The two highest-yield artifacts in the workshop: the auditor mindset filters and the trap-answer patterns. Print this and review it the morning of the exam.
| The trap (tempting but wrong) | What to do instead |
|---|---|
| Implement the technical fix yourself | Evaluate and report. Auditors evaluate the design and report deficiencies to management — they do not implement controls. |
| Wait and put it in the final report | Escalate critical findings — fraud, regulatory violations, material control failures — immediately to the audit committee. |
| Assess the risk before anything else | When a critical incident, suspected fraud, or imminent regulatory breach is involved, escalation comes before detailed risk assessment. |
| Accept the risk because the control is expensive | Cost is management's concern, not the auditor's reason to omit a finding. The auditor reports; management decides the response. |
| Audit log review is the best way to PREVENT access | Log review is detective. The preventive control is access enforcement — authentication and least-privilege permissions. |
| Management says controls are adequate, so move on | Professional skepticism: obtain evidence to corroborate the assertion before concluding. |
| Two years passed, so I can audit the system I built | Disclose and reassign. Prior involvement in a system always creates a self-review threat to independence. |
| It was an emergency, so no documentation was needed | Emergency changes require an expedited — but documented — process. “No process” is never the right emergency answer. |
| Backups run nightly offsite, so they're effective | Without documented restoration testing, backup adequacy cannot be confirmed. Job completion is not recoverability. |
| A CMDB exists, so configuration management is effective | Existence is not effectiveness. Verify the CMDB is reconciled to actual configurations. |
| The DRP’s capability sets the RTO | Backwards. The BIA sets the RTO/RPO from business impact; the DRP must be built and funded to meet them. A DRP that quietly redefines objectives down to what it can already do is the finding. |
| The GDPR 72-hour clock starts when the DPO is told | It starts when the organization becomes aware of the breach — not when the DPO, legal, or the board is notified. Internal routing delays do not pause the clock. |
| Let the DBA review their own database access logs | Privileged-user logs must be reviewed by someone independent of the DBA. Self-review of one’s own activity is no control at all. |
| Encryption is enabled, so the data is protected | Ask about key management. Keys stored with the data, never rotated, or with no revocation undermine the whole control — the most common encryption finding. |
| A policy exists, so the control is effective | A document is adequacy, not effectiveness. Verify it is implemented, followed, and producing evidence — existence is never proof of operation. |
| Management accepted the risk, so there’s nothing to report | Acceptance is valid only when it is within appetite, documented, and by the right authority. The auditor still reports it; silent or informal acceptance is itself the finding. |
CISA® Independent study aid — not affiliated with or endorsed by ISACA. Verify the current exam content outline at isaca.org.