CISA Domain 2B-4 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain B-4 (Quality Assurance and Quality Management of IT) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2B-4 Quality Assurance and Quality Management of IT Practice Test 001
10 questions • Single best answer
Question 1
During an audit of a government agency's IT quality assurance function, the IS auditor observes that QA analysts report directly to the development managers whose deliverables they inspect. Project deadlines routinely override quality gate sign-offs, and no exceptions are escalated to an independent authority. Which of the following findings is MOST significant to the IS auditor?
    Question 2
    A manufacturing company's IT department maintains both a quality assurance program and separate quality control activities. Management asks the IS auditor to confirm that the two responsibilities are correctly separated within the software delivery function. Which of the following activities is MOST appropriately classified as quality assurance rather than quality control?
      Question 3
      An enterprise claims that its IT organization operates a certified quality management system aligned with ISO 9001. The IS auditor is asked to verify that the QMS is functioning as intended, not merely certified on paper. Which of the following provides the BEST evidence of an effective quality management system?
        Question 4
        A financial services firm's IT quality management program reports a single measure: the number of defects found during testing each quarter. The count has declined steadily, which management presents to the board as proof of improving software quality. Which of the following is the IS auditor's BEST conclusion regarding this reporting?
          Question 5
          An IS auditor evaluates the maturity of a software provider's quality management processes. The organization performs quality activities, but only reactively, with practices varying by individual project team and no consistent measurement or defined standard process. Which characterization of the organization's process maturity is MOST appropriate?
            Question 6
            During a post-implementation review at a healthcare provider, the IS auditor finds that the new clinical system passed all functional tests but bypassed the planned quality assurance review before go-live because of schedule pressure. No compensating review was performed. Which of the following is the auditor's BEST course of action?
              Question 7
              A telecommunications company's IT quality program logs recurring production incidents but closes each one by restoring service, without analyzing the underlying causes. As a result, the same defects reappear across successive releases. Which recommendation should the IS auditor consider MOST appropriate to strengthen the quality management process?
                Question 8
                An IS auditor reviews an insurance company's IT quality management system and finds detailed, well-written procedures, but no evidence that senior management reviews quality performance results or allocates resources toward the stated quality objectives during the period under review. Which of the following findings is MOST significant to the IS auditor?
                  Question 9
                  A logistics firm states that its IT function follows a formal continuous improvement program for quality. To assess whether the improvement is real rather than nominal, the IS auditor gathers supporting information. Which of the following would provide the BEST evidence that the program is effective?
                    Question 10
                    A retail bank outsources application development to a third-party vendor and relies entirely on the vendor's internal quality assurance function. The IS auditor must assess assurance over the quality of the delivered software. Which of the following is the BEST approach for the IS auditor to take?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top