CISA Information System Auditing Process Practice Question
An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?
⚠ Common exam trap
CISA often tests the distinction between risk-based prioritization and convenience-based prioritization (location, budget, headcount), tempting candidates to pick a tangible, easily measured factor over the correct risk assessment output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The results of a risk assessment evaluating inherent risk and control effectiveness.
A risk-based audit approach prioritizes coverage based on the likelihood and impact of risk, which is precisely what a risk assessment evaluating inherent risk and control effectiveness produces. Inherent risk reflects the susceptibility of a process or unit to error or fraud before controls, while control effectiveness indicates how much of that risk is mitigated. Combining these two factors lets the auditor direct limited audit resources to the areas of greatest residual risk, which is the defining principle of risk-based auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The geographical location of each business unit.
Why it's wrong here
Geographic location does not indicate likelihood or impact of loss, so it cannot rank audit coverage under a risk-based approach. It is tempting because dispersed sites suggest logistical difficulty, and location would drive coverage when regulations or data residency obligations differ by jurisdiction.
- ✓
The results of a risk assessment evaluating inherent risk and control effectiveness.
Why this is correct
In a decentralised organisation, coverage should be prioritised by a risk assessment weighing inherent risk against control effectiveness across business units. This directs limited audit resources to the units with the greatest residual exposure, satisfying the stem's requirement for the most appropriate prioritisation factor.
- ✗
The budget allocated to each business unit for IT.
Why it's wrong here
Spending level reflects capacity, not the probability or impact of control failure, so it cannot prioritise coverage. It is tempting because well-funded units appear lower risk, and budget would be the correct focus when auditing value for money or investment justification.
- ✗
The number of employees in each business unit.
Why it's wrong here
Headcount measures unit size, not the likelihood or impact of risk, so it misdirects audit resources away from high-risk areas. It is tempting because larger units appear to warrant attention, and would be correct if the audit objective were resourcing or coverage proportional to population rather than risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.