CISA Domain 2A-4 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain A-4 (Enterprise Architecture and Considerations) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2A-4 Enterprise Architecture and Considerations Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor is reviewing the enterprise architecture (EA) program at a regional bank. The documented target-state architecture was approved three years ago, yet business units continue to procure systems that conflict with it and no exceptions are recorded. What should the IS auditor recommend FIRST?
    Question 2
    During an audit of a government agency's enterprise architecture (EA), the IS auditor wants to determine whether the EA is actually influencing technology investment decisions rather than serving as documentation. Which of the following would provide the BEST evidence that the EA is operating effectively?
      Question 3
      An IS auditor is reviewing the enterprise architecture (EA) function of a healthcare organization that recently completed several acquisitions and must consolidate overlapping clinical systems. The auditor observes multiple conditions across the integrated environment. Which of the following findings is MOST significant from a control assurance perspective?
        Question 4
        An IS auditor determines that an insurance company's enterprise architecture was developed independently by the IT department without input from business leadership. The architecture emphasizes technical standardization but does not clearly reference business capabilities or the organization's strategic objectives. What should the IS auditor do FIRST?
          Question 5
          A financial services firm is implementing new applications across several business lines. The IS auditor wants to assess whether the enterprise architecture is being enforced during solution delivery rather than only at design time. Which control provides the BEST assurance that new systems conform to the approved enterprise architecture?
            Question 6
            During a periodic review of enterprise architecture at a retail enterprise, the IS auditor notes that the current-state architecture contains numerous redundant and end-of-life technologies that the target-state architecture was intended to retire two years ago. Which of the following represents the GREATEST risk to the organization?
              Question 7
              An enterprise architecture program at a telecommunications company has produced detailed reference models, but architecture decisions are frequently overridden by project teams with no accountability. The IS auditor is evaluating the effectiveness of EA governance and enforcement. Which of the following is the MOST appropriate recommendation?
                Question 8
                An IS auditor is assessing whether a logistics company's enterprise architecture (EA) remains aligned with organizational objectives following a strategic shift toward cloud-based operations. The auditor must determine whether the EA is periodically revisited. Which of the following would BEST demonstrate that ongoing alignment is maintained?
                  Question 9
                  An IS auditor plans to test whether the enterprise architecture standards are consistently applied when new technology is introduced at an energy company. The auditor wants results that reflect actual practice rather than stated intent. Which testing approach would provide the MOST reliable evidence of compliance?
                    Question 10
                    A public-sector organization is adopting multiple cloud platforms and wants its enterprise architecture to address the risk of vendor lock-in and poor interoperability. The architecture must support the organization's long-term flexibility. From an EA perspective, which consideration is MOST important for the IS auditor to evaluate?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top