ExamGecko
Question list
Search
Search

Related questions











Question 520 - CISA discussion

Report
Export

During a database management evaluation an IS auditor discovers that some accounts with database administrator (DBA) privileges have been assigned a default password with an unlimited number of failed login attempts Which of the following is the auditor's BEST course of action?

A.
Identify accounts that have had excessive failed login attempts and request they be disabled
Answers
A.
Identify accounts that have had excessive failed login attempts and request they be disabled
B.
Request the IT manager to change administrator security parameters and update the finding
Answers
B.
Request the IT manager to change administrator security parameters and update the finding
C.
Document the finding and explain the risk of having administrator accounts with inappropriate security settings
Answers
C.
Document the finding and explain the risk of having administrator accounts with inappropriate security settings
Suggested answer: C

Explanation:

The auditor's best course of action is to document the finding and explain the risk of having administrator accounts with inappropriate security settings. This is because the auditor's role is to identify and report the issues, not to fix them or request others to fix them. The auditor should also communicate the impact of the finding, such as the possibility of unauthorized access, data tampering, or denial of service attacks. The auditor should not assume the responsibility of the IT manager or the DBA, who are in charge of changing the security parameters or disabling the accounts.Reference:

CISA Review Manual (Digital Version), Chapter 4, Section 4.2.21

CISA Online Review Course, Domain 1, Module 3, Lesson 32

asked 18/09/2024
Lukasz Malaczek
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first