Valid CISA Dumps shared by ExamDiscuss.com for Helping Passing CISA Exam! ExamDiscuss.com now offer the newest CISA exam dumps, the ExamDiscuss.com CISA exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CISA dumps with Test Engine here:
Which of the following provides an IS auditor the BEST evidence that a third-party service provider's information security controls are effective?
Correct Answer: C
Comprehensive and Detailed Step-by-Step Explanation: Toverify the effectivenessof a third-party provider'ssecurity controls, anindependent external audit reportis thestrongestevidence. * Option A (Incorrect):Security configuration documentsare helpful butdo not confirm effectivenesswithout validation. * Option B (Incorrect):Policies and procedures outlineintent, but anaudit confirms actual implementation. * Option C (Correct):External audit reports (e.g., SOC 2, ISO 27001)provideindependent assurancethat security controls are effective. * Option D (Incorrect):Management interviews providequalitativeinsights but arenot objective evidenceof control effectiveness. Reference:ISACA CISA Review Manual -Domain 3: Information Systems Acquisition, Development, and Implementation- Coversthird-party risk assessments and audit assurance.