CISA Practice Question: Information Systems Operations and Business Resilience
An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?
⚠ Common exam trap
The trap is confusing SLA metrics or exit strategies with audit rights; candidates must recognize that only a right-to-audit clause gives the organization the contractual authority to assess the vendor's controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right-to-audit clause
A right-to-audit clause in the contract explicitly grants the organization the right to audit the vendor's controls, processes, and compliance, which is essential for the IS auditor to assess the vendor's security posture. Without this clause, the organization may have no contractual authority to conduct audits or obtain audit reports, making it impossible to verify the effectiveness of controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service level agreement (SLA) metrics
Why it's wrong here
SLA metrics measure service performance such as response and resolution times, not the adequacy of the vendor's internal controls. They are tempting because they are the usual mechanism for holding a vendor accountable, which is the correct choice when the question asks about performance monitoring rather than control assurance.
- ✗
Subcontracting restrictions
Why it's wrong here
Subcontracting restrictions limit the vendor's ability to delegate work, but they do not grant the organisation the right to evaluate the vendor's own control environment. They are tempting because they address third-party risk, which is the correct choice when the concern is unauthorised delegation of services.
- ✗
Exit strategy provisions
Why it's wrong here
Exit strategy provisions govern transition and data return at contract termination, not ongoing assessment of the vendor's controls. They are tempting because they protect the organisation during offboarding, which is the correct choice when the question concerns continuity or termination risk rather than audit rights.
- ✓
Right-to-audit clause
Why this is correct
A right-to-audit clause contractually grants the organisation access to assess the vendor's controls, processes and evidence. Without it, the auditor cannot independently verify the outsourced help desk's control environment, directly satisfying the stem's assessment objective.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.