
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Auditing Process.
Question
During an audit of logical access controls, you find that user accounts are provisioned automatically from the HR system to the directory service. Management says the automated process enforces correct access, but there is no regular reconciliation between HR records and active accounts. Which audit procedure is most appropriate to address this situation?
Show the answer and explanation
Correct answer: A. Test the operating effectiveness of the automated provisioning by sampling HR-to-directory reconciliations, observing provisioning runs, and verifying a sample of user records.
The best next step is to test operating effectiveness of the automated provisioning control by obtaining and testing HR-to-directory reconciliations (or creating them for sampled periods), observing provisioning runs, and verifying a sample of user records. That provides direct evidence the control works as intended. Option 1 is wrong because accepting design without testing provides no evidence of operating effectiveness. Option 2 is incorrect because increasing substantive testing alone does not address identity management risks or provide assurance over access provisioning. Option 3 is premature: a finding may be warranted if testing shows deficiency, but the auditor should first gather evidence through appropriate procedures.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
