Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1795 discussion

Actual exam question from Isaca's CISA
Question #: 1795
Topic #: 1
[All CISA Questions]

Which of the following is the MOST effective control when granting access to a service provider for a cloud-based application?

  • A. Administrator access is provided for a limited period with an expiration date.
  • B. Access has been provided on a need-to-know basis.
  • C. User IDs are deleted when work is completed.
  • D. Access is provided to correspond with the service level agreement (SLA).
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
blehbleh
1 month ago
Selected Answer: A
I am pretty sure A is the correct answer as it has an expiration time. Option C says they are deleted when work is completed which is a good idea and should be done but when work is completed is very arbitrary. B doesn’t make a lot of sense. Access is provided on a need to know basis. I mean, duh. Right, they shouldn’t just access all the time whenever. Which is why I lean toward A. Because it has an expiration date so it doesn’t necessarily matter if the work got completed. They can get granted access again without it extending too long. Hopefully that makes sense to anyone else who is struggling with the options given.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...