ExamGecko
Question list
Search
Search

Related questions

Question 1100 - CISA discussion

Report
Export

During a review of system access, an IS auditor notes that an employee who has recently changed roles within the organization still has previous access rights. The auditor's NEXT step should be to:

A.
recommend a control to automatically update access rights.
Answers
A.
recommend a control to automatically update access rights.
B.
determine the reason why access rights have not been revoked.
Answers
B.
determine the reason why access rights have not been revoked.
C.
direct management to revoke current access rights.
Answers
C.
direct management to revoke current access rights.
D.
determine if access rights are in violation of software licenses.
Answers
D.
determine if access rights are in violation of software licenses.
Suggested answer: B

Explanation:

The NEXT step for the IS auditor after noting that an employee who has recently changed roles within the organization still has previous access rights should be to B. determine the reason why access rights have not been revoked. Identifying the cause of this situation is crucial for understanding whether it's due to oversight, process gaps, or other factors. Once the reason is determined, appropriate corrective actions can be recommended to ensure that access rights are aligned with the employee's current role and responsibilities1.

asked 18/09/2024
Fakhruddin Abbas
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first