hardMultiple SelectObjective-mapped
CISA Practice Question: An IS auditor is reviewing the human resources…
An IS auditor is reviewing the human resources practices in the IT department. Which THREE of the following controls are most effective in reducing the risk of fraud?
⚠ Common exam trap
The trap here is that candidates often mistake background checks and training as the most direct fraud controls, overlooking that job rotation, mandatory vacation, and segregation of duties are the classic triad of fraud deterrence and detection in IT audit, as emphasized by COBIT and ISACA guidelines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Job rotation among IT roles
Job rotation (C) is effective because it prevents any single employee from maintaining exclusive control over critical IT functions over time, reducing the window for concealing fraudulent activities. By periodically rotating roles, anomalies or unauthorized actions that might otherwise go unnoticed are more likely to be detected by the incoming staff member, thereby deterring fraud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Annual security awareness training
Why it's wrong here
Training is important for security awareness but does not directly prevent fraud.
- ✗
Background checks on new hires
Why it's wrong here
Background checks help screen out individuals with a history of fraud but are a preventive measure at hiring, not an ongoing control.
- ✓
Job rotation among IT roles
Why this is correct
Reduces the opportunity for fraud by limiting the time any one person controls a process.
- ✓
Segregation of duties in IT processes
Why this is correct
Prevents any single individual from having conflicting responsibilities, reducing fraud risk.
- ✓
Mandatory vacation for IT staff
Why this is correct
Forces staff to take time off, allowing detection of fraudulent activities that require ongoing manipulation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.