An IS auditor performing an access controls review should be
LEAST concerned if:

A. audit trails were not enabled.

B. programmers have access to the live environment.

C. group logons are being used for critical functions.

D. the same user can initiate transactions and also change
related parameters.

Answer Posted / guest

Answer: A

Audit trails not being enabled is of least concern, as it
will not result in an exposure. Programmers having access to
the live environment could result in unauthorized
transactions. Group logons used for critical functions is a
major concern. The same user who has access to and can
initiate transactions, as well as change the related
parameters, is an area of high concern.

Is This Answer Correct ?    4 Yes 0 No



Post New Answer       View All Answers


Please Help Members By Posting Answers For Below Questions

WHICH OF THE FOLLOWING IS OFTEN AN ADVANTAGE OF USING PROTOTYPING GOR DYDTEM DVELOPMENT

3123


purchase orders issued to vendors have been authorized as per the authorization matrix

1323