CMA Final · Cost and Management Audit · Information Systems Security Audit
During an IS security audit at a manufacturing company in Pune, the auditor finds that several former employees' user IDs remain active in the ERP system months after their exit. Which risk is most directly heightened by this finding?
The finding most directly raises the risk of unauthorised access and fraudulent transactions. Active user IDs of former employees are a weakness in logical access control, because anyone holding those credentials can view or alter ERP data without authorisation. Hardware, depreciation and bandwidth issues are unrelated.
- AUnauthorised access and possible fraudulent transactions through dormant accountsCorrect
- BLoss of data due to hardware failure at the primary server
- CInaccurate depreciation computation caused by wrong asset lives
- DDelay in backup scheduling due to network bandwidth limits
Explanation
Active IDs of ex-employees are a logical access weakness. They can be misused by the former employee or others to access or alter data. The other options relate to hardware, accounting parameters or network capacity, which are not connected to user ID management.
Did you get it right without looking?
One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.
More Information Systems Security Audit questions
- During an IS audit of a manufacturing company's ERP, the auditor wants to confirm that a programmer cannot both modify production code and m…
- An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor …
- In an information systems security audit, which control is a preventive control rather than a detective or corrective one?
- In an information systems security audit, which control is a preventive control designed to stop unauthorised persons from entering a payrol…
- Which of the following best describes the 'integrity' objective in the confidentiality-integrity-availability model used in information secu…
- An auditor reviewing a payroll application wants to verify that the program logic computes deductions correctly, by processing the auditor's…