CISA Domain 2B-3 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain B-3 (IT Performance Monitoring and Reporting) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2B-3 IT Performance Monitoring and Reporting Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor reviewing the IT performance management framework of a retail enterprise finds that all reported metrics are operational or technical, such as server uptime and help-desk ticket volume. None of the measures are linked to business objectives or strategic goals. Which of the following should the auditor recommend FIRST?
    Question 2
    An IS auditor examines a financial institution's IT performance dashboard. All key performance indicators are reported as within target, yet the number of security incidents has climbed steadily over the past two quarters despite the favorable metrics. Which of the following findings is MOST significant?
      Question 3
      An IS auditor wants to determine whether an enterprise's IT performance metrics genuinely support its strategic objectives. The IT department reports dozens of metrics each period, but management provides no documentation linking them to corporate goals. Which of the following would provide the BEST evidence of alignment?
        Question 4
        During a review of a government agency's IT performance reports, an IS auditor notes that key performance indicator values are manually keyed into a spreadsheet by the same operations team whose performance the metrics measure. No independent check is performed on the figures. Which of the following should concern the auditor MOST?
          Question 5
          An IS auditor is evaluating controls over the reliability of an organization's reported IT performance metrics. Several stakeholders rely on these figures for investment and staffing decisions. Which of the following controls provides the BEST assurance that the reported metrics are accurate and complete?
            Question 6
            A manufacturer's IT risk dashboard shows that a key risk indicator for unpatched critical vulnerabilities has exceeded its defined threshold for three consecutive months. No corresponding remediation or escalation activity has been recorded during that period. Which conclusion is MOST appropriate?
              Question 7
              An IS auditor finds that IT performance results are compiled each quarter by the IT department but are never presented to the board or the IT steering committee. Management states the results are used only internally by IT. What is the auditor's BEST course of action?
                Question 8
                An organization establishes all of its IT performance targets based solely on its own prior-year results. An IS auditor is assessing whether this practice yields meaningful insight into IT effectiveness. Which recommendation is MOST appropriate to improve the value of the organization's performance monitoring?
                  Question 9
                  An IS auditor is assessing whether an organization's IT key performance indicators actually drive corrective action rather than serving only as reporting formalities. The organization reports numerous indicators each quarter across several systems. Which of the following testing approaches would provide the BEST evidence?
                    Question 10
                    A cloud migration review finds that although the service provider issues detailed monthly performance reports, the organization does not independently verify the reported figures against its own monitoring data. Service credits and renewal decisions rely on these reports. Which finding is MOST significant?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top