Courseiva
hardMultiple Choice

CISA Practice Question: An auditor is reviewing IT policy compliance and…

An auditor is reviewing IT policy compliance and finds that a critical policy was last updated three years ago. The organization has undergone significant changes. What is the auditor's PRIMARY concern?

⚠ Common exam trap

CISA often tests root-cause prioritization — candidates pick awareness or enforcement because those sound like common audit findings, but the primary concern is strategic alignment of the policy content itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy may not be aligned with current business objectives

The primary concern with a policy that has not been updated for three years amid significant organizational change is that it may no longer align with current business objectives, risks, and operating environment. Policy relevance is the root issue; awareness, approval, and enforcement are downstream symptoms that may or may not exist. An outdated policy can direct behavior toward obsolete goals and create compliance gaps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Employees may not be aware of the policy

    Why it's wrong here

    Awareness is an operational communication issue, not the primary concern when the policy itself predates significant organisational change. The content may no longer match the current environment, so employees could be following obsolete rules. Awareness is tempting because it is a frequent policy-compliance finding, but it presupposes the policy is still valid.

  • ✗

    The policy may not have been approved by management

    Why it's wrong here

    Management approval is a one-off governance act; a three-year-old policy can still be approved. The real risk is that the policy no longer reflects the reorganised environment, so its controls may be obsolete. Approval status is tempting because unsigned policies are a common audit finding, but staleness against change is the concern here.

  • ✗

    The policy may not be enforced

    Why it's wrong here

    Enforcement concerns whether the policy is applied, not whether its content remains valid after three years of organisational change. A stale policy may mandate controls that no longer fit the environment. Enforcement is tempting because non-compliance is a common audit issue, but the stem's emphasis on significant change points to relevance, not application.

  • ✓

    The policy may not be aligned with current business objectives

    Why this is correct

    Significant organisational change can render a three-year-old policy misaligned with current business objectives, so the auditor's primary concern is that the policy no longer reflects what the organisation now needs to achieve. This addresses the stem's compliance concern directly: outdated policy content, not merely its review date or approval status.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.