CISA Information System Auditing Process Practice Question
An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)
⚠ Common exam trap
CISA often tests the evidence reliability hierarchy, tempting candidates to select inquiry or observation because they are easy to perform, when the exam expects the strongest (re-performance and system-generated logs).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Re-performance of access provisioning using a test account
Re-performance of access provisioning using a test account (A) is correct because the auditor independently executes the provisioning process and directly verifies whether the system enforces the intended access rules, yielding first-hand evidence that is stronger than documentation or interviews. Inspection of access violation audit logs (B) is correct because these logs are system-generated records that reveal actual attempts to exceed authorized access and whether the controls detected and responded to them, providing objective evidence of control operation. Inquiry of the security administrator (C) is not sufficient because it relies on management's assertions rather than independent verification. Inspection of user access review documentation (D) shows that reviews were documented but does not confirm the underlying access rights are actually correct or enforced. Observation of access request processing (E) only reflects the process at the moment observed and may not represent normal or complete control operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Re-performance of access provisioning using a test account
Why this is correct
Re-performance of access provisioning using a test account lets the auditor independently execute the control and observe actual system behaviour, producing direct evidence. This satisfies the stem's requirement for the strongest evidence of access control effectiveness.
- ✓
Inspection of access violation audit logs
Why this is correct
Inspecting access violation audit logs provides direct evidence that access controls actually detect and record unauthorised attempts, satisfying the auditor's need for operating effectiveness rather than design. Unlike policy review or interviews, logs are system-generated artefacts showing controls functioned during the audit period, delivering the strongest, independently verifiable evidence.
- ✗
Inquiry of the security administrator
Why it's wrong here
Inquiry alone yields verbal assertions that are easily biased and unverifiable, so it provides the weakest audit evidence. It is appropriate for gathering background, identifying risks or locating records, but effectiveness conclusions require inspection or reperformance of the control itself.
- ✗
Inspection of user access review documentation
Why it's wrong here
Review documentation is a record of what management asserts was performed, not proof the reviews occurred or that flagged access was revoked. It is useful corroboration, but inspecting the actual system-generated access listings and configurations provides stronger, independent evidence of control operation.
- ✗
Observation of access request processing
Why it's wrong here
Observation confirms a procedure was performed at that moment but not that it is applied consistently, and the auditor's presence may alter behaviour. It suits assessing physical or operational controls; for access controls, inspecting system-generated logs and configurations yields stronger evidence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.