CISA · Question #100
An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the ri
The correct answer is A. The ability of departed employees to actually access the system. The most important factor to assess the risk of unremoved departed employees is their actual ability to access the system, as this directly determines the potential for unauthorized activity.
Question
An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk?
Options
- AThe ability of departed employees to actually access the system
- BThe frequency of user access reviews performed by management
- CThe process for terminating access of departed employees
- DThe frequency of intrusion attempts associated with the accounts payable
How the community answered
(33 responses)- A73% (24)
- B9% (3)
- C3% (1)
- D15% (5)
Why each option
The most important factor to assess the risk of unremoved departed employees is their actual ability to access the system, as this directly determines the potential for unauthorized activity.
Even if accounts exist, the actual risk arises if departed employees can still use those accounts to log in and perform actions within the accounts payable system. The presence of accounts alone is a weakness, but active access represents a direct and immediate threat of unauthorized transactions or data manipulation, making it the most critical element of risk assessment.
The frequency of user access reviews indicates a control weakness or strength, but it doesn't directly quantify the immediate risk posed by currently accessible, unauthorized accounts.
The process for terminating access is the root cause of the problem, and while important for remediation, it doesn't immediately assess the *current* risk posed by existing, unremoved accounts.
The frequency of intrusion attempts is a general security metric for external threats, which is less relevant than assessing the risk posed by internal (or previously internal) users with potentially active accounts.
Concept tested: User access risk assessment (departed employees)
Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview
Topics
Community Discussion
No community discussion yet for this question.