Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is conducting a follow-up review of a previously identified high-risk finding. Management has implemented a compensating control instead of the recommended control. Which of the following is the MOST appropriate action for the auditor to take?

⚠ Common exam trap

The trap here is assuming that only the exact recommended control is acceptable, or conversely, that any management response resolves the finding without verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evaluate and test the compensating control to determine whether it effectively mitigates the risk.

In follow-up audits, when management implements a compensating control instead of the originally recommended control, the IS auditor must assess whether the alternative control effectively mitigates the identified risk. This requires testing the design and operating effectiveness of the compensating control. If it is found to be effective, the auditor can consider the finding resolved. If not, the finding remains open and may be escalated. Simply accepting or rejecting without evaluation is inappropriate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Evaluate and test the compensating control to determine whether it effectively mitigates the risk.

    Why this is correct

    When management implements a compensating control in lieu of the recommended control, the auditor must assess whether the alternative control adequately addresses the original risk. This involves testing the design and operating effectiveness of the compensating control to ensure it reduces the risk to an acceptable level. Only after such evaluation can the auditor conclude on the status of the finding.

  • ✗

    Report to the audit committee that management has failed to implement the recommended control.

    Why it's wrong here

    Reporting a failure without evaluating the compensating control is premature. Management may have chosen a valid alternative that addresses the risk. The auditor's role is to assess the compensating control's effectiveness before concluding whether the finding remains open. Escalating without analysis would be inaccurate and could harm the auditor's credibility.

  • ✗

    Reissue the original finding with a revised due date for implementation of the recommended control.

    Why it's wrong here

    Reissuing the finding with a new due date ignores management's response. If the compensating control is effective, the original finding may be resolved. The auditor should first evaluate the alternative control. Only if it is inadequate should the finding remain open or be escalated. Reissuing without evaluation is not aligned with follow-up procedures.

  • ✗

    Accept the compensating control as a satisfactory resolution without further testing.

    Why it's wrong here

    Accepting the compensating control without testing would violate the auditor's responsibility to verify that the risk has been adequately mitigated. The auditor must evaluate whether the alternative control actually reduces the risk to an acceptable level. Without testing, the auditor cannot provide assurance that the original finding has been effectively addressed, and this could lead to a false sense of security.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.