CISA Domain 1B-4 Practice Test 001

This practice test covers Domain 1 (Information Systems Auditing Process) Subdomain B-4 (Audit Data Analytics) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 1B-4 Audit Data Analytics Practice Test 001
10 questions • Single best answer
Question 1
A commercial bank's internal audit team plans to use generalized audit software to analyze the entire population of wire transfers for the fiscal year rather than relying on a statistical sample. The auditor receives a data extract of transaction records that was prepared and provided by the IT department. Before running any analytics routines against the file, what should the IS auditor do FIRST?
    Question 2
    During an audit of a large retailer's procurement cycle, the audit lead wants controls over purchase orders and receipts to be tested automatically, with exceptions flagged as transactions occur rather than reviewed weeks after period-end. The retailer processes high transaction volumes across many stores each day. Which data analytics approach BEST meets this stated objective?
      Question 3
      An IS auditor uses data analytics to examine a manufacturer's vendor disbursements and identifies 800 exceptions within a population of 120,000 payments. Management insists the disbursement process is well controlled and that the auditor's logic is flawed. Before documenting the exceptions as audit findings and communicating them to stakeholders, what should the auditor do FIRST?
        Question 4
        An audit team is selecting a testing strategy for a government agency's payroll transactions and has the analytics capability to process every record. During planning, leadership asks the auditor to justify recommending full-population analytics over traditional statistical sampling of the payroll file. Which statement BEST describes the primary advantage of the full-population approach in this situation?
          Question 5
          An IS auditor at an insurance company applies Benford's Law to a full year of claim-reimbursement amounts and finds that the leading-digit distribution deviates sharply from the frequencies the model predicts. No other testing has yet been performed on the population. Based on this analytical result alone, which conclusion is MOST appropriate for the auditor to reach?
            Question 6
            A financial services firm engages its IS auditor to perform a data analytics review over customer refund transactions processed during the year. The auditor is eager to move quickly and begins requesting data extracts so testing can start right away. To ensure the analytics engagement is effective and defensible, what should the auditor establish FIRST?
              Question 7
              An IS auditor reviewing a logistics company wants ongoing assurance that only authorized changes to master supplier data occur in the production system. The auditor proposes embedding routines inside the application that capture and record transactions meeting defined audit criteria, writing them to a separate file for later review. Which analytics technique is the auditor describing?
                Question 8
                An IS auditor obtains a system extract of purchase orders in order to perform full-population analytics but is concerned the file may not include every record generated during the period under review. The auditor wants strong assurance before drawing conclusions from the data. Which procedure provides the BEST assurance that the extracted dataset is complete?
                  Question 9
                  During a continuous-monitoring engagement at an energy utility, an IS auditor's analytics routine generates a high volume of daily exception alerts, and the majority prove on review to be false positives. Operations management complains that the alerts are unmanageable and are eroding confidence in the audit tool. What is the auditor's BEST course of action?
                    Question 10
                    An IS auditor presents data analytics results showing a cluster of after-hours journal entries posted by a single user to a cloud-based ERP during month-end close. Management explains that the entries relate to a legitimate automated closing job that runs overnight. Given only this explanation and the analytics output, which conclusion is MOST appropriate for the auditor?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top