CISA Audit Exam Prep 2026 practice questions and answers. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q11Which of the following roles ensures that software development processes comply with regulatory and compliance requirements to protect sensitive information?
✓ Correct answer: D. Compliance officer
Answer: Compliance officer The compliance officer is responsible for ensuring that software development processes adhere to all regulatory and compliance requirements, thereby protecting sensitive information. A systems architect designs the overall system structure. A project manager oversees project execution but doesn't focus on compliance. A database administrator manages database-related tasks.
Q12What type of security solution is implemented to mitigate risks for enterprise laptops and desktops?
✓ Correct answer: B. Endpoint Protection
Answer: Endpoint Protection Endpoint protection refers to a comprehensive security solution used to safeguard laptops, desktops, and other endpoints. It includes antivirus, anti-malware, and firewall features to protect against various types of threats. Security information and event management (SIEM) is a solution for aggregating logs to identify threats and intrusions. Data loss prevention (DLP) is used for preventing data exfiltration. An intrusion prevention system (IPS) is used to actively stop incidents.
Q13Which feature of a firewall helps to manage and control web traffic based on the content of the data packets?
✓ Correct answer: C. Deep Packet Inspection (DPI)
Answer: Deep Packet Inspection (DPI) Deep Packet Inspection (DPI) is a network packet filtering technique that examines the data part (and possibly also the header) of a packet as it passes an inspection point. DPI is used to detect intrusions, filter out unwanted content (such as malware), and manage network traffic efficiently. Port filtering restricts traffic based on port numbers. IP filtering blocks or allows traffic based on IP addresses. Packet header inspection only examines the header of data packets, not their content.
Q14An organization implements a cloud-based storage solution allowing employees to access their files from anywhere. What advantage does this setup provide, similar to benefits seen in a three-tier client-server architecture?
✓ Correct answer: A. Centralized data management
Answer: Centralized data management In a cloud-based storage solution, data is maintained centrally on remote servers. This setup allows for central management and access to data from multiple locations, similar to how a three-tier client-server architecture centralizes processing and data storage on central servers. Localized data storage and distributed processing do not reflect the centralized management aspect. Data redundancy refers to duplicating data to improve reliability, not centralized access.
Q15Public Key Infrastructure (PKI) is a framework for securing communications using pairs of cryptographic keys. In which environment is PKI primarily intended to be used?
✓ Correct answer: D. Internet and network communication
Answer: Internet and network communication Public Key Infrastructure (PKI) is designed to enable secure communication and authentication over internet and network systems. It uses pairs of cryptographic keys: a public key that can be shared widely and a private key that is kept secret. PKI supports various security services such as confidentiality, integrity, and non-repudiation. By establishing a framework of digital certificates and trusted certification authorities, PKI helps in validating the identity of parties involved in communications. This is essential for secure online transactions, protected emails, and virtual private networks (VPNs).
Q16An auditor is evaluating the cybersecurity measures of a company. They observe that the company uses multi-factor authentication (MFA) for remote access, employs encrypted communications for internal emails, regularly updates antivirus software, and restricts access to sensitive servers using biometric scanners. Based on this information, what should the auditor recommend?
✓ Correct answer: C. Implement logging and monitoring of biometric access
Answer: Implement logging and monitoring of biometric access While the company has robust cybersecurity measures in place such as MFA, encryption, regular antivirus updates, and biometric scanners, it should also ensure comprehensive logging and monitoring of biometric access. This will help in detecting and responding to potential breaches more effectively.
Q17What is the practice of searching through trash bins to find sensitive information that has been discarded without proper destruction?
✓ Correct answer: B. Dumpster diving
Answer: Dumpster diving Dumpster diving refers to the practice of searching through commercial or residential waste to find information that can be used for malicious purposes. This can include discarded confidential documents, old computers, or personal information. To prevent this, organizations should ensure that sensitive information is properly shredded or stored securely before disposal. Traffic analysis is used to monitor and examine network traffic. War chalking involves marking locations with wireless networks. War driving involves scanning for wireless networks while driving.
Q18An auditor is reviewing the organization's information access protocols. Data types are categorized as "highly sensitive," "sensitive," "internal," and "public." Which type only requires access controls during modification?
✓ Correct answer: A. Public
Answer: Public Public data is accessible to everyone. However, access controls are required when updating this information. Highly sensitive, sensitive, and internal data demand stricter access controls compared to public data.
Q19Firewalls are systems designed to prevent unauthorized access to or from a private network. What are the two basic kinds of firewalls?
✓ Correct answer: D. Packet-filtering and stateful inspection
Answer: Packet-filtering and stateful inspection Firewalls are classified mainly as packet-filtering and stateful inspection firewalls. Packet-filtering firewalls filter traffic based on pre-determined policies or rules set by the administrator. Stateful inspection firewalls, also known as dynamic packet filtering, monitor the state of active connections and make decisions based on the context of the traffic. This allows for more advanced filtering and better security than simple packet-filtering firewalls. By employing both types of firewalls, organizations can provide multilayered protection against unauthorized access while keeping network performance optimized.
Q20A company needs to ensure database transaction integrity between two sites. The primary database logs every change and sends these logs to a secondary site in real-time. The primary site proceeds with the transaction only after it confirms the secondary site has received the logs. What type of method is being used to ensure transaction integrity?
✓ Correct answer: D. Synchronous replication
Answer: Synchronous replication Synchronous replication ensures transaction integrity by replicating data in real-time to a secondary site and requiring confirmation from the secondary site before proceeding with the transaction at the primary site. Asynchronous replication, in contrast, sends data to the secondary site without waiting for confirmation. Data mirroring replicates data at frequent intervals but may not ensure real-time consistency. Log shipping involves periodically sending transaction logs to a secondary site, which does not guarantee immediate consistency.
Use the free CISA Audit Exam Prep 2026 sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.