nerdexam
Isaca

CISA · Question #546

An IS auditor learns that individual teams are allowed to implement and manage their use of robotic process automation (RPA). Which of the following controls would BEST enable the IT department to…

The correct answer is A. Uses of RPA are periodically evaluated to ensure they are functioning as intended. Periodically evaluating RPA uses to ensure they function as intended is the best governance control because it provides ongoing operational oversight of all decentralized RPA implementations, ensuring they continue to operate correctly over time. Option B (admin access to the…

Submitted by khalil_dz· Apr 18, 2026Governance and Management of IT

Question

An IS auditor learns that individual teams are allowed to implement and manage their use of robotic process automation (RPA). Which of the following controls would BEST enable the IT department to effectively govern the use of end-user computing (EUC) in this situation?

Options

  • AUses of RPA are periodically evaluated to ensure they are functioning as intended.
  • BIT has administrative access to the RPA management console.
  • CIT has access to view and manage all secrets stored within the RPA tool.
  • DUses of RPA are inventoried and assessed retroactively based on risk.

How the community answered

(59 responses)
  • A
    46% (27)
  • B
    17% (10)
  • C
    29% (17)
  • D
    8% (5)

Explanation

Periodically evaluating RPA uses to ensure they function as intended is the best governance control because it provides ongoing operational oversight of all decentralized RPA implementations, ensuring they continue to operate correctly over time. Option B (admin access to the RPA console) is an access control, not a governance mechanism. Option C (access to secrets) is a security control but does not address broader governance. Option D describes retroactive, reactive assessment, which is weaker than proactive, periodic evaluation and may leave risks undetected for extended periods.

Topics

#RPA#End-User Computing (EUC)#IT Governance#Control Effectiveness Monitoring

Community Discussion

No community discussion yet for this question.

Full CISA Practice