- Home
- ISACA Certification
- CISA Exam
- ISACA.CISA.v2026-01-26.q999 Practice Test
Question 571
.IS auditors are MOST likely to perform compliance tests of internal controls if, after their initial evaluation of the controls, they conclude that control risks are within the acceptable limits. True or false?
Correct Answer: A
IS auditors are most likely to perform compliance tests of internal controls if, after their initial evaluation of the controls, they conclude that control risks are within the acceptable limits. Think of it this way: If any reliance is placed on internal controls, that reliance must be validated through compliance testing. High control risk results in little reliance on internal controls, which results in additional substantive testing.
Question 572
Which of the following ACID property ensures that transaction will bring the database from one valid state
to another?
to another?
Correct Answer: B
Section: Information System Acquisition, Development and Implementation
Explanation/Reference:
Consistency - The consistency property ensures that any transaction will bring the database from one valid
state to another. Any data written to the database must be valid according to all defined rules, including but
not limited to constraints, cascades, triggers, and any combination thereof. This does not guarantee
correctness of the transaction in all ways the application programmer might have wanted (that is the
responsibility of application-level code) but merely that any programming errors do not violate any defined
rules.
For CISA exam you should know below information about ACID properties in DBMS:
Atomicity - Atomicity requires that each transaction is "all or nothing": if one part of the transaction fails, the
entire transaction fails, and the database state is left unchanged. An atomic system must guarantee
atomicity in each and every situation, including power failures, errors, and crashes. To the outside world, a
committed transaction appears (by its effects on the database) to be indivisible ("atomic"), and an aborted
transaction does not happen.
Consistency - The consistency property ensures that any transaction will bring the database from one valid
state to another. Any data written to the database must be valid according to all defined rules, including but
not limited to constraints, cascades, triggers, and any combination thereof. This does not guarantee
correctness of the transaction in all ways the application programmer might have wanted (that is the
responsibility of application-level code) but merely that any programming errors do not violate any defined
rules.
Isolation - The isolation property ensures that the concurrent execution of transactions results in a system
state that would be obtained if transactions were executed serially, i.e. one after the other. Providing
isolation is the main goal of concurrency control. Depending on concurrency control method, the effects of
an incomplete transaction might not even be visible to another transaction.[citation needed]
Durability - Durability means that once a transaction has been committed, it will remain so, even in the
event of power loss, crashes, or errors. In a relational database, for instance, once a group of SQL
statements execute, the results need to be stored permanently (even if the database crashes immediately
thereafter). To defend against power loss, transactions (or their effects) must be recorded in a non-volatile
memory.
The following were incorrect answers:
Atomicity - Atomicity requires that each transaction is "all or nothing": if one part of the transaction fails, the
entire transaction fails, and the database state is left unchanged.
Isolation - The isolation property ensures that the concurrent execution of transactions results in a system
state that would be obtained if transactions were executed serially, i.e. one after the other.
Durability - Durability means that once a transaction has been committed, it will remain so, even in the
event of power loss, crashes, or errors.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 218
Explanation/Reference:
Consistency - The consistency property ensures that any transaction will bring the database from one valid
state to another. Any data written to the database must be valid according to all defined rules, including but
not limited to constraints, cascades, triggers, and any combination thereof. This does not guarantee
correctness of the transaction in all ways the application programmer might have wanted (that is the
responsibility of application-level code) but merely that any programming errors do not violate any defined
rules.
For CISA exam you should know below information about ACID properties in DBMS:
Atomicity - Atomicity requires that each transaction is "all or nothing": if one part of the transaction fails, the
entire transaction fails, and the database state is left unchanged. An atomic system must guarantee
atomicity in each and every situation, including power failures, errors, and crashes. To the outside world, a
committed transaction appears (by its effects on the database) to be indivisible ("atomic"), and an aborted
transaction does not happen.
Consistency - The consistency property ensures that any transaction will bring the database from one valid
state to another. Any data written to the database must be valid according to all defined rules, including but
not limited to constraints, cascades, triggers, and any combination thereof. This does not guarantee
correctness of the transaction in all ways the application programmer might have wanted (that is the
responsibility of application-level code) but merely that any programming errors do not violate any defined
rules.
Isolation - The isolation property ensures that the concurrent execution of transactions results in a system
state that would be obtained if transactions were executed serially, i.e. one after the other. Providing
isolation is the main goal of concurrency control. Depending on concurrency control method, the effects of
an incomplete transaction might not even be visible to another transaction.[citation needed]
Durability - Durability means that once a transaction has been committed, it will remain so, even in the
event of power loss, crashes, or errors. In a relational database, for instance, once a group of SQL
statements execute, the results need to be stored permanently (even if the database crashes immediately
thereafter). To defend against power loss, transactions (or their effects) must be recorded in a non-volatile
memory.
The following were incorrect answers:
Atomicity - Atomicity requires that each transaction is "all or nothing": if one part of the transaction fails, the
entire transaction fails, and the database state is left unchanged.
Isolation - The isolation property ensures that the concurrent execution of transactions results in a system
state that would be obtained if transactions were executed serially, i.e. one after the other.
Durability - Durability means that once a transaction has been committed, it will remain so, even in the
event of power loss, crashes, or errors.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 218
Question 573
An IS audit reveals that an organization operating in business continuity mode during a pandemic situation has not performed a simulation test of the business continuity plan (BCP). Which of the following is the auditor's BEST course of action?
Correct Answer: B
Explanation
This is because the auditor's primary objective is to evaluate the adequacy and performance of the business continuity plan (BCP) in ensuring the continuity and resilience of the organization's critical functions and processes during a disruption. The auditor should review the actual results and outcomes of the business response, such as the recovery time, recovery point, service level, customer satisfaction, and incident management, and compare them with the predefined objectives and criteria of the BCP. The auditor should also identify and analyze any gaps, issues, or lessons learned from the business response, and provide recommendations for improvement12.
Answer A. Confirm the BCP has been recently updated. is not the best answer, because it is not directly related to the auditor's course of action. Confirming the BCP has been recently updated is a part of the audit planning and scoping process, not the audit execution or reporting process. The auditor should confirm the BCP has been recently updated before conducting the audit, not after revealing that a simulation test has not been performed. Moreover, confirming the BCP has been recently updated does not provide sufficient evidence of the effectiveness of the business response12.
Answer C. Raise an audit issue for the lack of simulated testing. is not the best answer, because it is not relevant to the auditor's course of action. Raising an audit issue for the lack of simulated testing is a part of the audit reporting and follow-up process, not the audit execution or evaluation process. The auditor should raise an audit issue for the lack of simulated testing after reviewing the effectiveness of the business response, not before or instead of doing so. Furthermore, raising an audit issue for the lack of simulated testing does not address the root cause or impact of the problem, nor does it provide any constructive feedback or guidance for improvement12.
Answer D. Interview staff members to obtain commentary on the BCP's effectiveness. is not the best answer, because it is not sufficient to guide the auditor's course of action. Interviewing staff members to obtain commentary on the BCP's effectiveness is a part of the audit evidence collection and analysis process, not the audit evaluation or conclusion process. The auditor should interview staff members to obtain commentary on the BCP's effectiveness as one of the sources of information, not as the only or main source of information. Additionally, interviewing staff members to obtain commentary on the BCP's effectiveness may be subjective, biased, or incomplete, and may not reflect the actual performance or outcomes of the business response12.
References:
Business Continuity Management Audit/Assurance Program
Business Continuity Plan Testing: Types and Best Practices
This is because the auditor's primary objective is to evaluate the adequacy and performance of the business continuity plan (BCP) in ensuring the continuity and resilience of the organization's critical functions and processes during a disruption. The auditor should review the actual results and outcomes of the business response, such as the recovery time, recovery point, service level, customer satisfaction, and incident management, and compare them with the predefined objectives and criteria of the BCP. The auditor should also identify and analyze any gaps, issues, or lessons learned from the business response, and provide recommendations for improvement12.
Answer A. Confirm the BCP has been recently updated. is not the best answer, because it is not directly related to the auditor's course of action. Confirming the BCP has been recently updated is a part of the audit planning and scoping process, not the audit execution or reporting process. The auditor should confirm the BCP has been recently updated before conducting the audit, not after revealing that a simulation test has not been performed. Moreover, confirming the BCP has been recently updated does not provide sufficient evidence of the effectiveness of the business response12.
Answer C. Raise an audit issue for the lack of simulated testing. is not the best answer, because it is not relevant to the auditor's course of action. Raising an audit issue for the lack of simulated testing is a part of the audit reporting and follow-up process, not the audit execution or evaluation process. The auditor should raise an audit issue for the lack of simulated testing after reviewing the effectiveness of the business response, not before or instead of doing so. Furthermore, raising an audit issue for the lack of simulated testing does not address the root cause or impact of the problem, nor does it provide any constructive feedback or guidance for improvement12.
Answer D. Interview staff members to obtain commentary on the BCP's effectiveness. is not the best answer, because it is not sufficient to guide the auditor's course of action. Interviewing staff members to obtain commentary on the BCP's effectiveness is a part of the audit evidence collection and analysis process, not the audit evaluation or conclusion process. The auditor should interview staff members to obtain commentary on the BCP's effectiveness as one of the sources of information, not as the only or main source of information. Additionally, interviewing staff members to obtain commentary on the BCP's effectiveness may be subjective, biased, or incomplete, and may not reflect the actual performance or outcomes of the business response12.
References:
Business Continuity Management Audit/Assurance Program
Business Continuity Plan Testing: Types and Best Practices
Question 574
When selecting audit procedures, an IS auditor should use professional judgment to ensure that:
Correct Answer: A
Section: Protection of Information Assets
Explanation:
Procedures are processes an IS auditor may follow in an audit engagement. In determining the appropriateness of any specific procedure, an IS auditor should use professional judgment appropriate to the specific circumstances. Professional judgment involves a subjective and often qualitative evaluation of conditions arising in the course of an audit. Judgment addresses a grey area where binary (yes/no) decisions are not appropriate and the auditor's past experience plays a key role in making a judgment.
ISACA's guidelines provide information on how to meet the standards when performing IS audit work.
Identifying material weaknesses is the result of appropriate competence, experience and thoroughness in planning and executing the audit and not of professional judgment. Professional judgment is not a primary input to the financial aspects of the audit.
Explanation:
Procedures are processes an IS auditor may follow in an audit engagement. In determining the appropriateness of any specific procedure, an IS auditor should use professional judgment appropriate to the specific circumstances. Professional judgment involves a subjective and often qualitative evaluation of conditions arising in the course of an audit. Judgment addresses a grey area where binary (yes/no) decisions are not appropriate and the auditor's past experience plays a key role in making a judgment.
ISACA's guidelines provide information on how to meet the standards when performing IS audit work.
Identifying material weaknesses is the result of appropriate competence, experience and thoroughness in planning and executing the audit and not of professional judgment. Professional judgment is not a primary input to the financial aspects of the audit.
Question 575
Which of the following function in traditional EDI translate data between the standard format and trading
partner's propriety format?
partner's propriety format?
Correct Answer: D
Section: Information System Acquisition, Development and Implementation
Explanation/Reference:
EDI Translator translates data between standard format (ANSI X12) and trading partner's propriety
information.
For CISA Exam you should know below information about Traditional EDI functions.
Moving data in a batch transmission process through the traditional EDI process generally involves three
functions within each trading partner's computer system
Communication handler - Process for transmitting and receiving electronic documents between trading
partners via dial-up lines, public switched networks, multiple dedicated lines or a value added network
(VAN). VAN use computerized message switching and storage capabilities to provide electronic mailbox
services similar to post offices. The VAN receives all the outbound transactions from an organization, sort
them by destination and passes them to precipitants when they log on to check their mailbox and receive
transmission.
EDI Interface -Interface function that manipulates and routes data between the application system and the
communication handler. The interface consists of two components
EDI Translator - The device translates data between standard format (ANSI X12) and trading partner's
propriety information.
Application Interface - This interface moves electronic transactions to or from the application systems and
perform data mapping. Data mapping is the process by which data are extracted from EDI translation
process and integrated with the data or process of receiving company.
3. Application System -The program that process the data sent to, or received from, the trading partner.
Although new controls should be developed for the EDI interface, the control for existing applications, if left
unchanged, are usually unaffected.
The following were incorrect answers:
Communication handler - Process for transmitting and receiving electronic documents between trading
partners via dial-up lines, public switched networks, multiple dedicated lines or a value added network
(VAN).
Application System -The program that process the data sent to, or received from, the trading partner.
Although new controls should be developed for the EDI interface, the control for existing applications, if left
unchanged, are usually unaffected.
Application Interface - This interface moves electronic transactions to or from the application systems and
perform data mapping.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 178
Explanation/Reference:
EDI Translator translates data between standard format (ANSI X12) and trading partner's propriety
information.
For CISA Exam you should know below information about Traditional EDI functions.
Moving data in a batch transmission process through the traditional EDI process generally involves three
functions within each trading partner's computer system
Communication handler - Process for transmitting and receiving electronic documents between trading
partners via dial-up lines, public switched networks, multiple dedicated lines or a value added network
(VAN). VAN use computerized message switching and storage capabilities to provide electronic mailbox
services similar to post offices. The VAN receives all the outbound transactions from an organization, sort
them by destination and passes them to precipitants when they log on to check their mailbox and receive
transmission.
EDI Interface -Interface function that manipulates and routes data between the application system and the
communication handler. The interface consists of two components
EDI Translator - The device translates data between standard format (ANSI X12) and trading partner's
propriety information.
Application Interface - This interface moves electronic transactions to or from the application systems and
perform data mapping. Data mapping is the process by which data are extracted from EDI translation
process and integrated with the data or process of receiving company.
3. Application System -The program that process the data sent to, or received from, the trading partner.
Although new controls should be developed for the EDI interface, the control for existing applications, if left
unchanged, are usually unaffected.
The following were incorrect answers:
Communication handler - Process for transmitting and receiving electronic documents between trading
partners via dial-up lines, public switched networks, multiple dedicated lines or a value added network
(VAN).
Application System -The program that process the data sent to, or received from, the trading partner.
Although new controls should be developed for the EDI interface, the control for existing applications, if left
unchanged, are usually unaffected.
Application Interface - This interface moves electronic transactions to or from the application systems and
perform data mapping.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 178
- Other Version
- 6715ISACA.CISA.v2026-02-11.q999
- 12029ISACA.CISA.v2025-05-24.q773
- 4973ISACA.CISA.v2024-10-22.q310
- 11255ISACA.CISA.v2023-10-02.q715
- 5626ISACA.CISA.v2023-03-29.q119
- 4644ISACA.CISA.v2023-02-09.q181
- 2851ISACA.CISA.v2023-02-06.q107
- 4441ISACA.CISA.v2022-08-28.q129
- 6125ISACA.CISA.v2022-02-25.q148
- 130ISACA.Actualtestpdf.CISA.v2021-11-13.by.sarah.721q.pdf
- 7778ISACA.CISA.v2021-11-11.q194
- 11190ISACA.CISA.v2021-10-08.q198
- 12292ISACA.CISA.v2021-09-28.q199
- 14915ISACA.CISA.v2021-09-11.q201
- Latest Upload
- 190Google.Professional-Cloud-DevOps-Engineer.v2026-09-16.q209
- 170AAPC.CPC.v2026-09-16.q132
- 125HP.HPE0-J82.v2026-09-16.q26
- 187F5.303.v2026-09-16.q147
- 181PaloAltoNetworks.NGFW-Engineer.v2026-09-16.q105
- 133Workday.Workday-Pro-Recruiting.v2026-09-15.q19
- 143ACAMS.CAMS-FCI.v2026-09-15.q36
- 160VMware.250-614.v2026-09-15.q42
- 205IAPP.CIPM.v2026-09-15.q217
- 177VMware.2V0-13.25.v2026-09-14.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA.v2026-01-26.q999 Practice Test
