CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 17


After an employee termination, a network account was removed, but the application account remained active. To keep this issue from recurring, which of the following is the BEST recommendation?

Show Answer
Correct Answer: AB

Integrating application accounts with network single sign-on is the best recommendation to prevent this issue from recurring. Single sign-on (SSO) ensures that when an employee's network account is deactivated, all associated application accounts are automatically deactivated as well. This eliminates the need for separate account management, reducing the risk of leaving active application accounts after network account removal. Periodic access reviews are also important, but they are a form of detective control, which means they identify issues after they have occurred rather than preventing them. Retraining system administration staff addresses human error but may not fully eliminate the risk.

Discussion

17 comments
Sign in to comment
Victor83516Option: B
Sep 6, 2022

It is indeed more convenient to use SSO to ensure that when employees leave, the application-related permissions are also cancelled. But whether or not SSO is imported, regular account permission reviews are still the most complete solution. Careful review of account permissions can help ensure that invalid accounts are indeed closed or deleted. So, I think answer is B.

DeeplaxmiOption: B
Sep 25, 2022

SSO makes systems more vulnerable for single point failure also. Hence keeping both network and applications access separte is always good. Hence, review of access is the best option.

frisbgOption: B
May 23, 2023

Issue is account removed after employee is terminated their contract therefor review should be conducted on periodic basis (at least quarterly ). SSO might look like a solution but then next time they may forget to remove network accounts, there is no insurance that account will be removed and as auditor you cant directly recommend business related controls to environment. It's up to company to decide to use SSO or IAM solution for automatic termination of accounts. Maybe software doesnt support it, you cant be sure.

katyakOption: A
Nov 6, 2023

The question is looking for preventive control. B is detective control so is not the correct answer. Single sign-on is defined as the process for consolidating all organization platform-based administration, authentication and authorization functions into a single centralized administrative function.

oldmagicOption: A
Jun 7, 2023

A is the correct answer Perform periodic access reviews will catch this issue, but will not prevent it. SSO will.

i91290Option: A
Jun 18, 2023

A is the right answer.

[Removed]Option: A
Jun 22, 2023

SSO is the right answer.

sbtt
Jul 26, 2023

is there a way to be sure 100 per cent? because im too convinced by SSO but who know what is the logic !

CISA2021Option: A
Jan 13, 2024

The answer is A. Remark the sentence "..To keep this issue from recurring.."

RachyOption: B
Jan 24, 2024

B is much better than A as single sign on May not necessary prevent the issue from recurring

SwallowsOption: A
Apr 6, 2024

If SSO is implemented, as soon as the network account is deleted, the application is no longer accessible.

firel0rdOption: B
Jul 3, 2024

A is indeed the most convenient option, but not all systems/applications will support SSO. So B

abeedfarooqui86Option: A
Sep 17, 2022

Preventive Control

MohamedAbdelaalOption: B
Apr 26, 2023

SSO makes systems vulnerable to unauthorized access

Kokoh23Option: A
Sep 23, 2023

In this question the issue is having an application w/ two different types of access. One account/password for the application (consider it local) and a domain account/System account & password. You can delete the system account and the application account will still exist. Combining them (requiring a system password w/ managed or limited permissions) better facilitates management. When the system account is deleted, account access is also removed.

6godOption: B
Nov 15, 2023

Incomplete integration: some applications might not be fully integrated with the SSO system, leaving room for discrepancies between network account termination and the deactivation of associated application accounts. Therefore periodic review is the best.

5b56aaeOption: C
Apr 14, 2024

I will retrain the staff

a84nOption: B
Apr 25, 2024

Answer: B