CISA Domain 4A-5 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain A-5 (Shadow IT and End-User Computing) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4A-5 Shadow IT and End-User Computing Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor examining the finance function of a manufacturing company discovers a complex spreadsheet with embedded macros that consolidates plant-level data into the monthly financial close. The spreadsheet resides on an analyst's local drive, is unknown to IT, and operates with no version control or independent review. Which finding is MOST significant?
    Question 2
    During an audit of a financial services firm, an IS auditor learns that several business units have independently adopted unsanctioned cloud applications outside of IT's knowledge to speed up their work. The auditor has not yet assessed what data these tools process or how widely they are used. What should the auditor do FIRST?
      Question 3
      A government agency relies on a departmental database application that was built years ago by a staff member who has since left the organization. The application supports benefit eligibility decisions but has no documentation, no source code control, and no defined owner accountable for its accuracy or maintenance. Which recommendation is MOST appropriate?
        Question 4
        An IS auditor is evaluating the compensating controls that management has implemented over end-user computing spreadsheets used to prepare regulatory reports. Management asserts that the existing controls are adequate to ensure the accuracy of the figures. Which of the following controls provides the BEST assurance over the integrity of these spreadsheets?
          Question 5
          A marketing team at a retail company has been using an unapproved consumer file-sharing service to store and exchange customer contact lists that contain personal data. The service was chosen for convenience, is not covered by any vendor agreement, and was never assessed by IT or legal. Which risk is MOST significant to the organization?
            Question 6
            An IS auditor wants to assess whether an organization has effectively identified the shadow IT operating within its environment. Management provides several artifacts in support of its position. Which of the following is the BEST evidence that shadow IT is being detected on an ongoing basis rather than only discussed?
              Question 7
              During a cloud migration review at an enterprise, an IS auditor identifies a business-critical analytics tool that a department procured directly on a corporate credit card, bypassing both IT and procurement entirely. The tool now processes sensitive customer data in production. Which recommendation should the auditor prioritize?
                Question 8
                An IS auditor reviews four end-user-developed applications that are in use across an organization, and confirms that none of them are subject to formal change control or independent review. Considering audit risk and potential business impact, which of these applications represents the MOST significant concern?
                  Question 9
                  An IS auditor concludes that shadow IT has become widespread across an organization primarily because business units feel that IT cannot deliver solutions quickly enough to meet their needs. Beyond remediating the individual unauthorized tools already discovered, which recommendation BEST addresses the root cause of the problem?
                    Question 10
                    In a follow-up audit, management reports that it has remediated the previously reported end-user computing risks by issuing a formal EUC policy and cataloging the organization's critical spreadsheets. To conclude whether the previously identified risk has now been sufficiently addressed, what is the auditor's BEST course of action?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top