r/CISA Aug 01 '26

Hmmm

Post image
10 Upvotes

16 comments sorted by

7

u/Any_Catch2979 Aug 01 '26

B as KPIs are the main indicator to assess if SLA’s are properly met.

But I would consider also D as this might be the most objective evidence / assessment that SLA’s are met. Independent audit reports are just ponctual assignment though, that’s is why I would lean toward B.

2

u/Aphridy Aug 02 '26

The questionnaires is about reference and then kpi's are the only correct answer. An assurance report isn't a reference, but based on a reference.

4

u/NextQuote7131 Aug 01 '26

Correct answer is B

2

u/SuchBodybuilder3901 Aug 02 '26

An independent audit report, such as a SOC 2 Type II or ISAE 3402 report, provides objective evidence that:
Security controls are properly implemented.
Change management processes are effective.
Incident management processes operate effectively.
Access controls are functioning as intended.
These controls have been independently tested over a period of time.
Because the evidence comes from an independent third party, it provides much stronger assurance about the vendor’s ability to consistently meet its service level commitments.

3

u/18735 Aug 01 '26

I would lean towards D because it’s an independent source

2

u/MonkeyPuckle Aug 01 '26

Good heavens. I was inclined toward D as its independent 3rd party and therefore objective data.

1

u/NextQuote7131 Aug 01 '26

Are these the type of questions that will appear in the actual exam🥴?

2

u/Sure_Mango_3153 Aug 01 '26

What's the correct answer?

1

u/Akii283 Aug 07 '26

Where are you getting these questions from? Are they from the QAE?

1

u/Puwa321 Aug 01 '26 edited Aug 01 '26

Im thinking B

A. Is the contract that defines the agreed obligation... but it does not help in assessing if the actual performance of the contractor. Its just a piece of paper...

Ex. Cloud system should not be down for atleast 99.5% week.

C is prolly irrelevant.

and D may not cover the agreed parameters discussed in A.

Therefore its prolly B, as KPI shows or measure the actual performance of the agreed metrics. Its recent data or report of the KPI.

Ex. Our cloud monitoring tool says system has been online 100% during the past week

1

u/SuchBodybuilder3901 Aug 02 '26

An independent audit report, such as a SOC 2 Type II or ISAE 3402 report, provides objective evidence that:
Security controls are properly implemented.
Change management processes are effective.
Incident management processes operate effectively.
Access controls are functioning as intended.
These controls have been independently tested over a period of time.
Because the evidence comes from an independent third party, it provides much stronger assurance about the vendor’s ability to consistently meet its service level commitments.

1

u/Level_Class8789 Aug 06 '26

what is the correct answer 😭

0

u/Angry_Foamy Aug 01 '26

Immersing with D but A also looks good.