Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)

⚠ Common exam trap

CISA often tests the evidence reliability hierarchy, tempting candidates to select inquiry or observation because they are easy to perform, when the exam expects the strongest (re-performance and system-generated logs).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Re-performance of access provisioning using a test account

Re-performance of access provisioning using a test account (A) is correct because the auditor independently executes the provisioning process and directly verifies whether the system enforces the intended access rules, yielding first-hand evidence that is stronger than documentation or interviews. Inspection of access violation audit logs (B) is correct because these logs are system-generated records that reveal actual attempts to exceed authorized access and whether the controls detected and responded to them, providing objective evidence of control operation. Inquiry of the security administrator (C) is not sufficient because it relies on management's assertions rather than independent verification. Inspection of user access review documentation (D) shows that reviews were documented but does not confirm the underlying access rights are actually correct or enforced. Observation of access request processing (E) only reflects the process at the moment observed and may not represent normal or complete control operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Re-performance of access provisioning using a test account

    Why this is correct

    Re-performance of access provisioning using a test account lets the auditor independently execute the control and observe actual system behaviour, producing direct evidence. This satisfies the stem's requirement for the strongest evidence of access control effectiveness.

  • ✓

    Inspection of access violation audit logs

    Why this is correct

    Inspecting access violation audit logs provides direct evidence that access controls actually detect and record unauthorised attempts, satisfying the auditor's need for operating effectiveness rather than design. Unlike policy review or interviews, logs are system-generated artefacts showing controls functioned during the audit period, delivering the strongest, independently verifiable evidence.

  • ✗

    Inquiry of the security administrator

    Why it's wrong here

    Inquiry alone yields verbal assertions that are easily biased and unverifiable, so it provides the weakest audit evidence. It is appropriate for gathering background, identifying risks or locating records, but effectiveness conclusions require inspection or reperformance of the control itself.

  • ✗

    Inspection of user access review documentation

    Why it's wrong here

    Review documentation is a record of what management asserts was performed, not proof the reviews occurred or that flagged access was revoked. It is useful corroboration, but inspecting the actual system-generated access listings and configurations provides stronger, independent evidence of control operation.

  • ✗

    Observation of access request processing

    Why it's wrong here

    Observation confirms a procedure was performed at that moment but not that it is applied consistently, and the auditor's presence may alter behaviour. It suits assessing physical or operational controls; for access controls, inspecting system-generated logs and configurations yields stronger evidence.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.