HomeCISA Audit Exam Prep 2026Questions 21–30
CISA Audit Exam Prep 2026Part 3 of 3

CISA Audit Exam Prep 2026 Exam Questions & Answers (21–30)

CISA Audit Exam Prep 2026 practice questions and answers. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CISA Audit Exam Prep 2026 questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q21In the context of business continuity planning, which of the following is NOT considered a key component of a disaster recovery plan?

    • ACommunication plans
    • BEmployee training programs
    • CData backup and recovery procedures
    • DEmergency response teams
    Show answer

    ✓ Correct answer: B. Employee training programs

    Answer: Employee training programs Employee training programs are important but are not typically a key component of the disaster recovery plan itself. Key components of a disaster recovery plan include data backup and recovery procedures, emergency response teams, and communication plans to ensure that critical business functions can be restored after a disaster.

  2. Q22An effective incident response plan should include several key phases. These phases encompass all of the following EXCEPT:

    • ADetection and analysis
    • BContainment, eradication, and recovery
    • CAnnual financial audit
    • DPreparation
    Show answer

    ✓ Correct answer: C. Annual financial audit

    Answer: Annual financial audit An effective incident response plan includes several key phases: preparation, detection and analysis, containment, eradication, and recovery. An annual financial audit is important for financial oversight but is not a component of an incident response plan. Preparation involves setting up and configuring an incident response capability. Detection and analysis determine if an incident has occurred and analyze its impact. Containment, eradication, and recovery aim to control the incident, eliminate the threat, and restore normal operations. The annual financial audit assesses financial practices and compliance but does not directly relate to handling information security incidents.

  3. Q23A company is currently defining how their disaster recovery procedures should be detailed and how their systems will need to operate to ensure business continuity. In which phase of the business continuity planning lifecycle are they?

    • ADesign
    • BTesting
    • CImplementation
    • DEvaluation
    Show answer

    ✓ Correct answer: A. Design

    Answer: Design In the business continuity planning lifecycle, the design phase is where specific details of disaster recovery procedures and the necessary system operations for ensuring business continuity are defined. The testing phase involves testing the disaster recovery plans. The implementation phase is when the plans are put into action. The evaluation phase is when the plans and processes are reviewed for effectiveness.

  4. Q24What is the term for the software that is implemented on servers and desktops to automatically gather and transmit log files to a central repository?

    • AVirtual machines
    • BMicroservices
    • CAgents
    • DContainers
    Show answer

    ✓ Correct answer: C. Agents

    Answer: Agents Agents are small software components used to gather and transmit data, such as log files, to a central repository for processing and storage. They are essential for automating system monitoring and backup tasks. Containers are self-contained software environments that include all necessary dependencies. Virtual machines are virtualized instances of physical machines. Microservices are a way of designing software as a collection of smaller, loosely coupled services.

  5. Q25Which of the following is NOT a phase in the standard risk management process for an information system?

    • AMonitoring risks
    • BImplementing risk mitigation measures
    • CIdentifying risks
    • DAssessing risks
    Show answer

    ✓ Correct answer: B. Implementing risk mitigation measures

    Correct answer: Implementing risk mitigation measures The standard risk management process includes identifying risks, assessing risks, and monitoring risks. However, actually implementing risk mitigation measures is beyond the scope of the risk management process itself.

  6. Q26In a corporate network environment, one of the key aspects an auditor should review is the network switch. What is the primary function of a network switch?

    • AMonitors network traffic for anomalies
    • BSets a flag indicating the status of each transmitted packet
    • CRoutes data based on IP addresses
    • DProvides communication linkage among different devices in the network
    Show answer

    ✓ Correct answer: D. Provides communication linkage among different devices in the network

    Answer: Provides communication linkage among different devices in the network. A network switch facilitates communication links between various devices within the network. The IS auditor needs to examine the security and functional performance of the switch, review the switch’s configuration settings, and assess any third-party audit reports regarding its operations. If such audits are not available, a physical inspection may be necessary. The other choices do not accurately describe the function of a network switch.

  7. Q27Which statement accurately describes an aspect of how a risk assessment process should be structured in an organization?

    • AOnly senior management should conduct the risk assessments.
    • BRisk assessments should only be conducted during internal audits.
    • CExternal auditors should be brought in for every assessment.
    • DClear criteria need to be established for evaluating risk levels.
    Show answer

    ✓ Correct answer: D. Clear criteria need to be established for evaluating risk levels.

    Clear criteria need to be established for evaluating risk levels in any risk assessment process. This ensures consistency and reliability in assessing potential risks. While risk assessments can involve various stakeholders, it is not essential for only senior management to conduct them, nor should they be confined to internal audits. It is also not always necessary to bring in external auditors for each assessment.

  8. Q28An auditor evaluates the quality of an information system control using a sample with a confidence level of 90%. What is the sampling risk?

    • AThe average of all sample values
    • B10%
    • C5%
    • DThe total variation of all samples
    Show answer

    ✓ Correct answer: B. 10%

    Answer: 10% The sampling risk is equal to 1 minus the confidence level. For a confidence level of 90%, the sampling risk is $$1 - 0.90$$, which is 0.10 (10%). The total variation of all samples refers to the measure of dispersion of the sample values, while the average of all sample values is the sample mean.

  9. Q29An auditor is assessing the compliance of internal controls in a financial institution. They select a sample size with a 95% confidence coefficient. What can be inferred about the reliability of the sample in representing the population?

    • AIt has an insufficient degree of comfort.
    • BIt has a high degree of comfort.
    • CIt has a low degree of comfort.
    • DIt has a very high degree of comfort.
    Show answer

    ✓ Correct answer: B. It has a high degree of comfort.

    Answer: It has a high degree of comfort. The confidence coefficient is the probability that the characteristics of a sample are a true representation of the population. For a greater confidence coefficient, a larger sample size should be used. A 90-percent confidence coefficient is considered low. A 99-percent confidence coefficient is very high. Below 90 percent is an insufficient degree of comfort.

  10. Q30An IS auditor is investigating a company's network security protocols. They discover that manual updates to the firewall rules are subject to human error due to the complexity and volume of rules. This scenario pertains to which of the following?

    • ADetection risk
    • BSampling risk
    • CControl risk
    • DInherent risk
    Show answer

    ✓ Correct answer: C. Control risk

    Answer: Control risk Control risk relates to the risk that a material error exists that would not be prevented or detected within an appropriate time period by the system of internal controls. In this example, the control risk associated with manual updates to the firewall rules would be high due to the complexity and volume of rules. Detection risk is the risk that material errors or misstatements will not be detected by the auditor. Inherent risk is the risk that something will occur without considering implemented controls. Sampling risk is the risk that the sampling method will not detect issues.

Free practice here. Timed mocks when you are ready.

Use the free CISA Audit Exam Prep 2026 sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.