Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Right-to-audit clause

A right-to-audit clause allows the organization or its auditor to review the provider's controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exit strategy

    Why it's wrong here

    An exit strategy covers transition and data return when the relationship ends, not ongoing verification of controls. It tempts because outsourcing contracts commonly require exit planning. The correct clause is right to audit, which grants the organisation contractual authority to inspect and test the provider's controls during the engagement.

  • ✗

    Service level agreement (SLA)

    Why it's wrong here

    An SLA defines performance and availability targets, not the organisation's right to audit or inspect the provider's controls. It tempts because SLAs are central to outsourcing contracts. The correct clause is the right-to-audit provision, which contractually grants verification access; SLAs measure service, they do not enable control testing.

  • ✗

    Vendor concentration risk clause

    Why it's wrong here

    A concentration risk clause addresses over-reliance on a single provider or shared dependencies, not verification rights. It tempts because concentration risk is a recognised outsourcing concern. The correct clause is right to audit, which contractually permits the organisation to inspect and test the provider's controls directly.

  • ✓

    Right-to-audit clause

    Why this is correct

    A right-to-audit clause contractually grants the organisation the ability to inspect the provider's controls, evidence and processes. This directly satisfies the stem's verification constraint, since without it the outsourcer could refuse audits, leaving control effectiveness unconfirmed.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.