Free CPA ISC (Information Systems & Controls) Information Systems and Data Management Practice Questions

Information systems and data management on the CPA ISC discipline exam cover IT governance frameworks (COBIT), database management concepts, data analytics, cloud computing models, and enterprise resource planning (ERP) systems.

412 Questions
173 Easy
153 Medium
86 Hard
2026 Syllabus

Sample Questions

Question 1 Easy
Which of the following BEST describes metadata in the context of data governance?
Solution
A is correct.

Metadata is data about data. It includes information such as data definitions (what each field means), data types and formats, source system origins, transformation rules applied during ETL, data lineage (how data flows and changes through systems), and ownership information. Metadata is foundational to data governance because it enables users to find, understand, trust, and properly use the organization's data assets.
Question 2 Medium
An internal audit team discovers that a programmer who developed several critical financial reporting modules also has the ability to promote code changes directly to the production environment. Which IT general control deficiency does this represent?
Solution
C is correct.

This is a segregation of duties violation within change management controls. A fundamental principle of IT general controls is that the person who develops or modifies code should not be the same person who promotes that code to production. This separation prevents a developer from introducing unauthorized or malicious changes without independent review and approval. When one person can both write and deploy code, the risk of unauthorized changes to financial reporting systems increases significantly.
Question 3 Hard
A company is migrating its on-premises data warehouse to a cloud-based solution. The data warehouse contains 10 years of financial transaction data subject to SOX compliance requirements. The ETL (Extract, Transform, Load) processes must be redesigned for the cloud environment. Which combination of controls is MOST critical to ensure data integrity and regulatory compliance during and after this migration?
Solution
B is correct.

A data warehouse migration involving SOX-regulated financial data requires multiple layers of controls: (1) reconciliation controls (record counts, hash values, control totals) at each migration stage verify that no data is lost, added, or altered during transfer; (2) parallel-run testing confirms that redesigned ETL processes produce the same results as legacy processes, ensuring that transformation logic is faithfully replicated; (3) a complete audit trail documents the migration process, supporting SOX compliance documentation; (4) access control validation ensures the cloud environment maintains the segregation of duties and access restrictions required under SOX.

About FreeFellow

FreeFellow is an AI-native exam prep platform for actuarial (SOA & CAS), CFA, CFP, CPA, CAIA, GARP FRM, IRS Enrolled Agent, IMA CMA, and FINRA / NASAA securities licensing candidates — built around modern AI as a core capability rather than as a bolt-on. Every lesson ships with AI-narrated audio. Every constructed-response item has a copy-to-AI prompt builder so candidates can paste their answer into their own ChatGPT or Claude for self-graded feedback. Fellow members get instant AI grading on essays against the official rubric (currently CFA Level III, expanding to other essay-bearing sections).

The 70% you need to pass — question bank, written solutions, lessons, formula sheet, mixed practice, readiness tracking — is free forever, with no trial period and no credit card. Become a Fellow ($59/quarter or $149/year per track) to unlock mock exams, flashcards with spaced repetition, performance analytics, AI essay grading, and a personalized study plan.