nerdexam
Isaca

CISM · Question #541

An information security manager has been notified that two senior executives have the ability to elevate their own privileges in the corporate accounting system, in violation of policy. What is the FI

The correct answer is D. Perform a system access review.. The first step is to perform a system access review to verify who holds elevated privileges and understand the scope of the violation before taking any disruptive action or escalating.

Submitted by fatema_kw· Apr 18, 2026Information Security Incident Management

Question

An information security manager has been notified that two senior executives have the ability to elevate their own privileges in the corporate accounting system, in violation of policy. What is the FIRST step to address this issue?

Options

  • AImmediately suspend the executives' access privileges.
  • BNotify the CISO of the security policy violation.
  • CPerform a full review of all system transactions over the past 90 days.
  • DPerform a system access review.

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    3% (1)
  • C
    3% (1)
  • D
    82% (27)

Explanation

The first step is to perform a system access review to verify who holds elevated privileges and understand the scope of the violation before taking any disruptive action or escalating.

Topics

#Privilege management#Access control#Policy violation#Incident response

Community Discussion

No community discussion yet for this question.

Full CISM Practice