Which of the following provides the MOST reliable audit evidence on the validity of transactions in a financial application?
Correct Answer: B
Substantive testing provides the most reliable audit evidence on the validity of transactions in a financial application. Substantive testing is an audit procedure that examines the financial statements and supporting documentation to see if they contain errors or misstatements. Substantive testing can help to verify that the transactions recorded in the financial applicationare authorized, complete, accurate, and properly classified. Substantive testing can include methods such as vouching, confirmation, analytical procedures, or physical examination.
CISA Exam Question 592
Email required for business purposes is being stored on employees' personal devices. Which of the following is an IS auditor's BEST recommendation?
Correct Answer: D
Implementing an email containerization solution on personal devices is the best recommendation for an IS auditor, because it allows the organization to separate and secure the email data from the rest of the device data. Email containerization creates a virtual environment that encrypts and isolates the email data, preventing unauthorized access, leakage, or loss of sensitive information12. Requiring passwords or antivirus protection on personal devices may not be sufficient or enforceable, while prohibiting employees from storing company email on personal devices may not be feasible or practical. References: 1: CISA Review Manual (Digital Version), Chapter 5, Section 5.4.3 2: CISA Online Review Course, Module 5, Lesson 4
CISA Exam Question 593
An IS auditor finds that the process for removing access for terminated employees is not documented What is the MOST significant risk from this observation?
Correct Answer: D
The most significant risk from this observation is that access rights may not be removed in a timely manner. If the process for removing access for terminated employees is not documented, there is no clear guidance or accountability for who, how, when, and what actions should be taken to revoke the access rights of the employees who leave the organization. This could result in delays, inconsistencies, or omissions in removing access rights, which could allow terminated employees to retain unauthorized access to the organization's systems and data. This could compromise the security, confidentiality, integrity, and availability of the information assets. References: CISA Review Manual (Digital Version) CISA Questions, Answers and Explanations Database
CISA Exam Question 594
Which of the following is the GREATEST benefit of adopting an international IT governance framework rather than establishing a new framework based on the actual situation of a specific organization1?
Correct Answer: D
The greatest benefit of adopting an international IT governance framework rather than establishing a new framework based on the actual situation of a specific organization is wide acceptance by different business and support units with IT governance objectives. An international IT governance framework, such as COBIT, provides a common language and understanding for IT governance among various stakeholders, such as management, users, auditors and regulators. This facilitates alignment, communication and collaboration among them. Readily available resources, comprehensive coverage and fewer resources expended are also benefits of adopting an international IT governance framework, but they are not the greatest benefit. References: CISA Review Manual (Digital Version) , Chapter 1, Section 1.3.1.
CISA Exam Question 595
An IS auditor is asked to provide feedback on the systems options analysis for a new project. The BEST course of action for the IS auditor would be to:
Correct Answer: C
Comprehensive and Detailed Explanation: The IS auditor should remain independent and objective. The best way to provide value without interfering in management decisions is to review and comment on the criteria used for evaluating alternatives, ensuring they are complete, relevant, and aligned with business needs. Option A: Identifying the "best" option compromises independence. Option B: Deferring to the audit report misses the chance to add timely value. Option D: Requesting another alternative intrudes on management's role. Option C: Correct - ensures appropriate evaluation criteria without biasing decisions. # ISACA Reference: CISA Review Manual 27th Edition, Domain 3, section on auditor's role in system development projects.