Isaca
CISA · Question #452
An IS auditor reviewing database security should be MOST concerned if the database administrator (DBA):
The correct answer is A. approves access roles. Allowing the DBA to both manage the database and approve user access roles concentrates too much power in one role. This violates the principle of segregation of duties and increases the risk of unauthorized or inappropriate access going undetected.
Submitted by tunde_lagos· Apr 18, 2026Protection of Information Assets
Question
An IS auditor reviewing database security should be MOST concerned if the database administrator (DBA):
Options
- Aapproves access roles
- Bresolves database locks
- Cexecutes recovery procedures
- Dassesses database performance
How the community answered
(43 responses)- A88% (38)
- B2% (1)
- C2% (1)
- D7% (3)
Explanation
Allowing the DBA to both manage the database and approve user access roles concentrates too much power in one role. This violates the principle of segregation of duties and increases the risk of unauthorized or inappropriate access going undetected.
Topics
#Segregation of Duties#Database Security#Access Control#DBA Responsibilities
Community Discussion
No community discussion yet for this question.