nerdexam
Isaca

CGEIT · Question #322

An independent consultant has been hired to conduct an ad hoc audit of an enterprise's information security office with results reported to the IT governance committee and the board Which of the follo

The correct answer is B. The scope and stakeholders of the audit. Before an audit begins, providing the consultant with the scope and stakeholders of the audit is most important to ensure the audit is focused, relevant, and covers all necessary areas.

Submitted by dimitri_ru· Apr 18, 2026Governance of Enterprise IT

Question

An independent consultant has been hired to conduct an ad hoc audit of an enterprise's information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?

Options

  • AAcceptance of the audit risks and opportunities
  • BThe scope and stakeholders of the audit
  • CThe organizational structure of the security office
  • DThe policies and framework used by the security office

How the community answered

(26 responses)
  • A
    15% (4)
  • B
    73% (19)
  • C
    4% (1)
  • D
    8% (2)

Why each option

Before an audit begins, providing the consultant with the scope and stakeholders of the audit is most important to ensure the audit is focused, relevant, and covers all necessary areas.

AAcceptance of the audit risks and opportunities

Acceptance of audit risks and opportunities is typically part of the audit planning and engagement letter, but the scope must be defined first to understand what risks or opportunities are being accepted.

BThe scope and stakeholders of the auditCorrect

Clearly defining the scope and stakeholders of the audit is critical because it sets the boundaries and objectives for the consultant's work, ensuring that the audit focuses on the specific areas and systems that the IT governance committee and board are concerned about. This prevents mission creep, ensures all relevant parties are identified for interviews or data collection, and ultimately leads to an audit report that directly addresses the enterprise's needs.

CThe organizational structure of the security office

The organizational structure of the security office provides context but does not define what the audit will cover or who needs to be involved from a governance perspective.

DThe policies and framework used by the security office

The policies and framework used by the security office are important evidence or criteria for the audit, but the scope defines which policies and frameworks are relevant to the audit engagement.

Concept tested: Audit scope definition

Topics

#Audit scope#Audit planning#Stakeholder management#IT governance oversight

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice