Home > Blog > ISACA Certified Information Systems Auditor > Auditing Active Directory: CISA Exam Guide

Auditing Active Directory: CISA Exam Guide

Deep Dive Cert Sensei Team 2031-02-24 8 min read

Auditing Active Directory for CISA involves verifying the security of Group Policy Objects (GPOs), reviewing membership of privileged groups like Domain Admins, analyzing forest trust relationships, and identifying stale accounts. The goal is to ensure the principle of least privilege is enforced and that identity management controls mitigate unauthorized access risks.

#CISA #Active Directory #ISACA #IT Audit #Identity Management

Why is auditing Active Directory critical for the CISA exam?

In the eyes of an ISACA auditor, Active Directory (AD) isn't just a directory service—it's the 'keys to the kingdom.' If AD is compromised, the entire enterprise is compromised. For the CISA exam, you need to move beyond the technical 'how-to' and focus on the 'why' from a risk and control perspective. You'll be tested on your ability to identify gaps in identity and access management (IAM) that could lead to unauthorized privilege escalation.

When you approach an AD audit, your primary objective is to ensure that the configuration aligns with the organization's security policy. This means verifying that the attack surface is minimized and that there is a clear audit trail for every administrative action. Remember, CISA focuses heavily on the effectiveness of controls; you aren't just looking for a setting, you're looking for evidence that the setting is monitored and maintained.

How do you effectively review Group Policy Objects (GPOs) for security?

GPOs are where the rubber meets the road for security enforcement. When auditing them, you're looking for 'GPO drift'—where settings have changed over time without proper change management. Pay close attention to password policies, account lockout thresholds, and user rights assignments. A common CISA scenario involves identifying overly permissive GPOs that allow non-administrative users to perform sensitive tasks, such as backing up files or changing system time.

I recommend focusing on the 'Least Privilege' principle. Are there GPOs that grant 'Log on as a service' to too many accounts? Are there legacy policies still active that conflict with new security mandates? Use the Group Policy Management Console (GPMC) to generate reports, but as an auditor, your job is to challenge the necessity of each policy. If a policy exists but cannot be mapped to a business requirement or security control, it's a finding.

What are the red flags when auditing privileged groups?

Privileged groups—specifically Domain Admins, Enterprise Admins, and Schema Admins—are the highest-risk areas in any AD environment. The biggest red flag is 'Privilege Creep,' where users are added to these groups for a temporary task and never removed. In a healthy environment, the Domain Admins group should be extremely small—often fewer than five people. If you see 20+ users in this group, you've found a significant control deficiency.

Beyond just the number of users, you must audit the *process* of how users are added. Is there a documented request and approval process? Is there a quarterly access review? On the CISA exam, you'll often be asked to determine the best way to mitigate the risk of privileged account abuse. The answer usually involves implementing a 'tiered administrative model' or using Just-In-Time (JIT) access, ensuring that admins only have high-level permissions when absolutely necessary.

How should you analyze trust relationships between forests?

Trust relationships allow users in one forest to access resources in another, but they can also create dangerous pathways for lateral movement. When auditing trusts, you need to distinguish between transitive and non-transitive trusts. A transitive trust means if Forest A trusts Forest B, and Forest B trusts Forest C, then Forest A implicitly trusts Forest C. This can lead to 'trust sprawl' and unintended access.

Focus your audit on the 'SID Filtering' and 'Selective Authentication' settings. Selective authentication is a critical control because it prevents users in a trusted forest from automatically being authenticated in the trusting forest; instead, you must explicitly grant them permissions to specific resources. If you find a forest-wide authentication trust with no restrictive filters, you're looking at a high-risk finding that could allow a compromise in a partner forest to leapfrog into your primary environment.

How do you identify stale accounts and orphaned SIDs?

Account lifecycle management is a cornerstone of Domain 5 in the CISA curriculum. Stale accounts—accounts that haven't been logged into for 30, 60, or 90 days—are prime targets for attackers because their compromise often goes unnoticed. Your audit should verify that the organization has an automated process for identifying and disabling these accounts. If the process is manual, it's likely failing.

Then there are orphaned SIDs (Security Identifiers). These occur when a user is deleted, but their SID remains in the Access Control List (ACL) of a folder or resource. While not as immediately dangerous as a stale admin account, orphaned SIDs indicate poor hygiene and can complicate security audits. Use PowerShell scripts or specialized auditing tools to find accounts with no associated user object. This is a classic operational audit task that demonstrates whether the 'Joiners, Movers, Leavers' (JML) process is actually working.

How can practice exams help you master AD auditing for CISA?

Knowing the technical details of Active Directory is one thing, but answering CISA questions is another. ISACA doesn't just ask 'What is a GPO?'; they ask 'Which of the following is the MOST effective control to prevent unauthorized GPO changes?' This shift from technical knowledge to risk-based decision-making is where most candidates struggle.

This is why we built Cert Sensei. We provide 1,000 expert-curated CISA practice questions that mirror the actual exam's complexity. Instead of just giving you a correct letter, we provide detailed expert reasoning for every answer, explaining why the 'most correct' option beats the 'partially correct' one. With our domain-level analytics, you can see exactly if you're struggling with the 'Protection of Information Assets' domain, allowing you to pivot your study time to where it actually moves the needle on your pass rate.

❓ Frequently Asked Questions

What is the most common finding when auditing AD privileged groups?

The most common finding is 'over-provisioning,' where too many users are members of the Domain Admins group. This is usually caused by a lack of periodic access reviews and a failure to implement a tiered administration model, violating the principle of least privilege.


How does a CISA auditor verify that GPOs are being applied correctly?

An auditor would review GPO reports via GPMC and use the 'gpresult /r' command on sample workstations to verify that the intended policies are actually being applied to the end-users and that no conflicting policies are overriding security settings.


Why is SID filtering important when auditing forest trusts?

SID filtering prevents a compromised forest from 'spoofing' a privileged SID (like the Enterprise Admin SID) to gain unauthorized access to the trusting forest. It ensures that only the SIDs actually belonging to the trusted domain are accepted.

More from ISACA Certified Information Systems Auditor

🧠

Test Your Knowledge

Ready to practice Certified Information Systems Auditor? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free