nerdexam
Isaca

CISA · Question #78

During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the

The correct answer is D. Verify whether the licensing agreement allows shared use.. Upon discovering shared license keys, the auditor's best course of action is to verify whether the software licensing agreement permits such usage to determine compliance and identify any potential violation.

Submitted by helene.fr· Apr 18, 2026Information Systems Auditing Process

Question

During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the auditor's BEST course of action?

Options

  • ARecommend the utilization of software licensing monitoring tools.
  • BRecommend the purchase of additional software license keys.
  • CValidate user need for shared software licenses.
  • DVerify whether the licensing agreement allows shared use.

How the community answered

(55 responses)
  • A
    22% (12)
  • B
    5% (3)
  • C
    15% (8)
  • D
    58% (32)

Why each option

Upon discovering shared license keys, the auditor's best course of action is to verify whether the software licensing agreement permits such usage to determine compliance and identify any potential violation.

ARecommend the utilization of software licensing monitoring tools.

Recommending monitoring tools is a solution-oriented action that should follow the determination of a non-compliance issue, not precede the verification of the license agreement itself.

BRecommend the purchase of additional software license keys.

Recommending the purchase of additional license keys assumes non-compliance, which needs to be verified first according to the existing agreement.

CValidate user need for shared software licenses.

While validating user need for shared licenses might inform future licensing strategies, it does not address the immediate compliance question of whether current sharing is allowed by the existing agreement.

DVerify whether the licensing agreement allows shared use.Correct

The auditor's primary responsibility is to assess compliance. By verifying the licensing agreement, the auditor establishes whether the observed behavior (shared use) is permissible or a violation, which is crucial before recommending any remedial actions or purchasing additional licenses.

Concept tested: Software licensing compliance audit

Source: https://www.isaca.org/resources/isaca-journal/issues/2009/volume-3/it-audit-and-assurance-standards-glossary-of-terms

Topics

#Software Licensing#Compliance#Audit Procedures#Contract Review

Community Discussion

No community discussion yet for this question.

Full CISA Practice