CISA Domain 3A-4 Practice Test 001

This practice test covers Domain 3 (Information Systems Acquisition, Development & Implementation) Subdomain A-4 (Control Identification and Design) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 3A-4 Control Identification and Design Practice Test 001
10 questions • Single best answer
Question 1
A government tax agency is designing a new online filing system that will process high volumes of citizen payment transactions. During the design phase, the IS auditor is asked to advise on when application control requirements should be addressed. At which point should control requirements be identified to provide the STRONGEST assurance?
    Question 2
    During an audit of a hospital's new patient billing application, the IS auditor examines how the design prevents invalid data from entering the database. The auditor wants to confirm that input controls were designed effectively. Which control provides the BEST assurance that only valid data is accepted at the point of entry?
      Question 3
      An IS auditor reviews the control design of a bank's newly developed loan origination system and finds it relies almost entirely on after-the-fact detective controls, with few preventive controls built into transaction processing. Which of the following should the auditor consider the MOST significant weakness in the control design?
        Question 4
        While evaluating the design of a manufacturing company's new procurement system, the IS auditor notes that a single role can create a vendor, approve a purchase order, and record the related goods receipt. Which of the following is the auditor's GREATEST concern regarding the system's control design?
          Question 5
          A retailer is designing a high-volume e-commerce order system that will process thousands of transactions per hour. The project team proposes relying on manual reviews to detect pricing and quantity errors after orders are placed. Which recommendation is MOST appropriate for the IS auditor to make regarding the control design?
            Question 6
            During the design review of a large employer's new payroll system, the IS auditor wants assurance that every batch submitted for processing is handled completely, with no records lost, added, or duplicated. Batches are submitted nightly from several regional offices. Which control provides the BEST assurance of processing completeness?
              Question 7
              An IS auditor is invited to participate in the design phase of a new enterprise resource planning implementation. Management questions why the auditor should be involved so early rather than after go-live. What is the BEST justification for identifying control requirements during the design phase?
                Question 8
                During a review of a credit card processor's new statement generation system, the IS auditor focuses on controls over system output. The auditor wants assurance that generated statements are accurate, complete, and released only to authorized recipients. Which control BEST addresses the risk at the output stage of processing?
                  Question 9
                  An IS auditor reviews the control design documentation for a telecommunications firm's new billing system and finds that several controls were built by developers but cannot be traced to any documented control requirement or identified risk. Which of the following is the auditor's MOST significant concern?
                    Question 10
                    A financial services firm's new trading system cannot fully enforce segregation of duties in its design because of the small size of the operations team. The IS auditor is asked how the organization should address this limitation in the control design. Which recommendation is MOST appropriate?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top