Courseiva
hardMultiple Choice

CISA Practice Question: Has outsourced its IT help desk to a third-party…

An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?

⚠ Common exam trap

Many exam-takers confuse operational or security controls (background checks, system access, meetings) with the contractual governance control (SLA) that directly enforces and measures service quality, leading them to pick a plausible but less critical option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service level agreement (SLA) with key performance indicators

A Service Level Agreement (SLA) with key performance indicators (KPIs) is the most critical control because it defines measurable targets (e.g., average speed to answer, first-call resolution rate, ticket closure time) and establishes contractual remedies for non-compliance. Without an SLA, the organization has no enforceable mechanism to hold the provider accountable for service quality, making it the foundational control for outsourced IT help desk governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Regular background checks on provider employees

    Why it's wrong here

    Background checks address personnel integrity and confidentiality risk, not whether the help desk resolves incidents within agreed service levels. They tempt because vetting sounds like strong due diligence, and they would be the correct choice where the concern is insider threat or data protection rather than service quality measurement.

  • ✗

    Access to provider's incident management system

    Why it's wrong here

    Read access to the provider's incident system gives visibility of tickets but no contractual obligation or independent verification of resolution quality. It tempts because live data feels authoritative, and it would be the correct choice when the organisation needs operational oversight of individual incidents rather than assurance of overall service performance.

  • ✗

    Monthly meetings with provider management

    Why it's wrong here

    Meetings discuss performance but generate no measurable evidence of service quality; service level agreements with defined metrics and reporting provide the enforceable control. Meetings tempt because governance contact feels reassuring, and they would be the right choice for relationship management or escalation, not for verifying service delivery.

  • ✓

    Service level agreement (SLA) with key performance indicators

    Why this is correct

    An SLA with key performance indicators defines measurable service targets, such as response and resolution times, against which the outsourced provider's performance is monitored. This satisfies the stem's requirement to ensure service quality, since without measurable KPIs the organisation cannot objectively verify or enforce the provider's obligations.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.