CISA · Question #159
An IS auditor finds a user account where privileged access is not appropriate for the user's role. Which of the following would provide the BEST evidence to determine whether the risk of this access…
The correct answer is B. Activity log for the account. The activity log for the account provides direct, objective evidence of what actions were actually performed using the privileged access. This tells the auditor whether the user exercised the inappropriate privileges and what they did - which is the definition of exploiting…
Question
An IS auditor finds a user account where privileged access is not appropriate for the user’s role. Which of the following would provide the BEST evidence to determine whether the risk of this access has been exploited?
Options
- AInterview with the user's manager
- BActivity log for the account
- CLast logon date for the account
- DDocumented approval for the account
How the community answered
(40 responses)- A8% (3)
- B75% (30)
- C15% (6)
- D3% (1)
Explanation
The activity log for the account provides direct, objective evidence of what actions were actually performed using the privileged access. This tells the auditor whether the user exercised the inappropriate privileges and what they did - which is the definition of exploiting that risk. An interview with the manager (A) and documented approval (D) speak to authorization, not exploitation. The last logon date (C) only confirms the account was accessed but provides no detail on what actions were taken or whether privileged functions were used.
Topics
Community Discussion
No community discussion yet for this question.