Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It focuses audit efforts on areas with the highest risk.

A risk-based approach allows the auditor to focus on areas with higher risk, thereby optimizing the use of audit resources and ensuring that significant risks are addressed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It ensures that all controls are tested equally.

    Why it's wrong here

    Risk-based auditing deliberately concentrates effort on higher-risk areas, so controls are not tested equally; equal coverage is the trait of a compliance-driven or cyclical audit. Uniform testing appeals where regulation mandates identical treatment of every control, but it wastes effort on low-risk items.

  • ✗

    It reduces the overall cost of the audit.

    Why it's wrong here

    Lower cost is a possible by-product of focusing effort on significant risks, not the primary benefit; an audit can still be expensive. Cost reduction appeals to budget-conscious management, but it describes an incidental outcome rather than the risk-based approach's purpose of directing attention to material exposures.

  • ✓

    It focuses audit efforts on areas with the highest risk.

    Why this is correct

    Risk-based auditing directs scarce audit resources toward the areas of greatest exposure, so coverage and testing concentrate where the likelihood and impact of failure are highest. This satisfies the stem's demand for the primary benefit by aligning audit effort with the organisation's most significant risks rather than treating all infrastructure equally.

  • ✗

    It guarantees the detection of material misstatements.

    Why it's wrong here

    Auditing provides reasonable, not absolute, assurance; sampling and inherent limitations mean material misstatements can escape detection regardless of approach. The guarantee framing tempts auditors seeking defensible coverage, yet it describes an unattainable outcome rather than any real audit methodology.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.