Browse all practice questions for the CISA Domain 2 Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISA Domain 2 Practice Exam 2026 - Free CISA Practice Questions and Study Guide for Domain 2 course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is the most critical aspect for an IS auditor to consider when reviewing an enterprise's project portfolio?
  • What is essential for an IS auditor to check in an outsourced help desk service agreement?
  • Which of the following is the best practice for ensuring compliance in IT policies?
  • When should an IS auditor be most concerned about the security policy?
  • When an organization outsources its help desk, what is the IS auditor's greatest concern in the contract review?
  • What is the MOST critical factor for maintaining a successful security policy?
  • What is the primary concern when employees are unaware of the organization's information security policy?
  • During an audit, which situation is MOST concerning for an organization that outsources IS processing to a private network?
  • What is essential for an effective IT strategy within an organization?
  • During which phase of e-business security assessment should risks first be identified?
  • An organization seeking to improve its risk management strategies should prioritize which governance aspect?
  • What is the main concern for an IS auditor when a service provider outsources work involving confidential information?
  • What primary concern should an IS auditor have regarding compliance with IT governance?
  • What does risk transfer address primarily?
  • What is the most effective way to achieve value delivery from IT to the business?
  • Which of the following is typically included in an organization's strategic plan?
  • What is the purpose of aligning IT risk with business objectives?
  • What is the most critical success factor when developing a formal enterprise security program?
  • What is the most important element for the successful implementation of IT governance?
  • What is the most effective method for ensuring contract compliance with a vendor after signing?
  • Which risk management practice is likely to expose an organization to the greatest compliance risk?
  • What strategy should IT management employ when evaluating new technology implementations?
  • How can the risk associated with electronic evidence gathering be mitigated?
  • As a result of profitability pressure, what is the BEST recommendation of an IS auditor to senior management?
  • Which activity is essential for minimizing the risk associated with short-term employees in an IS audit department?
  • What is the most likely effect of a lack of senior management commitment to IT strategic planning?
  • Which element should be included in an organization's information security policy?
  • Which role is responsible for implementing, monitoring, and enforcing the security rules established by management?
  • What is a major role of documentation in the meetings of the IT steering committee?
  • What is a key responsibility of senior management concerning risk?
  • Which responsibility should NOT be expected of a chief security officer?
  • What is the best reason for implementing conditions on secondary employment for IT staff?
  • When should vendors be invited to IT steering committee meetings?
  • A decision support system primarily aids management in:
  • What should be the IS auditor's approach to incidents not documented in the risk assessment plan?
  • When software development is outsourced to a startup company, what should an IS auditor recommend?
  • What does a balanced scorecard help organizations measure?
  • What does a lack of adequate security controls define?
  • What is the primary risk when performance indicators for an IT balanced scorecard are not objectively measurable?
  • What aspect of IT strategy review is relevant for assessing its effectiveness?
  • What is the MOST important objective when implementing an IT governance framework?
  • Why do many organizations require mandatory vacations for employees?
  • What crucial element must an outsourcing contract specify?
  • Upon termination, what is the most critical action an organization must take?
  • Which risk management strategy is exemplified when an organization requires job rotation?
  • What is a primary responsibility of an IT steering committee?
  • What is a crucial outcome from the IT steering committee maintaining accurate minutes?
  • Which of the following is critical for an IS auditor to review in regards to a vendor's service level agreement?
  • During a risk management review, what is the most important consideration?
  • Which method is considered the most reliable for assuring the integrity of new staff?
  • What mechanism helps mitigate risks from using a third-party vendor for critical applications?
  • Which of the following is considered the best enabler for strategic alignment between business and IT?
  • When assessing the alignment of IT strategies with business objectives, what is key for an IS auditor to verify?
  • What is the MOST important element for the effective design of an information security policy?
  • Which activity should be prioritized to assess the operational performance of an IT process?
  • What composition should an IT steering committee ideally have?
  • Which action should be prioritized to limit access to confidential data when an employee leaves?
  • What is the PRIMARY benefit of establishing a steering committee for IT investment oversight?
  • How can an organization best ensure its policies are effective in guiding legal compliance?
  • What is a potential limitation of using a maturity model for strategic alignment?
  • What practice enhances strategic alignment in IT governance?
  • What is a LAN administrator typically restricted from?
  • Who is best suited to determine an enterprise's risk appetite?
  • Upon an employee's resignation, what should be done first if they had access to confidential information?
  • Which option best describes the importance of goals and metrics in the context of strategic alignment?
  • Which issue must a comprehensive email policy specifically address?
  • The primary benefit of an enterprise architecture initiative is to do what?
  • What aspect of an organization’s security should be evaluated when implementing new technology?
  • Which is a likely consequence of poorly managed electronic evidence?
  • Which factor most likely indicates that a customer data warehouse should remain in-house?
  • Which scenario presents the highest potential risk related to an organization's information security policy?
  • Why is it essential to have a software escrow agreement with a vendor?
  • What is a characteristic of an effective information security compliance program?
  • Which combination of roles should raise the most concern for an IS auditor regarding separation of duties?
  • What positive outcome does strategic alignment in information security governance provide?
  • What is necessary for ensuring the effectiveness of an information security policy?
  • What critical element should be addressed in an organization's information security program to prevent breaches?
  • What presents the greatest risk during a merger involving the replacement of legacy systems?
  • Which of the following reflects a priority in discussing IT governance issues?
  • Errors in audit procedures PRIMARILY impact which of the following risks?
  • What benefit does using a decision support system provide for management?
  • What is the purpose of an IT balanced scorecard in aligning IT with business objectives?
  • When prioritizing areas for IT governance implementations, what should be the most important consideration?
  • A top-down approach to the development of operational policies primarily ensures what?
  • What role does the executive sponsor play in a security program?
  • What is the greatest concern for an IS auditor if they discover several IT projects implemented without approval from the steering committee?
  • Which situation is specifically addressed by a software escrow agreement?
  • Which is considered an effective control for managing risks associated with software products?
  • Which critical aspect should be assessed when an employee is given access to sensitive information?
  • Which security clause is MOST important to include in a master services agreement for software protection?
  • What does an effective IT strategy ideally ensure according to best practices?
  • What aspect does NOT contribute directly to optimizing IT performance?
  • What is a key aspect of an IT policy’s effectiveness?
  • Inadequate ownership policy for data may lead to what critical risk?
  • What is one of the primary benefits of using key performance indicators in a service level agreement?
  • When considering a major technology upgrade, what is the MOST crucial factor to evaluate?
  • What is a primary benefit of implementing a source code escrow agreement?
  • When unique user accounts are not assigned in a call center, what is the most appropriate recommendation?
  • What should an organization ensure when customizing its approach to email retention?
  • What is the first step an IS auditor should take when reviewing the software quality management process?
  • The chief information security officer typically does NOT handle which of the following tasks?
  • What does risk mitigation entail in the context of IT security?
  • What method is considered the best for ensuring organizational policies comply with legal requirements?
  • In developing information security policies, what should be the primary focus of an IS auditor?
  • What is a common purpose of assessing employee performance evaluations in the context of security?
  • What provides the most assurance of confidentiality when a service provider delegates work to a subcontractor?
  • What is typically a responsibility of the chief information security officer?
  • In the context of IT strategic planning, what is essential for the plan to articulate?
  • When reviewing the IT short-range plan, what is the primary focus an IS auditor should consider?
  • What is one of the key aspects that must be included in an outsourcing contract?
  • What is the primary responsibility of the board of directors regarding IT strategy?
  • What concern should an IS auditor prioritize when reviewing an organization's governance model?
  • What should be a top priority in the short-term planning for IT departments?
  • After conducting a threat and vulnerability analysis, what is the BEST method to determine whether suggested controls should be implemented?
  • Before implementing an IT balanced scorecard, what must an organization define?
  • Why would an auditor be concerned about outsourcing core activities?
  • Which factor provides the most value to strategic IT initiative decision-making?
  • What should be a primary concern for an IS auditor regarding the organization's information security policy?
  • What is the most important IS audit consideration when outsourcing a customer credit review system?
  • When an IS auditor finds unapproved IT policies that are being followed, what should they do first?
  • What control best ensures that a service provider's employees adhere to security policies?
  • In relation to service provider selection, which should be considered imperative in agreements?
  • In a small IT department where individuals perform more than one role, which practice represents the greatest risk?
  • What is the primary purpose of job descriptions from a control perspective?
  • Which type of insurance provides coverage for losses arising from fraudulent acts by employees?
  • Which responsibility is most likely assigned to an IT steering committee?
  • Which benefit does open system architecture provide?
  • In risk measurement, what is a relevant consideration regarding network risks?
  • What is the primary consideration for an IS auditor reviewing IT project prioritization?
  • Why is a RACI chart important in project management?
  • What is the GREATEST concern when a department uses a cloud application without consulting IT?
  • What is a suitable compensating control when segregation of duties concerns exist between IT support staff and end users?
  • What is the greatest risk posed by inadequate policy definition for ownership of data and systems?
  • What is the output of the risk management process primarily used for?
  • Which method is essential for reviewing the effectiveness of IT investments?
  • What should be the first objective of an IS auditor reviewing outsourced IT services?
  • What is the first step in developing a security architecture?
  • Which method of managing risk involves sharing that risk with another party?
  • A poor choice of passwords is classified as what type of security issue?
  • What signifies a vulnerability within an information system?
  • What is the primary goal of an IT performance measurement process?
  • In short-term planning for an IT department, what does an IS auditor deem most relevant?
  • Who is primarily responsible for establishing the level of acceptable risk within an organization?
  • Which of the following best defines the responsibility of IT management regarding security policies?
  • Which condition is of greatest concern for an IS auditor when reviewing outsourced IT services?
  • What is the ultimate purpose of IT governance?
  • When a business unit selects a new application without consulting IT, what is the PRIMARY risk?
  • What must effective IT governance ensure?
  • What is the first step in establishing an information security program?
  • What is the first step in creating a firewall policy?
  • What is the primary goal of requiring system administrators to sign off on daily backups?
  • What should an IS auditor FIRST reference when conducting an IS audit?
  • Which measure of security risk should be considered within an IT security risk management program?
  • When reviewing the classification levels of information assets, what is MOST important to consider?
  • In a strategic IT plan, what assessment should an IS auditor expect to find?
  • What is the GREATEST concern in evaluating an organization's IT governance framework?
  • To best align an IT project portfolio with organizational priorities, what should an IS auditor recommend?
  • What key aspect should be documented before evaluating the effectiveness of information security controls?
  • In reviewing a business process reengineering effort, what is the primary concern?
  • If a team is struggling to project financial losses from a risk, what should they pursue to evaluate the potential impact?
  • Overall quantitative business risk is best expressed as what?
  • What is a significant risk if critical IT policies lack management approval?
  • Who is typically responsible for approving an information security policy?
  • Which function is typically part of an IT steering committee?
  • Which aspect should concern an IS auditor most when reviewing an information security policy?
  • What is a critical risk to monitor during business process reengineering?
  • When reviewing a quality management system, what should the IS auditor primarily focus on collecting evidence for?
  • Which of the following is not a direct responsibility of an IT steering committee?
  • Which responsibility is NOT typically associated with the IT steering committee?
  • The increasing rate of technology change emphasizes the importance of which process?
  • What recommendation is most appropriate when no risk management function exists in an IT department?
  • Before evaluating management's risk assessment of information systems, an IS auditor should first review what?
  • When assessing cross-training practices, an IS auditor should focus on the risk of what?
  • Which user profile is of MOST concern to an IS auditor auditing an electronic funds transfer system?
  • Which method primarily achieves transparency of IT's cost, value, and risk in IT governance?
  • What recommendation should be made concerning undefined responsibilities in IT management?
  • What is the primary benefit of implementing a security program within a governance framework?
  • What is the primary consideration when reviewing a vendor for a critical business application?
  • In addressing differing profitability reports, what practice should be implemented for better data interpretation?
  • Effective IT governance ensures that the IT plan is consistent with what organizational aspect?
  • What is the primary purpose of a mandatory vacation policy?
  • Which benefit does a well-defined IT strategy provide to an organization?
  • Which role combination represents the biggest risk regarding system access?
  • Which practice should be minimized in an effective IT steering committee?
  • What is of MOST interest to an IS auditor reviewing an organization's risk strategy?
  • If an organization’s software vendor is unresponsive, what is a recommended action?
  • What is the best method for assessing IT risk?
  • After examining existing e-business applications for vulnerabilities, what should the IS auditor do next?
  • When outsourcing IT services, what should IT management primarily focus on?
  • In a contract for a proprietary application solution, what should be included according to best practices?
  • What is the primary objective of value delivery in effective information security governance?
  • What does effective alignment of IT with business strategy ensure?
  • Involvement of senior management is most critical in the development of which plans?
  • What should an IS auditor report when noticing that a separate project to develop a future-state representation is ongoing?
  • Which of the following focuses specifically on ensuring business and IT plans are linked?
  • What is the most critical consideration for an IS auditor when evaluating an organization's IT strategy?
  • What should be considered FIRST when implementing a risk management program?
  • What is the MOST important consideration for an IS auditor when reviewing a service level agreement?
  • What is a significant implementation risk within decision support systems?
  • How should segregation of duties be enforced in a scenario with only one DBA having root access?
  • When reviewing risk policies, what element should be evaluated last?
  • What is the PRIMARY objective of implementing corporate governance?
  • What is the primary control purpose of required vacations for employees?
  • What is the primary goal of requiring employees to take a mandatory vacation each year?
  • Which factor is NOT a primary focus for an IS auditor in IT governance?
  • What factor is considered most important for facilitating compliance with a newly developed IT policy?
  • When evaluating IT governance implementation effectiveness, what is the most critical factor?
  • To support organizational goals, what should the IT department focus on?
  • What is the MOST important aspect for an auditor when obtaining cloud hosting services from a vendor?
  • What should be ensured when developing security policies according to industry standards?
  • What is the main purpose of assessing the performance of an outsourcing provider?
  • IT governance is primarily the responsibility of which group?
  • Which characteristic is NOT ideal for an IT steering committee?
  • Why is conducting periodic audits essential for vendor management?
  • What is the primary focus when auditing the coordination of IT projects?
  • An IS auditor reviews an organizational chart primarily for what reason?
  • What measure is best for prioritizing IT projects based on overall investment performance?
  • Which issue is the most concerning when reviewing human resources policies?
  • What is the primary reason for separating responsibilities among IT personnel?
  • What should be of primary concern to an IS auditor reviewing external IT service provider management?
  • Which method best supports the prioritization of new IT projects?
  • What is essential for the long-term support of a purchased product from a vendor?
  • In what scenario should the IT steering committee focus on strategic matters?
  • Why are control objectives important in IT governance?
  • Which option is crucial for managing the integrity of a cloud-based application controlled by a department?
  • What is an acceptable method for verifying messages within an electronic funds transfer system?
  • What is a potential risk when employees are cross-trained for job roles?
  • What is the primary purpose of an IS control objective?
  • What should an IS auditor recommend when finance and marketing departments report differing product profitability results?
  • In a feasibility study, why is it important for an IS auditor to review a vendor's business continuity plan?
  • Which of the following is NOT a recommended reason to keep patient benefit data in-house?
  • What should an IS auditor primarily focus on when determining protection levels for an information asset?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy