CISA Governance and Management of IT Practice Question
An organization outsources its data center operations. What is the BEST way to ensure the service provider's controls are effective?
⚠ Common exam trap
CISA often tests the misconception that a provider's internal audit reports or SLA monitoring are sufficient assurance; the trap is choosing a self-reported or performance-only measure instead of independent third-party audit evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct periodic third-party audits
Periodic third-party audits provide independent, objective assurance that the service provider's controls are designed and operating effectively. Unlike internal audit reports produced by the provider, third-party audits (e.g., SOC 2, ISO 27001 certification) are performed by an independent firm and give the outsourcing organization reliable evidence for governance and compliance purposes. This is the best way to verify control effectiveness because it removes the provider's self-assessment bias.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct periodic third-party audits
Why this is correct
Periodic third-party audits provide independent, objective verification that the outsourced provider's controls operate effectively, testing evidence rather than relying on self-reported assurances. This satisfies the stem's requirement to assure control effectiveness across an outsourced data centre.
- ✗
Rely on the provider's internal audit reports
Why it's wrong here
The provider's internal audit reports are self-produced evidence, lacking the independence needed to assure the customer that controls operate effectively; independent attestation such as SOC 2 is required. Relying on them is tempting because they are readily available and low cost, and they would be acceptable as supplementary evidence alongside independent assurance.
- ✗
Monitor service level agreements only
Why it's wrong here
SLAs measure availability and performance metrics, not whether the provider's control environment actually operates effectively, so they cannot evidence control assurance. Monitoring SLAs is tempting because it is a legitimate ongoing vendor-management activity, and it would be the correct choice when the requirement is tracking contracted service performance rather than validating controls.
- ✗
Require the provider to implement all organizational controls
Why it's wrong here
Imposing the organisation's own controls on the provider ignores that the provider's environment, staffing and processes differ, so those controls may not operate as designed; assurance comes from independent verification against recognised criteria. Requiring control implementation is tempting because it appears to guarantee coverage, and it would be correct when the organisation retains direct operational control.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.