nerdexam
Isaca

CISA · Question #178

An IS auditor is planning a review of an organization's cybersecurity incident response maturity. Which of the following methodologies would provide the MOST reliable conclusions?

The correct answer is B. Data analytics testing. Assessing cybersecurity incident response maturity requires evaluating patterns across large volumes of incident records, response times, escalation paths, and remediation actions. Data analytics testing (B) enables objective, comprehensive analysis of these datasets - it can ide

Submitted by haru.x· Apr 18, 2026Information System Auditing Process

Question

An IS auditor is planning a review of an organization’s cybersecurity incident response maturity. Which of the following methodologies would provide the MOST reliable conclusions?

Options

  • AJudgmental sampling
  • BData analytics testing
  • CVariable sampling
  • DCompliance testing

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    56% (15)
  • C
    11% (3)
  • D
    26% (7)

Explanation

Assessing cybersecurity incident response maturity requires evaluating patterns across large volumes of incident records, response times, escalation paths, and remediation actions. Data analytics testing (B) enables objective, comprehensive analysis of these datasets - it can identify trends, anomalies, and gaps that human judgment alone might miss, producing evidence-based, reproducible conclusions. Judgmental sampling (A) relies on the auditor's subjective selection of items, introducing bias and limiting coverage. Variable sampling (C) is designed to estimate a quantity within a population (e.g., error rate) and is not suited for maturity assessments. Compliance testing (D) verifies whether specific controls were followed but does not evaluate the effectiveness or maturity of the overall program.

Topics

#Audit methodologies#Data analytics#Incident response#Maturity assessment

Community Discussion

No community discussion yet for this question.

Full CISA Practice