Courseiva
easyMultiple Select

CISA Practice Question: Which TWO of the following are primary objectives…

Which TWO of the following are primary objectives of the audit planning phase? (Select TWO.)

⚠ Common exam trap

Test-takers frequently confuse the planning phase with the execution phase, leading candidates to select 'develop detailed audit procedures' (Option A) as a planning objective, when it is actually a step in the audit program development after planning is complete.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify and assess risks relevant to the audit

Option B is correct because identifying and assessing risks relevant to the audit is a core purpose of audit planning; planning determines which areas are risky and therefore where audit effort should be focused, consistent with risk-based auditing standards. Option E is correct because defining the audit scope and objectives establishes what the audit will cover, its boundaries, and what it is intended to achieve, which is a fundamental planning activity that guides all subsequent work. Option A is not a primary planning objective because developing detailed audit procedures typically occurs after planning, during the design/programming stage, once scope, objectives, and risks are understood. Option C is not a planning objective because testing the effectiveness of internal controls is an execution/fieldwork activity, not something accomplished during planning. Option D is not a planning objective because issuing the final audit report is the concluding/reporting phase, which occurs after fieldwork and evidence evaluation are complete.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Develop detailed audit procedures

    Why it's wrong here

    Detailed audit procedures are developed during fieldwork execution, after planning has fixed scope, objectives and criteria. It is tempting because procedure design feels preparatory, yet planning's objectives are defining scope, understanding the entity and assessing risk to build the audit programme.

  • ✓

    Identify and assess risks relevant to the audit

    Why this is correct

    Audit planning determines scope, objectives and the risks that could cause material misstatement, so identifying and assessing relevant risks is a primary objective. This scoping of risk directs the nature, timing and extent of subsequent audit procedures.

  • ✗

    Test the effectiveness of internal controls

    Why it's wrong here

    Testing control effectiveness occurs during fieldwork, when evidence is gathered and evaluated. It is tempting because controls dominate audit work, but planning instead defines objectives, scope, criteria and resource requirements. Control testing is an execution activity, not a planning objective.

  • ✗

    Issue the final audit report

    Why it's wrong here

    Issuing the final report happens at the reporting stage, after fieldwork and review are complete. It is tempting because the report is the visible audit output, but planning instead establishes objectives, scope, criteria and resourcing. Reporting is a separate phase, not a planning objective.

  • ✓

    Define audit scope and objectives

    Why this is correct

    Defining scope and objectives is a primary objective of audit planning: it establishes the boundaries, resources and criteria the engagement will address, ensuring the audit is directed at the relevant risks before fieldwork begins. Without this, subsequent testing lacks a baseline against which evidence is assessed.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.