CISA Domain 2B-2 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain B-2 (Vendor Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2B-2 IT Vendor Management Practice Test 001
10 questions • Single best answer
Question 1
During an audit of a healthcare provider, an IS auditor finds that a critical claims-processing function was outsourced without a formal service-level agreement. Vendor performance is tracked only through occasional informal email updates from the account manager, and no metrics or remedies are documented. Which of the following should the auditor recommend FIRST?
    Question 2
    An IS auditor is evaluating whether an outsourced payroll provider is meeting its contractual obligations. The business owner asserts that the vendor performs very well but is unable to produce any supporting records to substantiate that assertion. Which of the following would provide the BEST evidence of the vendor's actual performance against the contract?
      Question 3
      During a review of vendor management at a manufacturing firm, an IS auditor examines several cloud provider contracts that support production systems and notes a number of weaknesses across the agreements. The provider hosts sensitive engineering data critical to operations. Which of the following findings should the auditor consider the MOST significant?
        Question 4
        An IS auditor is assessing the vendor selection process for a new core banking platform. Management awarded the contract to the supplier that scored lowest against the defined security requirements because it offered the lowest overall price. The security gap was significant. Which of the following is the auditor's BEST course of action?
          Question 5
          A financial services firm relies on a third-party provider that in turn subcontracts application hosting to another company. During the vendor audit, the IS auditor learns that the organization has no visibility into the subcontractor's control environment and does not monitor it in any way. Which risk should the auditor highlight as MOST relevant?
            Question 6
            During a government agency audit, an IS auditor reviews SLA monitoring for an outsourced network services contract. The vendor's reported metrics consistently show near-perfect availability, yet business users complain of frequent outages that disrupt daily operations. The reported figures and user experience clearly diverge. Which of the following should the auditor do FIRST?
              Question 7
              An IS auditor is reviewing an organization's process for offboarding a software-as-a-service vendor whose contract has been terminated. The organization stored significant volumes of customer data in the vendor's environment. Which of the following controls would provide the BEST assurance that organizational data is protected at contract exit?
                Question 8
                An IS auditor is evaluating how an enterprise oversees its portfolio of IT vendors. Every supplier currently receives the same annual due-diligence questionnaire regardless of the services it provides or how critical it is to operations. Which of the following recommendations would MOST improve the vendor management program?
                  Question 9
                  During an audit of a retailer, an IS auditor finds that a key vendor's most recent SOC 2 Type II report contains several exceptions affecting access-management controls. The business owner acknowledges that no one has reviewed the report since it was received. What is the auditor's BEST recommendation?
                    Question 10
                    An IS auditor is reviewing contract management for a critical ERP support vendor. The agreement contains no provision addressing continuity of service if the vendor becomes insolvent or ceases operations, even though the organization depends entirely on this supplier to maintain the system. Which of the following findings should the auditor rank as the HIGHEST priority?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top