CISA Domain 4A-2 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain A-2 (IT Asset Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4A-2 IT Asset Management Practice Test 001
10 questions • Single best answer
Question 1
During an audit of a regional hospital's IT asset management program, the IS auditor notes that decommissioned servers awaiting disposal are stored in an unlocked area, and disposal records do not indicate whether drives were sanitized. Several units previously hosted patient data. Which finding is MOST significant?
    Question 2
    An IS auditor reviewing a bank's software asset management process discovers that the number of deployed instances of a licensed database product exceeds the entitlements recorded in the procurement system. Management asserts that unused licenses from retired servers cover the gap. What should the auditor do FIRST?
      Question 3
      An IS auditor wants to determine whether an enterprise's hardware asset inventory is complete. The IT department maintains a manually updated spreadsheet and also runs an automated network discovery tool weekly. Which of the following provides the BEST evidence that all network-connected devices are recorded in the asset register?
        Question 4
        During an audit of a government agency, the IS auditor finds no single group is accountable for maintaining the IT asset register. Multiple teams update it inconsistently using different naming conventions, producing duplicate and orphaned records that undermine the accuracy of management reporting. Which recommendation is MOST appropriate?
          Question 5
          A telecommunications company outsources disposal of retired storage media to a third-party vendor. The vendor issues a monthly summary invoice listing quantities collected. During the audit, the IS auditor seeks assurance that data on disposed media cannot be recovered. Which control provides the BEST assurance?
            Question 6
            During a review of an enterprise's IT operations, an IS auditor compares an automated discovery scan to the asset register and identifies numerous network-connected devices that do not appear in the register. Management cannot readily identify the owners of these devices. Which conclusion is MOST appropriate?
              Question 7
              An IS auditor examining asset lifecycle controls at a logistics company finds that new hardware is frequently deployed to production before being recorded in the asset register, and physical tagging occurs weeks later. What should the auditor do FIRST to assess the impact of this condition?
                Question 8
                During an enterprise IT audit, the IS auditor notes that the IT asset register maintained by operations and the fixed-asset ledger maintained by finance show materially different counts of computing equipment, and no periodic reconciliation is performed between them. Which of the following is the MOST significant concern?
                  Question 9
                  An IS auditor evaluating an insurer's IT asset management program observes that several end-of-life servers no longer supported by the vendor remain in production and continue to process live customer transactions. Which risk is MOST directly associated with retaining these unsupported assets in the environment?
                    Question 10
                    While auditing a retailer's IT operations, an IS auditor wants to test whether the assets recorded in the IT asset register actually exist and are deployed as documented. The register contains several thousand hardware entries across multiple sites. Which testing approach provides the BEST evidence of asset existence?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top