nerdexam
Isaca

CISA · Question #100

An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the ri

The correct answer is A. The ability of departed employees to actually access the system. The most important factor to assess the risk of unremoved departed employees is their actual ability to access the system, as this directly determines the potential for unauthorized activity.

Submitted by jordan8· Apr 18, 2026Protection of Information Assets

Question

An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk?

Options

  • AThe ability of departed employees to actually access the system
  • BThe frequency of user access reviews performed by management
  • CThe process for terminating access of departed employees
  • DThe frequency of intrusion attempts associated with the accounts payable

How the community answered

(33 responses)
  • A
    73% (24)
  • B
    9% (3)
  • C
    3% (1)
  • D
    15% (5)

Why each option

The most important factor to assess the risk of unremoved departed employees is their actual ability to access the system, as this directly determines the potential for unauthorized activity.

AThe ability of departed employees to actually access the systemCorrect

Even if accounts exist, the actual risk arises if departed employees can still use those accounts to log in and perform actions within the accounts payable system. The presence of accounts alone is a weakness, but active access represents a direct and immediate threat of unauthorized transactions or data manipulation, making it the most critical element of risk assessment.

BThe frequency of user access reviews performed by management

The frequency of user access reviews indicates a control weakness or strength, but it doesn't directly quantify the immediate risk posed by currently accessible, unauthorized accounts.

CThe process for terminating access of departed employees

The process for terminating access is the root cause of the problem, and while important for remediation, it doesn't immediately assess the *current* risk posed by existing, unremoved accounts.

DThe frequency of intrusion attempts associated with the accounts payable

The frequency of intrusion attempts is a general security metric for external threats, which is less relevant than assessing the risk posed by internal (or previously internal) users with potentially active accounts.

Concept tested: User access risk assessment (departed employees)

Source: https://learn.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Topics

#Access control#Risk assessment#User deprovisioning#Information security audit

Community Discussion

No community discussion yet for this question.

Full CISA Practice