CAS-003 · Question #457
The Chief Information Security Officer (CISO) suspects that a database administrator has been tampering with financial data to the administrator's advantage. Which of the following would allow a…
The correct answer is D. Mandatory vacation. A method of preventing fraud which provides you with an opportunity to review employees’ activities. The typical mandatory vacation policy requires that employees take at least one vacation a year in a full-week increment so that they are away from work for at least five days…
Question
The Chief Information Security Officer (CISO) suspects that a database administrator has been tampering with financial data to the administrator's advantage. Which of the following would allow a third-party consultant to conduct an on-site review of the administrator's activity?
Options
- ASeparation of duties
- BJob rotation
- CContinuous monitoring
- DMandatory vacation
How the community answered
(49 responses)- A8% (4)
- B4% (2)
- C2% (1)
- D86% (42)
Explanation
A method of preventing fraud which provides you with an opportunity to review employees’ activities. The typical mandatory vacation policy requires that employees take at least one vacation a year in a full-week increment so that they are away from work for at least five days in a row. During that time, your corporate audit and security teams have time to investigate and discover any discrepancies in employee activity. When employees understand the security focus of the mandatory vacation policy, the risk of fraudulent activities decreases.
Topics
Community Discussion
No community discussion yet for this question.