Question 1 of 10 · Information Systems Auditing Process
What does an integrated test facility involve?
An integrated test facility processes dummy-entity transactions alongside live data, so the auditor can test controls in the production system and compare the results to expectations. It is not a separate mirror environment or offline reperformance.
Question 2 of 10 · Governance and Management of IT
What should an auditor examine in a service level agreement?
An SLA is only as good as its measurement, so the auditor checks whether performance is measured independently of the supplier's own reporting. Financial terms, duration and contacts matter less for assurance.
Question 3 of 10 · Information Systems Acquisition, Development and Implementation
What should source code escrow protect against?
Source code escrow protects the customer if the supplier fails or stops supporting the product, by releasing the code so the system can still be maintained. It does not prevent modification or settle ownership disputes.
Question 4 of 10 · Information Systems Operations and Business Resilience
An auditor requests evidence that backups are usable. Which satisfies the request?
The only real evidence that backups work is a restore test with the recovered data verified. Job completion logs, verbal assurance or a schedule show backups ran, not that they can be restored.
Question 5 of 10 · Protection of Information Assets
What is the audit concern where data loss prevention is deployed without accurate classification?
Without accurate classification, a data loss prevention tool has to guess what is sensitive, so it both blocks legitimate work and misses real exfiltration. Cost, performance and reporting are secondary to that effectiveness gap.
Question 6 of 10 · Information Systems Auditing Process
Which is the principal benefit of computer-assisted audit techniques?
Computer-assisted audit techniques let the auditor test the entire population rather than a sample, which removes sampling risk. Time saved or automated reports are secondary benefits.
Question 7 of 10 · Governance and Management of IT
What should an auditor examine regarding licence compliance?
Licence compliance is tested by reconciling what the organisation is entitled to use against what is actually deployed. Agreements, purchase records and policy on their own do not show whether usage exceeds entitlement.
Question 8 of 10 · Information Systems Acquisition, Development and Implementation
An auditor is invited to design controls for a system under development. What is the correct response?
An auditor who designs controls cannot later give independent assurance over them. Advising on principles keeps the benefit of early involvement without compromising independence; disclosure does not cure the conflict.
Question 9 of 10 · Information Systems Operations and Business Resilience
Which recovery test is least disruptive?
A read-through (checklist) test has people review the plan on paper, so it disrupts nothing. Simulation, parallel and full interruption tests progressively involve real systems and operations.
Question 10 of 10 · Protection of Information Assets
What is the audit significance of unsynchronised clocks across systems?
If system clocks are not synchronised, events from different sources cannot be put in order, so an incident timeline cannot be reliably established. Authentication and certificate problems can occur, but the audit issue is evidential.
0 of 10
Information Systems Auditing Process
Governance and Management of IT
Information Systems Acquisition, Development and Implementation
Information Systems Operations and Business Resilience
Protection of Information Assets
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.