Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is leading an audit engagement and discovers that a key member of the audit team lacks the technical expertise to evaluate a newly implemented cloud encryption control. The audit manager insists the team member proceed anyway to save time. According to ISACA IT Audit Standards, what is the MOST appropriate action for the IS auditor to take?

⚠ Common exam trap

The trap here is assuming that documenting a competence limitation in the report excuses the auditor from the standard's requirement to obtain the necessary expertise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain the necessary expertise through additional training or by engaging a qualified specialist.

ISACA IT Audit Standards require that the audit team collectively possess the competencies needed for the engagement. When a specific technical skill is missing, the auditor should acquire it through training or engage a qualified specialist. This preserves the validity of the audit opinion and satisfies professional standards. Proceeding with known incompetence, reassigning the entire engagement, or expanding scope does not remedy the underlying proficiency deficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Proceed with the audit as planned and note the limitation in the audit report.

    Why it's wrong here

    Proceeding without the necessary competence violates the ISACA standard requiring auditors to possess the knowledge, skills, and experience needed for the engagement. Simply noting the limitation in the report does not discharge the auditor's professional obligation, and it may result in an invalid opinion. The standard expects the auditor to obtain the required expertise or decline the assignment rather than document a known deficiency in capability.

  • ✗

    Delegate the entire engagement to the audit manager who has more experience.

    Why it's wrong here

    Delegating the entire engagement does not resolve the competence gap for the specific technical area and may not be feasible under resourcing constraints. The ISACA standards place responsibility on the audit function to ensure the team collectively has the required competencies. Shifting the whole engagement to one manager does not guarantee the specialized cloud encryption expertise needed and ignores proper engagement planning.

  • ✗

    Expand the audit scope to include additional systems to compensate for the knowledge gap.

    Why it's wrong here

    Broadening the scope does not address the missing technical competence and is unrelated to the standards' requirement for auditor proficiency. Increasing the audit surface area would likely introduce more risk of an invalid conclusion. The correct response is to close the competence gap, not to dilute the engagement by adding unrelated systems, which could also strain the team's existing capabilities further.

  • ✓

    Obtain the necessary expertise through additional training or by engaging a qualified specialist.

    Why this is correct

    ISACA IT Audit Standards require that auditors possess or obtain the competencies necessary to perform the engagement. When a team member lacks the technical skill to evaluate a control, the auditor should either ensure appropriate training or bring in a qualified specialist. This preserves the integrity of the audit opinion and complies with the standards' competence requirement, rather than accepting an inherent limitation.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.