During an audit of a financial application, it was determined that many terminated users' accounts were not disabled. Which of the following should be the IS auditor's NEXT step?
A.
Perform a review of terminated users' account activity.
B.
Conclude that IT general controls are ineffective.
C.
Communicate risks to the application owner.
D.
Perform substantive testing of terminated users' access rights.
When an IS auditor discovers that terminated users' accounts have not been disabled, this poses a security and fraud risk. The NEXT best step is to determine whether these accounts were used after termination, which would indicate unauthorized access or malicious activity.
Why A is BEST:
It helps assess actual impact or risk (e.g., did someone use the account to perform unauthorized transactions?).
It provides evidence-based insights to support further action, such as escalation or control recommendations.
It aligns with the principle of investigating before concluding or escalating.
Why not the others?
B. Conclude that IT general controls are ineffective
✘ Premature without first assessing actual usage or impact.
C. Communicate risks to the application owner
✘ Important, but should follow a review of the account activity for context and severity.
D. Perform substantive testing of terminated users' access rights
✘ Useful later, but activity review takes priority to assess whether the risk materialized.
an auditors job is to inform and detect and not necessarily review the access (although that could be the next step) answer C is the more correct answer for an auditor
Which is more important? C that helps enhance awareness of the owner or A investigate further to detect malicious activity? I will go with A. C comes next.
Communicating the identified risks to the application owner is crucial for raising awareness and initiating corrective actions. The application owner needs to understand the potential security implications of not disabling terminated users' accounts, including unauthorized access to sensitive financial data and increased risk of security breaches. Once the risks are communicated, the application owner can take appropriate measures, such as disabling unused accounts and implementing better account management practices. After this step, performing a review of terminated users' account activity (option A) might be necessary to assess any potential unauthorized access or suspicious activities associated with those accounts.
should communicate this finding to app owner so appropriate control can tale place to mitigate the risk. then, substantial testing can proceed if needed.
A. Performing Substantive testing of terminated users' access rights wont be the action since question already says that accounts were not disabled. That means they might have some sort of access. Performing review of account activity in 1st place would definitely provide with the clear picture.
If an IS auditor discovers that many terminated users' accounts have not been disabled, the next step should be to review the account activity of those terminated users. This helps to determine if there has been any unauthorized access or fraudulent activities carried out using these accounts.
Perform substantive testing of terminated users' access rights: This step may be useful in understanding the extent of the problem, but the immediate concern is to review the account activity to determine if there has been any unauthorized access or fraudulent activities using the terminated users' accounts.
This section is not available anymore. Please use the main Exam Page.CISA Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Greens
2 months agodarkgalaxy
2 months, 2 weeks agoRS66
1 year, 1 month agoSwallows
1 year, 2 months agoa84n
1 year, 3 months agolingtianx1127
1 year, 4 months agoBA27
1 year, 9 months agoBA27
1 year, 11 months agoSBD600
2 years, 3 months agoDavid_Hu
2 years, 8 months ago2022cisa
2 years, 10 months agoinddir
2 years, 10 months agoDeeplaxmi
2 years, 10 months agoJinkleberry
3 years, 4 months agoTolution
3 years, 11 months agoKyuSsica
3 years, 9 months agoZephaniah
2 years, 11 months ago