nerdexam
Isaca

CISA · Question #159

An IS auditor finds a user account where privileged access is not appropriate for the user's role. Which of the following would provide the BEST evidence to determine whether the risk of this access…

The correct answer is B. Activity log for the account. The activity log for the account provides direct, objective evidence of what actions were actually performed using the privileged access. This tells the auditor whether the user exercised the inappropriate privileges and what they did - which is the definition of exploiting…

Submitted by chen.hong· Apr 18, 2026Information System Auditing Process

Question

An IS auditor finds a user account where privileged access is not appropriate for the user’s role. Which of the following would provide the BEST evidence to determine whether the risk of this access has been exploited?

Options

  • AInterview with the user's manager
  • BActivity log for the account
  • CLast logon date for the account
  • DDocumented approval for the account

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    75% (30)
  • C
    15% (6)
  • D
    3% (1)

Explanation

The activity log for the account provides direct, objective evidence of what actions were actually performed using the privileged access. This tells the auditor whether the user exercised the inappropriate privileges and what they did - which is the definition of exploiting that risk. An interview with the manager (A) and documented approval (D) speak to authorization, not exploitation. The last logon date (C) only confirms the account was accessed but provides no detail on what actions were taken or whether privileged functions were used.

Topics

#Audit Evidence#Activity Logs#Privileged Access#Risk Exploitation

Community Discussion

No community discussion yet for this question.

Full CISA Practice