easyMultiple ChoiceObjective-mapped
Best Evidence That Access Rights Are Appropriately Assigned
An IS auditor is reviewing the logical access controls of a system. Which of the following is the BEST evidence that access rights are appropriately assigned?
Quick Answer
The answer is a recent user access review report signed by department managers. This is the best evidence that access rights are appropriately assigned because it provides documented, detective-level confirmation that data owners—the department managers—have explicitly verified and approved each user’s access privileges. Unlike preventive controls such as role-based templates or automated provisioning logs, a signed review report directly validates that the rights assigned are correct and current, serving as an authoritative attestation from those who own the data. On the CISA exam, this question tests your understanding that logical access control audits prioritize evidence of independent verification over system-generated logs; a common trap is choosing an access control list or provisioning policy, which show intent but not actual validation. Remember the memory tip: “Sign-off from the boss proves access isn’t a loss”—the manager’s signature is the gold standard for proving appropriate assignment.
⚠ Common exam trap
It's easy for candidates to confuse a control design document (access control matrix) with evidence of control effectiveness, failing to recognize that only a recent, signed user access review provides proof that the assigned rights have been validated by the data owner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A recent user access review report signed by department managers
The best evidence because a user access review report signed by department managers provides documented confirmation that the assigned access rights have been explicitly verified and approved by the data owners. This is a detective control that directly validates the appropriateness of access assignments, whereas the other options are either preventive or detective controls that do not confirm the correctness of the rights themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An audit log showing all successful and failed login attempts
Why it's wrong here
Shows activity but not whether access rights are appropriate.
- ✗
A password policy requiring complex passwords
Why it's wrong here
Password policy addresses authentication, not authorization.
- ✗
An access control matrix defining roles and permissions
Why it's wrong here
Defines intended access but not actual assignment.
- ✓
A recent user access review report signed by department managers
Why this is correct
Management sign-off confirms proper assignment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An IS auditor is reviewing the logical access controls of a financial application. Which of the following is the BEST way to verify that user access rights are appropriate?
medium- A.Interview the IT security manager about the access control process.
- B.Review the access control list for each user.
- C.Re-perform a sample of transactions to detect unauthorized access.
- ✓ D.Compare the user access rights with the job descriptions and responsibilities.
Why D: Comparing user access rights directly against job descriptions and responsibilities is the most effective method to verify that access is appropriate based on the principle of least privilege. This approach ensures that each user's permissions align with their actual job functions, which is the core objective of a logical access control review. Interviewing or reviewing lists alone does not validate the appropriateness of access against business roles.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.