Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1000 discussion

Actual exam question from Isaca's CISA
Question #: 1000
Topic #: 1
[All CISA Questions]

Which of the following should be the GREATEST concern for an IS auditor performing a post-implementation review for a major system upgrade?

  • A. Changes are promoted to production by the development group.
  • B. Developers have access to the testing environment.
  • C. Object code can be accessed by the development group.
  • D. Change approvals are not formally documented.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Staanlee
Highly Voted 1 year, 10 months ago
Selected Answer: D
The correct answer is D, Change approvals are not formally documented. When performing a post-implementation review for a major system upgrade, the greatest concern for an IS auditor should be whether change approvals are formally documented. This is because formal documentation of change approvals is an important control measure that helps to ensure that changes to systems and applications are authorized and properly controlled. If change approvals are not formally documented, there is a risk that unauthorized changes may be made to the system, which could compromise the system's integrity and security.
upvoted 7 times
...
PurpleParrot
Most Recent 3 months, 1 week ago
Selected Answer: A
Option A pauses the greatest risk because developers with promotion privileges might bypass formal approval processes, either intentionally or unintentionally. So even if change approvals were documented, the developers still could bring about unapproved changes
upvoted 1 times
...
RS66
3 months, 3 weeks ago
Selected Answer: A
A. Changes are promoted to production by the development group. This is still the greatest concern for an IS auditor performing a post-implementation review for a major system upgrade. Directly bypassing the necessary change control and approval processes by allowing the development team to promote changes to production poses a significant risk to system integrity, security, and overall control. While options B, C, and D represent potential issues, they are generally mitigated by other controls and processes. Option A, however, directly undermines the fundamental principle of segregation of duties and change management.
upvoted 1 times
...
Swallows
6 months ago
Selected Answer: A
Allowing changes to be promoted directly to production by the development group poses a higher risk to the stability and security of the production environment, as it bypasses many of the controls and safeguards that should be in place to manage changes effectively.
upvoted 2 times
...
Sibsankar
6 months, 3 weeks ago
Auditor will look first Change Approval, if it is signed then he look who is executing the job. Here change approval is not signed , so correct answer will be D
upvoted 1 times
...
KAP2HURUF
10 months, 3 weeks ago
Selected Answer: A
In this context, while undocumented change approvals (Option D) are a serious concern, the direct involvement of developers in promoting changes to production (Option A) can pose a more immediate risk to the integrity and security of the system, especially in a major system upgrade where numerous and potentially significant changes are being made. This approach can undermine the control environment and increase the risk of errors or unauthorized alterations to the system.
upvoted 3 times
...
FAGFUR
1 year ago
Selected Answer: C
The greatest concern for an IS auditor performing a post-implementation review for a major system upgrade is that object code can be accessed by the development group. Object code represents the compiled form of the source code, and it contains the machine-readable instructions that the computer can execute. Allowing the development group to access object code in a production environment poses a significant security risk. It could lead to unauthorized changes, debugging, or exploitation of vulnerabilities, potentially compromising the integrity and security of the system.
upvoted 2 times
...
SuperMax
1 year, 1 month ago
Selected Answer: D
D. Change approvals are not formally documented. This is because the lack of formal documentation for change approvals can lead to a higher risk of unauthorized or untested changes being introduced into the production environment, potentially causing significant issues and security vulnerabilities. While the other options (A, B, and C) are also important considerations, the absence of formal change approval documentation can have broader and more immediate consequences for the system’s integrity and security.
upvoted 2 times
...
jsalamba
1 year, 8 months ago
Selected Answer: C
Correct Answer is C: "Object code can be accessed by the development group," should be the greatest concern for an IS auditor performing a post-implementation review for a major system upgrade. Object code contains the machine-readable version of the software and includes the actual instructions that the computer executes to perform a particular task. Object code is not meant to be easily readable or modifiable by developers. However, if the development group has access to the object code, they could potentially modify the code and introduce errors or vulnerabilities, which could impact the security, functionality, or stability of the system. It is important to restrict access to object code to authorized personnel only and ensure that appropriate change management procedures are in place to manage changes to the code.
upvoted 1 times
...
Tsubasa1234
1 year, 9 months ago
Answer is A.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...