How CISA Questions Are Written
Every option can be true and only one can be best. The reading technique that separates candidates who know the material from candidates who pass.
What this makes you able to do
Interpret a qualified exam stem and select the best answer from a set of individually defensible options.
By the end you can
- Identify the qualifier in a question stem and state what it is asking you to rank.
- Apply the standard tiebreakers when two options are both professionally defensible.
- Eliminate distractors that are true statements but wrong answers.
Transcript
How C-I-S-A questions are written. Every option can be true, and only one can be best. This lesson is about the reading technique that separates candidates who know the material from candidates who pass.
You have fifteen years of audit experience. You read a question, you recognise every word, and you find that three of the four options are things you have genuinely recommended to clients. You pick one. It is marked wrong. This is the single most common way experienced candidates lose marks, and the problem is not knowledge.
The problem is that the exam is not asking what you would do. It is asking what a model information systems auditor, following the standards, would do at that exact point in the process. Once you see that difference, a whole category of wrong answers becomes obvious.
So here is the habit that pays for itself. Before you read a single option, find the word in capitals and underline it. That word is not decoration. It changes the entire task you are being asked to perform.
FIRST asks about sequence. Several options may be perfectly correct actions, but only one of them comes first in a defensible order. Establishing the facts comes before evaluating them. Evaluating comes before recommending. And recommending comes before escalating.
BEST asks you to rank quality. Every option in front of you may be a real, sensible control. You judge them against what the question actually specifies. If the question says prevent, then a detective control cannot be the best answer, no matter how good a control it is.
MOST and GREATEST ask about magnitude, usually of risk or of concern. Look for the option with the widest consequence, not the one that is most technically interesting. And watch for MOST LIKELY, which asks about probability rather than severity. A catastrophic but improbable outcome loses to a mundane and common one.
There is a reason to underline the qualifier before you look at the options rather than after. Candidates who read the options first anchor on a phrase that sounds familiar, and then argue backwards to justify it. Reading the qualifier first tells you what you are looking for, so you are choosing rather than defending.
Now, the harder case. Sometimes two options are both genuinely defensible, and both are things a competent auditor might do. These are the questions that separate a pass from a near miss, and there are rankings that resolve almost all of them.
Governance beats technology. If one option addresses the policy, the ownership or the accountability, and another applies a technical fix, the exam usually prefers the governance answer. A firewall rule does not fix the absence of a network security standard.
Prevention beats detection, and detection beats correction, unless the question tells you otherwise. And assessment comes before action. Almost any option that begins with performing a risk assessment or determining the impact will outrank an option that jumps straight to a remedy.
Independence outranks usefulness. An auditor who could be more helpful by designing the control still must not, because the assurance role is worth more than the advice. And management owns the decision. You report, you recommend, and you evaluate. Any option where the auditor implements a control, approves an exception, or accepts a risk on management behalf is wrong for that reason alone.
Which brings us to the instinct that costs the most marks, and that instinct is pragmatism. In real life you would get the production password handed back today and sort out the paperwork afterwards. On the exam that option is a trap, because it skips assessment and it moves the auditor into management chair. The column on the right is not what a better auditor would do on Monday. It is what the exam is measuring.
So carry this question into the exam room with you. The wrong internal question is, is this statement true, because in a well written C-I-S-A question the distractors are usually true. They are simply not the best, or not first, or not what the qualifier asked for. The right internal question is, does this statement answer the qualifier.
And finally, the clock. One hundred and fifty questions in two hundred and forty minutes is ninety six seconds per question, and that includes review. Long scenario questions will take you more, so short recall questions have to take you much less. Flag it and move on rather than defending a first instinct for four minutes. That is time taken from three other questions you would have answered correctly.
1.An IS auditor discovers during fieldwork that a developer has standing write access to the production database. What should the auditor do FIRST?
2.Which of the following is the BEST control to prevent unauthorised changes reaching production?
3.An IS auditor is asked by the CIO to help design a new access recertification process during the same year the auditor is scheduled to audit access management. What is the auditor's GREATEST concern?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
