Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed but no evidence of follow-up exists for two anomalies identified in one review. Which of the following conclusions is MOST appropriate?

⚠ Common exam trap

The trap here is jumping straight to a conclusion of effectiveness because the scheduled review occurred, without examining whether the review produced the corrective action the control exists to trigger.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The exceptions should be evaluated for cause and effect before concluding on control effectiveness

When testing identifies exceptions, the auditor evaluates their nature, cause, and effect before concluding on the control. Documented reviews without documented follow-up suggest the detection element worked but the response element may not have. Determining whether the anomalies were resolved, ignored, or escalated elsewhere is essential to deciding whether the control objective was actually achieved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The control is ineffective because any deviation, regardless of cause, invalidates the entire control

    Why it's wrong here

    Not every deviation renders a control ineffective. The auditor must evaluate the nature, cause, and effect of the exceptions and consider whether they represent a systematic failure or an isolated lapse. Concluding ineffectiveness without that evaluation overstates the finding and may not reflect the actual risk.

  • ✗

    The control is operating effectively because the reviews were performed as scheduled

    Why it's wrong here

    Performing the review is only part of the control. The control's purpose is to detect and resolve inappropriate privileged activity, so the absence of documented follow-up for identified anomalies means the control did not achieve its objective on those occasions, and effectiveness cannot be concluded from the review activity alone.

  • ✗

    The control should be retested with a larger sample to determine whether the exceptions are isolated

    Why it's wrong here

    Extending testing may be useful, but it is not the immediate and most appropriate action. The auditor already has evidence of deviations and should first understand their cause and effect; only then can the auditor decide whether additional testing would add value or whether the finding is already supportable.

  • ✓

    The exceptions should be evaluated for cause and effect before concluding on control effectiveness

    Why this is correct

    The auditor must investigate why follow-up did not occur and what the anomalies were before judging the control. If the anomalies were benign or resolved outside the log, the control may still be effective; if they indicate a systemic gap in escalation, the control objective may not be met. Evaluation precedes conclusion.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.