exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 184 discussion

Actual exam question from Isaca's CISA
Question #: 184
Topic #: 1
[All CISA Questions]

During an audit of a financial application, it was determined that many terminated users' accounts were not disabled. Which of the following should be the IS auditor's NEXT step?

  • A. Perform a review of terminated users' account activity.
  • B. Conclude that IT general controls are ineffective.
  • C. Communicate risks to the application owner.
  • D. Perform substantive testing of terminated users' access rights.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Greens
2 months ago
Selected Answer: A
When an IS auditor discovers that terminated users' accounts have not been disabled, this poses a security and fraud risk. The NEXT best step is to determine whether these accounts were used after termination, which would indicate unauthorized access or malicious activity. Why A is BEST: It helps assess actual impact or risk (e.g., did someone use the account to perform unauthorized transactions?). It provides evidence-based insights to support further action, such as escalation or control recommendations. It aligns with the principle of investigating before concluding or escalating. Why not the others? B. Conclude that IT general controls are ineffective ✘ Premature without first assessing actual usage or impact. C. Communicate risks to the application owner ✘ Important, but should follow a review of the account activity for context and severity. D. Perform substantive testing of terminated users' access rights ✘ Useful later, but activity review takes priority to assess whether the risk materialized.
upvoted 1 times
...
darkgalaxy
2 months, 2 weeks ago
Selected Answer: C
an auditors job is to inform and detect and not necessarily review the access (although that could be the next step) answer C is the more correct answer for an auditor
upvoted 1 times
...
RS66
1 year, 1 month ago
Selected Answer: A
Which is more important? C that helps enhance awareness of the owner or A investigate further to detect malicious activity? I will go with A. C comes next.
upvoted 1 times
...
Swallows
1 year, 2 months ago
Selected Answer: C
Communicating the identified risks to the application owner is crucial for raising awareness and initiating corrective actions. The application owner needs to understand the potential security implications of not disabling terminated users' accounts, including unauthorized access to sensitive financial data and increased risk of security breaches. Once the risks are communicated, the application owner can take appropriate measures, such as disabling unused accounts and implementing better account management practices. After this step, performing a review of terminated users' account activity (option A) might be necessary to assess any potential unauthorized access or suspicious activities associated with those accounts.
upvoted 2 times
...
a84n
1 year, 3 months ago
Selected Answer: C
Q: During an audit of a financial application, it was determined that the users' accounts were not disabled. Answer: C
upvoted 1 times
...
lingtianx1127
1 year, 4 months ago
Selected Answer: C
should communicate this finding to app owner so appropriate control can tale place to mitigate the risk. then, substantial testing can proceed if needed.
upvoted 1 times
...
BA27
1 year, 9 months ago
A. Perform a review of terminated users' account activity.
upvoted 2 times
...
BA27
1 year, 11 months ago
A. Performing Substantive testing of terminated users' access rights wont be the action since question already says that accounts were not disabled. That means they might have some sort of access. Performing review of account activity in 1st place would definitely provide with the clear picture.
upvoted 2 times
...
SBD600
2 years, 3 months ago
Selected Answer: A
If an IS auditor discovers that many terminated users' accounts have not been disabled, the next step should be to review the account activity of those terminated users. This helps to determine if there has been any unauthorized access or fraudulent activities carried out using these accounts. Perform substantive testing of terminated users' access rights: This step may be useful in understanding the extent of the problem, but the immediate concern is to review the account activity to determine if there has been any unauthorized access or fraudulent activities using the terminated users' accounts.
upvoted 3 times
...
David_Hu
2 years, 8 months ago
Selected Answer: D
D. should test whether the terminated employee could access the system first.
upvoted 1 times
...
2022cisa
2 years, 10 months ago
C - is the answer ! Even after checking , if nothing is found the risk continues to exist. So this should be communicated as a first step
upvoted 1 times
inddir
2 years, 10 months ago
Correct. C is the answer. it is the next step. A can follow C
upvoted 1 times
...
...
Deeplaxmi
2 years, 10 months ago
as the question is about terminated users , i would go with D.
upvoted 2 times
...
Jinkleberry
3 years, 4 months ago
A is one of the activities of substantive testing. I would go for D as it will include A in it. Correct ans is D.
upvoted 2 times
...
Tolution
3 years, 11 months ago
D please. When compliance is violated, substantive testing is next for transaction related items. Already you're doing a review.
upvoted 3 times
KyuSsica
3 years, 9 months ago
agree with A. check whether there is unauthorized activity first
upvoted 3 times
Zephaniah
2 years, 11 months ago
I THINK A FIRST THEN D.. SO A
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...