Greatest Concern in Post-Implementation Audit of Job Scheduler
A post-implementation audit has been completed for the deployment of a sophisticated job scheduling tool. Which of the following observations would be of GREATEST concern?
Community Votes
50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests prioritization of audit findings by contrasting a configuration gap against a fundamental access control violation that destroys non-repudiation.
This CISA question evaluates your ability to prioritize audit findings, highlighting why shared administrative credentials pose a higher risk than unencrypted data or project delays. It establishes that unique user accountability for privileged access is the paramount concern in IT audits.
Candidates frequently choose the missing encryption option because it appears as an obvious security flaw, overlooking that CISA prioritizes individual accountability for administrative functions over general data protection settings in this context.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D represents the greatest concern because using a generic account for administrative access fundamentally violates core IT audit principles of individual accountability and non-repudiation. Without unique credentials, it becomes impossible to trace specific actions to an individual, severely compromising incident investigation and forensic auditing capabilities. CISA doctrine consistently ranks the absence of unique privileged access controls above many configuration gaps because it undermines the entire audit trail.Why the Other Options Are Wrong
Option A involves vendor customization protocols, which are operational concerns but do not immediately compromise system integrity or security. Option B reflects standard project management variance and carries no direct security or compliance impact for an audit. Option C highlights a missing encryption feature, which is a valid security risk, but job schedulers often process internal system tasks where encryption may be handled at the infrastructure level, making the loss of administrative accountability a more critical and immediate audit failure.Community Comment Notes
Several learners initially leaned toward the encryption option due to its apparent security severity, but experienced auditors emphasize that administrative credential sharing completely breaks the audit chain. As user pLulu noted, generic accounts "makes it difficult to track individual user actions," which directly contradicts mandatory logging requirements for privileged systems. The consensus correctly identifies that while data protection matters, losing the ability to track who modified the scheduler is a definitive audit failure.Exam Strategy
Always prioritize findings that destroy audit trails or eliminate individual accountability when asked for the "greatest concern" in an audit scenario. Evaluate options through the lens of non-repudiation and privileged access management before selecting configuration or procedural gaps.
Frequently Asked Questions
Why is missing encryption less concerning than a generic account?
Encryption protects data confidentiality, but a generic account destroys accountability and breaks the audit trail for all administrative actions. CISA prioritizes non-repudiation for privileged access.
Does customizing a tool without provider approval matter?
It creates support and compliance issues, but lacks the immediate security and accountability risks of shared privileged credentials. Vendor approval workflows are secondary to core access controls.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →