CMA Final · Cost and Management Audit · Information Systems Security Audit
In an information systems security audit, which control is a preventive control designed to stop unauthorised persons from entering a payroll application?
Unique user IDs with passwords and role-based access rights are the preventive control, because they stop unauthorised entry before it happens. Failed-login reports and log reviews only detect misuse afterwards, while backup restoration is corrective, repairing damage after the event.
- AUnique user IDs protected by passwords and role-based access rightsCorrect
- BA daily exception report of failed login attempts reviewed by the manager
- CRestoration of data from a backup tape after a crash
- DA post-incident forensic review of server logs
Explanation
Preventive controls act before a violation occurs. Unique IDs with passwords and role-based rights block unauthorised entry. Exception reports of failed logins are detective, backup restoration is corrective, and log forensics after an incident is also detective.
Did you get it right without looking?
One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.
More Information Systems Security Audit questions
- A firm's disaster recovery plan states that after an outage, systems must be running within 4 hours, and that no more than 30 minutes of tra…
- An auditor finds that a cost accounting application's database administrator can also approve journal entries and delete audit log records. …
- Which of the following best describes the purpose of a 'segregation of duties' control in a computerised cost accounting environment?
- During an IS security audit at a manufacturing company in Pune, the auditor finds that several former employees' user IDs remain active in t…
- During an IS audit of a manufacturing company's ERP, the auditor wants to confirm that a programmer cannot both modify production code and m…
- An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor …