Courseiva
mediumMultiple Select

CISA Practice Question: An IS auditor is reviewing the design phase of a…

An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?

⚠ Common exam trap

Many exam-takers confuse detective controls (like audit logging) or security controls (like encryption) with preventive controls that directly stop unauthorized actions, failing to recognize that only preventive controls like approval workflows and segregation of duties address the root cause of unauthorized purchases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory approval workflows for purchase orders above a threshold.

Option A is correct because mandatory approval workflows for purchase orders above a defined threshold enforce an authorization control at the point of transaction, ensuring that high-value purchases cannot be committed without the required management sign-off, which directly prevents unauthorized purchases. Option C is correct because segregation of duties between requisition and approval ensures that the person initiating a purchase cannot also authorize it, removing the ability for a single individual to create and approve unauthorized purchases and providing a preventive, design-level control. Option B is not correct because automated performance reports on purchase cycle times are a detective/operational efficiency metric and do not prevent unauthorized purchases. Option D is not correct because real-time audit logging is a detective control that records activity after the fact rather than preventing unauthorized purchases. Option E is not correct because encryption of purchase order data in transit protects confidentiality against interception but does not address the authorization of purchases.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mandatory approval workflows for purchase orders above a threshold.

    Why this is correct

    Mandatory approval workflows enforce segregation of duties, ensuring purchase orders exceeding a defined threshold require authorised sign-off before commitment. This directly prevents unauthorised purchases by blocking orders that lack the required approval chain, satisfying the design-phase control objective.

  • ✗

    Automated performance reports on purchase cycle times.

    Why it's wrong here

    Cycle-time reports measure procurement efficiency after the fact and enforce nothing at authorisation. It is tempting because performance reporting supports management oversight, and it would be the correct design control when the objective is detecting process bottlenecks or measuring operational effectiveness rather than blocking unauthorised purchases.

  • ✓

    Segregation of duties between requisition and approval.

    Why this is correct

    Separating requisition from approval ensures no single user can both raise and authorise a purchase, directly blocking the unauthorised-purchase risk named in the stem. This design-level segregation prevents fraud or error before transactions occur, rather than detecting them afterwards through review.

  • ✗

    Real-time audit logging of all purchase transactions.

    Why it's wrong here

    Logging records purchases after they occur, providing detective evidence rather than preventing unauthorised purchases at entry. It is tempting because audit trails are a core IS control, and real-time logging would be the right choice when the objective is monitoring, investigation or meeting retention requirements.

  • ✗

    Encryption of purchase order data in transit.

    Why it's wrong here

    Encryption in transit protects purchase order confidentiality against interception; it does not verify who may raise a purchase. It is tempting because encryption is a fundamental security control, and it would be the right choice when the risk is eavesdropping or tampering on the network path rather than unauthorised purchasing.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.