CISA Domain 1B-5 Practice Test 001

This practice test covers Domain 1 (Information Systems Auditing Process) Subdomain B-5 (Reporting and Communication Techniques) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 1B-5 Reporting and Communication Techniques Practice Test 001
10 questions • Single best answer
Question 1
A public university's IS audit team has completed fieldwork on its student records system and is now drafting the final report. During the closing meeting, the system owner disputes one finding and provides new documentation indicating that a compensating control already exists. Before the report is issued, what should the IS auditor do FIRST?
    Question 2
    An IS auditor is preparing to communicate the results of a review of a healthcare provider's identity and access management controls. Several findings involve technical configuration weaknesses, but the primary recipient of the report is the organization's audit committee. Which reporting approach is MOST appropriate for communicating to this audience?
      Question 3
      During an audit of a manufacturing firm's procurement system, the IS auditor identifies a control weakness that could allow duplicate vendor payments to be processed. Fieldwork is only half complete, but the exposure appears significant and is currently ongoing. Regarding communication, what is the auditor's BEST course of action?
        Question 4
        An IS audit report on a government agency's disaster recovery program contains ten findings of varying severity, ranging from minor to critical. The agency's senior leadership has limited time to review the full document. Which reporting element BEST helps decision-makers focus on the matters that require the most urgent attention?
          Question 5
          A financial services organization's IS auditor has finalized a report that contains a finding management strongly disagrees with. Management has submitted a written response asserting that the associated risk is acceptable and requires no further action. How should the auditor MOST appropriately handle this disagreement in the final report?
            Question 6
            An IS auditor is drafting recommendations after completing an audit of a large retailer's change management process. One finding is well documented at the symptom level, but its underlying cause has not yet been clearly established. Which characteristic is MOST important for the recommendation to be effective and actionable for management?
              Question 7
              Six months after issuing an audit report on an insurer's data center operations, the IS auditor begins post-audit follow-up procedures. Management has reported that all of the agreed corrective actions were completed on schedule. Which approach provides the BEST assurance that the reported remediation is actually effective?
                Question 8
                An IS auditor is finalizing a report and must communicate an overall conclusion on the effectiveness of a logistics company's IT general controls. The evidence shows that most controls are operating effectively, but one pervasive weakness affects multiple systems. How should the auditor MOST appropriately frame the overall conclusion?
                  Question 9
                  A cloud migration review at a media company produced several findings that management has agreed to remediate over the coming quarter. As the auditor documents the agreed action plan within the report, which element is MOST important for enabling effective and timely post-audit follow-up at a later date?
                    Question 10
                    While drafting the final report, an IS auditor discovers that a previously reported finding was based on incomplete data and significantly overstated the exposure. The report has already been shared in draft form with management, but it has not yet been formally issued. What is the auditor's BEST course of action?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top