Courseiva

CISA Information System Auditing Process Practice Question

During an audit of a data center, the IS auditor observes that visitors are escorted at all times but the visitor log is not reconciled to the badge access system. Which of the following BEST describes the audit concern?

⚠ Common exam trap

The trap here is assuming that a preventive control such as escorting is sufficient without a detective control to verify it actually occurred.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Physical access controls are not operating effectively because the two records are not reconciled.

The audit concern is that the detective control of reconciling visitor logs with badge records is not operating, so unauthorized access could go undetected. Escorting alone is preventive and can fail. Both records have distinct value, and the absence of reconciliation is the control gap. The finding should be documented rather than closed or dismissed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The badge access system is more reliable than the visitor log, so the log can be discarded.

    Why it's wrong here

    Both records serve different purposes. The badge system records electronic entries, while the visitor log captures identity and purpose. Discarding the log would remove a source of accountability and make it harder to investigate incidents. The concern is the absence of reconciliation, not the redundancy of one record, so eliminating the log does not address the control gap.

  • ✗

    Visitor logs are not required by any standard, so the finding should be closed.

    Why it's wrong here

    Even if a specific standard does not mandate visitor logs, the organization's own control design includes them, and the lack of reconciliation creates a gap between designed and operating controls. Auditors assess controls against the organization's objectives and recognized frameworks, not only against explicit mandates. Closing the finding would ignore a real detective control weakness.

  • ✗

    The escort requirement is sufficient on its own, so no further action is needed.

    Why it's wrong here

    Escorting is a preventive control, but it can fail through human error or social engineering. Detective controls such as reconciliation are needed to identify failures. Relying solely on escorts without verifying entry records leaves the organization unable to detect unauthorized access. The observation of an unreconciled log directly undermines the assurance that escorts were always present.

  • ✓

    Physical access controls are not operating effectively because the two records are not reconciled.

    Why this is correct

    The lack of reconciliation between the visitor log and the badge system means unauthorized or unescorted access could go undetected. The control objective is to ensure all physical entries are authorized and monitored. Without reconciliation, the log and badge records cannot be relied upon to detect discrepancies, so the control is not operating effectively.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.