CISA Domain 2A-1 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain A-1 (Laws, Regulations, and Industry Standards) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2A-1 Laws, Regulations, and Industry Standards Practice Test 001
10 questions • Single best answer
Question 1
A multinational manufacturer processes employee and customer data across facilities in several countries, each subject to different privacy laws. During a governance audit, the IS auditor finds no consolidated register mapping applicable regulations to specific data-processing activities. Which of the following should the auditor recommend FIRST to strengthen regulatory compliance oversight?
    Question 2
    A healthcare provider is subject to sector-specific privacy and breach-notification regulations. The IS auditor is assessing how management stays current with regulatory changes affecting its information systems and patient data. Which of the following provides the BEST evidence that the organization maintains ongoing awareness of evolving legal requirements?
      Question 3
      A new data-protection law takes effect in a jurisdiction where an online retailer stores and processes customer records. The board has asked the IS auditor to assess the organization's exposure and readiness. Before evaluating the adequacy of existing controls, which of the following should the auditor do FIRST?
        Question 4
        A payment-processing company asserts full compliance with a major card-industry security standard to its acquiring bank. During the audit, the IS auditor reviews the most recent self-assessment questionnaire and its supporting evidence. Which of the following findings would be MOST significant in challenging the compliance assertion?
          Question 5
          During an IT governance review at a government agency, the IS auditor notes that regulatory-compliance obligations are tracked informally by individual system owners with no central oversight or accountability. Which of the following represents the auditor's MOST appropriate conclusion regarding governance of legal and regulatory compliance?
            Question 6
            An enterprise operating in a heavily regulated sector wants assurance that changes in laws and industry standards are reflected in its policies and controls before they take effect. The IS auditor is evaluating the change-monitoring mechanism. Which control provides the BEST assurance that regulatory changes are addressed on time?
              Question 7
              A cloud service provider serving customers worldwide must satisfy privacy requirements from multiple jurisdictions, some of which impose conflicting obligations. The IS auditor is reviewing how management reconciles these conflicts within its control framework and policies. Which of the following recommendations is MOST appropriate for managing the conflicting requirements?
                Question 8
                An IS auditor is verifying whether an organization's information security controls comply with a mandated national cybersecurity framework. Management provides a control-mapping spreadsheet asserting that each requirement is fully met. Which of the following is the BEST audit approach to validate the compliance claim independently?
                  Question 9
                  Following a security incident at an insurance firm, regulators require breach notification within a defined statutory time limit. The IS auditor is assessing whether the organization can meet this obligation. Which of the following provides the BEST evidence that the notification requirement can be satisfied?
                    Question 10
                    An IS auditor reviewing a utility company's governance finds that its information security policies reference a superseded version of an industry standard that has since been revised. Management is unaware of the update. Which of the following is the auditor's MOST appropriate recommendation to management?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top