CISA Domain 2A-7 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain A-7 (Data Governance and Classification) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2A-7 Data Governance and Classification Practice Test 001
10 questions • Single best answer
Question 1
During an audit of a multinational manufacturing company's data governance program, the IS auditor finds that data classification labels exist but business units apply them inconsistently, and no single role is accountable for classification decisions across the various enterprise systems. What should the IS auditor recommend FIRST?
    Question 2
    An IS auditor is assessing whether a commercial bank's data classification scheme is operating effectively in practice rather than merely existing on paper. Which of the following would provide the BEST evidence that classification is being applied appropriately to the bank's regulated information assets across its lines of business?
      Question 3
      During a data governance review at an insurance company, an IS auditor identifies several potential findings related to data classification, stewardship, and control alignment. Which of the following findings is MOST significant from a control and risk assurance perspective and should be prioritized for reporting?
        Question 4
        An IS auditor reviews data governance roles at a government agency where business managers approve access to their data sets, IT administrators maintain the storage systems, and a central governance team defines enterprise data standards. Which role should be held accountable for determining the classification of a given data set?
          Question 5
          An IS auditor evaluating a large national retailer's data governance program finds duplicate and conflicting customer records spread across several transactional systems, resulting in unreliable management reporting and repeated marketing errors. Which single data governance practice is MOST likely missing from the retailer's overall program?
            Question 6
            A financial services company classifies its data primarily by internal business value but has never mapped those classifications to applicable data protection laws and regulatory requirements. After confirming this gap during fieldwork, what is the IS auditor's BEST recommendation to strengthen the data classification scheme?
              Question 7
              During an audit of an enterprise data governance program, the IS auditor determines that all data receives the same baseline set of security controls regardless of its assigned classification level. Which of the following represents the MOST significant risk arising from this uniform control practice?
                Question 8
                An IS auditor reviewing a telecommunications provider's data governance program finds that no data retention or disposal requirements have been defined or tied to the organization's data classification levels for any of its systems. Which finding is MOST appropriate for the auditor to report regarding this gap?
                  Question 9
                  An organization is establishing a formal data governance program and asks the IS auditor for guidance on how to build it effectively. Considering leading practice for data governance and classification, which of the following should the organization do FIRST to lay a sound and sustainable foundation?
                    Question 10
                    An IS auditor completes testing of a hospital's data classification controls and finds data owners formally assigned, labels consistently applied, and protective controls proportional to sensitivity, though the enterprise data catalog omits two minor low-risk systems. Which conclusion is MOST appropriate based on the available evidence?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top