8 real CISA flashcards, sampled across every domain the exam tests. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.
The full deck has 720 flashcards. For a domain-by-domain breakdown and a study plan, read the CISA study guide.
schoolConceptInformation Systems Operations and Business Resilience
How should the software asset register and the CMDB relate in a mature IT asset management programme?
arrow_downward
The software asset register (which captures licence entitlements and deployment counts) should be reconciled periodically against the CMDB (which captures the operational footprint of installed software). This reconciliation is the primary control that surfaces under-licensing, over-licensing, and unsupported software, evidencing licence compliance, supporting renewal planning, and detecting unsupported versions that increase security and continuity risk.
errorMisconceptionInformation Systems Operations and Business Resilience
The CMDB can replace the software asset register because configuration items already include installed software components and version data.
arrow_downward
Although the CMDB does record installed software as configuration items, it tracks operational state for service management, not licence entitlements or contractual rights. A CMDB cannot satisfy software asset management obligations on its own; a separate software asset register is required to capture rights granted by licences, and the two records must be reconciled to evidence compliance.
schoolConceptProtection of Information Assets
How do ISO/IEC 27001 and ISO/IEC 27002 relate to each other in an information security framework?
arrow_downward
ISO/IEC 27001 specifies the certifiable requirements for an information security management system, including risk assessment, risk treatment and Annex A controls. ISO/IEC 27002 is the companion guidance that explains how each Annex A control may be implemented. They are complementary, not alternatives.
errorMisconceptionProtection of Information Assets
a committed future remediation date downgrades a current policy breach from a finding to an observation.
arrow_downward
Acknowledgement and a future fix do not change the present state. Audit findings reflect the control's condition during the audit period, so a current breach exposing personal data remains a finding with risk rated on present exposure.
schoolConceptInformation Systems Auditing Process
On what basis does ISACA require an IS auditor to select auditable units for the annual audit plan?
arrow_downward
ISACA IS Audit and Assurance Standards require the annual plan to reflect the organisation's current risk profile. The auditor combines inherent risk in each unit, the strength of related controls and residual detection risk to rank units, so scarce assurance effort lands where the chance and impact of material misstatement or control failure is greatest.
errorMisconceptionInformation Systems Auditing Process
Fixed three-year rotation of auditable units is the defensible basis for the annual plan because it guarantees coverage.
arrow_downward
Fixed-rotation cycles are tempting because they look fair and predictable, but ISACA standards require selection driven by current inherent and control risk, not calendar rotation that ignores threat changes. Predictable coverage is not the same as risk-relevant coverage.
schoolConceptGovernance and Management of IT
How does COBIT 2019 and ISO/IEC 38500 distinguish IT governance from IT management within an enterprise?
arrow_downward
IT governance is the board-level activity of evaluating, directing and monitoring the use of IT so that it supports stakeholder needs and strategic objectives, while IT management plans, builds, runs and monitors IT activities within the direction set by governance. COBIT 2019 codifies this split by labelling EDM objectives as governance and APO, BAI, DSS and MEA objectives as management. ISO/IEC 38500 frames the same separation as the three governance tasks of evaluate, direct and monitor. The two roles are linked but distinct, and adopting a control framework does not collapse the distinction; segregation of decision rights is preserved by design.
errorMisconceptionGovernance and Management of IT
IT governance is the daily oversight of IT operations exercised by the chief information officer, while IT management is the strategic stewardship exercised by the audit committee.
arrow_downward
This inverts the recognised roles. The board and its committees govern by evaluating, directing and monitoring the use of IT, while the chief information officer manages day-to-day delivery within governance constraints. Treating the chief information officer as the governance actor and the audit committee as a management actor undermines the segregation of decision rights established by COBIT 2019 and ISO/IEC 38500.
Examworthy is not affiliated with or endorsed by ISACA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CISA and related marks belong to their respective owners.