CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 13


During the evaluation of controls over a major application development project, the MOST effective use of an IS auditor's time would be to review and evaluate:

Show Answer
Correct Answer: CD

The most effective use of an IS auditor's time during the evaluation of controls over a major application development project would be to review and evaluate project plans. Project plans provide a comprehensive view of the project, including objectives, timelines, resource allocations, and risk management practices. By examining project plans, an IS auditor can better understand the project's governance, assess whether appropriate controls have been integrated throughout the lifecycle, and identify any potential gaps or deficiencies in the control structure.

Discussion

16 comments
Sign in to comment
EBTURKOption: D
May 28, 2023

Reviewing and evaluating project plans is the most effective use of an IS auditor's time when assessing controls over a major application development project. Project plans outline the overall strategy, objectives, timelines, resources, and milestones of the project. By examining project plans, the auditor can gain insight into the project's governance structure, risk management practices, and control mechanisms.

dahateOption: C
Jun 18, 2023

Its about evaluating controls not the project health. So the correct answer is C

saado9Option: D
Mar 29, 2023

D. project plans.

BankseyOption: D
Mar 31, 2023

From my perspective project plans give the most overall picture of the application

007GeorgeoOption: C
Apr 29, 2023

the evaluation of controls is application test cases.

TTH1019Option: D
Jun 3, 2023

D: Reviewing and evaluating project plans allows the IS auditor to assess the overall structure and organization of the application development project. It provides insights into the project's scope, objectives, timeline, resource allocation, and management approach. By examining the project plans, the IS auditor can identify potential risks, gaps, or deficiencies in project management practices that could impact the success of the project

007GeorgeoOption: C
Apr 29, 2023

the evaluation of controls is application test cases.

[Removed]Option: D
Jun 22, 2023

Is that answer "C"? I thought Project Plans summarize overall strategy.

ShareyesOption: D
Feb 6, 2024

it is talking about time efficiency, just like audit plan, it should be D-project plan

echo_certOption: A
Feb 9, 2024

Any A? The question is about evaluation of controls that would be used to audit the system and not an evaluation of the system being developed. So in essence, adequacy of the controls.

fori12Option: C
Mar 19, 2024

i will go with c , as project plan is IT Steering Committee Responsibility

SwallowsOption: C
Apr 6, 2024

The answer sould be C.

5b56aaeOption: C
Apr 14, 2024

test cases have the most relevant information about controls

a84nOption: C
Apr 25, 2024

Answer: C

poopsmcgoopsOption: B
Jun 27, 2024

a & d are not related to evaluation of controls. c is a subset of b, so in order to accurately evulate controls you need to look at acceptance testing

poopsmcgoops
Jun 27, 2024

also b should be happening at the end so you have a full idea of what all the controls are to even test

SwallowsOption: D
Jul 14, 2024

The project plan shows the overall progress, resource allocation, risk management, etc., and provides important information for judging the effectiveness of controls. Although application test cases are also important, the evaluation of the project plan is more effective in understanding the progress and control of the entire project.