ExamGecko
Question list
Search
Search

Related questions











Question 347 - CISA discussion

Report
Export

An IS auditor finds that the process for removing access for terminated employees is not documented What is the MOST significant risk from this observation?

A.
Procedures may not align with best practices
Answers
A.
Procedures may not align with best practices
B.
Human resources (HR) records may not match system access.
Answers
B.
Human resources (HR) records may not match system access.
C.
Unauthorized access cannot he identified.
Answers
C.
Unauthorized access cannot he identified.
D.
Access rights may not be removed in a timely manner.
Answers
D.
Access rights may not be removed in a timely manner.
Suggested answer: D

Explanation:

The most significant risk from this observation is that access rights may not be removed in a timely manner. If the process for removing access for terminated employees is not documented, there is no clear guidance or accountability for who, how, when, and what actions should be taken to revoke the access rights of the employees who leave the organization. This could result in delays, inconsistencies, or omissions in removing access rights, which could allow terminated employees to retain unauthorized access to the organization's systems and data. This could compromise the security, confidentiality, integrity, and availability of the information assets.Reference:

CISA Review Manual (Digital Version)

CISA Questions, Answers & Explanations Database

asked 18/09/2024
Neha Dua
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first