easyMultiple Select
CISA Practice Question: Which TWO of the following are primary objectives…
Which TWO of the following are primary objectives of an information system audit?
⚠ Common exam trap
It's easy for candidates to confuse operational or management responsibilities (like performance tuning or patch implementation) with the auditor's role of evaluating controls and identifying process improvements, leading candidates to select options that describe IT tasks rather than audit objectives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify areas for improvement in IT processes
An information system audit is fundamentally an assurance engagement, so its primary objectives are to evaluate the effectiveness of internal controls (D) — determining whether controls are designed and operating to provide reasonable assurance over confidentiality, integrity, and availability of information and IT services — and to identify areas for improvement in IT processes (C), since audit findings and recommendations drive corrective action and process maturity. Both C and D align with the auditor's independent, objective assessment role rather than with operational execution. Option A is not a primary audit objective because optimizing performance is an IT management/operations responsibility; the auditor may assess performance-related controls but does not ensure optimal performance. Option B is also an operational task performed by IT staff (e.g., patch management), not an audit objective, and option E belongs to financial accounting/reporting, not to the IS audit function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure optimal performance of IT systems
Why it's wrong here
An information system audit provides independent assurance over controls, risk and compliance; performance tuning is an operational management responsibility, not an audit objective. It is tempting because auditors do examine efficiency and effectiveness, but that is evidence gathering for assurance, not a primary objective of optimising system performance itself.
- ✗
Implement security patches and updates
Why it's wrong here
Auditing evaluates controls and reports assurance; it does not remediate systems, so patching is an operational IT task, not an audit objective. It is tempting because audit findings often recommend patching, but the audit's role is to assess and report, while implementation belongs to system administrators.
- ✓
Identify areas for improvement in IT processes
Why this is correct
Identifying areas for improvement in IT processes is a core assurance objective: the auditor evaluates controls against criteria and reports weaknesses, feeding remediation and continuous improvement. This satisfies the stem's requirement for a primary objective, since information system audits exist to assess effectiveness and recommend enhancements, not merely to detect fraud or verify accounts.
- ✓
Evaluate the effectiveness of internal controls
Why this is correct
Auditing internal controls tests whether they operate as designed, confirming the control environment actually mitigates identified risks. This directly satisfies the stem's requirement to assess control effectiveness, distinguishing it from objectives such as verifying data integrity or evaluating system efficiency.
- ✗
Prepare financial statements for external reporting
Why it's wrong here
Preparing financial statements is a management and finance function; information system audits assess whether systems safeguarding assets and data integrity support reliable reporting, not produce the statements. It is tempting because auditors review financial systems and controls, and would be relevant when auditing reporting integrity, but statement preparation is not an audit objective.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.