ExamGecko
Question list
Search
Search

Related questions

Question 122 - CISA discussion

Report
Export

Which of the following is the BEST compensating control when segregation of duties is lacking in a small IS department?

A.
Background checks
Answers
A.
Background checks
B.
User awareness training
Answers
B.
User awareness training
C.
Transaction log review
Answers
C.
Transaction log review
D.
Mandatory holidays
Answers
D.
Mandatory holidays
Suggested answer: C

Explanation:

The best compensating control when segregation of duties is lacking in a small IS department is transaction log review. Transaction log review can help detect any unauthorized or fraudulent activities performed by IS staff who have access to multiple functions or systems. Transaction log review can also provide an audit trail for accountability and investigation purposes. The other options are not as effective as transaction log review in compensating for the lack of segregation of duties. Background checks are preventive controls that can help screen potential employees for any criminal records or dishonest behavior, but they do not prevent existing employees from abusing their access privileges. User awareness training is a detective control that can help educate users on how to report any suspicious or abnormal activities in the IS environment, but it does not monitor or verify the actions of IS staff. Mandatory holidays are deterrent controls that can discourage IS staff from engaging in fraudulent activities by requiring them to take periodic leave, but they do not prevent or detect such activities when they occur.Reference:CISA Review Manual (Digital Version), Chapter 3, Section 3.2

asked 18/09/2024
Xiaoyi Wu
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first