CISA Domain 2A-3 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain A-3 (IT Policies, Standards, Procedures and Practices) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2A-3 IT Policies, Standards, Procedures and Practices Practice Test 001
10 questions • Single best answer
Question 1
During an external audit of a manufacturing company, the IS auditor notes that IT policies exist but have not been reviewed or updated in five years. During that period the company adopted several cloud services and became subject to new data protection regulations. Which finding is MOST significant?
    Question 2
    An IS auditor reviews a bank's information security documentation and finds a high-level policy stating that access to systems must be restricted. However, there is no document specifying the mandatory password length, complexity, and account lockout thresholds that employees are required to follow. Which type of document is MOST likely missing?
      Question 3
      During a governance audit of a government agency, the IS auditor discovers that several IT procedures conflict with the agency's overarching IT security policy. Business units consistently follow the local procedures rather than the policy, and no exceptions were formally documented. What should the IS auditor do FIRST?
        Question 4
        An IS auditor is assessing whether a retail organization's acceptable use policy is operating effectively, not merely whether it exists. Management asserts that all employees comply with the policy and that violations are rare. Which of the following provides the BEST evidence that the policy is effective?
          Question 5
          A financial services firm maintains a comprehensive set of IT policies, but the IS auditor finds no evidence that the policies are periodically reviewed or that a specific owner has been assigned to maintain them. Several policies reference obsolete systems. Which recommendation is MOST appropriate?
            Question 6
            An IS auditor examines an insurance company's IT policies and notes they were adapted directly from a generic industry template. The auditor is concerned the policies may not address the company's specific legal and regulatory obligations, including recently enacted data privacy requirements. What should the auditor evaluate NEXT?
              Question 7
              An IS auditor determines that a company's IT standards are frequently ignored because they were developed by the IT department without input from business units or senior management endorsement. Employees state they were unaware the standards applied to them. Which of the following is the MOST significant underlying cause of the non-compliance?
                Question 8
                An IS auditor wants to determine whether a telecommunications company's data retention procedures are actually being followed in practice, rather than simply confirming that an approved procedure document exists. Management insists that compliance is consistently high across all departments. Which testing approach would provide the MOST reliable assurance?
                  Question 9
                  An IS auditor notes that a manufacturing firm's IT policy prohibits the use of removable media, yet several departments routinely use USB drives under exceptions that the CISO states were approved verbally. No documentation of the exceptions or supporting risk analysis is available. What should the IS auditor do FIRST?
                    Question 10
                    A prior audit recommended that an energy company formalize and document its IT standards to strengthen governance. During the follow-up review, the IS auditor finds that the standards were drafted but never formally approved, published, or communicated to staff, and no owner was assigned. Which conclusion is MOST appropriate?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top