CISA Information System Auditing Process Practice Question
An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)
⚠ Common exam trap
CISA often tests the inherent-versus-control risk boundary, tempting candidates to select control-related options (monitoring, access controls) as inherent-risk factors because they sound risk-relevant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Complexity of the cloud architecture
Inherent risk is assessed before considering controls, so the auditor should focus on factors that increase risk exposure independent of mitigation. Option A (Complexity of the cloud architecture) is correct because multi-tenant, virtualized, and distributed architectures increase the likelihood of misconfigurations, service dependencies, and attack surface, raising inherent risk. Option D (Sensitivity of data stored in the cloud) is correct because the classification and regulatory obligations of the data (e.g., PII, PCI DSS, PHI) directly determine the impact if confidentiality, integrity, or availability is compromised. Option E (Recent changes to the cloud environment) is correct because changes such as new deployments, migrations, or configuration updates introduce instability and unverified states that elevate inherent risk. Options B (Effectiveness of monitoring controls) and C (Strength of access controls) are not inherent risk factors; they are control effectiveness considerations evaluated during the control risk assessment, after inherent risk has been determined.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Complexity of the cloud architecture
Why this is correct
Complexity of the cloud architecture directly elevates inherent risk, since intricate multi-tenant, hybrid or interconnected designs enlarge the attack surface and obscure control gaps before any mitigation exists. It satisfies the stem's inherent-risk constraint by capturing design-driven uncertainty the auditor must weigh independently of implemented controls.
- ✗
Effectiveness of monitoring controls
Why it's wrong here
Monitoring control effectiveness describes how well a control operates, which feeds residual risk after inherent risk is rated. Inherent risk reflects exposure absent controls, so this belongs to control assessment. It would be the right consideration when evaluating whether detected threats are being addressed.
- ✗
Strength of access controls
Why it's wrong here
Access control strength is a control attribute, evaluated during control testing to derive residual risk. Inherent risk is assessed before controls are considered, so this factor belongs to the control-effectiveness stage. It would be relevant when judging whether identified exposures are adequately mitigated.
- ✓
Sensitivity of data stored in the cloud
Why this is correct
Sensitivity of data stored in the cloud drives inherent risk: highly confidential or regulated data attracts greater impact if compromised, elevating the assessed risk before considering mitigating controls, and directly influencing audit scope and depth.
- ✓
Recent changes to the cloud environment
Why this is correct
Recent changes to the cloud environment alter the likelihood of control failure, so they directly affect inherent risk before any controls are tested. This satisfies the stem's requirement to assess inherent risk, since change introduces instability and new exposure in the provider's infrastructure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.