ExamGecko
Question list
Search
Search

Related questions

Question 42 - CISA discussion

Report
Export

An IS auditor discovers an option in a database that allows the administrator to directly modify any table. This option is necessary to overcome bugs in the software, but is rarely used. Changes to tables are automatically logged. The IS auditor's FIRST action should be to:

A.
recommend that the option to directly modify the database be removed immediately.
Answers
A.
recommend that the option to directly modify the database be removed immediately.
B.
recommend that the system require two persons to be involved in modifying the database.
Answers
B.
recommend that the system require two persons to be involved in modifying the database.
C.
determine whether the log of changes to the tables is backed up.
Answers
C.
determine whether the log of changes to the tables is backed up.
D.
determine whether the audit trail is secured and reviewed.
Answers
D.
determine whether the audit trail is secured and reviewed.
Suggested answer: D

Explanation:

The IS auditor's first action after discovering an option in a database that allows the administrator to directly modify any table should be to determine whether the audit trail is secured and reviewed. This is because direct modification of database tables can pose a significant risk to data integrity, security, and accountability. An audit trail is a record of all changes made to database tables, including who made them, when they were made, and what was changed. An audit trail can help to detect unauthorized or erroneous changes, provide evidence for investigations or audits, and support data recovery or restoration. The IS auditor should assess whether the audit trail is protected from tampering or deletion, and whether it is regularly reviewed for anomalies or exceptions.

asked 18/09/2024
Maurice Daly
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first