712-50 exam dumps

712-50 practice question 59 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 59

Single answerIT Audit Management (5 questions)

A newly appointed CISO is preparing for the annual external IT audit of a global manufacturing company. In the prior year, auditors reported repeated findings in user access reviews, change management evidence, and inconsistent control performance across regional ERP instances. This year, the CEO has asked the CISO to reduce audit disruption to business operations while also improving the likelihood of a clean audit outcome. Which action should the CISO take FIRST to most effectively improve audit readiness and management of the audit process?

  1. A

    Establish a risk-based internal audit readiness program that maps key controls to business processes, assigns control owners, validates evidence quality before the external audit, and tracks remediation of prior findings

  2. B

    Ask regional IT managers to send all available logs, screenshots, and policy documents to the external auditors at the start of fieldwork so the auditors can determine what is relevant

  3. C

    Delay remediation work on prior findings until the external auditors confirm that the same issues remain in scope for the current audit cycle

  4. D

    Focus primarily on negotiating the audit timeline with the external audit firm to minimize interviews and walkthroughs for operational staff

Show answer and explanation

Correct answer: A

Explanation

In IT audit management, the CISO should first establish a structured, risk-based audit readiness process rather than treating the external audit as a documentation exercise. Repeated findings in access reviews, change management, and inconsistent regional control execution indicate systemic issues in control ownership, design consistency, and evidence management. Best practice is to identify in-scope controls based on business risk, map them to systems and processes, assign accountable owners, test readiness before fieldwork, and track remediation of prior findings through formal governance. This approach aligns with widely accepted control and audit practices found in ISACA guidance, the IIA's Three Lines Model, COBIT's governance and management objectives, and common internal control principles reflected in frameworks such as COSO. It also reduces disruption because the organization can centralize evidence requests, eliminate unnecessary submissions, and proactively resolve gaps before auditors arrive.

  • A. Correct.

    Correct. A risk-based audit readiness program is the most effective first step because it addresses the root causes of recurring findings and reduces disruption by organizing evidence, ownership, and remediation before fieldwork begins. Mapping controls to business processes and systems helps ensure audit coverage is aligned to actual risk areas, especially where ERP environments vary by region. Assigning accountable control owners and validating evidence quality in advance improves completeness, accuracy, and timeliness of responses. Tracking prior findings is also essential because repeat findings often indicate ineffective remediation and are scrutinized closely by auditors, audit committees, and regulators.

  • B. Incorrect.

    Incorrect. Sending all possible evidence to external auditors without internal validation is inefficient and increases audit disruption rather than reducing it. It can overwhelm auditors, expose inconsistencies, and signal weak audit governance. A mature audit management approach filters and quality-checks evidence first, ensures it is tied to specific control objectives, and coordinates submissions through designated owners or a central PMO-style function.

  • C. Incorrect.

    Incorrect. Delaying remediation is a poor governance decision. Prior findings should be assessed and remediated as early as possible, particularly if they involve foundational controls such as access reviews and change management. Even if scope shifts, unresolved issues may still represent material control weaknesses or indicate broader deficiencies in the control environment. Waiting for auditors to confirm scope undermines management's responsibility for internal control effectiveness.

  • D. Incorrect.

    Incorrect. Managing audit logistics is useful, but it should not be the primary first action. Negotiating timelines may reduce some operational burden, but it does not improve control effectiveness, evidence quality, or closure of prior issues. If underlying deficiencies remain, a streamlined schedule will not prevent adverse findings and may even compress the time available to respond effectively.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam