CISA — Exam-Day One-Pager

The two highest-yield artifacts in the workshop: the auditor mindset filters and the trap-answer patterns. Print this and review it the morning of the exam.

The auditor mindset filters

  1. “Is this what an auditor does — or a technician?” If it sounds like building or fixing something, it’s probably wrong.
  2. “What is the PRIMARY concern?” Two answers can look correct; pick the more root-cause, more consequential one.
  3. “Does this protect the organization — or just fix the symptom?” Root-cause findings and governance-level recommendations beat tactical fixes.
  4. First instinct; independent questions. Don’t change answers without a specific reason; don’t let one hard question spiral.

Trap-Answer Patterns — and What To Do

The trap (tempting but wrong)What to do instead
Implement the technical fix yourselfEvaluate and report. Auditors evaluate the design and report deficiencies to management — they do not implement controls.
Wait and put it in the final reportEscalate critical findings — fraud, regulatory violations, material control failures — immediately to the audit committee.
Assess the risk before anything elseWhen a critical incident, suspected fraud, or imminent regulatory breach is involved, escalation comes before detailed risk assessment.
Accept the risk because the control is expensiveCost is management's concern, not the auditor's reason to omit a finding. The auditor reports; management decides the response.
Audit log review is the best way to PREVENT accessLog review is detective. The preventive control is access enforcement — authentication and least-privilege permissions.
Management says controls are adequate, so move onProfessional skepticism: obtain evidence to corroborate the assertion before concluding.
Two years passed, so I can audit the system I builtDisclose and reassign. Prior involvement in a system always creates a self-review threat to independence.
It was an emergency, so no documentation was neededEmergency changes require an expedited — but documented — process. “No process” is never the right emergency answer.
Backups run nightly offsite, so they're effectiveWithout documented restoration testing, backup adequacy cannot be confirmed. Job completion is not recoverability.
A CMDB exists, so configuration management is effectiveExistence is not effectiveness. Verify the CMDB is reconciled to actual configurations.
The DRP’s capability sets the RTOBackwards. The BIA sets the RTO/RPO from business impact; the DRP must be built and funded to meet them. A DRP that quietly redefines objectives down to what it can already do is the finding.
The GDPR 72-hour clock starts when the DPO is toldIt starts when the organization becomes aware of the breach — not when the DPO, legal, or the board is notified. Internal routing delays do not pause the clock.
Let the DBA review their own database access logsPrivileged-user logs must be reviewed by someone independent of the DBA. Self-review of one’s own activity is no control at all.
Encryption is enabled, so the data is protectedAsk about key management. Keys stored with the data, never rotated, or with no revocation undermine the whole control — the most common encryption finding.
A policy exists, so the control is effectiveA document is adequacy, not effectiveness. Verify it is implemented, followed, and producing evidence — existence is never proof of operation.
Management accepted the risk, so there’s nothing to reportAcceptance is valid only when it is within appetite, documented, and by the right authority. The auditor still reports it; silent or informal acceptance is itself the finding.

CISA® Independent study aid — not affiliated with or endorsed by ISACA. Verify the current exam content outline at isaca.org.