Hard1 markMultiple Choice
Area I: Information SystemsAccess ControlArea I

CPA · Question 64 · Area I: Information Systems

An auditor is testing 'Logical Access'. They find that the 'Administrator' group contains 15 users, including 5 who left the company years ago. This violates which principle?

Answer options:

A.

Encryption

B.

Recertification / Access Review

C.

Two-Factor Authentication

D.

Input Validation

How to approach this question

The process of checking 'Do these people still need access?' is Recertification.

Full Answer

B.Recertification / Access Review✓ Correct
Access Recertification (or User Access Review) is the control where management reviews user access rights periodically to ensure they are still appropriate. This would have identified the terminated users.

Common mistakes

Confusing with Termination procedures (which failed, but the Review is the detective control that catches it).

Practice the full CPA ISC Practice Exam 4

82 questions · hints · full answers · grading

More questions from this exam