Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 17 discussion

Actual exam question from Isaca's CISA
Question #: 17
Topic #: 1
[All CISA Questions]

After an employee termination, a network account was removed, but the application account remained active. To keep this issue from recurring, which of the following is the BEST recommendation?

  • A. Integrate application accounts with network single sign-on.
  • B. Perform periodic access reviews.
  • C. Retrain system administration staff.
  • D. Leverage shared accounts for the application.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Victor83516
Highly Voted 2 years, 2 months ago
Selected Answer: B
It is indeed more convenient to use SSO to ensure that when employees leave, the application-related permissions are also cancelled. But whether or not SSO is imported, regular account permission reviews are still the most complete solution. Careful review of account permissions can help ensure that invalid accounts are indeed closed or deleted. So, I think answer is B.
upvoted 9 times
...
chadeeu
Most Recent 1 week, 6 days ago
Selected Answer: A
This is just a matter of careful reading. To keep this issue from recurring (Preventative), you would use SSO to ensure that disabling the network account would in turn disable access for the application. Performing periodic access reviews is a corrective control, addressing application accounts that were not disabled after the fact (at this point, you are past preventing it).
upvoted 1 times
...
1Naa
2 weeks ago
Selected Answer: A
This centralizes user access management. Linking application accounts to SSO system automatically revokes access to all integrated applications with the termination of a network account
upvoted 1 times
...
firel0rd
4 months, 2 weeks ago
Selected Answer: B
A is indeed the most convenient option, but not all systems/applications will support SSO. So B
upvoted 2 times
...
a84n
6 months, 3 weeks ago
Selected Answer: B
Answer: B
upvoted 1 times
...
Swallows
7 months, 1 week ago
Selected Answer: A
If SSO is implemented, as soon as the network account is deleted, the application is no longer accessible.
upvoted 3 times
...
Rachy
9 months, 3 weeks ago
Selected Answer: B
B is much better than A as single sign on May not necessary prevent the issue from recurring
upvoted 2 times
...
CISA2021
10 months, 1 week ago
Selected Answer: A
The answer is A. Remark the sentence "..To keep this issue from recurring.."
upvoted 3 times
...
6god
1 year ago
Incomplete integration: some applications might not be fully integrated with the SSO system, leaving room for discrepancies between network account termination and the deactivation of associated application accounts. Therefore periodic review is the best.
upvoted 1 times
...
katyak
1 year ago
Selected Answer: A
The question is looking for preventive control. B is detective control so is not the correct answer. Single sign-on is defined as the process for consolidating all organization platform-based administration, authentication and authorization functions into a single centralized administrative function.
upvoted 3 times
...
Kokoh23
1 year, 1 month ago
In this question the issue is having an application w/ two different types of access. One account/password for the application (consider it local) and a domain account/System account & password. You can delete the system account and the application account will still exist. Combining them (requiring a system password w/ managed or limited permissions) better facilitates management. When the system account is deleted, account access is also removed.
upvoted 1 times
...
i91290
1 year, 5 months ago
Selected Answer: A
A is the right answer.
upvoted 3 times
...
oldmagic
1 year, 5 months ago
Selected Answer: A
A is the correct answer Perform periodic access reviews will catch this issue, but will not prevent it. SSO will.
upvoted 3 times
...
frisbg
1 year, 5 months ago
Selected Answer: B
Issue is account removed after employee is terminated their contract therefor review should be conducted on periodic basis (at least quarterly ). SSO might look like a solution but then next time they may forget to remove network accounts, there is no insurance that account will be removed and as auditor you cant directly recommend business related controls to environment. It's up to company to decide to use SSO or IAM solution for automatic termination of accounts. Maybe software doesnt support it, you cant be sure.
upvoted 3 times
...
MohamedAbdelaal
1 year, 6 months ago
Selected Answer: B
SSO makes systems vulnerable to unauthorized access
upvoted 1 times
...
Deeplaxmi
2 years, 1 month ago
SSO makes systems more vulnerable for single point failure also. Hence keeping both network and applications access separte is always good. Hence, review of access is the best option.
upvoted 3 times
...
abeedfarooqui86
2 years, 2 months ago
Selected Answer: A
Preventive Control
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...