CISA Domain 2A-5 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain A-5 (Enterprise Risk Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2A-5 Enterprise Risk Management Practice Test 001
10 questions • Single best answer
Question 1
During an audit of the enterprise risk management (ERM) program at a global manufacturing company, the IS auditor finds IT risks are tracked in a separate spreadsheet maintained by the IT department and are never aggregated into the enterprise risk register reviewed by the board. What should the IS auditor recommend FIRST?
    Question 2
    A healthcare provider's board approved an enterprise risk appetite statement last year. During an audit, the IS auditor notes that individual system owners set their own risk acceptance thresholds, and several accepted risks exceed the board's stated tolerance without escalation. Which finding is MOST significant?
      Question 3
      A financial institution maintains an enterprise risk register that lists more than 200 risks. The IS auditor observes that most entries have not been updated since the register was first created two years ago and that no individual risk owner is assigned to any entry. What is the auditor's BEST conclusion?
        Question 4
        A government agency assigns responsibility for identifying and managing IT risk entirely to its internal audit function, which also independently provides assurance over the same risks. During the audit, the IS auditor evaluates this arrangement against a three-lines governance model. Which concern is MOST significant?
          Question 5
          An enterprise's ERM program rates all IT risks using a simple high/medium/low scale, and the IS auditor finds that two risks rated 'high' received far less management attention than one rated 'medium' tied to a strategic initiative. What should the IS auditor recommend to improve risk prioritization?
            Question 6
            During an audit of a retailer that recently migrated its core systems to a third-party cloud provider, the IS auditor notes the ERM program still reflects the prior on-premises environment and that no reassessment of risk was performed after the migration was completed. Which finding is MOST significant?
              Question 7
              An organization's ERM policy states that the board is accountable for overseeing enterprise risk, but the IS auditor finds risk reports are prepared by IT and sent directly to operational managers, with no summary provided to the board. Which is the auditor's MOST appropriate conclusion?
                Question 8
                A manufacturing firm's ERM program defines key risk indicators (KRIs) with escalation thresholds. During testing, the IS auditor finds that several KRIs breached their defined thresholds months ago, yet no corrective action was taken and no breach was escalated to management. What should the IS auditor do FIRST?
                  Question 9
                  An IS auditor is evaluating whether a company's ERM program supports strategic decision-making. The auditor notes the enterprise risk assessment is performed annually but is not referenced during the approval of major IT investments. Which finding BEST supports a conclusion that ERM is not integrated with governance?
                    Question 10
                    Following a prior audit, an organization agreed to assign owners for all enterprise IT risks. During follow-up, the IS auditor finds owners were named but many are unaware of their assignment and have taken no mitigating action. Which conclusion is MOST appropriate regarding risk ownership?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top