Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is planning an audit of a cloud service provider's security controls. The auditor has limited access to the provider's internal systems. Which of the following would be the MOST effective way to obtain assurance over the provider's security controls?

⚠ Common exam trap

The trap here is relying on the provider's self-assessment or interviews when independent third-party audit reports are available and provide stronger, more objective evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the provider's independent audit reports (e.g., SOC 2 Type II).

When an IS auditor has limited access to a cloud service provider's internal systems, reviewing the provider's independent audit reports (such as SOC 2 Type II) is the most effective way to obtain assurance over security controls. These reports are prepared by independent auditors and cover the design and operating effectiveness of controls over a period. They provide reliable, third-party evidence. Self-assessments, penetration testing, and interviews are less reliable or comprehensive for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform penetration testing of the cloud environment.

    Why it's wrong here

    Penetration testing can identify vulnerabilities but may not provide comprehensive assurance over the provider's security controls. It is a point-in-time assessment and may not cover all control areas. Also, the provider may not permit penetration testing. While useful, it is not the most effective way to gain broad assurance over the provider's control environment, especially when access is limited.

  • ✗

    Interview the provider's IT security manager.

    Why it's wrong here

    Interviews provide oral evidence, which is generally less reliable than documentary evidence. The security manager may have a biased perspective. While interviews can provide context, they should not be the primary source of assurance. The auditor should seek independent, documentary evidence to corroborate interview statements. Therefore, interviews alone are not the most effective method.

  • ✓

    Review the provider's independent audit reports (e.g., SOC 2 Type II).

    Why this is correct

    Independent audit reports, such as SOC 2 Type II, provide an objective assessment of the provider's controls over a period. They are prepared by an independent auditor and cover the design and operating effectiveness of controls. This is a highly effective way to obtain assurance when direct access is limited. The IS auditor can review the report, assess the scope, and determine if it meets the audit objectives.

  • ✗

    Rely on the provider's self-assessment questionnaire.

    Why it's wrong here

    A self-assessment questionnaire is not independent evidence. The provider may present an overly favorable view. While it can be a starting point, it lacks the objectivity of independent verification. The auditor should seek more reliable evidence, such as independent audit reports, to gain assurance over the provider's security controls. Relying solely on self-assessment would not provide sufficient appropriate evidence.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.