List of questions
Related questions
Question 277 - IIA-CIA-Part1 discussion
An internal auditor performed a risk assessment and concluded that the controls over access privileges to a bank account were appropriate. Later, the auditor learned that a contractor was using a shared password provided by an authorized user of the account. Which of the following statements best describes the auditor's application of due professional care?
A.
Due professional care was exercised, despite the auditor's failure to identify the significant risk.
B.
Due professional care was not exercised because the auditor failed to identify all the significant risks during the risk assessment.
C.
Due professional care was not exercised because the residual risk from the possibility of authorized users sharing their passwords was not considered.
D.
Due professional care was not exercised because the auditor failed to conduct interviews to obtain testimonial evidence of possible password sharing
Your answer:
0 comments
Sorted by
Leave a comment first