ExamGecko
Question list
Search
Search

Related questions

Question 178 - CISA discussion

Report
Export

During an audit of a financial application, it was determined that many terminated users' accounts were not disabled. Which of the following should be the IS auditor's NEXT step?

A.
Perform substantive testing of terminated users' access rights.
Answers
A.
Perform substantive testing of terminated users' access rights.
B.
Perform a review of terminated users' account activity
Answers
B.
Perform a review of terminated users' account activity
C.
Communicate risks to the application owner.
Answers
C.
Communicate risks to the application owner.
D.
Conclude that IT general controls ate ineffective.
Answers
D.
Conclude that IT general controls ate ineffective.
Suggested answer: B

Explanation:

The IS auditor's next step after determining that many terminated users' accounts were not disabled is to perform a review of terminated users' account activity. This means that the IS auditor should check whether any of the terminated users' accounts were accessed or used after their termination date, which could indicate unauthorized or fraudulent activity. The IS auditor should also assess the impact and risk of such activity on the confidentiality, integrity, and availability of IT resources and data. The other options are not as appropriate as performing a review of terminated users' account activity, as they do not provide sufficient evidence or assurance of the extent and effect of the problem.Reference:CISA Review Manual, 27th Edition, page 240

asked 18/09/2024
samuel crook
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first