For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeCPA®CPA ISC Practice Exam 3Question 05
    Medium1 markMultiple Choice
    Area I: Information SystemsChange ManagementSegregation of Duties

    CPA · Question 05 · Area I: Information Systems

    During a walkthrough of the change management process, an auditor observes that the 'Developer' role in the ERP system has access to 'Migrate to Production'. The IT Manager explains this is necessary for emergency fixes overnight when the Change Manager is unavailable. What is the auditor's BEST course of action?

    Answer options:

    A.

    Accept the explanation as a valid business requirement.

    B.

    Recommend that the Developer role be removed entirely.

    C.

    Identify this as a Segregation of Duties (SoD) deficiency and recommend a separate 'Emergency ID' with monitoring.

    D.

    Require that the Change Manager work overnight shifts.

    How to approach this question

    Recognize the SoD conflict (Dev vs Prod) and select the standard audit recommendation for emergency access (Firecall/Emergency ID).

    Full Answer

    C.Identify this as a Segregation of Duties (SoD) deficiency and recommend a separate 'Emergency ID' with monitoring.✓ Correct
    Allowing developers standing access to migrate code to production is a critical Segregation of Duties (SoD) failure. The standard solution for emergencies is a 'Firecall' or 'Emergency' ID that is checked out, monitored, and reviewed immediately after use.

    Common mistakes

    Accepting the client's explanation of 'business necessity' without requiring a compensating control.
    Question 04All questionsQuestion 06

    Practice the full CPA ISC Practice Exam 3

    82 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A CPA is advising a client who is migrating their legacy on-premise ERP system to a cloud-based s...MediumQ02During a review of a client's cloud governance structure, an auditor notes that the client uses a...MediumQ03An auditor is evaluating the 'Processing Integrity' principle for a financial institution's loan ...HardQ04A company uses a batch processing system to update inventory records overnight. The 'Grandfather-...HardQ06An auditor is reviewing a SQL query used to extract 'Active Customers' for a marketing report. Th...Hard
    View all 82 questions →