exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1774 discussion

Actual exam question from Isaca's CISA
Question #: 1774
Topic #: 1
[All CISA Questions]

Which of the following observations should be of GREATEST concern to an IS auditor assessing access controls for the accounts payable module of a finance system?

  • A. Payment files are stored on a shared drive in a writable format prior to processing.
  • B. Accounts payable staff have access to update vendor bank account details.
  • C. The IS auditor was granted access to create purchase orders.
  • D. Configured delegation limits do not align to the organization's delegations policy.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
46080f2
1 month, 2 weeks ago
Selected Answer: B
justification after reading the CISA Review Manual: It emphasizes that updating vendor bank details should be segregated from payment processing to prevent fraud (e.g., unauthorized changes to divert payments). If accounts payable staff can modify vendor banking information, it creates a risk of collusion or fraudulent transactions without detection. Privilege Creep and Authorization: The manual highlights the importance of enforcing the Principle of Least Privilege (POLP). Granting unnecessary access to sensitive functions (e.g., vendor bank details) violates POLP and increases the attack surface. Risk of Fraud: Uncontrolled access to vendor banking details directly enables financial misappropriation. The manual states that compensating controls are critical when SoD cannot be fully enforced, but such access without oversight is a severe control gap
upvoted 1 times
...
pLulu
5 months ago
B. Accounts payable staff have access to update vendor bank account details. This is because allowing accounts payable staff to update vendor bank account details poses a significant risk of fraud or error. It can lead to unauthorized changes, which might result in payments being diverted to incorrect or fraudulent accounts. This risk is higher compared to the other options, which, while concerning, do not pose as direct a threat to financial integrity and security.
upvoted 1 times
...
Enig
5 months, 2 weeks ago
A. Payment files are stored on a shared drive in a writable format prior to processing. It means that i can possibly modify the file before finance processing. B is required for finance operation.
upvoted 1 times
...
blehbleh
6 months, 1 week ago
Selected Answer: B
This is B. We are talking about access controls. B is the only one that is referencing access controls for the accounts payable staff to modify the vendor account details.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago