Courseiva
easyMultiple Select

CISA Practice Question: Which TWO of the following are primary objectives…

Which TWO of the following are primary objectives of an information system audit?

⚠ Common exam trap

It's easy for candidates to confuse operational or management responsibilities (like performance tuning or patch implementation) with the auditor's role of evaluating controls and identifying process improvements, leading candidates to select options that describe IT tasks rather than audit objectives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify areas for improvement in IT processes

An information system audit is fundamentally an assurance engagement, so its primary objectives are to evaluate the effectiveness of internal controls (D) — determining whether controls are designed and operating to provide reasonable assurance over confidentiality, integrity, and availability of information and IT services — and to identify areas for improvement in IT processes (C), since audit findings and recommendations drive corrective action and process maturity. Both C and D align with the auditor's independent, objective assessment role rather than with operational execution. Option A is not a primary audit objective because optimizing performance is an IT management/operations responsibility; the auditor may assess performance-related controls but does not ensure optimal performance. Option B is also an operational task performed by IT staff (e.g., patch management), not an audit objective, and option E belongs to financial accounting/reporting, not to the IS audit function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure optimal performance of IT systems

    Why it's wrong here

    An information system audit provides independent assurance over controls, risk and compliance; performance tuning is an operational management responsibility, not an audit objective. It is tempting because auditors do examine efficiency and effectiveness, but that is evidence gathering for assurance, not a primary objective of optimising system performance itself.

  • ✗

    Implement security patches and updates

    Why it's wrong here

    Auditing evaluates controls and reports assurance; it does not remediate systems, so patching is an operational IT task, not an audit objective. It is tempting because audit findings often recommend patching, but the audit's role is to assess and report, while implementation belongs to system administrators.

  • ✓

    Identify areas for improvement in IT processes

    Why this is correct

    Identifying areas for improvement in IT processes is a core assurance objective: the auditor evaluates controls against criteria and reports weaknesses, feeding remediation and continuous improvement. This satisfies the stem's requirement for a primary objective, since information system audits exist to assess effectiveness and recommend enhancements, not merely to detect fraud or verify accounts.

  • ✓

    Evaluate the effectiveness of internal controls

    Why this is correct

    Auditing internal controls tests whether they operate as designed, confirming the control environment actually mitigates identified risks. This directly satisfies the stem's requirement to assess control effectiveness, distinguishing it from objectives such as verifying data integrity or evaluating system efficiency.

  • ✗

    Prepare financial statements for external reporting

    Why it's wrong here

    Preparing financial statements is a management and finance function; information system audits assess whether systems safeguarding assets and data integrity support reliable reporting, not produce the statements. It is tempting because auditors review financial systems and controls, and would be relevant when auditing reporting integrity, but statement preparation is not an audit objective.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.