidence and cannot demonstrate six-month configuration stability.
- A current baseline comparison cannot detect temporary rule changes that were reversed before the audit.
Question 106
Topic: Operations and Resilience
An IS auditor reviews the approved resilience record for an active-active service. Each member has identical capacity.
Document excerpt: Quarterly resilience record
| Entry | Recorded value |
|---|---|
| Normal demand | 4,800 tx/min |
| Forecast peak | 9,200 tx/min |
| Sustainable capacity | 6,400 tx/min per member, load-tested |
| Resilience requirement | No rejections at forecast peak after one-member failure; failover <=30 seconds |
| Latest failover test | 18 seconds at 5,600 tx/min; no rejections |
Which audit conclusion is BEST supported?
Options:
A. The resilience control is adequate because combined pair capacity exceeds the required peak.
B. The resilience control is effective because failover completes within the stated recovery target.
C. The resilience control is inadequately designed because one member cannot sustain the required peak.
D. The resilience control remains unassessable until a failure occurs during an actual peak period.
Best answer: C
Explanation: Redundancy provides service-level resilience only when the surviving resources can handle the workload specified by the resilience requirement. Although failover completed within 30 seconds at 5,600 tx/min, each member can sustain only 6,400 tx/min. A member failure during the 9,200 tx/min forecast peak would therefore create a 2,800 tx/min capacity shortfall and violate the no-rejection requirement.
The pair’s combined capacity is irrelevant to the stated single-member-failure condition. An actual peak incident is also unnecessary to identify this design deficiency because the approved forecast and load-tested capacity already demonstrate the gap.
- Meeting the failover-time target verifies switchover performance only, not sufficient surviving capacity at peak demand.
- Combined capacity applies while both members operate and does not establish capacity after one member fails.
- Waiting for an actual peak failure is unnecessary because existing test evidence already shows the required workload exceeds surviving capacity.
Question 107
Topic: Operations and Resilience
An IS auditor reviews the following service management document. Which conclusion is BEST supported by the evidence?
Document excerpt:
Incident closure: Close after service restoration and business confirmation. Recurrence: On the second occurrence of the same error within 30 days, create and link a problem record. Correction: Implement a permanent correction through the approved change process. Restart: An approved recovery action, not a change.
| Record | Date | Recovery evidence | Status / problem ID |
|---|---|---|---|
| INC-441 | April 3 | X17; restart; confirmed | Closed / blank |
| INC-468 | April 9 | X17; restart; confirmed | Closed / blank |
| INC-502 | April 16 | X17; restart; confirmed | Closed / blank |
Options:
A. Conclude the incident closures were valid, but required problem linkage for investigation and controlled correction was absent.
B. Conclude the incident closures were valid because problem creation begins only after root cause confirmation.
C. Conclude the incident closures were premature because all related records must remain open through permanent correction.
D. Conclude the incident closures were invalid because each restart required an emergency change approval.
Best answer: A
Explanation: Incident and problem records have different completion criteria. Each incident contains the evidence required for closure: the restart restored service and the business confirmed recovery. Closure does not assert that the underlying defect was removed. However, the second X17 occurrence within 30 days triggered the separate requirement to create and link a problem record. The blank problem fields mean the required investigation trail and route to a controlled permanent correction are not evidenced. The approved restart is a recovery action; a later permanent correction would be subject to change management. Keeping incidents open would distort restoration tracking rather than address the missing problem-management control.
- Keeping incidents open conflates service restoration with the separate problem investigation and correction lifecycle.
- Waiting for diagnosis ignores that recurrence itself triggers the problem record used to investigate root cause.
- Classifying each restart as a change conflicts with the document’s explicit treatment of it as an approved recovery action.
Question 108
Topic: IT Governance and Management
An IS auditor is evaluating succession and recovery capability for a legacy payment service that must be restored within 8 hours. The runbook and architecture documents are current. During the latest exercise, the designated substitute could not resolve startup errors; the sole specialist intervened and completed recovery in 7 hours. The specialist plans to retire in 6 months.
Which evidence would provide the strongest support that key-person dependency has been reduced?
Options:
A. A specialist-led restore observed by the substitute with deviations documented
B. A substitute-led tabletop walkthrough covering each documented recovery scenario
C. A representative restore independently completed by the substitute within 8 hours
D. A provider contract requiring 8-hour restoration and naming qualified support staff
Best answer: C
Explanation: Key-person risk remains when successful recovery depends on tacit knowledge held by one specialist. Current documentation supports control design, but the substitute’s failed attempt shows that the recovery capability has not been transferred effectively. The specialist’s 7-hour recovery demonstrates recoverability only while that individual remains available. Stronger evidence is a representative exercise in which the substitute performs the restoration independently and meets the 8-hour recovery objective.
Walkthroughs, observation, and contractual commitments can support succession planning, but they do not demonstrate that another resource can execute the recovery successfully.
- A tabletop walkthrough tests understanding but not the substitute’s ability to perform an actual restoration.
- A provider contract states an obligation but does not demonstrate that provider staff can restore this system within the objective.
- Observing a specialist-led restore improves knowledge transfer but leaves successful execution dependent on the specialist.
Question 109
Topic: IT Governance and Management
An IS auditor is evaluating supplier diversification for continuity of a critical payment service.
- Risk tolerance: No single service operator may process more than 40% of peak transactions.
- Control state: Procurement measures concentration by contracted legal entity.
- Evidence: The resellers provide billing and first-line support, but cannot switch operators during an outage.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The critical payment service contracts 25%, 20%, and 15% of peak transaction volume through three separate resellers, and each reseller runs its transactions on Operator X.
Which recommendation BEST addresses the identified control weakness?
Options:
A. Map ultimate operators, aggregate Operator X at 60%, and evaluate resilience treatment against the 40% tolerance.
B. Review Operator X controls in each reseller file, retain separate shares, and compare each reseller with the 40% tolerance.
C. Group resellers by corporate ownership, aggregate each group’s shares, and compare each group with the 40% tolerance.
D. Model reseller outages independently, use 25% as the maximum disruption, and assess recovery plans for that scenario.
Best answer: A
Explanation: Supplier concentration should be measured at the point of common operational dependency, not solely by contractual counterparty. The three resellers are commercial intermediaries, while Operator X processes their combined transaction volume. Because none can switch operators during an outage, a failure at Operator X could simultaneously affect 25% + 20% + 15% = 60% of peak transactions. This exceeds the approved 40% tolerance, so the current control is not designed to detect the relevant concentration. The auditor should recommend dependency mapping and aggregated exposure reporting; management remains responsible for selecting a response such as diversification, failover capability, or formally governed risk acceptance. Reviewing provider controls is useful but does not resolve the hidden concentration.
- Reviewing provider controls may assess Operator X’s control environment, but retaining separate shares leaves the combined exposure undetected.
- Grouping by corporate ownership overlooks correlated dependencies across legally unrelated resellers using the same operator.
- Modeling independent reseller failures understates the disruption because an Operator X outage could affect all three shares simultaneously.
Question 110
Topic: Information Asset Protection
An IS auditor is evaluating emergency privileged access used to restore a critical payment service.
Approved procedure:
- The incident commander may authorize named responders before access begins.
- Security management reviews the activation within 24 hours.
- Each responder receives a separate temporary vault checkout.
- Access ends at incident closure or after two hours, whichever occurs first.
Evidence:
- Both responders were authorized at 02:04; work began at 02:07.
- Only the lead checked out the generic emergency credential. Both responders used the same privileged terminal.
- Logs associate every command with the generic account and lead’s checkout, not the individual entering it.
- Security management reviewed access at 09:10. Access ended with incident closure at 03:01.
Which conclusion is BEST supported?
Options:
A. Conclude privileged-access approval operated ineffectively because security management reviewed activation after restoration work began.
B. Conclude the controls operated effectively because ticket, vault, recording, and review evidence document the emergency event.
C. Conclude emergency authorization operated ineffectively because only the lead responder checked out the temporary credential.
D. Conclude privileged-session accountability operated ineffectively because shared checkout prevents attribution to each authorized responder.
Best answer: D
Explanation: Emergency approval, access duration, and session accountability are distinct control assertions. The incident commander authorized both named responders before work, security management completed its permitted retrospective review within 24 hours, and access ended when the incident closed. However, the responders shared one vault checkout and privileged terminal. Because the logs identify only the generic account and lead’s checkout, they cannot establish which person performed each command. This is an operating-effectiveness failure in session accountability even though the approval and expiration requirements were satisfied.
- The later security review complied with the approved 24-hour retrospective-review procedure.
- A vault checkout is not the authorization decision; the incident commander had already authorized both named responders.
- The collected records do not form a complete accountability trail because individual commands cannot be linked to their actors.
Question 111
Topic: Operations and Resilience
An IS auditor is validating April service availability. April has 43,200 minutes.
SLA excerpt:
Monthly availability = (eligible minutes - unavailable eligible minutes) / eligible minutes. Eligible minutes exclude only approved maintenance windows with at least 72 hours’ customer notice. Time beyond an approved window remains eligible. Round to three decimals.
Availability record:
| Event | Approved window | Notice | Unavailable |
|---|---|---|---|
| Planned maintenance | 120 min | 96 hr | 120 min |
| Service outage | None | None | 45 min |
| Emergency patch | None | 2 hr | 30 min |
| Planned maintenance | 60 min | 96 hr | 90 min |
Which monthly availability should the auditor report?
Options:
A. Report monthly availability as 99.757%.
B. Report monthly availability as 99.756%.
C. Report monthly availability as 99.895%.
D. Report monthly availability as 99.340%.
Best answer: B
Explanation: The SLA excludes only the two approved maintenance windows that met the 72-hour notice requirement. The emergency patch and the 30-minute overrun remain within the measured service period. Thus, eligible time is 43,020 minutes and eligible unavailability is 105 minutes.
\[ \begin{aligned} E &= 43{,}200-(120+60)=43{,}020 \\ D &= 45+30+(90-60)=105 \\ A &= \frac{E-D}{E}\times 100\% \\ &= 99.7559\% \approx 99.756\% \end{aligned} \]An exclusion must be applied consistently to both the measurement window and its associated downtime.
- Full-month denominator produces 99.757% by removing qualifying maintenance from downtime but not from eligible minutes.
- Excessive exclusions produce 99.895% by treating the emergency patch and maintenance overrun as excluded time.
- No exclusions produces 99.340% by counting approved maintenance windows as both eligible time and unavailable time.
Question 112
Topic: IT Governance and Management
An IS auditor is reviewing a quarterly IT dashboard that the board uses to prioritize remediation funding. Source reconciliation controls operated effectively, and the reported values agree with underlying records.
Audit evidence:
- Critical incidents, cumulative year to date: Q1 6; Q2 11; Q3 15.
- Service availability, measured separately each quarter: Q1 99.6%; Q2 99.4%; Q3 99.7%.
- Open high-risk issues, measured at each quarter-end: Q1 12; Q2 9; Q3 7.
The dashboard labels every series as quarterly performance. Management concludes that critical incident performance worsened each quarter because the reported total increased. What should the auditor recommend before the board relies on this conclusion?
Options:
A. Investigate operational causes of adverse movements and annotate conclusions with supporting evidence.
B. Recast incidents as quarterly increments and disclose each measure’s reporting basis.
C. Reperform source calculations and document the resulting movement for each measure.
D. Convert each series to percentage changes and rank measures by relative movement.
Best answer: B
Explanation: Trend analysis requires comparable reporting periods and measurement bases. The cumulative incident totals must be converted to quarterly increments: Q1 has 6 incidents, Q2 has 5, and Q3 has 4. Availability already represents separate quarterly intervals, while open issues are snapshots of outstanding items at specific dates. Although the source values are accurate, presenting these different measurement bases under one quarterly label can produce unsupported conclusions.
Percentage conversion or additional source verification cannot correct a mismatch between cumulative, interval, and point-in-time measures.
- Reperforming accurate source calculations addresses reliability, not whether the reporting periods are comparable.
- Investigating operational causes is premature because the reported incident movement has not been normalized.
- Percentage changes standardize scale but do not correct differences among cumulative, interval, and snapshot measures.
Question 113
Topic: Information Asset Protection
An IS auditor reviews the control record for customer data classified as Restricted.
Approved standard:
Restricted classification metadata must remain attached to every copy. Preventive and detective safeguards must operate through disposal after seven years.
| Lifecycle stage | Recorded controls |
|---|---|
| Storage | Cloud database encrypted; KMS uses a separate administrator role |
| Use and export | Weekly CSV export removes metadata; workspace permits local downloads |
| Endpoint | DLP controls transfers only when the Restricted label is present |
| Archive | Immutable encrypted backups; daily reconciliation; quarterly restore tests |
| Disposal | Database, workspace, and tagged backups expire after seven years |
Which control gap is BEST supported by this evidence?
Options:
A. The backup process creates unverified recovery points between quarterly restoration tests.
B. The disposal process creates retained archive copies after operational purging is completed.
C. The export process creates unlabeled downloads to which endpoint DLP will not apply.
D. The key process creates provider access to data despite the separate KMS role.
Best answer: C
Explanation: Layered controls must remain effective as information moves through its lifecycle. Here, endpoint DLP depends on the Restricted label, but the export process removes metadata before files can be downloaded. Consequently, the exported customer data loses the attribute that activates its endpoint protection. Encryption of the database and backups does not protect downloaded plaintext copies from unauthorized transfer.
Using the same cloud provider for data and key management is not inherently deficient when administrative roles are separated. Daily backup reconciliation and quarterly restoration provide distinct evidence of backup operation and recoverability. The disposal record also covers database, workspace, and tagged backup copies at the required retention point.
The critical weakness is the broken dependency between classification metadata and DLP enforcement.
- Provider key management is not inherently a control failure because the record documents role separation for key administration.
- Quarterly restore testing provides periodic recoverability evidence. The stated standard does not require every recovery point to be individually restored; the directly evidenced gap is lost classification metadata.
- Archive retention aligns with the seven-year requirement because tagged backups expire with the other recorded copies.
Question 114
Topic: Operations and Resilience
An IS auditor is reviewing a proposed nightly production schedule. Which conclusion should the auditor report based on the scheduling record?
Production scheduling record (proposed)
Write-freeze window: 02:00-03:00
FIN_POST completion deadline: 02:00
Job Start rule Maximum duration
ORDER_CLOSE Fixed start at 22:00 30 minutes
SALES_AGG After ORDER_CLOSE succeeds 40 minutes
FX_LOAD File arrival between 23:00-01:30 15 minutes
FIN_POST After SALES_AGG and FX_LOAD 50 minutes
Pilot note: Average FX file arrival was 23:20.
Options:
A. Readiness is not demonstrated because event-driven posting lacks a fixed scheduled start.
B. Readiness is demonstrated because the average FX arrival supports completion before the freeze.
C. Readiness is not demonstrated because the latest permitted FX arrival causes a freeze overlap.
D. Readiness is demonstrated because predecessor controls prevent posting until both inputs complete.
Best answer: C
Explanation: Production readiness requires the complete dependency chain to meet its processing window under permitted operating conditions, not merely during an average run. ORDER_CLOSE and SALES_AGG can finish by 23:10. However, the FX file may arrive as late as 01:30, making FX_LOAD complete at 01:45. FIN_POST then requires up to 50 minutes, so it may run until 02:35. This violates the 02:00 deadline and overlaps the write-freeze window. The dependency controls enforce correct sequencing, but they do not ensure timely completion. Therefore, the schedule does not provide sufficient evidence of production readiness.
- Predecessor controls protect processing order but do not ensure completion within the required window.
- Average arrival time does not address the latest arrival permitted by the operating record.
- Event-driven scheduling is appropriate for dependencies; the problem is insufficient time after the latest file arrival.
Question 115
Topic: Operations and Resilience
An IS auditor reviews this disaster recovery runbook excerpt. Which startup sequence should the auditor recommend?
Restore and validate each prerequisite before starting a dependent component. When multiple components are eligible, restore the one with the shortest recovery time objective (RTO) first.
| Component | RTO | Prerequisite |
|---|---|---|
| Network core | 1 hour | None |
| DNS | 2 hours | Network core |
| Identity service | 3 hours | DNS |
| Order database | 4 hours | Identity service |
| Ordering application | 5 hours | Order database |
| Payroll application | 8 hours | Identity service |
Options:
A. Network core, DNS, identity service, order database, payroll application, ordering application
B. Network core, DNS, order database, identity service, ordering application, payroll application
C. Network core, DNS, identity service, payroll application, order database, ordering application
D. Network core, DNS, identity service, order database, ordering application, payroll application
Best answer: D
Explanation: Recovery sequencing must first follow technical dependencies. The network core enables DNS, DNS enables the identity service, and identity enables both the order database and payroll application. At that point, the order database has the shorter RTO and must be restored first. Restoring it makes the ordering application eligible; its RTO is then shorter than payroll’s, so it comes next.
RTO priority applies only among components whose prerequisites are already available. It cannot justify starting a business workload before a required shared service.
- Starting payroll before ordering ignores the shorter RTO of the ordering application once its database is available.
- Starting payroll before the order database ignores the runbook’s RTO rule among components enabled by identity.
- Starting the order database before identity violates its explicit prerequisite.
Question 116
Topic: IT Governance and Management
An IS auditor is reviewing the design and implementation of privileged-access authorization, which is intended to prevent users from granting themselves elevated access.
Current control state:
- The approved security policy requires the requester and authorizer to be different individuals.
- The operating procedure allows the requester to act as delegated approver when the resource owner is unavailable.
- The workflow permits this delegation.
- In eight sampled delegated requests, requesters self-approved and followed the procedure exactly.
- No policy exception or compensating control has been approved.
Which primary assessment should the auditor make?
Options:
A. Conclude a design deficiency because the procedure permits self-approval contrary to policy.
B. Conclude an operating effectiveness deficiency because sampled requesters used delegated approval.
C. Conclude evidence is insufficient until a larger sample quantifies delegated self-approval frequency.
D. Conclude effective implementation because sampled requests consistently followed the documented procedure.
Best answer: A
Explanation: Control design assesses whether policies, procedures, and supporting workflows collectively address the intended risk. Here, the policy requires independent authorization, but both the procedure and workflow permit requesters to approve their own access. The procedure therefore defeats the policy’s control intent.
Consistent execution of a flawed procedure does not demonstrate policy compliance. The samples instead confirm that the design conflict has been implemented as documented. Additional sampling may help determine the extent of exposure, but it is unnecessary to establish the existing design deficiency.
- Operating effectiveness is not the primary issue because personnel followed the procedure as designed; the procedure itself conflicts with policy.
- Effective implementation cannot be concluded because procedural compliance does not satisfy the independent authorization requirement.
- More sampling may quantify exposure, but the documented self-approval mechanism already establishes the design conflict.
Question 117
Topic: Information Asset Protection
An IS auditor is reviewing a collaboration service introduced for external project work. The enterprise data-handling policy still applies to restricted data at every destination.
Evidence:
- Existing DLP monitors email, proxied web traffic, and connected cloud repositories.
- Service traffic bypasses the web proxy, and no cloud DLP connector is enabled.
- Endpoint DLP does not inspect browser uploads.
- A targeted search found restricted files in the service, but no related DLP events.
Which conclusion is best supported?
Options:
A. Conclude that enterprise classification rules extend current DLP coverage to collaboration-service content.
B. Conclude that endpoint DLP provides equivalent coverage for uploads to the collaboration service.
C. Conclude that DLP deployment has a coverage gap for collaboration-service content.
D. Conclude that service access logs compensate for absent DLP monitoring of collaboration-service content.
Best answer: C
Explanation: DLP assurance distinguishes policy scope from technical deployment coverage. The unchanged policy establishes how restricted data should be handled, but it does not automatically inspect every new destination. Here, the collaboration service bypasses the web proxy, lacks a cloud DLP connector, and is outside the endpoint agent’s browser-upload scope. The discovery of restricted files with no corresponding DLP events corroborates a deployment coverage gap.
Access logs may identify users and transfers, but they do not provide content discovery or policy enforcement. The key issue is not whether the policy applies; it is whether controls are deployed along the actual data path.
- Classification rules define required handling but do not create monitoring coverage in an unconnected service.
- Endpoint monitoring cannot cover these transfers because browser uploads are explicitly outside its configured scope.
- Access logs record activity but do not inspect content or enforce sensitive-data handling rules.
Question 118
Topic: Auditing Process
An IS auditor is evaluating whether accounts payable can rely on an automated three-way match to prevent overpayments throughout the fiscal year. The application currently blocks invoices when purchase order, receipt, and invoice amounts differ by more than 2%.
Evidence:
- The process owner demonstrated the current configuration.
- An annual system-generated exception report was provided.
- Two developers can modify matching rules and deploy them to production.
- Three deployments affecting matching lacked independent approval.
- The system retains current configuration values but no historical values.
Which assessment is BEST supported?
Options:
A. Treat the three unapproved deployments as application-control exceptions and project their rate across the invoice population.
B. Restrict additional testing to deployment dates because the control exposure existed only while matching logic was being changed.
C. Withhold reliance until the GITC impact is assessed and year-long operation is supported by alternative evidence.
D. Rely on the control because the current configuration and annual exception report demonstrate consistent operation throughout the year.
Best answer: C
Explanation: Automated three-way matching is an application control, while production access and deployment approval are general IT controls supporting its continued integrity. The current demonstration establishes only the present configuration, not operating effectiveness throughout the fiscal year. Developers could alter the matching logic, unapproved deployments occurred, and historical configuration values are unavailable. Consequently, the auditor cannot establish that the 2% threshold operated consistently for the full period from the evidence provided. Alternative evidence or additional testing is needed before relying on the automated control. The GITC deficiencies weaken reliance but do not, by themselves, prove that every invoice was processed incorrectly.
- Current configuration and an annual report do not establish that matching rules remained unchanged throughout the year.
- Projecting deployment exceptions across invoices incorrectly combines a GITC change population with an application transaction population.
- Testing only deployment dates ignores that modified matching logic could continue operating after each deployment.
Question 119
Topic: Auditing Process
An IS auditor is testing the operating effectiveness of a pre-release refund approval control for annual financial-control assurance.
- The annual extract reconciles to 90,000 refunds but does not identify processing route.
- During the final three weeks, 9,000 refunds used a new batch service; management says the control was unchanged.
- A random sample of 30 refunds contains no transactions from those three weeks.
- A preliminary whole-population analytic flags eight potential exceptions, all during those weeks.
What is the auditor’s BEST response before concluding?
Options:
A. Validate the flagged exceptions, combine them with the original sample, and retain the annual conclusion.
B. Report a period-wide control failure from the exception cluster and withdraw reliance for the entire year.
C. Enlarge the simple random sample and project one exception rate across the annual population.
D. Obtain route-level totals, stratify at the change date, and test a sufficient post-change sample.
Best answer: D
Explanation: Random selection reduces selection bias but does not guarantee coverage of a materially different processing regime. The new batch service processed 10% of annual volume, yet the sample contains no transactions from that period, while every potential exception clusters there. Although the annual extract reconciles in total, it does not identify or reconcile the processing-route subsets. The auditor should establish those subsets, stratify the population at the change date, and obtain sufficient appropriate evidence for post-change operation. Results can then be assessed separately before determining whether a year-wide conclusion is supportable. Testing known anomalies alone is directed testing, not representative sampling.
- Larger undivided sample: It may still underrepresent the changed route, while one projected rate assumes a homogeneous population.
- Exception-only testing: Investigating flagged transactions does not provide representative evidence about nonflagged post-change transactions.
- Period-wide failure: Potential exceptions require validation and do not establish that the control failed before the processing change.
Question 120
Topic: Operations and Resilience
An IS auditor reviews the following policy excerpt and production change register.
Scheduling policy excerpt
Standard changes require process-owner approval before activation. Application analysts may create and test rules but may not approve or activate their own rules. Scheduler administrators may request and activate approved changes. Emergency changes require process-owner ratification within one business day.
Change register
| Record | Type and originator | Owner approval | Production activation |
|---|---|---|---|
| SC-102 | Standard; Analyst A created/tested | Before activation | Administrator B |
| SC-103 | Standard; Administrator C requested | Before activation | Administrator C |
| SC-104 | Standard; Analyst D created/tested | Before activation | Analyst D |
| SC-105 | Emergency; Analyst E created/tested | Next morning | On-call Administrator F, previous evening |
Which record most clearly demonstrates a control failure?
Options:
A. SC-102: analyst creation and testing of the same rule
B. SC-103: administrator request and activation of the same change
C. SC-104: analyst creation and activation of the same rule
D. SC-105: emergency activation before process-owner ratification
Best answer: C
Explanation: Authorization and segregation of duties address different control objectives. Process-owner approval authorizes a production change, while segregation prevents one individual from controlling incompatible stages. For SC-104, owner approval satisfies the authorization requirement, but Analyst D both created and activated the automation rule. This directly violates the policy and increases the risk that unauthorized or incorrectly tested logic could reach production.
Creating and testing a rule is permitted for an analyst. A scheduler administrator may request and activate a change after independent owner approval. Emergency activation before approval is also permitted when ratification occurs within one business day. Therefore, valid authorization does not compensate for an explicit segregation-of-duties violation.
- Creating and testing SC-102 is permitted because approval and production activation remained with other roles.
- Requesting and activating SC-103 is permitted because the process owner provided independent authorization before activation.
- Activating SC-105 before approval follows the emergency procedure because ratification occurred within one business day.
Question 121
Topic: Information Asset Protection
An IS auditor is assessing quarterly remote access used by third-party administrators to maintain a production billing system.
Approved standard:
- Privileged sessions use phishing-resistant MFA.
- Endpoints are enrolled in the organization’s MDM and pass posture checks.
- VDI disables file transfer, clipboard redirection, and printing.
Reconciled logs for all 60 sessions:
- The identity provider recorded passwords plus mobile-push approvals.
- All devices passed patch and EDR checks; 9 of 15 device IDs were absent from MDM.
- VDI restrictions remained enabled with no administrative overrides.
Which assessment is best supported?
Options:
A. Conclude only authentication fails, while posture and VDI controls meet the standard.
B. Conclude all controls meet the standard because each session passed the configured checks.
C. Conclude only device enrollment fails, while mobile-push and VDI controls meet the standard.
D. Conclude authentication and device enrollment fail, while VDI data controls meet the standard.
Best answer: D
Explanation: The approved standard’s specific properties determine compliance. Password plus mobile-push approval provides two factors, but push approval is not phishing-resistant because it can be induced through social engineering or a fraudulent authentication request. Device posture checks establish patch and EDR status, not enrollment in the organization’s MDM; the inventory reconciliation confirms that nine devices lacked required enrollment. Conversely, the reconciled VDI evidence covers every session and shows that file transfer, clipboard redirection, and printing remained disabled with no overrides.
Passing implemented checks does not establish compliance when those checks do not enforce every approved requirement.
- Treating posture compliance as enrollment fails because patch and EDR checks do not prove MDM registration, and nine device IDs were absent.
- Treating mobile push as phishing-resistant fails because approval-based push authentication remains susceptible to phishing and social engineering.
- Relying on passed configured checks overlooks that the implemented authentication and device checks are weaker than the approved standard.
Question 122
Topic: Acquisition and Implementation
An IS auditor reviews the requirements traceability record for an accounts-payable SaaS implementation. Release approval is pending.
Each baseline requirement must cite an approved business requirements document (BRD) or approved change request and link to configuration and business acceptance evidence.
| ID | Requirement and source | Configuration | Acceptance |
|---|---|---|---|
| R-101 | Match tolerance 2%; BRD-4 approved | CFG-12 | UAT-31 passed |
| R-102 | Retain invoices 7 years; BRD-7 approved | CFG-18 | UAT-35 passed |
| R-103 | Dual-approve bank changes; workshop W-9, approval not recorded | CFG-22 | UAT-41 passed |
| R-104 | Reconcile payments daily; CR-6 approved | CFG-25 | UAT-44 passed |
Which finding should the auditor raise before release?
Options:
A. R-104 lacks traceability because an approved change cannot supplement the BRD.
B. R-103 lacks the approved BRD or change-request source required for the baseline.
C. R-101 lacks implementation evidence because a configuration record is insufficient.
D. R-102 lacks acceptance evidence because retention must be tested in production.
Best answer: B
Explanation: Requirements traceability should establish an unbroken path from an authorized business need through implementation and acceptance testing. R-103 has configuration and passed UAT links, but those downstream records demonstrate only that functionality was implemented and tested. They do not prove that the business authorized the requirement for inclusion in the baseline. The baseline requires an approved BRD or change request, so approving workshop notes alone would not satisfy the stated source rule. The missing permitted source creates a requirements governance and scope-control exception before release.
An approved change request is an acceptable source under the stated policy. Likewise, configuration and UAT references provide the required implementation and acceptance links at this stage. Complete downstream testing cannot compensate for an unauthorized or unsupported requirement origin.
- Approved change source: R-104 cites an approved change request, which the policy expressly permits as a baseline source.
- Production-only testing: R-102 has passed business acceptance evidence; production operation is not required to establish pre-release traceability.
- Configuration evidence: R-101 includes the configuration link required by the traceability policy.
Question 123
Topic: Information Asset Protection
An IS auditor must select the primary procedure for a security specialist to perform. The system owner signed this authorization record:
Record: ST-27
Objective: Directly identify known vulnerability indicators visible to
unauthenticated Internet clients on every exposed TCP service.
Targets: Three public portal IP addresses
Authorized: External active probing, read-only authenticated host checks,
non-destructive web requests, and passive perimeter capture
Constraints: Maximum 20 requests/second; no exploitation, disruption,
or production-data modification
Which vendor-neutral procedure best satisfies the stated assurance objective?
Options:
A. Run a dynamic web application assessment with non-destructive crawling and safe input-validation checks.
B. Run a passive perimeter traffic assessment with packet capture and service-fingerprint correlation.
C. Run a credentialed host vulnerability assessment with read-only access and rate-limited local configuration checks.
D. Run an external unauthenticated vulnerability assessment with rate-limited enumeration and safe detection checks.
Best answer: D
Explanation: Security-testing evidence should match the objective’s scope and perspective while remaining within explicit authorization. The record seeks direct evidence of vulnerability indicators visible to unauthenticated Internet clients across every exposed TCP service. An external unauthenticated vulnerability assessment can enumerate those services and apply safe detection checks under the stated rate limit. It does not establish actual exploitability, but exploitation is prohibited and is not required by the objective.
Credentialed scanning changes the assessment perspective, dynamic application testing covers primarily web behavior, and passive analysis depends on traffic that happens to be observed. The decisive factors are external perspective, complete service scope, and non-exploit testing.
- Credentialed host checks provide detailed patch and configuration evidence but do not reproduce an unauthenticated Internet client’s perspective.
- Dynamic application testing addresses web interfaces but does not cover every exposed TCP service.
- Passive traffic analysis observes existing activity but cannot ensure that all exposed services and vulnerability indicators are examined.
Question 124
Topic: Auditing Process
An IS auditor must determine whether all employee and contractor accounts were disabled within 24 hours of separation. The sampling design was approved for the planned confidence level and tolerable deviation rate.
Workpaper excerpt:
Population source: HR employee separation report
Filter: Worker type = Employee
Population count: 1,240
Completeness check: Agrees to HR employee dashboard
Selection: Random sample of 60 records
Procedure: Compare separation and IAM disablement timestamps
Result: No deviations identified
What is the primary source of the assurance gap?
Options:
A. Sampling risk because 60 records may not represent all workforce separations
B. Population-definition error because contractor separations are absent from the sampling frame
C. Procedure-execution error because disablement rather than account deletion was tested
D. Interpretation error because the reconciliation covered an employee-only dashboard
Best answer: B
Explanation: A sampling frame must include the full population covered by the audit objective. Here, the objective includes employees and contractors, but both the source report and completeness check cover employees only. Random selection and an appropriate sample size cannot compensate for records that had no chance of selection. This is a nonsampling error involving population definition and completeness, not sampling risk arising from possible differences between a valid sample and its defined population.
The timestamp comparison matches the stated disablement criterion. The employee-dashboard reconciliation may prove that the employee report is complete, but it does not establish completeness for the required workforce population.
- Sampling risk concerns representativeness within a valid population and does not address contractors excluded from the sampling frame.
- Testing disablement timestamps matches the stated control criterion; account deletion was not required.
- The employee-only reconciliation validates the limited source but does not create an interpretation error or establish contractor coverage.
Question 125
Topic: Acquisition and Implementation
An organization plans the first production deployment of a warehouse dispatch application before seasonal volume begins. An IS auditor is performing an advisory readiness review; the change authority, not audit, approves deployment.
- Authorized package: Build B117 for Saturday.
- Required evidence: Business UAT approval and a rollback rehearsal within 30 minutes.
- Rollback criteria: Reverse if order variance exceeds 0.5% or a critical interface is unavailable for 10 minutes.
- Evidence: B117 passed UAT and rolled back in 25 minutes.
- Current package: B118, containing a defect fix added after approval, passed automated release checks. No updated authorization, UAT approval, or rollback rehearsal covers B118.
Which assessment should the IS auditor report?
Options:
A. Assess B118 as ready because automated checks passed and approved rollback triggers remain available.
B. Assess B118 as not ready until its authorization and required verification evidence are completed.
C. Assess B118 as not ready until stricter rollback triggers are approved and rehearsed.
D. Assess B118 as ready with enhanced monitoring because B117 met the required rollback duration.
Best answer: B
Explanation: Deployment authorization and readiness evidence must apply to the actual package being released. The approval, business UAT, and rollback rehearsal cover B117, while the production package is B118. Automated checks support B118’s technical integrity but do not extend the authorization or demonstrate the required business acceptance and rollback capability for that build.
The auditor should report the readiness gap while leaving deployment authorization and remediation decisions to management. The existing rollback thresholds are not shown to be inadequate, and additional production monitoring cannot replace required predeployment evidence.
- Automated checks do not replace the required change authorization, business UAT, and rollback rehearsal for B118.
- Enhanced monitoring occurs after deployment, while B117’s successful rehearsal does not establish B118’s readiness.
- Stricter triggers do not resolve the actual deficiency, which is the mismatch between the approved package and deployment package.
Questions 126-150
Question 126
Topic: Auditing Process
An IS audit manager reviews the following draft engagement planning record before approval.
Draft planning record
| Field | Entry |
|---|---|
| Objective | Conclude on privileged-access control effectiveness across all production environments for the prior year |
| Population | On-premises: 2,000 accounts; cloud: 2,400; subsidiary: 600 |
| Planned testing | Sample 30 on-premises accounts and related logs |
| Exclusions | Cloud logs arrive after reporting; subsidiary testing requires an unavailable specialist |
| Substitute evidence | Management attestations and a prior-year design review |
| Constraints | Two generalist auditors, four weeks, no extension; enterprise-wide report |
Which recommendation should the manager make?
Options:
A. Escalate the mismatch and revise the objective, timing, or resources before approval.
B. Use the attestations and prior design review to cover the excluded environments.
C. Approve the plan and disclose the omitted environments as final-report scope limitations.
D. Expand the on-premises sample and extrapolate effectiveness across all production environments.
Best answer: A
Explanation: An engagement’s scope, evidence, skills, and time must be sufficient to meet its assurance objective. The plan omits cloud and subsidiary environments containing 3,000 of 5,000 privileged accounts, yet proposes an enterprise-wide conclusion. Testing more on-premises accounts cannot establish control operation in environments with different technologies and processes. Management attestations provide indirect evidence, while a prior-year design review does not establish operating effectiveness during the period under audit. The mismatch should be escalated before approval so audit management can revise the objective, obtain appropriate resources and access, or change the timing. Disclosing the limitation only in the final report does not cure the unsupported objective.
- Final-report disclosure acknowledges the limitation but does not make the planned evidence sufficient for enterprise-wide assurance.
- Extrapolating on-premises results is inappropriate because the excluded environments are distinct populations with untested controls.
- Attestations and a prior design review do not demonstrate current-period operating effectiveness in the excluded environments.
Question 127
Topic: IT Governance and Management
An IS auditor reviews governance of a spreadsheet extract used for customer credit approvals. The audit date is February 15, 2025.
Data-copy standard and register excerpt
Standard:
1. Register source ID, data owner, and extraction date.
2. After a master-record correction, reconcile the copy
and record the date before further decision use.
3. Delete decision-use copies within 30 days of extraction.
Copy ID: E-17
Source ID: CUSTOMER-MASTER
Data owner: Credit Operations
Extracted: January 20, 2025
Master correction: February 3, 2025
Reconciliation date: [blank]
Decision use: February 10, 2025
Deleted: February 12, 2025
Which audit conclusion is BEST supported by the excerpt?
Options:
A. Master maintenance effectiveness is unsupported for E-17’s correction timing.
B. Lineage effectiveness is unsupported for E-17’s source identification.
C. Retention effectiveness is unsupported for E-17’s deletion timing.
D. Reconciliation effectiveness is unsupported for E-17’s post-correction use.
Best answer: D
Explanation: The standard requires a decision-use copy to be reconciled after a master-record correction and before any further use. E-17 was used on February 10, after the February 3 correction, while its reconciliation date remained blank. The available evidence therefore does not demonstrate that the reconciliation control operated as required for this use.
Retention is a separate control: E-17 was deleted 23 days after extraction, within the 30-day limit. The register also contains the required source ID, owner and extraction date. Finally, the standard provides no deadline for correcting the master record, so correction timing cannot be evaluated from this evidence. The decisive issue is unsupported reconciliation before continued use of a potentially outdated copy.
- Retention timing: Deletion occurred 23 days after extraction, which satisfies the stated 30-day limit.
- Source identification: The register includes
CUSTOMER-MASTER, meeting the stated source ID requirement. - Correction timing: No service level or deadline establishes that the master correction was untimely.
Question 128
Topic: Information Asset Protection
An IS auditor confirmed that the service record is complete for the contract year. Which conclusion is most appropriate based on the approved cloud service schedule?
Service schedule and record:
Provider responsibilities
- Run daily backups and retain them for 35 days.
- Perform a restore test after an authorized customer request.
- Deliver restore-test results to the customer.
Customer responsibilities
- Define recovery objectives.
- Request at least one restore test each contract year.
- Validate the restored application and data.
Contract-year record
- Backup jobs: Successful
- Restore-test requests: None
- Customer validations: None
Options:
A. A shared control gap exists; each party had to initiate the annual restore test.
B. A provider control gap exists; its restore-test duty applied without a customer request.
C. No control gap exists; successful backup records satisfy the annual recovery requirement.
D. A customer control gap exists; the provider’s restore-test duty was not triggered.
Best answer: D
Explanation: Cloud outsourcing does not eliminate responsibilities retained by the customer. The service schedule assigns backup operation to the provider but makes restoration testing conditional on an authorized customer request. It separately requires the customer to request an annual test and validate the restored application and data. Because the complete record contains neither a request nor validation, the customer did not operate its retained recovery control. The provider had no contractual trigger to perform the test, although it remained responsible for successful backup operations. Backup-job success demonstrates that backup processes ran, not that data can be restored within the required recovery objectives.
- Provider ownership misreads a conditional duty as an obligation to initiate testing independently.
- Shared initiation confuses joint remediation after failure with responsibility for starting and validating a test.
- Backup success does not demonstrate restoration capability or satisfaction of the annual testing requirement.
Question 129
Topic: IT Governance and Management
An IS auditor is assessing whether the IT risk register used by the risk committee to prioritize resilience funding is complete. The approved ERM process uses quarterly workshops and a 5x5 qualitative matrix.
Evidence:
- The business impact analysis identifies online sales as critical and a sole DNS provider as a dependency.
- The vendor inventory confirms this dependency.
- Workshop scope excluded infrastructure vendors.
- The registered cloud-outage scenario covers only compute-region failure.
- All recorded risks have owners, inherent and residual ratings, and required response plans.
Which assessment is best supported?
Options:
A. IT risk analysis is incomplete because the approved qualitative matrix does not calculate monetary loss exposure.
B. IT risk analysis is complete because every recorded risk has inherent and residual ratings.
C. IT risk identification is complete because the cloud-region outage scenario implicitly includes supporting provider failures.
D. IT risk identification is incomplete because sole-provider DNS failure was excluded from scenario development.
Best answer: D
Explanation: Complete IT risk identification should trace critical business services to supporting applications, infrastructure, suppliers, and single points of failure. The business impact analysis and vendor inventory both identify the sole DNS provider, but the workshop excluded infrastructure vendors and the cloud-outage scenario covers only compute-region failure. The DNS failure scenario therefore remains unidentified and unanalyzed.
Proper scoring of recorded risks cannot compensate for an incomplete risk population. Qualitative analysis may be appropriate when permitted by the approved ERM method; monetary estimates are not universally required. The key issue is the missing critical dependency, not the scoring method applied to existing entries.
- Monetary quantification is not required because the approved ERM method permits the qualitative 5x5 matrix.
- Implicit cloud coverage fails because the documented scenario covers only compute-region failure, not supporting providers.
- Completed ratings address recorded risks but cannot establish completeness when a known critical dependency was omitted.
Question 130
Topic: IT Governance and Management
An IS auditor is reviewing enterprise architecture governance for consolidated customer-risk reporting.
Control state and evidence:
- Two business units have approved exceptions allowing separate customer applications.
- Local applications must remain operational to support different workflows.
- Customer status conflicts for 8% of shared identifiers.
- Reports select the most recently updated record, regardless of its source.
- Application owners are assigned, but no enterprise data owner or authoritative source is defined.
Which recommendation would BEST address the assurance concern?
Options:
A. Require application owners to reconcile conflicting records monthly and document corrections in their respective systems.
B. Standardize customer-status definitions across both applications while retaining approval authority within each business unit.
C. Assign an enterprise data owner to define record authority and govern synchronization between approved systems.
D. Configure the reporting platform to deduplicate records using recency rules and monitor data-load exceptions.
Best answer: C
Explanation: Enterprise information governance requires accountability for data that crosses application and business-unit boundaries. Application owners manage their systems, but an enterprise data owner determines which records are authoritative, how conflicts are resolved and which integration controls preserve consistency. The approved architecture exceptions permit separate applications; they do not justify competing authority over critical customer data.
The 8% conflict rate and source-independent recency rule show that consolidated reporting cannot reliably identify the valid customer status. Enterprise ownership should therefore precede detailed synchronization, reconciliation and exception-handling rules. Technical matching or local corrections can support this governance structure but cannot replace it.
- Recency-based deduplication assumes the newest record is valid, although the evidence establishes no authoritative source or precedence rule.
- Monthly reconciliation detects conflicts after they occur but leaves cross-unit resolution authority undefined.
- Common definitions improve semantic consistency but do not resolve competing business-unit authority over shared records.
Question 131
Topic: Operations and Resilience
An IS auditor reviews this approved business impact analysis excerpt and disaster recovery exercise record.
Document excerpt
Business impact analysis
- Unavailability becomes unacceptable after 6 hours.
- Service should resume within 4 hours of disruption.
- At most 20 minutes of committed transactions may be lost.
Recovery exercise
- Complete outage began: 09:00
- Service resumed: 12:40
- Latest recovered transaction: 08:25
Which conclusion should the auditor draw?
Options:
A. The exercise failed the RTO and RPO but remained within the MTD.
B. The exercise met the RTO and RPO but exceeded the MTD.
C. The exercise met the RPO and MTD but failed the RTO.
D. The exercise met the RTO and MTD but failed the RPO.
Best answer: D
Explanation: Maximum tolerable disruption (MTD) is the longest outage the business can tolerate before impacts become unacceptable, which is 6 hours here. The recovery time objective (RTO) is the 4-hour target for restoring service. Because service resumed after 3 hours 40 minutes, both limits were met.
The recovery point objective (RPO) limits acceptable data loss. At the 09:00 disruption, the latest recovered transaction was from 08:25, creating a 35-minute recovery gap. This exceeds the 20-minute RPO. Meeting the MTD does not replace the stricter RTO target.
- Treating the RPO as met overlooks that the recovered data was 35 minutes old, exceeding the 20-minute limit.
- Claiming the MTD was exceeded conflicts with the 3-hour 40-minute outage, which was below 6 hours.
- Claiming the RTO failed misclassifies the service restoration, which occurred within the 4-hour target.
Question 132
Topic: Auditing Process
A manufacturer is revising its internal audit charter to support independent assurance over internal and cloud-based systems. An IS auditor reviews the draft before audit committee approval.
Draft provisions:
- The audit committee approves the charter and risk-based audit plan.
- Internal audit may access all relevant organization-controlled records, systems, premises and personnel.
- Provider evidence may be obtained within the organization’s contractual rights.
- Management owns remediation; internal audit evaluates and follows up.
- The chief audit executive reports functionally to the audit committee, but the CIO must authorize release of IS audit results to the committee.
Which assessment is BEST supported?
Options:
A. Reporting responsibility is inadequate because management approval can block escalation to the audit committee.
B. Access authority is inadequate because provider evidence remains subject to contractual rights.
C. Planning authority is inadequate because the audit committee approves the risk-based audit plan.
D. Audit responsibility is inadequate because management, rather than internal audit, owns remediation.
Best answer: A
Explanation: An audit charter should establish sufficient authority, access, responsibilities and functional reporting to support independent assurance. Although the draft names the audit committee as the chief audit executive’s functional reporting line, the CIO can prevent IS audit results from reaching that committee. This management gatekeeping could suppress or delay significant findings and makes the functional reporting relationship ineffective.
The other provisions reflect appropriate role boundaries. External provider access depends partly on contractual rights, management remains accountable for remediation, and audit committee approval of the risk-based plan supports oversight. The charter must permit direct communication of audit results to the governing body without approval from the function being audited.
- Provider access may depend on contract terms because an internal charter cannot grant rights against an external service provider.
- Remediation ownership properly remains with management, while internal audit evaluates and follows up on corrective action.
- Plan approval by the audit committee strengthens functional oversight rather than limiting internal audit authority.
Question 133
Topic: Operations and Resilience
An IS auditor reviews the following problem-management record.
Standard PM-04
Open a problem after 3 related incidents in 30 days.
Close only after causal analysis, permanent correction,
and a 30-day recurrence review are documented.
Problem PRB-204
Incidents: April 3, 11, 18, and 25, 2025
Opened: April 18, 2025
Recovery target: Met for each incident
Status: Closed on April 26, 2025
Root cause: API timeout; no analysis attached
Workaround: Restart integration service
Permanent correction: None; continue workaround
Recurrence review: Not scheduled
Which recommendation should the auditor make?
Options:
A. Enforce problem closure only after causal evidence, permanent correction, and recurrence review are documented.
B. Enforce trend review only after categorization evidence, threshold validation, and problem creation are documented.
C. Enforce known-error use only after workaround testing, service-desk notification, and usage review are documented.
D. Enforce incident closure only after escalation evidence, recovery validation, and service-level review are documented.
Best answer: A
Explanation: Problem management seeks to identify and remove the cause of recurring incidents, whereas incident management prioritizes service restoration. The problem record was opened when the third related incident occurred, and every incident met its recovery target. However, the record was closed despite lacking causal-analysis evidence, a permanent correction, and the required recurrence review. An API timeout describes the observed failure condition but is not, by itself, evidence of its underlying cause. Restarting the service is a workaround that restores operations but leaves recurrence risk unresolved. Closure should therefore be prevented until the evidence required by the standard is documented.
- Incident recovery met its target, so the record does not support a weakness in restoration or service-level review.
- Trend detection worked because the problem record was opened when the third related incident occurred within 30 days.
- Workaround governance may support known-error handling, but it does not resolve the unsupported closure or missing permanent correction.
Question 134
Topic: Acquisition and Implementation
An IS auditor is assessing release readiness for an accounts payable system. The acceptance standard and UAT record state:
Acceptance standard:
- Every MUST requirement must pass UAT.
- The business process owner approves final UAT results after retests.
UAT record:
R-101 Three-way match [MUST] PASS Apr 8
R-114 Two approvals above $100,000 [MUST] FAIL Apr 8
R-114 Retest [MUST] PASS Apr 11
R-126 Export remittance file [SHOULD] DEFERRED
Owner sign-off, Apr 9:
"I approve the UAT results recorded as of this date."
QA release note, Apr 12:
"All MUST tests now pass; production release recommended."
No later business-owner approval is documented. Which conclusion is BEST supported?
Options:
A. Conclude readiness is unsupported because the deferred preferred requirement lacks an executed UAT case.
B. Conclude readiness is unsupported because the owner did not approve the final post-retest results.
C. Conclude readiness is supported because QA’s recommendation validates the owner’s earlier UAT approval.
D. Conclude readiness is supported because all mandatory requirements passed before QA’s release recommendation.
Best answer: B
Explanation: User acceptance testing establishes that the system satisfies business requirements, while business-owner sign-off evidences accountable acceptance of the final results. R-114 is mandatory and eventually passed, so mandatory testing was complete on April 11. However, the owner’s April 9 approval expressly covered results recorded by that date, when R-114 had failed. The acceptance standard requires the owner to approve final results after retests. QA’s later recommendation confirms test status but cannot substitute for the designated owner’s approval. The deferred preferred requirement does not block release because the standard requires all mandatory requirements, not preferred requirements, to pass.
- Passing all mandatory tests addresses test completion but not the required accountable acceptance after retesting.
- The deferred preferred requirement does not violate the stated release criterion, which applies to mandatory requirements.
- QA’s recommendation supports the testing status but cannot replace approval assigned specifically to the business process owner.
Question 135
Topic: Auditing Process
An internal audit quality assurance manager is assessing whether a closed corrective action improved workpaper quality so audit conclusions remain supportable.
Control state: The methodology and template require test evidence to be linked to conclusions. Engagement supervisors must review and sign each workpaper.
Evidence:
- Training attendance rose from 72% to 97%, with 92% average post-test scores.
- The corrective action was closed based on training completion.
- Three later QA samples found linkage deficiencies in 6 of 20, 5 of 20, and 6 of 20 workpapers.
- Every deficient workpaper had timely supervisor sign-off.
Which action should the quality assurance manager take next?
Options:
A. Reopen the item, repeat training for affected teams, and verify completion through post-test results.
B. Reopen the item, redesign workpaper templates, and verify deployment across affected teams through implementation records.
C. Reopen the item, increase quarterly QA sampling, and verify improvement through overall exception trends.
D. Reopen the item, assess supervisory review on affected files, and retest subsequent workpapers against the methodology.
Best answer: D
Explanation: Training attendance and test scores show participation and knowledge, but they do not establish practical application or sustained operating effectiveness. Deficiencies remained between 25% and 30% across three later samples, and supervisors signed every deficient workpaper. This evidence indicates that both engagement-level review and the prior remediation closure process require examination. The manager should determine how deficient workpapers passed supervisory review and should keep remediation open until testing of later workpapers demonstrates effective evidence-to-conclusion linkage. Increasing sample size could refine the estimated deficiency rate, but it would not directly address the apparent failure of supervision and follow-up.
- Repeat training relies again on participation and knowledge measures rather than evidence that staff apply the methodology in completed workpapers.
- Increase sampling may improve prevalence estimates but does not directly assess why supervisory review accepted deficient workpapers.
- Redesign templates addresses design even though the existing template already requires the missing linkage; deployment records would not prove effective use.
Question 136
Topic: Operations and Resilience
An IS auditor reviews the following interface control record.
Procedure excerpt:
Operations closes a batch when the gateway returns a delivery acknowledgment. Validation rejects are recorded in a separate queue.
| Processing state | Record count |
|---|---|
| Sender output | 25,000 |
| Gateway acknowledged | 25,000 |
| Validation accepted | 24,982 |
| Validation rejected | 18 |
| Target posted | 24,982 |
The batch status is Complete, and the procedure does not require rejected records to be resolved. Which recommendation would BEST address the control weakness?
Options:
A. Reconcile accepted totals to posted totals, reporting rejects as separate data-quality incidents.
B. Reconcile sent, accepted, rejected, and posted totals, tracking rejects through resolution.
C. Reconcile sent totals to gateway acknowledgments, retransmitting batches lacking delivery confirmation.
D. Reconcile gateway acknowledgments to validation receipts, sampling posted records for transaction accuracy.
Best answer: B
Explanation: A transport acknowledgment establishes delivery to an interface endpoint, not successful business processing. Here, all 25,000 records reached the gateway, but downstream validation rejected 18 and only 24,982 were posted. An effective interface control should reconcile each material processing state: records sent, received, accepted, rejected, and posted. Rejected records should remain open with ownership and resolution evidence rather than being excluded from a completed batch.
A delivery-only reconciliation addresses transmission completeness, while an end-to-end reconciliation addresses business processing completeness.
- Delivery confirmation and retransmission address missing batches but do not detect records rejected after successful transport.
- Matching accepted records to postings confirms one processing segment but excludes the unresolved rejected population.
- Receipt reconciliation and sampling may test accuracy, but they do not account fully for every rejected record.
Question 137
Topic: Auditing Process
An engagement manager is preparing one global conclusion from geographically distributed audit work. The underlying workpapers remain available, and the global lead has not completed the required review.
Closeout record excerpt
GLOBAL AUDIT PROGRAM - approved
Exception: account enabled more than 24 hours after termination
Ineffective: exception rate above 5%
Escalation: any confirmed post-termination use
Review: global lead sign-off before consolidation
REGIONAL CLOSEOUT
West: more than 24 hours; threshold 10%; 6/80; effective
Central: more than 48 hours; threshold 5%; 2/70; effective
East: more than 24 hours; threshold 5%; 4/60; ineffective
East note: one account used after termination; not escalated
What should the engagement manager do before issuing the global conclusion?
Options:
A. Issue a qualified global conclusion, escalate the confirmed use, and mandate common criteria and review procedures for future audits.
B. Recalculate the regional ratings from reported counts, escalate the confirmed use, and complete global lead review before consolidation.
C. Accept locally reviewed ratings, weight them by sample size, escalate the confirmed use, and disclose the threshold differences.
D. Require reassessment against global criteria, escalate the confirmed use, and complete global lead review before consolidation.
Best answer: D
Explanation: Distributed audit results must use consistent criteria, thresholds, escalation rules, and supervisory review before they support a combined conclusion. West reported an effective rating even though 6 of 80 exceptions equals 7.5%, exceeding the global 5% threshold. Central counted only delays exceeding 48 hours, so its summary may omit exceptions between 24 and 48 hours. East identified post-termination use but did not perform the required escalation. The available workpapers should therefore be reassessed under the approved global program, with discrepancies resolved and global lead review completed. Recalculating or weighting inconsistent summaries cannot make the underlying evidence comparable.
- Recalculating reported counts cannot identify Central exceptions omitted by its 48-hour criterion.
- Weighting local ratings preserves inconsistent definitions and West’s conflict with the approved threshold.
- Qualifying immediately is premature because the available workpapers can still be reassessed and reviewed.
Question 138
Topic: Information Asset Protection
An IS auditor is evaluating payroll archives in Managed Vault for January through June. The service was used throughout that period.
- A SOC 2 Type II report covers Managed Vault from January 1 through March 31, with no relevant exceptions.
- A provider letter says no relevant control changes occurred from April through June; it contains no independent testing.
- The provider’s release notice and change record show that automated deletion was replaced on May 1.
- The provider operates storage and deletion controls; the customer configures retention rules and reviews access.
What evidence should the auditor obtain before concluding on the six-month period?
Options:
A. Evaluate the report and provider letter as sufficient six-month evidence, and test the assigned customer controls.
B. Defer all provider-control assessment until the next annual report, and use the letter to conclude on customer controls.
C. Evaluate the report, corroborate April–June control operation including the May change, and test the assigned customer controls.
D. Evaluate the report and May design documents as sufficient six-month evidence, and test the assigned customer controls.
Best answer: C
Explanation: The Type II report provides relevant evidence for January through March. The remaining period needs appropriate evidence, particularly because a documented change contradicts the provider letter. The auditor should investigate that discrepancy and obtain evidence of operation before and after the May change, using suitable assurance or alternative procedures. Customer-configured retention and access controls also require testing. A provider representation does not extend independent testing or establish operation of customer controls.
- Report plus letter: The letter is a management representation, and its no-change assertion conflicts with documented evidence.
- Design documents: Design evidence does not establish operation during April through June.
- Wait for next year: Appropriate alternative procedures may be available now; the provider letter cannot establish customer-control operation.
Question 139
Topic: Acquisition and Implementation
An internal IS auditor is assessing whether a new settlement interface is ready for project closure. Vendor hypercare ends Friday.
- Operations accepted the handover after runbook, alert-handling, and escalation tests.
- Lessons learned were documented, and process-improvement actions have owners.
- A daily reconciliation detects and corrects intermittent transaction omissions before the settlement deadline.
- The technical team estimates a permanent correction will take six weeks, but no owner or target date is approved, and no one owns reconciliation monitoring after hypercare.
Governance permits closure with a known defect only after the business risk owner accepts the residual risk and dated owners are documented for control monitoring and remediation.
Which action should the auditor recommend?
Options:
A. Assign the correction to the project manager and close after its target date is recorded in lessons learned.
B. Defer closure until business risk acceptance and dated ownership for reconciliation monitoring and permanent remediation are documented.
C. Extend project support until the permanent interface correction is deployed, tested, and formally accepted by operations.
D. Transfer the defect to problem management and close after operations verifies reconciliation for one additional reporting cycle.
Best answer: B
Explanation: Post-implementation closure requires both effective operational handover and governed disposition of unresolved items. The tested runbook, alert handling, escalation process, and signed operational acceptance support the handover. The daily reconciliation is an operating compensating control, so the permanent correction need not precede closure under the stated governance rule. However, vendor departure would leave the control and remediation activities without accountable owners. Management must document business acceptance of the residual risk and assign dated responsibility for continued reconciliation monitoring and permanent remediation before closure. Lessons learned address future improvement, not ownership of the current production risk.
- Additional reconciliation testing provides more operating evidence but does not establish the required risk acceptance or future ownership.
- Waiting for permanent correction is unnecessary because governance permits closure with an accepted residual risk and controlled workaround.
- Recording remediation in lessons learned does not assign sustainable monitoring responsibility or document business risk acceptance.
Question 140
Topic: Acquisition and Implementation
An IS auditor reviews the following project governance record before user acceptance testing (UAT).
Project status record:
Overall status: Green
Schedule variance: +2 days (green threshold: <= 5 days)
Cost variance: -1.2% (green threshold: <= 3%)
Next milestone: UAT begins July 8
Critical requirement: Migrate all customer balances
Reconciliation tolerance: TBD
Business acceptance approval: Pending
Status rationale: Schedule and cost are within thresholds
Which audit procedure should be performed first to assess whether the on-track status is adequately supported?
Options:
A. Compare current defect severity and aging with the system-test exit thresholds.
B. Trace critical requirements to approved, measurable criteria and corresponding UAT test cases.
C. Reperform schedule and cost variances against the baseline and underlying project records.
D. Compare forecast staffing through go-live with the approved project resource plan.
Best answer: B
Explanation: Project status should reflect the likelihood of delivering required business outcomes, not merely compliance with schedule and cost thresholds. The reconciliation tolerance is undefined and business approval is pending for a critical migration requirement. Consequently, the project lacks an objective basis for designing UAT tests and determining whether migrated balances are acceptable. Requirements traceability should establish that each critical requirement has approved, measurable acceptance criteria and associated testing.
Recalculating performance metrics may validate the dashboard figures, but it cannot resolve uncertainty about what successful delivery means.
- Reperforming variances verifies dashboard arithmetic but does not establish whether the required business outcome can be accepted.
- Reviewing defects evaluates current testing results, which cannot replace undefined business acceptance criteria.
- Comparing staffing evaluates resource capacity rather than the completeness and testability of required outcomes.
Question 141
Topic: Information Asset Protection
An IS auditor is reviewing a security program dashboard that reports Framework status: Adopted. The program office provides the following quarterly assurance record; no additional evidence is available.
Exhibit: Security framework assurance record
Review period: Previous 12 months
Approved policies mapped to framework: 96 of 96 controls
Named control owners: 96 of 96 controls
Implementation artifacts requested: 96
Implementation artifacts submitted: 0
Operating records requested: 12 months
Operating records submitted: 0
Owner response: Controls are in use; confirmation by interview
Which assessment is best supported by this record?
Options:
A. Reported adoption supports policy alignment, not implementation or sustained operation.
B. Reported adoption remains unassessable until independent framework certification is obtained.
C. Reported adoption supports implementation, but sustained operating effectiveness remains unverified.
D. Reported adoption supports design and implementation, pending operating effectiveness testing.
Best answer: A
Explanation: Framework adoption claims must be evaluated at distinct assurance levels. Approved policies mapped to framework controls and assigned owners demonstrate documented alignment and governance intent. They do not demonstrate that the controls were deployed, configured, or consistently performed. Here, owners provided only interview confirmations, while no implementation artifacts or operating records were submitted. Inquiry without corroborating evidence is insufficient to substantiate implementation or sustained operating effectiveness.
The auditor can recognize the documented policy alignment while qualifying the broader adoption claim. Because evidence is missing at the implementation stage, the auditor cannot conclude that only operating effectiveness remains to be tested.
- Implementation assumed fails because owner interviews are not corroborated by deployment, configuration, or other implementation records.
- Design and implementation assumed fails because policy mapping demonstrates intent but does not establish that controls were placed into operation.
- Certification required fails because independent certification is not a prerequisite for assessing adoption when sufficient internal evidence is available.
Question 142
Topic: Information Asset Protection
An IS auditor reviews an organization’s outsourced security monitoring arrangement. The approved procedure contains the complete escalation record for priority 1 (P1) events.
Procedure excerpt:
Provider SOC:
- Monitor and triage alerts continuously
- Send P1 alerts to security-alerts@example.com
Customer:
- Authorize containment after business impact review
Escalation:
- Acknowledgment target: 15 minutes
- If unacknowledged, resend to the same mailbox
- Customer escalation owner: Unassigned
- Business incident coordinator: Unassigned
Which recommendation best addresses the control weakness shown?
Options:
A. Expand P1 SLA metrics to cover alert delivery, acknowledgment tracking, and response coordination.
B. Assign an accountable customer on-call role for P1 acknowledgment, escalation, and response coordination.
C. Add secondary P1 notification channels for alert delivery, acknowledgment tracking, and response coordination.
D. Delegate P1 incident command to the provider for acknowledgment, containment, and response coordination.
Best answer: B
Explanation: Outsourcing security monitoring transfers detection and notification activities, but the customer remains accountable for responding to events that affect its business. The procedure assigns technical monitoring to the provider yet leaves both customer escalation ownership and incident coordination unassigned. Consequently, an alert may be delivered within the SLA without anyone having clear authority to assess business impact, authorize action, or coordinate the response. Assigning an accountable on-call customer role closes this design gap. Provider authority, additional communication channels, and broader metrics may support the process, but none substitutes for retained customer ownership of critical-event escalation.
- Provider incident command cannot replace customer accountability for business impact decisions and risk ownership.
- Secondary notification channels improve delivery resilience but still leave no accountable customer responder.
- Additional SLA metrics improve performance measurement but do not assign response authority or responsibility.
Question 143
Topic: Auditing Process
An IS auditor is testing whether terminated employee accounts were disabled within 24 hours during the quarter. Before finalizing the audit conclusion, the auditor reviews this workpaper excerpt:
HR termination register: 12 employees
IAM export: 10 employees
Export filter: Business unit = Headquarters
IAM results: 9 disabled within 24 hours; jlee disabled after 31 hours
IT director: "All 12 accounts were disabled on time."
Ticket note for jlee: "Actual disablement was at 18 hours;
the IAM timestamp was delayed." No supporting log is attached.
Which action would BEST support a defensible audit conclusion?
Options:
A. Obtain another management representation confirming timely revocation, retain the ticket note, and conclude the control operated effectively.
B. Use the 10 exported rows as a judgmental sample, project the observed deviation, and report the estimated exception rate.
C. Inspect the approved procedure and IAM disablement configuration, document the export limitation, and conclude the control was suitably designed.
D. Obtain unfiltered IAM event logs for all 12 users, reconcile them to HR, and corroborate the disputed timestamp.
Best answer: D
Explanation: Audit evidence must be sufficient in quantity and appropriate in relevance and reliability. The filtered IAM export omits two employees, so it does not cover the stated population. It also contradicts management’s claim by showing a 31-hour disablement. The ticket explanation is inquiry evidence without corroborating system records. The auditor should obtain a complete export, reconcile it to the HR register, and examine reliable records supporting or refuting the claimed timestamp delay. Management authority does not make an unsupported explanation reliable. A conclusion about operating effectiveness should wait until the incomplete population and contradictory evidence are resolved.
- Projecting from the extract is unsupported because the filtered records are not a valid selection from the complete population.
- Another management representation repeats inquiry evidence and does not substantiate the claimed 18-hour disablement.
- Procedures and configuration support control design, not whether the control operated effectively throughout the quarter.
Question 144
Topic: Operations and Resilience
An IS auditor is validating service credits after a customer claims an outage began at 02:07 and the provider claims 02:16. Source clocks are synchronized, and the records are complete.
Agreement rule:
An outage begins at the earliest validated time when customers cannot complete checkout transactions.
| Time | Evidence |
|---|---|
| 02:07 | Database latency threshold breached; checkouts continued |
| 02:11 | Last successful checkout |
| 02:12 | First failed checkout; subsequent attempts failed |
| 02:16 | Provider monitor declared an incident |
| 02:19 | Customer opened a support ticket |
Which outage start time should the auditor support?
Options:
A. 02:19, when customer support opened the ticket
B. 02:07, when database latency breached its threshold
C. 02:12, when checkout transactions first became unavailable
D. 02:16, when provider monitoring declared the incident
Best answer: C
Explanation: Service-level measurements must follow the agreement’s defined measurement rule. Here, the rule measures customer inability to complete checkout transactions, not infrastructure degradation, automated detection or incident reporting. The synchronized and complete records show successful transactions through 02:11 and sustained failures beginning at 02:12. Therefore, 02:12 is the supported start of business-service unavailability.
The latency breach indicates degradation, while the monitoring alert and support ticket indicate later detection and reporting events. None changes when customers actually lost the contracted service.
- Latency threshold breach does not establish an outage because customers continued completing checkouts after the threshold was exceeded.
- Monitoring declaration occurred after a persistence delay and represents detection rather than the start of unavailability.
- Support ticket creation records customer reporting time, which can occur after the service has already failed.
Question 145
Topic: Acquisition and Implementation
An IS auditor is reviewing a newly implemented sales-return application. Its business purpose is to prevent credits for quantities exceeding those shipped. The clerk was authorized to enter returns.
Evidence:
- Approved requirement: cumulative returns must not exceed quantity shipped.
- Validation specification: verifies the order exists and the current return is between 1 and 999 units.
- User acceptance tests cover only those specified checks.
- Production log: 10 units shipped, 3 previously returned, and a new return of 8 accepted.
What is the auditor’s best assessment?
Options:
A. Attribute the exception to faulty deployment of an otherwise complete validation design.
B. Attribute the exception to incomplete cross-field validation design and acceptance-test coverage.
C. Treat the exception as inconclusive until downstream reconciliation controls are tested.
D. Attribute the exception to excessive transaction authority assigned to return clerks.
Best answer: B
Explanation: Input validation must enforce relationships among fields and related transactions, not merely validate individual field ranges. Although the approved requirement defined the cumulative-return limit, the detailed validation specification omitted that rule, and user acceptance testing followed the incomplete specification. The accepted transaction confirms the resulting design gap: prior and current returns total 11 units against 10 shipped.
The clerk’s authorization establishes permission to enter returns, not permission to enter inconsistent data. Downstream reconciliation might reduce financial impact, but it would not demonstrate that the required preventive input control was completely designed or tested.
- Deployment failure: No evidence indicates that a correctly specified validation rule was implemented incorrectly; the detailed design omitted the rule.
- Authorization scope: The clerk held the appropriate role, while transaction consistency is an input-validation responsibility.
- Downstream reconciliation: A detective control may identify excess credits later, but it does not resolve the missing preventive validation and test coverage.
Question 146
Topic: Acquisition and Implementation
An IS auditor reviews the following requirements traceability record before implementation. Each requirement must be supported by an explicit design mechanism.
Record: Bank-detail change feature
SEC-04 Requirement: Step-up MFA before bank-detail changes.
Design: API rejects changes unless MFA age <= 5 minutes.
PRV-02 Requirement: Display only the last 4 digits and never log
full account numbers.
Design: UI masks account numbers; observability captures full request bodies.
AUD-06 Requirement: Append-only log of actor, old/new masked values,
timestamp, and outcome; retain 7 years.
Design: Mutable 90-day log stores actor, timestamp, and "profile_updated".
Which conclusion is BEST supported?
Options:
A. Conclude security is adequately designed; report privacy and auditability gaps.
B. Conclude all three are adequately designed; proceed to operating-effectiveness testing.
C. Conclude privacy is adequately designed; report security and auditability gaps.
D. Conclude auditability is adequately designed; report security and privacy gaps.
Best answer: A
Explanation: Design effectiveness is evaluated by tracing each approved requirement to mechanisms capable of satisfying it. The API’s recent-MFA check directly supports the security requirement. The privacy design is inadequate because display masking does not prevent observability tooling from recording full account numbers. The audit design is also inadequate: it omits the old and new masked values and outcome, permits modification, and retains records for only 90 days rather than 7 years.
Operating-effectiveness testing occurs after implementation, but identified design deficiencies should be reported before then. A future test cannot make an incomplete control design adequate.
- Treating privacy as adequate overlooks that full request-body capture violates the prohibition against logging complete account numbers.
- Treating auditability as adequate overlooks missing event details, insufficient retention, and the absence of append-only protection.
- Deferring all concerns to operating testing confuses design adequacy with evidence that an adequately designed control operated consistently.
Question 147
Topic: Auditing Process
The IS audit director must determine whether the proposed engagement satisfies the organization’s external quality review requirement.
Excerpt: Proposed engagement record
Engagement: External quality review of IS audit
Commissioned by: Audit committee
Lead assessor: Consultant who designed the IS audit methods
and workpaper templates that the review would assess
Planned work:
- Retest privileged access, emergency changes, and backups
- Rate IT management's remediation of control exceptions
Not in scope:
- IS audit governance, planning, supervision, evidence,
reporting, and follow-up
Which recommendation BEST addresses the external quality review requirement?
Options:
A. Use an independent assessor to evaluate operational IT controls and remediation.
B. Use the named assessor to evaluate operational IT controls and remediation.
C. Use an independent assessor to evaluate IS audit governance and engagement performance.
D. Use the named assessor to evaluate IS audit governance and engagement performance.
Best answer: C
Explanation: An external quality review assesses the audit function itself, including its independence, governance, planning, methodology, engagement execution, evidence, reporting, follow-up, and conformance with applicable standards. Retesting access, changes, backups, and remediation instead assesses operational IT controls owned by management. The named consultant also designed audit methods and templates that the required review would examine, creating a self-review threat. Being outside the organization and appointed by the audit committee does not automatically establish independence. Both defects must therefore be addressed: the assessor must be independent, and the scope must focus on IS audit governance and engagement performance.
- Scope change only: Evaluating audit practices fixes the scope, but the named consultant would review methods that the consultant designed.
- Assessor change only: An independent assessor resolves self-review, but testing operational controls still does not assess audit-function quality.
- Current plan unchanged: External appointment does not cure either the inappropriate operational scope or the assessor’s self-review threat.
Question 148
Topic: Auditing Process
An internal audit will assure the audit committee that a new ERP privileged-access control was suitably designed and operated effectively during its first six months.
During implementation, the assigned auditor recommended control criteria. During a system-owner vacancy, the auditor also accepted delegated management authority, approved the role matrix, and authorized production release. Management then operated the control. Another qualified auditor is available, and the audit charter requires objectivity.
What should the chief audit executive do to address the independence threat?
Options:
A. Retain the former approver as evaluator and disclose the prior management role to the audit committee.
B. Assign the control evaluation to the uninvolved auditor, using the former approver only for factual implementation context.
C. Retain the former approver as evaluator and require independent supervisory review of all significant audit judgments.
D. Retain the former approver as evaluator and expand transaction sampling with corroborating system-generated access logs.
Best answer: B
Explanation: A self-review threat arises when an auditor evaluates work or decisions for which the auditor previously had management responsibility. Recommending criteria in an advisory capacity would not necessarily impair objectivity if management retained decision authority. Here, however, the auditor accepted delegated authority, approved the role matrix, and authorized release. The planned assurance work covers the same control’s design and operation.
Because another qualified auditor is available, reassignment is the appropriate safeguard. The former approver may supply factual context, but the uninvolved auditor should control testing, evidence evaluation, and conclusions. Supervisory review, additional evidence, or disclosure may support audit quality or transparency, but none removes the conflict while the former approver remains the evaluator.
- Supervisory review does not eliminate self-review when the former decision-maker still performs the evaluation.
- Expanded testing improves evidence sufficiency but does not address impaired objectivity.
- Committee disclosure communicates the threat but does not adequately safeguard objectivity when reassignment is feasible.
Question 149
Topic: Operations and Resilience
An IS auditor is assessing a centralized log archive used to reconstruct outages and security incidents. Management states that its control preserved every ingested operational log for 12 months and made unauthorized alteration or deletion detectable.
Audit evidence:
- Retention is set to 400 days, and daily source counts reconcile to ingestion counts.
- Monthly samples remain retrievable and pass built-in hash validation.
- Quarterly reviews confirm appropriate platform administrator assignments.
- Administrators can delete archived records and archive-resident administrator activity logs; no independent copy or monitoring exists.
Which assessment is most appropriate?
Options:
A. Report no deficiency because retrieval and hash testing support record preservation.
B. Report no deficiency because quarterly reviews support authorized privileged access.
C. Report a retention deficiency because testing did not inspect every archived record.
D. Report deficient tamper protection over privileged deletion and audit-trail controls.
Best answer: D
Explanation: Retention, access governance and tamper protection are separate control assertions. The reconciliations and monthly samples support completeness at ingestion and continued availability of sampled records. Hash validation supports the integrity of records that still exist. However, it does not reveal deleted records unless deletion evidence is preserved independently. Quarterly access reviews establish that administrator assignments are approved, but they do not make incompatible deletion capabilities safe. Because administrators can erase both operational records and the corresponding activity logs, unauthorized deletion might not be detected. This is a tamper-protection design deficiency that successful operating tests cannot overcome.
- Retrieval and hash checks verify retained samples, but do not detect records and deletion evidence removed by the same administrator.
- Quarterly reviews validate role assignments, not whether the assigned role has incompatible or insufficiently monitored privileges.
- Full-population inspection is unnecessary when reconciled populations and representative sampling provide sufficient retention evidence.
Question 150
Topic: Information Asset Protection
An IS auditor reviews a procurement portal that uses a client certificate as the sole evidence that a supplier officer is authorized to change payment details.
The certificate chain is valid, the certificate is current, and a challenge confirms possession of the corresponding private key. However, issuance records show that the registration authority verified only access to a supplier-branded email account; required identity proof and employer authorization were not performed.
Which conclusion is BEST supported?
Options:
A. The certificate supports no assurance because deficient identity proofing invalidates the chain and signature verification.
B. The certificate supports the requester’s identity and key possession, but not the authority to change payment details.
C. The certificate supports key possession and chain integrity, but not the requester’s claimed identity or authority.
D. The certificate supports supplier affiliation and transaction authority, but not continuing possession of the corresponding private key.
Best answer: C
Explanation: PKI assurance depends on both cryptographic validation and trustworthy certificate issuance. A valid chain confirms that certificate signatures lead to a trusted certification authority, while the successful challenge demonstrates possession of the corresponding private key. Neither fact proves that the certificate was issued to the claimed person or that the person has authority to change supplier payment details.
Because the registration authority omitted required identity proof and employer authorization, the portal cannot rely on the certificate alone for its stated business purpose. Weak enrollment reduces identity and authorization assurance without invalidating otherwise successful cryptographic checks.
- Treating identity as established overlooks that verifying an email account does not satisfy the required personal identity proofing.
- Treating transaction authority as established ignores the missing employer authorization, while the successful challenge already confirms private-key possession.
- Treating the entire certificate as useless confuses unreliable issuance authorization with failure of cryptographic chain validation.
Review your attempt
Award one point for each correct choice. Your raw practice percentage is correct answers divided by 150, multiplied by 100. This is not ISACA’s scaled score or a pass prediction; 450/800 is not a valid conversion to an official passing percentage.
| Domain | Correct | Available |
|---|---|---|
| Auditing process | Record your result | 27 |
| Governance and management | Record your result | 27 |
| Acquisition and implementation | Record your result | 18 |
| Operations and resilience | Record your result | 39 |
| Information asset protection | Record your result | 39 |
Review guessed answers as well as mistakes. Write the decisive fact and why your nearest alternative answered a different question, assumed unavailable evidence or exceeded the stated role. Use the scenario guide for worked reasoning and the study plan to schedule fresh practice.
Continue in the web app
Use IT Mastery for interactive CISA practice with mixed sets, timed mocks, topic drills, explanations, and progress tracking.