712-50 exam dumps

712-50 practice question 58 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 58

Single answerIT Audit Management (5 questions)

A newly appointed CISO is preparing the annual IT audit plan for a global organization that has recently migrated several critical business processes to a cloud-based ERP platform and expanded into two new regulatory jurisdictions. Internal audit has limited capacity, and the board audit committee has asked for assurance that audit effort is aligned to the organization's most significant information risks. Which approach should the CISO recommend FIRST to ensure the audit plan is both risk-based and defensible to senior leadership?

  1. A

    Build the audit plan primarily around findings from the prior year's audits so that unresolved issues receive continued attention

  2. B

    Prioritize audits of systems that process the largest transaction volumes because they are most important to business operations

  3. C

    Perform an enterprise risk assessment that incorporates business impact, control maturity, regulatory obligations, and recent environmental changes, then map audit coverage to the highest residual risk areas

  4. D

    Schedule audits evenly across all business units to demonstrate fairness and avoid over-focusing on any single function

Show answer and explanation

Correct answer: C

Explanation

The correct answer is the risk-based planning approach grounded in an enterprise risk assessment. In IT Audit Management at the CCISO level, the CISO is expected to ensure that audit activity supports governance objectives and provides assurance over the organization's most significant risks. Leading practices from the Institute of Internal Auditors (IIA) emphasize that internal audit plans should be based on a documented risk assessment and updated to reflect changes in the business, systems, regulation, and control environment. Similarly, frameworks such as ISACA COBIT and NIST guidance support prioritizing assurance activities based on business context, threat exposure, compliance obligations, and control maturity. In this scenario, cloud migration and expansion into new jurisdictions materially change the risk profile, so a plan based mainly on prior audits, transaction volume, or equal coverage would be weaker and harder to justify to senior leadership and the audit committee.

  • A. Incorrect.

    This is a reasonable consideration, but it is not the best first step for building an annual IT audit plan. Prior-year findings should inform planning, especially for follow-up activity, but relying primarily on historical issues can cause the organization to miss emerging risks introduced by cloud migration, new jurisdictions, or changes in the threat landscape. A risk-based audit plan must look forward as well as backward.

  • B. Incorrect.

    High transaction volume may correlate with operational importance, but volume alone is not a sufficient basis for audit prioritization. Some lower-volume systems may carry greater regulatory, confidentiality, integrity, or availability risk. This option reflects a common misconception that business criticality can be inferred only from throughput rather than from a broader assessment of inherent risk, control effectiveness, and residual risk.

  • C. Correct.

    This is the best answer because IT audit management should be driven by a current, enterprise-aligned risk assessment. The scenario specifically highlights major changes: cloud ERP adoption, expansion into new jurisdictions, and limited audit capacity. A defensible audit plan should therefore consider business impact, legal and regulatory exposure, changes in architecture and vendors, and the effectiveness of existing controls so that scarce audit resources are applied to the highest residual risks. This approach aligns with risk-based internal auditing practices and provides clear justification to the audit committee.

  • D. Incorrect.

    Even distribution of audits may appear equitable, but it is not risk-based and can result in inefficient use of limited audit resources. In mature governance models, audit coverage is prioritized according to risk, not organizational symmetry. This option reflects a governance misunderstanding: the goal of an audit plan is not equal attention for all areas, but appropriate attention for the areas that matter most to the enterprise.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam