Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is designing substantive test procedures for a newly implemented automated accounts payable system and wants to rely less on the client's automated controls. The auditor decides to use computer-assisted audit techniques to test the completeness and accuracy of transaction processing. Which TWO of the following techniques would BEST provide direct evidence about the population of transactions? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any computer-assisted audit technique provides population-level evidence, when test data and integrated test facilities only examine how the system handles injected entries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generalized audit software to extract and analyze the full accounts payable transaction file

Direct evidence about a transaction population requires the auditor to examine or reprocess the actual data. Generalized audit software extracts and analyzes the full accounts payable file, while parallel simulation reprocesses live transactions through auditor-controlled logic and compares results. Both operate on real transactions. Test data, integrated test facilities, and change log reviews address control design or change activity, not the completeness and accuracy of the recorded population.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reviewing the change management log for modifications to the accounts payable application

    Why it's wrong here

    Reviewing change logs helps the auditor understand whether unauthorized or untested changes could affect processing integrity, but it is indirect evidence about the control environment rather than direct evidence about transaction completeness and accuracy. A clean change log does not prove that transactions were recorded correctly. It supports risk assessment and reliance decisions but does not substitute for techniques that examine the actual transaction population.

  • ✗

    Integrated test facility that posts simulated transactions alongside live processing

    Why it's wrong here

    An integrated test facility evaluates whether application controls operate correctly during normal processing, but its focus is control behavior rather than the completeness and accuracy of the real transaction population. The simulated entries must be reversed and they do not represent actual vendor obligations. For direct evidence about recorded transactions, the auditor needs to interrogate the actual data, not observe how the system handles injected test entries.

  • ✓

    Generalized audit software to extract and analyze the full accounts payable transaction file

    Why this is correct

    Generalized audit software can read the client's data files directly and perform calculations, comparisons, and summarizations across the entire transaction population. This gives the auditor direct, independent evidence about completeness and accuracy without relying on the client's own reports or manual sampling. Because it works on the full population, it also supports identifying unusual items and re-performing control logic, which is exactly the kind of direct evidence this engagement requires.

  • ✓

    Parallel simulation that reprocesses live transactions using auditor-controlled logic

    Why this is correct

    Parallel simulation takes the client's actual transaction data and reprocesses it through auditor-controlled logic, then compares the results with the client's output. Because it uses the real population, it provides direct evidence about whether transactions were processed completely and accurately. Discrepancies between the two sets of results point to processing errors or unauthorized logic, making this a strong substantive technique for this scenario.

  • ✗

    Test data submitted through the production system to observe how the application processes it

    Why it's wrong here

    Test data verifies whether application controls behave as designed, but it only demonstrates how the system processes the specific fictitious transactions submitted. It does not provide evidence about the actual population of live accounts payable transactions, so it cannot directly support a conclusion about completeness and accuracy of recorded data. It is useful for testing programmed edit and validation controls, not for examining the real transaction file.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.