nerdexam
Isaca

CISA · Question #631

Which of the following should be of MOST concern to an IS auditor who has identified several end-user computing (EUC) applications within an organization?

The correct answer is D. The applications are not governed by appropriate policies. The absence of appropriate governance policies over end-user computing applications is the greatest concern because it increases the risk of inconsistent controls, data integrity issues, unauthorized changes, and regulatory noncompliance across the organization.

Submitted by jian89· Apr 18, 2026Governance and Management of IT

Question

Which of the following should be of MOST concern to an IS auditor who has identified several end-user computing (EUC) applications within an organization?

Options

  • AThe applications' backups are not regularly tested.
  • BThere is only one staff member trained on the applications.
  • CThe applications' administrators are from various departments.
  • DThe applications are not governed by appropriate policies.

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    4% (1)
  • C
    7% (2)
  • D
    75% (21)

Explanation

The absence of appropriate governance policies over end-user computing applications is the greatest concern because it increases the risk of inconsistent controls, data integrity issues, unauthorized changes, and regulatory noncompliance across the organization.

Topics

#EUC governance#IT policy#IS audit concerns#Risk management

Community Discussion

No community discussion yet for this question.

Full CISA Practice