CISA Domain 1B-3 Practice Test 001

This practice test covers Domain 1 (Information Systems Auditing Process) Subdomain B-3 (Audit Evidence Collection Techniques) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 1B-3 Audit Evidence Collection Techniques Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor at a healthcare organization is gathering evidence to support conclusions about the effectiveness of patient-record access controls. Several sources are available, including verbal statements from IT staff, screenshots supplied by the administrator, and access logs the auditor extracts directly. Which source provides the MOST reliable audit evidence?
    Question 2
    During a financial institution's audit of its loan-approval workflow, an IS auditor must confirm that segregation of duties operates as designed. The auditor is choosing among several techniques to validate the control's actual operation. Which approach provides the BEST evidence that the control is functioning effectively?
      Question 3
      While collecting evidence during an ERP audit, an IS auditor finds that interview responses about change-approval practices conflict with entries recorded in the system's change log. The discrepancy could indicate a control weakness or an incomplete log. What should the IS auditor do FIRST?
        Question 4
        An IS auditor testing a payroll application's authorization controls has examined one processed transaction and confirmed it was properly approved. The auditor is preparing to conclude that the control operated effectively across the entire period under review. Which concern about this evidence is MOST significant?
          Question 5
          A government agency's IS auditor is verifying balances processed through an outsourced payment platform. Internal reports produced by the agency show the amounts as reconciled and complete. To strengthen assurance over the reported figures, which additional evidence would be MOST appropriate for the auditor to obtain?
            Question 6
            During a data center audit, an IS auditor personally observes that badge access to the server room is enforced on the day of the site visit. The auditor intends to conclude that physical access controls operated effectively throughout the entire year. Which limitation of this evidence is MOST significant?
              Question 7
              An IS auditor reviewing an enterprise's backup operations receives a verbal statement from operations staff that daily backups complete successfully without errors. Before drawing a conclusion, the auditor wants to substantiate this claim with more reliable evidence. Which action would BEST corroborate the staff's statement?
                Question 8
                During an audit prompted by suspected unauthorized transactions, an IS auditor collects electronic records that may later support disciplinary or legal action by management. Preserving the evidentiary value of these records is critical. Which practice is MOST important to maintain the integrity and reliability of the collected evidence?
                  Question 9
                  An IS auditor is evaluating whether terminated employees' system access is revoked promptly. So far the auditor has only interviewed HR and IT personnel, who both confirm that the deprovisioning process operates as intended. Which conclusion about the sufficiency of this evidence is MOST appropriate?
                    Question 10
                    While concluding on a firewall configuration control, an IS auditor is prioritizing which forms of evidence to rely on. The available options include management inquiry, direct observation, inspection of change records, and auditor reperformance. Which type generally provides the STRONGEST assurance that the control operates effectively?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top