Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 154

Mary Smith

Mon, 17 Mar 2025

CISA—Certified Information Systems Auditor - Part 154

1. If an IS auditor observes that an IS department fails to use formal documented methodologies, policies, and standards, what should the auditor do?

A) Lack of IT documentation is not usually material to the controls tested in an IT audit.
B) The auditor should at least document the informal standards and policies. Furthermore, the IS auditor should create formal documented policies to be implemented.
C) The auditor should at least document the informal standards and policies, and test for a compliance. Furthermore, the IS auditor should recommend management that formal documented policies be developed and implemented.
D) The auditor should at least document the informal standards and policies, and test for compliance. Furthermore, the IS auditor should create formal documented policies to be implemented.



2. What often results in project scope creep when functional requirements are not defined as well as they could be?

A) Inadequate software baselining
B) Insufficient strategic planning
C) Inaccurate resource allocation
D) Project delays



3. Fourth-Generation Languages (4GLs) are most appropriate for designing the application's graphical user interface (GUI). They are inappropriate for designing any intensive data- calculation procedures. True or false?

A) True
B) False
C)
D)



4. Run-to-run totals can verify data through which stage(s) of application processing?

A) Initial
B) Various
C) Final
D) Output



5. ________ (fill in the blank) is/are ultimately accountable for the functionality, reliability, and security within IT governance.

A) Data custodians
B) The board of directors and executive officers
C) IT security administration
D) Business unit managers



1. Right Answer: C
Explanation: If an IS auditor observes that an IS department fails to use formal documented methodologies, policies, and standards, the auditor should at least document the informal standards and policies, and test for compliance. Furthermore, the IS auditor should recommend to management that formal documented policies be developed and implemented.

2. Right Answer: A
Explanation: Inadequate software baselining often results in project scope creep because functional requirements are not defined as well as they could be.

3. Right Answer: A
Explanation: Fourth-generation languages (4GLs) are most appropriate for designing the application's graphical user interface (GUI). They are inappropriate for designing any intensive data-calculation procedures.

4. Right Answer: B
Explanation: Run-to-run totals can verify data through various stages of application processing.

5. Right Answer: B
Explanation: The board of directors and executive officers are ultimately accountable for the functionality, reliability, and security within IT governance.

0 Comments

Leave a comment