CISA Protection of Information Assets Practice Question
An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)
⚠ Common exam trap
The trap here is accepting management's statement that conflicts are caught at provisioning, when the auditor must test both the ruleset that defines conflicts and the actual users provisioned under it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Examine a sample of users provisioned in the last quarter to confirm that conflicting access was not granted.
Effective SoD assurance requires both design and operating evidence. Reviewing the conflict ruleset confirms that the detection logic covers the right combinations of duties, while testing recently provisioned users confirms the control actually prevented conflicts in practice. Together they address whether the control is correctly defined and whether it operates as intended. Password policy, backups, and interviews do not provide direct evidence about conflicting access assignments in the ERP system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the ERP system's database backups complete successfully each night.
Why it's wrong here
Backup success is an availability and recovery control. It ensures data can be restored after loss or corruption but has no relationship to whether users hold conflicting access rights. SoD effectiveness is evaluated by examining role assignments, rulesets, and provisioning outcomes. Backup verification would be relevant to a different audit objective and does not test the segregation control described in the scenario.
- ✗
Confirm that the ERP system's password policy enforces complexity and expiration requirements.
Why it's wrong here
Password complexity and expiration strengthen authentication but do not address whether a single user can perform incompatible duties. SoD is about the combination of privileges assigned to an identity, not about credential strength. A user with a strong password can still hold conflicting roles. This procedure tests a different control area and would not provide evidence about the effectiveness of ongoing segregation of duties enforcement.
- ✓
Examine a sample of users provisioned in the last quarter to confirm that conflicting access was not granted.
Why this is correct
Provisioning-time detection can fail if the tool is bypassed, if roles change later, or if emergency access is granted outside the workflow. Testing a sample of recently provisioned users verifies whether the control actually prevented conflicting combinations in practice. This substantive test provides evidence that the designed control operated on real transactions, complementing a review of the ruleset and revealing gaps between policy and execution.
- ✗
Interview the ERP administrator to confirm that SoD conflicts are taken seriously.
Why it's wrong here
An interview provides management's perspective and can reveal tone and awareness, but it is not sufficient evidence of operating effectiveness. Administrators may believe conflicts are handled properly while exceptions go undetected. Auditors need to inspect configuration and test actual user access to confirm the control works. Relying on assertions without corroborating evidence would leave the audit conclusion unsupported, especially for a high-risk control area like segregation of duties.
- ✓
Review the ruleset used by the access management tool to identify conflicting role combinations.
Why this is correct
The ruleset defines which combinations of duties are considered conflicting. If the ruleset is incomplete, outdated, or excludes critical transaction pairs, the tool will not flag genuine conflicts regardless of how well provisioning works. Reviewing the ruleset tests the foundation of the control and helps the auditor determine whether detection logic covers the organization's actual business processes and risk areas, making it a direct test of ongoing effectiveness.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.