Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?

⚠ Common exam trap

CISA often tests the misconception that an SLA with penalties or data localization clauses provide equivalent assurance to a right-to-audit — candidates must recognize that only the right-to-audit gives the auditor legal standing to obtain control evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Right-to-audit clause.

The right-to-audit clause is the most critical contractual provision for an IS auditor because it grants the organization the legal right to inspect the cloud provider's controls, processes, and records — either directly or via third-party attestations (SOC 2, ISO 27001). Without it, the auditor cannot obtain sufficient evidence to opine on the effectiveness of controls over outsourced data and processing. It is the contractual foundation that makes all other assurance activities possible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data localization requirements.

    Why it's wrong here

    Data localisation constrains where data is stored, but it does not by itself guarantee the security, privacy or audit rights the auditor must secure in the contract. It is tempting because residency is a common regulatory demand, and it would be correct when legislation mandates in-country storage.

  • ✓

    Right-to-audit clause.

    Why this is correct

    A right-to-audit clause contractually guarantees the IS auditor independent access to the provider's controls, records and evidence. Without it, the organisation cannot verify that the outsourced service meets its security and compliance obligations, leaving assurance dependent solely on the provider's own reporting.

  • ✗

    Automatic renewal terms.

    Why it's wrong here

    Automatic renewal terms govern contract duration and termination notice, giving no assurance over data protection, access control or breach notification. It is tempting because renewal affects cost and lock-in, and it would be correct when the audit objective is avoiding unintended contract extension rather than safeguarding data.

  • ✗

    Service level agreement (SLA) with penalties.

    Why it's wrong here

    An SLA with penalties addresses availability and performance remedies, but it does not establish the auditor's primary concern: the provider's obligation to protect data confidentiality, integrity and compliance. It is tempting because measurable service commitments feel like the strongest contractual safeguard, and it would be correct when availability is the dominant risk.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.