mediumMultiple Choice
CISA Practice Question: An IS auditor is reviewing the audit follow-up…
An IS auditor is reviewing the audit follow-up process. The auditor notes that management has implemented corrective actions for 80% of previous audit findings. What should the auditor conclude?
⚠ Common exam trap
Test-takers frequently assume a high percentage (80%) implies overall effectiveness, but CISA requires verification that all findings, especially high-risk ones, are resolved or formally accepted, not just a majority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Further investigation of outstanding findings is needed
An 80% closure rate indicates that 20% of findings remain unresolved. ISACA standards require auditors to verify that all high-risk findings are remediated before concluding on control effectiveness. Without evidence that the outstanding 20% are low-risk or have an accepted risk, the auditor must investigate further to ensure residual risk is within the organization's appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The audit scope was too narrow
Why it's wrong here
The follow-up review measures remediation of prior findings; it reveals nothing about whether the original audit scope was adequate. Scope sufficiency is assessed during audit planning, not follow-up. This option tempts auditors who suspect missed risks, and would be correct if evidence showed the original scope omitted material systems.
- ✓
Further investigation of outstanding findings is needed
Why this is correct
Eighty per cent completion leaves 20% of findings unresolved, so the auditor cannot conclude remediation is effective. Outstanding findings require follow-up to determine whether management has accepted the risk, delayed action, or lacks the capability to implement corrective measures.
- ✗
The audit process is effective
Why it's wrong here
An 80% remediation rate shows management partially addressed findings; it does not demonstrate that the audit process itself is effective. Process effectiveness is evidenced by findings being valid, risk-based and accepted. This tempts because high remediation appears to validate the audit, and would be correct if all findings were resolved and quality reviews confirmed the methodology.
- ✗
Management is compliant with all recommendations
Why it's wrong here
80% implementation leaves 20% of findings unresolved, so management cannot be compliant with all recommendations. The figure describes partial remediation only. This option is tempting because a high completion rate suggests diligence, and full compliance would be the correct conclusion only if every finding were closed or formally risk-accepted.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.