🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor19 / 148
Question 19 of 148

An IS auditor is testing whether user access requests are properly approved before provisioning. Using attribute sampling, the auditor sets a tolerable deviation rate of 5% and tests 60 access requests. The auditor finds 4 requests that were provisioned without documented approval, yielding a sample deviation rate of 6.67%. What is the auditor's MOST appropriate next step?

Reviewed for accuracy · Report an issueNext question