CISA Domain 5A-1 Practice Test 001

This practice test covers Domain 5 (Protection of Information Assets) Subdomain A-1 (Information Asset Security Frameworks, Standards, and Guidelines) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 5A-1 Information Asset Security Frameworks, Standards, and Guidelines Practice Test 001
10 questions • Single best answer
Question 1
An audit manager is reviewing a manufacturing company's decision to adopt ISO/IEC 27001 as the foundation for its information security program. Several competing frameworks were considered, and management now wants assurance that the selection is appropriate and defensible. What should the IS auditor evaluate FIRST?
    Question 2
    A government agency has mapped its security controls to the NIST Cybersecurity Framework and asserts full alignment. Management points to the completed mapping as evidence of a strong security posture. During fieldwork, the IS auditor finds the mappings exist on paper but several mapped controls are not operating. Which conclusion is MOST appropriate?
      Question 3
      An IS auditor is examining a SaaS provider's ISO/IEC 27001 implementation ahead of a certification audit. Management states that not all Annex A controls were implemented, citing documented risk-based treatment decisions. To determine which controls the organization deemed applicable and the justification for each exclusion, which document provides the BEST evidence?
        Question 4
        During an audit of a retail company that processes card payments, the IS auditor is selecting the criteria to assess the cardholder data environment. The company also follows internal security guidelines that are less stringent than industry mandates. Which basis is MOST appropriate for evaluating these controls?
          Question 5
          An energy utility is beginning to adopt the NIST Cybersecurity Framework and asks the IS auditor how to establish where its security program currently stands. Management wants a structured, repeatable way to prioritize improvements and justify future security investment. Which activity should the auditor recommend the organization perform FIRST?
            Question 6
            A university adopts a recognized control baseline and applies every control in it uniformly across all systems, including low-risk public information portals that host no sensitive data. The IS auditor notes significant effort spent on controls with little bearing on those systems. Which recommendation is MOST appropriate?
              Question 7
              An insurance company has implemented a security framework and can show documented policies for every control domain. However, the IS auditor finds no risk assessment underlies the control selection, and the controls appear to have been copied directly from the framework without tailoring. Which finding is MOST significant?
                Question 8
                A telecommunications provider's IT department independently selected and rolled out a new security framework, but senior management was not involved and has not formally endorsed the initiative. The IS auditor is assessing governance over the effort. Which concern should the auditor raise as MOST important?
                  Question 9
                  An IS auditor reviews a logistics firm's security documentation and finds that its standards and detailed procedures were written before any framework or overarching security policy was ever established. As a result, staff are unsure which requirements are authoritative. Which recommendation would BEST address the underlying weakness?
                    Question 10
                    A hospital must satisfy multiple overlapping security frameworks and regulations, which has created duplicated and sometimes conflicting control requirements across its compliance teams. Management asks the IS auditor for guidance to reduce redundant effort without losing coverage. Which approach should the auditor recommend as MOST effective?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top