CISA Audit Exam Prep 2026 practice questions and answers. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q21In the context of business continuity planning, which of the following is NOT considered a key component of a disaster recovery plan?
✓ Correct answer: B. Employee training programs
Answer: Employee training programs Employee training programs are important but are not typically a key component of the disaster recovery plan itself. Key components of a disaster recovery plan include data backup and recovery procedures, emergency response teams, and communication plans to ensure that critical business functions can be restored after a disaster.
Q22An effective incident response plan should include several key phases. These phases encompass all of the following EXCEPT:
✓ Correct answer: C. Annual financial audit
Answer: Annual financial audit An effective incident response plan includes several key phases: preparation, detection and analysis, containment, eradication, and recovery. An annual financial audit is important for financial oversight but is not a component of an incident response plan. Preparation involves setting up and configuring an incident response capability. Detection and analysis determine if an incident has occurred and analyze its impact. Containment, eradication, and recovery aim to control the incident, eliminate the threat, and restore normal operations. The annual financial audit assesses financial practices and compliance but does not directly relate to handling information security incidents.
Q23A company is currently defining how their disaster recovery procedures should be detailed and how their systems will need to operate to ensure business continuity. In which phase of the business continuity planning lifecycle are they?
✓ Correct answer: A. Design
Answer: Design In the business continuity planning lifecycle, the design phase is where specific details of disaster recovery procedures and the necessary system operations for ensuring business continuity are defined. The testing phase involves testing the disaster recovery plans. The implementation phase is when the plans are put into action. The evaluation phase is when the plans and processes are reviewed for effectiveness.
Q24What is the term for the software that is implemented on servers and desktops to automatically gather and transmit log files to a central repository?
✓ Correct answer: C. Agents
Answer: Agents Agents are small software components used to gather and transmit data, such as log files, to a central repository for processing and storage. They are essential for automating system monitoring and backup tasks. Containers are self-contained software environments that include all necessary dependencies. Virtual machines are virtualized instances of physical machines. Microservices are a way of designing software as a collection of smaller, loosely coupled services.
Q25Which of the following is NOT a phase in the standard risk management process for an information system?
✓ Correct answer: B. Implementing risk mitigation measures
Correct answer: Implementing risk mitigation measures The standard risk management process includes identifying risks, assessing risks, and monitoring risks. However, actually implementing risk mitigation measures is beyond the scope of the risk management process itself.
Q26In a corporate network environment, one of the key aspects an auditor should review is the network switch. What is the primary function of a network switch?
✓ Correct answer: D. Provides communication linkage among different devices in the network
Answer: Provides communication linkage among different devices in the network. A network switch facilitates communication links between various devices within the network. The IS auditor needs to examine the security and functional performance of the switch, review the switch’s configuration settings, and assess any third-party audit reports regarding its operations. If such audits are not available, a physical inspection may be necessary. The other choices do not accurately describe the function of a network switch.
Q27Which statement accurately describes an aspect of how a risk assessment process should be structured in an organization?
✓ Correct answer: D. Clear criteria need to be established for evaluating risk levels.
Clear criteria need to be established for evaluating risk levels in any risk assessment process. This ensures consistency and reliability in assessing potential risks. While risk assessments can involve various stakeholders, it is not essential for only senior management to conduct them, nor should they be confined to internal audits. It is also not always necessary to bring in external auditors for each assessment.
Q28An auditor evaluates the quality of an information system control using a sample with a confidence level of 90%. What is the sampling risk?
✓ Correct answer: B. 10%
Answer: 10% The sampling risk is equal to 1 minus the confidence level. For a confidence level of 90%, the sampling risk is $$1 - 0.90$$, which is 0.10 (10%). The total variation of all samples refers to the measure of dispersion of the sample values, while the average of all sample values is the sample mean.
Q29An auditor is assessing the compliance of internal controls in a financial institution. They select a sample size with a 95% confidence coefficient. What can be inferred about the reliability of the sample in representing the population?
✓ Correct answer: B. It has a high degree of comfort.
Answer: It has a high degree of comfort. The confidence coefficient is the probability that the characteristics of a sample are a true representation of the population. For a greater confidence coefficient, a larger sample size should be used. A 90-percent confidence coefficient is considered low. A 99-percent confidence coefficient is very high. Below 90 percent is an insufficient degree of comfort.
Q30An IS auditor is investigating a company's network security protocols. They discover that manual updates to the firewall rules are subject to human error due to the complexity and volume of rules. This scenario pertains to which of the following?
✓ Correct answer: C. Control risk
Answer: Control risk Control risk relates to the risk that a material error exists that would not be prevented or detected within an appropriate time period by the system of internal controls. In this example, the control risk associated with manual updates to the firewall rules would be high due to the complexity and volume of rules. Detection risk is the risk that material errors or misstatements will not be detected by the auditor. Inherent risk is the risk that something will occur without considering implemented controls. Sampling risk is the risk that the sampling method will not detect issues.
Use the free CISA Audit Exam Prep 2026 sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.