nerdexam
Isaca

CISA · Question #18

What is the PRIMARY reason to adopt a risk-based IS audit strategy?

The correct answer is C. To prioritize available resources and focus on areas with significant risk. The primary reason to adopt a risk-based IS audit strategy is to prioritize available resources effectively. This ensures that audit efforts are focused on areas with the most significant risks to the organization, maximizing the impact of the audit.

Submitted by ahmad_uae· Apr 18, 2026Information System Auditing Process

Question

What is the PRIMARY reason to adopt a risk-based IS audit strategy?

Options

  • ATo achieve synergy between audit and other risk management functions
  • BTo reduce the time and effort needed to perform a full audit cycle
  • CTo prioritize available resources and focus on areas with significant risk
  • DTo identify key threats, risks, and controls for the organization

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    93% (25)
  • D
    4% (1)

Why each option

The primary reason to adopt a risk-based IS audit strategy is to prioritize available resources effectively. This ensures that audit efforts are focused on areas with the most significant risks to the organization, maximizing the impact of the audit.

ATo achieve synergy between audit and other risk management functions

Achieving synergy with other risk management functions is a beneficial outcome, but not the primary driving reason for adopting a risk-based audit strategy itself, which is resource prioritization.

BTo reduce the time and effort needed to perform a full audit cycle

While a risk-based approach might reduce effort on low-risk areas, its main goal is effective risk mitigation and resource optimization, not merely reducing overall audit time.

CTo prioritize available resources and focus on areas with significant riskCorrect

A risk-based IS audit strategy primarily aims to optimize the use of limited audit resources by directing them towards areas and systems that pose the greatest risk to the organization's objectives, assets, and information. By focusing on significant risks, auditors can ensure that the most critical vulnerabilities are identified and addressed, providing the most value to the organization.

DTo identify key threats, risks, and controls for the organization

Identifying key threats, risks, and controls is a necessary prerequisite step in conducting a risk assessment, which then informs the adoption and implementation of a risk-based audit strategy, rather than being the strategy's primary reason for adoption.

Concept tested: Risk-based auditing principles

Topics

#Risk-based audit#Audit strategy#Resource prioritization#Significant risk

Community Discussion

No community discussion yet for this question.

Full CISA Practice