
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Auditing Process.
Question
While auditing user provisioning controls, you select a random sample of 50 provisioning transactions from a population of 5,000 and find 4 instances where access was granted without documented approval. What is the most appropriate next step?
Show the answer and explanation
Correct answer: C. Increase the sample size and perform additional targeted testing to determine whether exceptions are pervasive.
Finding exceptions in a sample indicates a potential issue, but professional auditing standards require determining whether exceptions are pervasive before drawing population-level conclusions. Expanding the sample and performing additional targeted procedures helps assess the extent, root causes, and whether errors are isolated. Extrapolating immediately risks over- or under-stating the issue because the initial sample may not be sufficiently precise. Reporting a significant deficiency without further evaluation may be premature; the auditor should first determine scope and materiality. Concluding the control is effective ignores the observed exceptions and fails to evaluate their significance across the population.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
