nerdexam
EC-Council

712-50 · Question #116

An IT auditor has recently discovered that because of a shortage of skilled operations personnel, the security administrator has agreed to work one late night shift a week as the senior computer…

The correct answer is A. Inform senior management of the risk involved. Option A is correct because the IT auditor's primary responsibility is to identify control weaknesses and report them to those who have authority to act - in this case, senior management. The security administrator performing operator duties creates a segregation of duties…

IS Management Controls and Auditing Management

Question

An IT auditor has recently discovered that because of a shortage of skilled operations personnel, the security administrator has agreed to work one late night shift a week as the senior computer operator. The most appropriate course of action for the IT auditor is to:

Options

  • AInform senior management of the risk involved.
  • BAgree to work with the security officer on these shifts as a form of preventative control.
  • CDevelop a computer assisted audit technique to detect instances of abuses of the arrangement.
  • DReview the system log for each of the late night shifts to determine whether any irregular actions

How the community answered

(37 responses)
  • A
    76% (28)
  • B
    8% (3)
  • C
    14% (5)
  • D
    3% (1)

Explanation

Option A is correct because the IT auditor's primary responsibility is to identify control weaknesses and report them to those who have authority to act - in this case, senior management. The security administrator performing operator duties creates a segregation of duties violation: the same person who controls security settings could also manipulate operations or cover up misuse, which is a significant risk that management must be made aware of to make an informed decision.

Why the distractors are wrong:

  • B is wrong because the auditor working the shift would themselves violate independence and objectivity - auditors must remain independent, not become part of operations or controls.
  • C is wrong because developing a detection technique only addresses the symptom after the fact; it doesn't resolve the underlying control weakness, and the auditor's job isn't to design compensating controls - that's management's role.
  • D is wrong for a similar reason - reviewing logs is a detective control the auditor might perform as part of investigation, but it's not the most appropriate first step, and it still doesn't address the root problem or inform those responsible.

Memory tip: Think "Report Up, Stay Independent." Whenever an auditor finds a control gap, the answer is almost always to escalate to management first - the auditor's job is to report risks, not fix them or participate in operations.

Topics

#Segregation of Duties#Internal Controls#Audit Independence#Risk Reporting

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice