CISA Information System Auditing Process Practice Question
An IS auditor is designing test procedures for an audit of an organization's network perimeter. The auditor plans to use computer-assisted audit techniques (CAATs) to analyze firewall log data covering six months. Which TWO of the following are the MOST important considerations when using CAATs in this engagement? (Choose two.)
⚠ Common exam trap
The trap here is focusing on tool-related logistics such as appliance brand or license cost, while overlooking that CAAT results are only valid when the extracted data is complete, unaltered, and protected throughout the analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security and confidentiality controls over the extracted log data and the CAAT environment
When CAATs are used, the auditor must first establish that the data being analyzed is complete and accurate, because flawed input guarantees flawed conclusions about firewall activity over six months. Equally important, extracted logs and the analysis environment must be secured so the audit does not introduce confidentiality or integrity risks. Appliance brand, team experience, and license cost affect logistics but not the fundamental reliability or safety of the CAAT results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The brand and model of the firewall appliance generating the logs
Why it's wrong here
The specific vendor and model of the appliance may affect log format and parsing, but it is not among the most important considerations for using CAATs. A properly designed CAAT can accommodate different formats through normalization. What matters more is whether the data analyzed is complete, accurate, and properly protected, not which manufacturer produced the perimeter device.
- ✓
Security and confidentiality controls over the extracted log data and the CAAT environment
Why this is correct
Extracted firewall logs can reveal network topology, internal addressing, and traffic patterns, so the data and the environment where CAATs run must be protected. If analysis occurs on an unsecured workstation or copies of logs are left on shared drives, the audit itself creates a confidentiality and security exposure. Safeguarding the data throughout analysis and retention is therefore a key consideration.
- ✗
Whether the audit team has prior experience auditing firewall rules
Why it's wrong here
Team experience influences efficiency and judgment, but it is not a primary consideration for the CAAT itself. The reliability of CAAT results depends on data integrity and on safeguards over the analysis environment, not on whether the auditors previously audited firewalls. Experience can be supplemented through training or specialist support, whereas unaddressed data or security weaknesses directly invalidate the conclusions drawn from the tool.
- ✓
Completeness and integrity of the firewall log data extracted for analysis
Why this is correct
CAAT conclusions are only as reliable as the underlying data. If logs are incomplete due to dropped events, rotation gaps, or excluded devices, any analysis of denied or accepted traffic will misstate conditions. Verifying that extraction captured the full six-month population and that the data was not altered during transfer is therefore essential before relying on CAAT results to conclude on perimeter controls.
- ✗
The cost of the CAAT software license compared to manual testing
Why it's wrong here
Cost efficiency may influence tool selection, but it is not a primary consideration for the validity of CAAT-based testing. A cheaper tool applied to complete, protected data produces sound results, while an expensive tool applied to incomplete or unsecured data does not. Prioritizing license cost over data integrity and data protection would misplace the auditor's focus in this perimeter audit.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.