Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISA Exam - Topic 3 Question 25 Discussion

An organization processing high volumes of financial transactions has implemented log file analysis on a central log server to continuously monitor compliance with its fraud policy. Which of the following poses the GREATEST risk to this control?
B) Data entry staff have privileged access to the log server.
A) IT operations staff have the right to restart the log server.
C) IT operations staff are able to stop the payment processing system.
D) Software developers have read access to the log server.

Isaca CISA Exam - Topic 3 Question 25 Discussion

Actual exam question for Isaca's CISA exam
Question #: 25
Topic #: 3
[All CISA Questions]

An organization processing high volumes of financial transactions has implemented log file analysis on a central log server to continuously monitor compliance with its fraud policy. Which of the following poses the GREATEST risk to this control?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Eve
8 months ago
Not sure about this. Aren't all options risky in their own way?
upvoted 0 times
...
Lisbeth
9 months ago
I think B is the worst too. Data entry staff shouldn't have that kind of access.
upvoted 0 times
...
Hoa
9 months ago
A little surprised that D isn't seen as a bigger threat. Developers can mess things up!
upvoted 0 times
...
Rhea
9 months ago
I disagree, C seems riskier. Stopping payments could cause major issues.
upvoted 0 times
...
Theola
9 months ago
B is definitely the biggest risk. Privileged access is no joke.
upvoted 0 times
...
Jennifer
9 months ago
This question reminds me of a practice one where we talked about access controls. I think stopping the payment system could be a big issue, so maybe C is the answer?
upvoted 0 times
...
Christiane
9 months ago
I'm not entirely sure, but I feel like allowing IT operations to restart the log server might create vulnerabilities too.
upvoted 0 times
...
Valentin
9 months ago
I remember we discussed how privileged access can lead to manipulation of logs, so I think option B could be a major risk.
upvoted 0 times
...
Kimbery
9 months ago
I thought developers having read access was a concern, but I can't recall if it was the greatest risk. I guess it could be D, but I'm not confident.
upvoted 0 times
...
Carlee
9 months ago
Hmm, I'm a bit unsure about this. I'll need to review my notes on agile approaches and how they differ from traditional project management.
upvoted 0 times
...
Fredric
9 months ago
This looks like a classic OSPF adjacency question. I'll carefully review the packet exchange and OSPF states to determine the current adjacency state.
upvoted 0 times
...
Ollie
10 months ago
This seems like a straightforward question. I think option B is the way to go - writing the file to the /workspace directory and reading it back in the subsequent build step.
upvoted 0 times
...
Remona
10 months ago
I'm pretty sure this is about the financial aspects of self-funded healthcare plans. Option C looks promising - without an insurer, they'd avoid paying those extra risk charges.
upvoted 0 times
...

Save Cancel