CISA Information System Auditing Process Practice Question
An IS auditor is conducting an audit of a payroll application and needs to verify that user access rights match each employee's current job responsibilities. Which of the following is the MOST appropriate source of evidence for this test?
⚠ Common exam trap
It's easy for candidates to confuse authentication-related evidence, such as password settings or failed logins, with authorization evidence needed to prove that access rights align with current job responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The payroll application's user access list and the human resources department's current job descriptions
Verifying that access rights match job responsibilities requires comparing what rights exist with what rights should exist. The application's user access list establishes actual entitlements, while HR's current job descriptions establish the authorized baseline. Agreement between these two independent records supports a conclusion on access appropriateness. Walkthroughs, failed login reports, and password settings each address different control objectives and cannot demonstrate role alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The payroll application's password complexity configuration settings
Why it's wrong here
Password complexity settings are authentication controls that govern credential strength; they say nothing about authorization or role alignment. Even with strong passwords, users may hold inappropriate or outdated access rights. Reviewing this configuration tests a different control area and cannot provide evidence that payroll access rights correspond to employees' current job responsibilities.
- ✗
A report of failed login attempts over the past quarter
Why it's wrong here
Failed login attempts indicate authentication activity, not whether users hold rights consistent with their duties. A user could log in successfully every day while retaining excessive access from a previous position. This evidence addresses security monitoring and intrusion detection concerns, which are unrelated to the audit objective of verifying that payroll access rights match current job responsibilities.
- ✗
A walkthrough of the payroll application with the system administrator
Why it's wrong here
A walkthrough demonstrates how the system functions and how access is administered, but it does not show whether individual users' rights match their current job responsibilities. The administrator may explain the intended authorization model while excessive or stale rights remain in place. Walkthroughs support understanding of the process, not substantive testing of access appropriateness across the payroll user population.
- ✓
The payroll application's user access list and the human resources department's current job descriptions
Why this is correct
Comparing the application's user access list against current HR job descriptions directly tests whether access aligns with responsibilities. The access list shows what rights users actually hold, and HR records represent the authoritative source of current roles after transfers and promotions. Together they provide independent, documentary evidence that supports a conclusion on authorization appropriateness for the payroll application.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.