CISA Domain 5A Practice Test 001

This practice test covers Domain 5 (Protection of Information Assets) Subdomain A (Information Asset Security and Control) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA Practice Test — 5A (Information Asset Security and Control)
10 questions • Single best answer
Question 1
During an external audit of a commercial bank, the IS auditor finds that terminated employees' network accounts stayed active for an average of 45 days after departure because HR and IT had no integrated deprovisioning workflow. Records show several of these accounts accessed core banking systems after termination. Which of the following should be the auditor's MOST significant concern?
    Question 2
    An IS auditor reviewing a large retailer's data-at-rest protections finds that a database of customer payment records is encrypted, but the encryption keys are stored in plaintext in a configuration file on the same server that hosts the database. Which of the following is the auditor's MOST appropriate conclusion regarding this control?
      Question 3
      A government agency implements a public key infrastructure to support digital signatures for online citizen services. During the audit, the IS auditor notes there is no defined process for revoking certificates or for publishing and distributing a certificate revocation list. Which of the following risks is MOST significant?
        Question 4
        An IS auditor is reviewing a manufacturer's migration of a customer-facing application to a public cloud provider under an infrastructure-as-a-service model. Management asserts that the cloud provider is fully responsible for securing the operating systems and workloads deployed in the environment. Which of the following should the auditor do FIRST?
          Question 5
          During an audit of an insurance company, the IS auditor observes that a data loss prevention solution is deployed but configured only in monitor mode, generating alerts without blocking transfers. Analysts review the alerts weekly, and several confirmed exfiltration events went unaddressed for several days. Which finding is MOST significant?
            Question 6
            An IS auditor examining an enterprise network finds that the internal network is entirely flat, with production servers, user workstations, and guest wireless devices all residing on a single shared segment. Firewall filtering exists only at the internet perimeter of the network. Which of the following recommendations is MOST appropriate?
              Question 7
              An IS auditor reviewing a colocation data center notes that badge access to the server floor is logged, but the logs are never reviewed, and several active badges still belong to former contractors. The environmental monitoring systems are functioning normally. Which of the following is the auditor's BEST course of action?
                Question 8
                A financial services firm asserts that its information security program is aligned with a recognized industry framework. The IS auditor finds the controls were mapped to that framework two years ago but were never reassessed, despite significant changes to the technology environment since then. Which of the following is the auditor's MOST appropriate conclusion?
                  Question 9
                  An IS auditor assessing a logistics company's bring-your-own-device program finds that employees routinely access corporate email and file shares from personal smartphones that have no mobile device management enrollment and no remote-wipe capability configured. Which of the following risks should the auditor highlight as MOST significant?
                    Question 10
                    During an audit of an enterprise resource planning system at a utility company, the IS auditor finds that database administrators share a single privileged account whose activity cannot be attributed to any individual. Emergency access is granted through this shared account without any documented approval. Which of the following is the auditor's MOST significant concern?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top