nerdexam
Isaca

CISA · Question #362

Which of the following is MOST important for an IS auditor to determine when reviewing the design and implementation of controls?

The correct answer is A. Whether there is a proper balance between the magnitude of the risk and the control measures. The most important factor for an IS auditor to determine when reviewing the design and implementation of controls is whether there is a proper balance between the magnitude of the risk and the control measures implemented. Effective risk management involves aligning the level of

Submitted by sofia.br· Apr 18, 2026Governance and Management of IT

Question

Which of the following is MOST important for an IS auditor to determine when reviewing the design and implementation of controls?

Options

  • AWhether there is a proper balance between the magnitude of the risk and the control measures
  • BWhether the implemented controls closely align with domestic and international industry best
  • CWhether adequate resources are available for frequent and stringent control monitoring
  • DWhether identified risks are being completely mitigated through the proper application of control

How the community answered

(49 responses)
  • A
    92% (45)
  • B
    2% (1)
  • C
    4% (2)
  • D
    2% (1)

Explanation

The most important factor for an IS auditor to determine when reviewing the design and implementation of controls is whether there is a proper balance between the magnitude of the risk and the control measures implemented. Effective risk management involves aligning the level of control with the potential impact of the risk, ensuring that resources are appropriately allocated to mitigate significant risks without overburdening the organization with unnecessary controls.

Topics

#Risk Management#Control Effectiveness#Control Design#Audit Review

Community Discussion

No community discussion yet for this question.

Full CISA Practice