Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is conducting an audit of a payroll application and needs to verify that user access rights match each employee's current job responsibilities. Which of the following is the MOST appropriate source of evidence for this test?

⚠ Common exam trap

It's easy for candidates to confuse authentication-related evidence, such as password settings or failed logins, with authorization evidence needed to prove that access rights align with current job responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The payroll application's user access list and the human resources department's current job descriptions

Verifying that access rights match job responsibilities requires comparing what rights exist with what rights should exist. The application's user access list establishes actual entitlements, while HR's current job descriptions establish the authorized baseline. Agreement between these two independent records supports a conclusion on access appropriateness. Walkthroughs, failed login reports, and password settings each address different control objectives and cannot demonstrate role alignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The payroll application's password complexity configuration settings

    Why it's wrong here

    Password complexity settings are authentication controls that govern credential strength; they say nothing about authorization or role alignment. Even with strong passwords, users may hold inappropriate or outdated access rights. Reviewing this configuration tests a different control area and cannot provide evidence that payroll access rights correspond to employees' current job responsibilities.

  • ✗

    A report of failed login attempts over the past quarter

    Why it's wrong here

    Failed login attempts indicate authentication activity, not whether users hold rights consistent with their duties. A user could log in successfully every day while retaining excessive access from a previous position. This evidence addresses security monitoring and intrusion detection concerns, which are unrelated to the audit objective of verifying that payroll access rights match current job responsibilities.

  • ✗

    A walkthrough of the payroll application with the system administrator

    Why it's wrong here

    A walkthrough demonstrates how the system functions and how access is administered, but it does not show whether individual users' rights match their current job responsibilities. The administrator may explain the intended authorization model while excessive or stale rights remain in place. Walkthroughs support understanding of the process, not substantive testing of access appropriateness across the payroll user population.

  • ✓

    The payroll application's user access list and the human resources department's current job descriptions

    Why this is correct

    Comparing the application's user access list against current HR job descriptions directly tests whether access aligns with responsibilities. The access list shows what rights users actually hold, and HR records represent the authoritative source of current roles after transfers and promotions. Together they provide independent, documentary evidence that supports a conclusion on authorization appropriateness for the payroll application.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.