ExamGecko
Question list
Search
Search

Related questions











Question 427 - CISA discussion

Report
Export

Which of the following is the MOST efficient way to identify segregation of duties violations in a new system?

A.
Review a report of security rights in the system.
Answers
A.
Review a report of security rights in the system.
B.
Observe the performance of business processes.
Answers
B.
Observe the performance of business processes.
C.
Develop a process to identify authorization conflicts.
Answers
C.
Develop a process to identify authorization conflicts.
D.
Examine recent system access rights violations.
Answers
D.
Examine recent system access rights violations.
Suggested answer: A

Explanation:

The most efficient way to identify segregation of duties violations in a new system is to review a report of security rights in the system. Segregation of duties is a control principle that aims to prevent or detect errors, fraud, or abuse by ensuring that no single individual has the ability to perform incompatible or conflicting functions or activities within a system or process. A report of security rights in the system can provide a comprehensive and accurate overview of the roles, responsibilities, and access levels assigned to different users or groups in the system, and can help to identify any potential segregation of duties violations or risks.The other options are not as efficient as reviewing a report of security rights in the system, because they either rely on observation or testing rather than analysis, or they focus on existing rather than potential violations.Reference:CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.2

asked 18/09/2024
Derrick Dave T Alvarez
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first