nerdexam
Isaca

CISA · Question #606

An external IS auditor is reviewing the continuous monitoring system for a large bank and notes several potential issues. Which of the following would present the GREATEST concern regarding the reliab

The correct answer is C. The monitoring thresholds are not subject to change management.. Monitoring thresholds define when alerts fire - if those thresholds can be changed without a formal change management process, anyone with access could raise or suppress them without authorization, audit trail, or peer review, directly destroying the system's reliability and inte

Submitted by yousef_jo· Apr 18, 2026Governance and Management of IT

Question

An external IS auditor is reviewing the continuous monitoring system for a large bank and notes several potential issues. Which of the following would present the GREATEST concern regarding the reliability of the monitoring system?

Options

  • AThe system results are not reviewed by senior management.
  • BThe alert threshold is updated periodically.
  • CThe monitoring thresholds are not subject to change management.
  • DThe monitoring system was configured by a third party.

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    24% (12)
  • C
    58% (29)
  • D
    12% (6)

Explanation

Monitoring thresholds define when alerts fire - if those thresholds can be changed without a formal change management process, anyone with access could raise or suppress them without authorization, audit trail, or peer review, directly destroying the system's reliability and integrity. This is the greatest concern because it's a systemic control gap that could silently invalidate every output the monitoring system produces.

Why the distractors are wrong:

  • A - Senior management review is a governance preference, not a reliability requirement; monitoring results can legitimately be reviewed at lower levels through delegation.
  • B - Periodic threshold updates are actually good practice; it means the system is being tuned to reflect a changing risk environment, not a red flag.
  • D - Third-party configuration is common and acceptable as long as proper controls exist; the origin of configuration alone doesn't indicate unreliability.

Memory tip: Ask yourself "who guards the guards?" - Change management is the gatekeeper that ensures critical controls (like alert thresholds) can only be modified through an authorized, documented, and reviewed process. No change management = no trustworthy output.

Topics

#Change Management#Continuous Monitoring#System Reliability#IT Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice