CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 198


During an operational audit of a biometric system used to control physical access, which of the following should be of GREATEST concern to an IS auditor?

Show Answer
Correct Answer: AC

When auditing a biometric system used to control physical access, the greatest concern should be false positives. False positives occur when the system incorrectly grants access to unauthorized individuals, posing a significant security risk. This compromises the integrity and security of the controlled area, potentially allowing unauthorized access to sensitive areas or information. While false negatives (denying access to authorized users) are also an issue, the immediate risk to security from unauthorized access is generally considered more critical.

Discussion

10 comments
Sign in to comment
DeeplaxmiOption: A
Sep 28, 2022

A- False Positive.. giving access to persons who should not be given access is a concern..

StaanleeOption: C
Dec 3, 2022

C- False negative is correct. An instance in which a security tool intended to detect a particular threat fails to do so

007GeorgeoOption: C
May 4, 2023

C for sure

analuisamoreira
Jun 26, 2024

Why is that?

mibg83Option: C
Jun 6, 2023

False negatives occur when the biometric system fails to correctly identify an authorized user, leading to a denial of access to individuals who should be granted access

[Removed]Option: A
Dec 13, 2023

False positive leads to unauthorized access in this case

RachyOption: A
Jan 12, 2024

Answer is False Positive. A If you are reading this, don’t be confused

a84nOption: C
Apr 26, 2024

Q: the GREATEST concern for a biometric system used to control PHYSICAL access Answer: C - False Negative if it was about a biometric system used to control logical access then the greatest concern is A False Positive

analuisamoreiraOption: C
Jun 26, 2024

I completly disagree with letter C. Given unauthorized people to access any place is a greatest concern that not granting an allowed person to it. It's unauthorized access.

akosigengenOption: C
Mar 2, 2024

c. should be more concerning coz it affects the business if authorized users are not allowed

RS66Option: A
Jun 30, 2024

False negative is a concern but the IS auditor's convern. Auditor is concerned more with false positives.