CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 273


A bank's web-hosting provider has just completed an internal IT security audit and provides only a summary of the findings to the bank's auditor. Which of the following should be the bank's GREATEST concern?

Show Answer
Correct Answer: A

A bank's greatest concern in this scenario would be if the audit scope did not address critical areas. If critical areas are missed, it could result in security vulnerabilities that go undetected, posing significant risk to the bank. The other options, while important, do not pose as great a risk as missing critical areas in the audit.

Discussion

6 comments
Sign in to comment
ZephaniahOption: A
Sep 7, 2022

A. Greatest concern should be the critical arears to be audited. keyword is greatest

MunaMOption: C
Sep 6, 2022

Answer should be C because of Independence

3008Option: A
Jul 30, 2023

The bank's greatest concern in this scenario is the possibility that the audit scope may not have addressed critical areas (Option A). The summary provided by the web-hosting provider may not provide the bank with sufficient information to determine whether the audit scope was adequate and whether all critical areas were assessed

DeeplaxmiOption: C
Sep 6, 2022

yes, i also think it should be C as the question is not about auditors concern but banks concern.

RachyOption: C
Jan 16, 2024

Why is the answer not C? I think the question is not about content of the audit but who they submitted the audits findings to. So the bank greatest concern here is the auditors not independent of the bank

analuisamoreira
Jun 27, 2024

Internal auditors are independent and reliable

blues_leeOption: A
Jan 30, 2024

a is correct