nerdexam
CompTIA

CAS-003 · Question #457

The Chief Information Security Officer (CISO) suspects that a database administrator has been tampering with financial data to the administrator's advantage. Which of the following would allow a…

The correct answer is D. Mandatory vacation. A method of preventing fraud which provides you with an opportunity to review employees’ activities. The typical mandatory vacation policy requires that employees take at least one vacation a year in a full-week increment so that they are away from work for at least five days…

Enterprise Security Operations

Question

The Chief Information Security Officer (CISO) suspects that a database administrator has been tampering with financial data to the administrator's advantage. Which of the following would allow a third-party consultant to conduct an on-site review of the administrator's activity?

Options

  • ASeparation of duties
  • BJob rotation
  • CContinuous monitoring
  • DMandatory vacation

How the community answered

(49 responses)
  • A
    8% (4)
  • B
    4% (2)
  • C
    2% (1)
  • D
    86% (42)

Explanation

A method of preventing fraud which provides you with an opportunity to review employees’ activities. The typical mandatory vacation policy requires that employees take at least one vacation a year in a full-week increment so that they are away from work for at least five days in a row. During that time, your corporate audit and security teams have time to investigate and discover any discrepancies in employee activity. When employees understand the security focus of the mandatory vacation policy, the risk of fraudulent activities decreases.

Topics

#mandatory vacation#insider threat#fraud detection#administrative controls

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice