exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 697 discussion

Actual exam question from Isaca's CISA
Question #: 697
Topic #: 1
[All CISA Questions]

Which of the following is the MOST efficient way to identify segregation of duties violations in a new system?

  • A. Observe the performance of business processes.
  • B. Develop a process to identify authorization conflicts.
  • C. Review a report of security rights in the system.
  • D. Examine recent system access rights violations.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Swallows
9 months ago
Selected Answer: C
While developing a process (option B) to identify authorization conflicts can be valuable in the long term, it requires more time and effort initially to define the criteria, implement monitoring mechanisms, and ensure ongoing compliance. In contrast, reviewing a security rights report provides immediate insights into segregation of duties issues present in the system. Therefore, option C is the most efficient way for an IS auditor to identify segregation of duties violations in a new system.
upvoted 2 times
...
topikal
9 months, 2 weeks ago
Selected Answer: C
C is more appropriate
upvoted 1 times
...
Yejide03
1 year ago
C. Review a report of security rights in the system. Reviewing a report of security rights in the system allows the auditor to quickly identify any conflicts in authorization assignments. By analyzing the roles, permissions, and access rights assigned to different users or user groups, the auditor can assess whether there are any instances where conflicting duties are assigned to the same individual. This method provides a systematic and comprehensive approach to identifying SoD violations without the need for extensive manual observation or analysis.
upvoted 1 times
...
3008
1 year, 4 months ago
Selected Answer: B
system would be voluminous and time consuming to review; therefore, this technique is not as effective as building a program. As complexities increase, it becomes more difficult to verify the effectiveness of the systems and complexity is not, in itself, a link to segregation of duties. It is good practice to review recent access rights violation cases; however, it may require a significant amount of time to truly identify which violations actually resulted from an inappropriate segregation of duties
upvoted 1 times
...
starzuu
1 year, 8 months ago
why not C? developing a system takes time--may not be the most efficient
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago