Correct Answer: D
The best answer is D. Compliance audit.
The auditor is testing whether employee behavior complies with organizational rules or policy regarding the use of the organization's car. ISACA defines IT compliance as adherence to mandated requirements from laws, regulations, contractual obligations, and internal policies. Since the scenario is about checking whether employees are following the organization's rule on permitted use, the audit is primarily a compliance-oriented review.
Option A could be tempting because misuse of a company car might be abusive, but the question does not say the auditor is investigating intentional deception or a suspected fraud scheme. Option B is incorrect because this is not primarily about fair presentation of financial statements. Option C is not the best fit because the audit objective is not evaluation of business function performance, but adherence to policy.
Therefore, the correct answer is D, because the auditor is determining whether employees are complying with the organization's established usage rules.
References (Official ISACA):
* ISACA, IT Compliance - compliance includes adherence to internal policies.
* ISACA, An Integrated Approach to Security Audits - audits assess adherence to required controls and obligations.