nerdexam
Isaca

CISA · Question #634

IT management wants transferred staff to have current and previous role access to facilitate transitioning and training of new staff. Which of the following is the GREATEST risk to the organization…

The correct answer is A. An increased likelihood that internal fraud will not be detected. Allowing transferred staff to retain access from previous roles violates the principle of least privilege and increases the risk of inappropriate access. This creates a greater likelihood that internal fraud or unauthorized activities could occur without detection, as users may…

Submitted by sofia.br· Apr 18, 2026Governance and Management of IT

Question

IT management wants transferred staff to have current and previous role access to facilitate transitioning and training of new staff. Which of the following is the GREATEST risk to the organization from this practice?

Options

  • AAn increased likelihood that internal fraud will not be detected
  • BAn increased impact from loss of key staff
  • CAn increased number of help desk tickets due to password changes
  • DAn increased number of user access recertification records

How the community answered

(28 responses)
  • A
    50% (14)
  • B
    14% (4)
  • C
    7% (2)
  • D
    29% (8)

Explanation

Allowing transferred staff to retain access from previous roles violates the principle of least privilege and increases the risk of inappropriate access. This creates a greater likelihood that internal fraud or unauthorized activities could occur without detection, as users may retain access to systems or data unrelated to their current responsibilities.

Topics

#Access Management#Segregation of Duties (SoD)#Internal Controls#Fraud Risk

Community Discussion

No community discussion yet for this question.

Full CISA Practice