exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 66 discussion

Actual exam question from Isaca's CISA
Question #: 66
Topic #: 1
[All CISA Questions]

During an internal audit of automated controls, an IS auditor identifies that the integrity of data transfer between systems has not been tested since successful implementation two years ago. Which of the following should the auditor do NEXT?

  • A. Review previous system interface testing records.
  • B. Document the finding in the audit report.
  • C. Review relevant system changes.
  • D. Review IT testing policies and procedures.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
murphseal
Highly Voted 2 years, 3 months ago
The first thing you need to do is review the policies and procedures because this may not even be a finding. If testing isn't required within that timeframe then nothing needs to be done.
upvoted 9 times
...
murphseal
Highly Voted 2 years, 3 months ago
The first thing you need to do is review the policies and procedures because this may not even be a finding. If testing isn't required within that timeframe then nothing needs to be done.
upvoted 5 times
...
Greens
Most Recent 1 week, 1 day ago
Selected Answer: C
C. Review relevant system changes is the best next step because it helps the auditor determine whether any modifications have occurred in the systems or interfaces that could affect data integrity. If no changes have occurred since implementation, the risk may be lower. If changes have been made, the lack of re-testing becomes a more serious control gap. Comparisons: A. Review previous system interface testing records – Useful to establish a baseline, but not sufficient on its own. You still need to assess what has changed since that time. B. Document the finding in the audit report – This may be appropriate eventually, but the auditor needs to gather more context (such as system changes) before determining the risk and significance of the finding. D. Review IT testing policies and procedures – Helps understand expected practices, but it doesn’t assess the actual risk posed by the current situation.
upvoted 1 times
...
teamt
3 months, 3 weeks ago
Selected Answer: C
Answer: C Reviewing system changes can reveal if there have been updates, modifications, or integrations that could affect data integrity.
upvoted 1 times
...
a84n
8 months ago
Selected Answer: C
Answer: C
upvoted 2 times
...
5b56aae
8 months, 1 week ago
Selected Answer: D
D is about testing
upvoted 2 times
...
Swallows
8 months, 3 weeks ago
Selected Answer: D
Policies should identify rules for how often IT testing should be performed.
upvoted 1 times
...
Ijahbee
9 months, 1 week ago
Selected Answer: C
It says automated control, therefore, it would be performing correctly since the last test if there has been no changes to the application.
upvoted 4 times
...
Yejide03
11 months ago
Selected Answer: D
What does the policy say first? That would determine the other options listed.
upvoted 3 times
...
I_finite
1 year, 3 months ago
Selected Answer: D
Confirm what the Policy states for the testing timeframe.
upvoted 3 times
...
starzuu
1 year, 5 months ago
Selected Answer: D
its definitely not A. I think it must be D.
upvoted 1 times
...
necoll007
1 year, 5 months ago
C is completely WRONG. As an IS auditor, you’d want to check their policies and procedures to see what they have documented as a standard review timeframe.
upvoted 3 times
...
3008
1 year, 6 months ago
Selected Answer: D
d is answer
upvoted 4 times
...
007Georgeo
1 year, 7 months ago
Selected Answer: C
The answer is correct, Review the changes
upvoted 4 times
...
Delta67
1 year, 9 months ago
C Review the changes, still include the finding in the audit report.
upvoted 2 times
...
Broesweelies
1 year, 10 months ago
Selected Answer: A
The next step the IS auditor should take in this scenario is to review previous system interface testing records. This will provide the auditor with information about how the system interfaces were tested during the implementation two years ago and whether any issues were identified at that time. It will also help the auditor determine if any changes have been made to the system interfaces since the previous testing.
upvoted 2 times
saado9
1 year, 9 months ago
CHAT GPT IS NOT ALWAYS TRUE! STOP POSTING PLEASE IF YOU ARE NOT SURE!
upvoted 8 times
...
...
Zephaniah
2 years, 3 months ago
Why not D. Am confused.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...