nerdexam
Isaca

CISA · Question #572

An IS auditor observes that an organization uses generic user IDs for access to licensed enterprise resource planning (ERP) software. Which of the following should be the auditor's GREATEST concern?

The correct answer is A. Difficulty of determining accountability for user actions. When multiple users share a generic user ID, individual actions cannot be attributed to a specific person. This breaks accountability - a foundational principle of access control and audit trails. If a fraudulent transaction, unauthorized change, or security incident occurs…

Submitted by femi9· Apr 18, 2026Protection of Information Assets

Question

An IS auditor observes that an organization uses generic user IDs for access to licensed enterprise resource planning (ERP) software. Which of the following should be the auditor's GREATEST concern?

Options

  • ADifficulty of determining accountability for user actions
  • BIncreased operational overhead for access management
  • CPotential breach of copyright laws
  • DNoncompliance with licensing terms

How the community answered

(40 responses)
  • A
    73% (29)
  • B
    3% (1)
  • C
    10% (4)
  • D
    15% (6)

Explanation

When multiple users share a generic user ID, individual actions cannot be attributed to a specific person. This breaks accountability - a foundational principle of access control and audit trails. If a fraudulent transaction, unauthorized change, or security incident occurs, investigators cannot determine who was responsible, making enforcement and forensic investigation impossible. Increased operational overhead (B) is a lesser concern. A potential breach of copyright laws (C) is not directly related to shared accounts. Noncompliance with licensing terms (D) could be a secondary concern but is far less critical from an IS audit and risk perspective than the complete loss of accountability and auditability.

Topics

#Access Control#Accountability#User Identification#Audit Findings

Community Discussion

No community discussion yet for this question.

Full CISA Practice