nerdexam
CompTIA

CAS-002 · Question #5

The internal auditor at Company ABC has completed the annual audit of the company's financial system. The audit report indicates that the accounts receivable department has not followed proper…

The correct answer is C. Implement mandatory training E. Review company procedures. When auditors identify a procedural compliance failure, the ISO should address both the root cause through training and the process gap by reviewing procedures.

Enterprise Security

Question

The internal auditor at Company ABC has completed the annual audit of the company's financial system. The audit report indicates that the accounts receivable department has not followed proper record disposal procedures during a COOP/BCP tabletop exercise involving manual processing of financial transactions. Which of the following should be the Information Security Officer's (ISO's) recommendation? (Select TWO).

Options

  • AWait for the external audit results
  • BPerform another COOP exercise
  • CImplement mandatory training
  • DDestroy the financial transactions
  • EReview company procedures

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    12% (3)
  • C
    77% (20)
  • D
    8% (2)

Why each option

When auditors identify a procedural compliance failure, the ISO should address both the root cause through training and the process gap by reviewing procedures.

AWait for the external audit results

Waiting for an external audit is a passive response that delays corrective action and leaves the compliance gap unresolved in the interim.

BPerform another COOP exercise

Performing another COOP exercise without first correcting the training and procedural deficiencies would likely reproduce the same compliance failures.

CImplement mandatory trainingCorrect

Mandatory training directly addresses the finding that staff did not follow proper record disposal procedures, ensuring employees understand their obligations and the correct steps to take during manual processing scenarios.

DDestroy the financial transactions

Destroying financial transactions could constitute improper destruction of records and potentially obstruct audit trails or legal obligations.

EReview company proceduresCorrect

Reviewing company procedures ensures that the documented processes are clear, current, and aligned with regulatory and policy requirements, closing any ambiguity that may have contributed to the non-compliance observed during the exercise.

Concept tested: Incident response to audit findings - training and procedure review

Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

Topics

#COOP/BCP#record disposal#security training#audit compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice