CAS-001 · Question #301
The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees: - Employee A. Works in the accounts receivable office…
The correct answer is B. The manager should only be able to review the data and approve purchase orders. This question tests the principle of Separation of Duties (SoD). The core problem is that Employee C (the manager) can both enter financial data (like Employee A) AND approve purchase orders (like Employee B). This dual capability creates a fraud risk: the manager could enter…
Question
The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees:
- Employee A. Works in the accounts receivable office and is in charge
of entering data into the finance system.
- Employee B. Works in the accounts payable office and is in charge of
approving purchase orders.
- Employee C. Is the manager of the finance department, supervises
Employee A and Employee B, and can perform the functions of both Employee A and Employee B. Which of the following should the auditor suggest be done to avoid future security breaches?
Options
- AAll employees should have the same access level to be able to check on each others.
- BThe manager should only be able to review the data and approve purchase orders.
- CEmployee A and Employee B should rotate jobs at a set interval and cross-train.
- DThe manager should be able to both enter and approve information.
How the community answered
(49 responses)- A4% (2)
- B76% (37)
- C6% (3)
- D14% (7)
Explanation
This question tests the principle of Separation of Duties (SoD). The core problem is that Employee C (the manager) can both enter financial data (like Employee A) AND approve purchase orders (like Employee B). This dual capability creates a fraud risk: the manager could enter fraudulent transactions and then self-approve them with no independent check. Answer B is correct because restricting the manager to only reviewing data and approving purchase orders (not entering data) eliminates this conflict of interest. Option A is wrong because giving everyone the same access violates least privilege. Option C (job rotation) is a compensating control but doesn't fix the manager's over-privileged access. Option D would make the problem worse by explicitly codifying the dangerous dual role.
Topics
Community Discussion
No community discussion yet for this question.