CISA Certified Information Systems Auditor – Question2508

The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?

A.
Inherent
B. Detection
C. Control
D. Business

Correct Answer: B

Explanation:

Explanation:
Detection risks are directly affected by the auditor’s selection of audit procedures and techniques. Inherent risks are not usually affected by an IS auditor. Control risks are controlled by the actions of the company’s management. Business risks are not affected by an IS auditor.

CISA Certified Information Systems Auditor – Question2507

An IS auditor is reviewing access to an application to determine whether the 10 most recent “new user” forms were correctly authorized. This is an example of:

A.
variable sampling.
B. substantive testing.
C. compliance testing.
D. stop-or-go sampling.

Correct Answer: C

Explanation:

Explanation:
Compliance testing determines whether controls are being applied in compliance with policy. This includes tests to determine whether new accounts were appropriately authorized. Variable sampling is used to estimate numerical values, such as dollar values.
Substantive testing substantiates the integrity of actual processing; such as balances on financial statements. The development of substantive tests is often dependent on the outcome of compliance tests. If compliance tests indicate that there are adequate internal controls, then substantive tests can be minimized. Stop-or-go sampling allows a test to be stopped as early as possible and is not appropriate for checking whether procedures have been followed.

CISA Certified Information Systems Auditor – Question2506

An IS auditor is using a statistical sample to inventory the tape library. What type of test would this be considered?

A.
Substantive
B. Compliance
C. Integrated
D. Continuous audit

Correct Answer: A

Explanation:

Explanation:
Using a statistical sample to inventory the tape library is an example of a substantive test.

CISA Certified Information Systems Auditor – Question2504

What is a data validation edit control that matches input data to an occurrence rate? Choose the BEST answer.

A.
Accuracy check
B. Completeness check
C. Reasonableness check
D. Redundancy check

Correct Answer: C

Explanation:

Explanation:
A reasonableness check is a data validation edit control that matches input data to an occurrence rate.

CISA Certified Information Systems Auditor – Question2503

Processing controls ensure that data is accurate and complete, and is processed only through which of the following?

A.
Documented routines
B. Authorized routines
C. Accepted routines
D. Approved routines

Correct Answer: B

Explanation:

Explanation:
Processing controls ensure that data is accurate and complete, and is processed only through authorized routines.

CISA Certified Information Systems Auditor – Question2502

Data edits are implemented before processing and are considered which of the following?

A.
Deterrent integrity controls
B. Detective integrity controls
C. Corrective integrity controls
D. Preventative integrity controls

Correct Answer: D

Explanation:

Explanation:
Data edits are implemented before processing and are considered preventive integrity controls.

CISA Certified Information Systems Auditor – Question2500

________________ should be implemented as early as data preparation to support data integrity at the earliest point possible.

A.
Control totals
B. Authentication controls
C. Parity bits
D. Authorization controls

Correct Answer: A

Explanation:

Explanation:
Control totals should be implemented as early as data preparation to support data integrity at the earliest point possible.

CISA Certified Information Systems Auditor – Question2499

When should an application-level edit check to verify that availability of funds was completed at the electronic funds transfer (EFT) interface?

A.
Before transaction completion
B. Immediately after an EFT is initiated
C. During run-to-run total testing
D. Before an EFT is initiated

Correct Answer: D

Explanation:

Explanation:
An application-level edit check to verify availability of funds should be completed at the electronic funds transfer (EFT) interface before an EFT is initiated.