10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free ACISE questions are organized by exam domain, so you can see how each part of the Associate Certified Information Systems Examiner blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: TECHNICAL
Question 1
A bank converted its loan-servicing system six weeks ago. Its proposed InTREx work program reduces testing in reliance on an audit completed before the conversion. Customers have since reported unexplained balance differences. Which scope revision is most responsive to the changed risk?
Show answer & explanation
Correct answer: D - Reconcile converted loan balances to source records and test the controls over data migration.
Question 2
An IT examination identifies recurring weaknesses in access administration and recovery testing. Management reacts to examiner requests but does not identify significant risks independently. Increased supervision is necessary, although financial or operational failure is considered unlikely. Audit and change-management controls remain satisfactory. Which URSIT composite rating fits this overall condition?
Show answer & explanation
Correct answer: C - 3 - Less than satisfactory
Domain 2: CONCEPTUAL
Question 3
A core processor's SOC 2 Type 2 report covers the bank's service and the relevant review period, with no reported exceptions. It identifies quarterly access reviews performed by the bank as complementary user entity controls. The bank has not performed those reviews. How should the examiner interpret the report's assurance?
Show answer & explanation
Correct answer: B - It supports the tested provider controls, but does not resolve the bank's unperformed access reviews.
Question 4
During an authorized test of a lender's borrower portal, a customer signs in with a password and a registered security key. Without changing identity, the customer changes the loan identifier in an API request and receives another borrower's statement. The session remains encrypted. Which failure best explains the disclosure?
Show answer & explanation
Correct answer: A - Missing authorization checks for the requested loan record.
Question 5
A payment-service recovery test records: outage at 08:00; application servers restarted at 10:30; network connections restored and payment submission and reconciliation available at 12:45; newest recoverable transaction timestamped 07:50. All times are on the same day. With a four-hour recovery time objective and a 30-minute recovery point objective, which result belongs in the test record?
Show answer & explanation
Correct answer: C - Recovery time objective missed: 4 hours 45 minutes; recovery point objective met: 10 minutes of data loss.
Question 6
Ransomware is actively encrypting a bank's departmental file servers. Authorized responders can isolate the affected network segment without interrupting payments on a separate, monitored segment. Offline backups are available, but the entry point remains unknown. Which response should take priority?
Show answer & explanation
Correct answer: D - Isolate the affected segment and preserve relevant evidence while investigating the compromise.
Question 7
Two validated vulnerabilities compete for remediation resources. An internet-facing payment service has a CVSS v4.0 Base score of 8.3, no effective compensating control, and exposure to exploitation already observed in the wild. A disconnected laboratory system holding synthetic data has a score of 9.6; its isolation is verified. Which risk-prioritization decision is best supported?
Show answer & explanation
Correct answer: A - Prioritize the payment service: its High severity, active exploitation, and exposure outweigh the laboratory system's higher score.
Domain 3: LEGAL/COMPLIANCE
Question 8
An FTC-covered mortgage lender maintains customer information concerning 3,400 consumers. An intruder acquires encrypted files containing 720 consumers' customer information and the usable decryption key. No misuse has been identified. Under the FTC Safeguards Rule, which reporting decision is correct?
Show answer & explanation
Correct answer: B - Notify the FTC as soon as possible, no later than 30 days after discovery of the event.
Question 9
At an insured state nonmember bank, the IT administrator maintains the information-security program and performs its key-control tests. A qualified reviewer who is independent of program development and maintenance evaluates the test procedures, evidence, and conclusions. Which assessment is consistent with the Interagency Guidelines Establishing Information Security Standards?
Show answer & explanation
Correct answer: B - Independent review can meet the testing-independence requirement without the reviewer personally performing every test.
Domain 4: COMMUNICATIONS
Question 10
At a fact-validation meeting, management challenges a draft finding that 12 privileged-user access reviews were overdue. The examiner verifies that the approved policy required quarterly reviews throughout the period and that all 12 were completed on time. The draft used a monthly schedule from a retired procedure; no applicable rule required monthly reviews. The examiner should:
Show answer & explanation
Correct answer: A - Withdraw the overdue-review finding and document the corrected criterion and supporting evidence.
That's 10 of 1,030
The full bank has 1,020 more ACISE questions with explanations.