Greatest Concern in Post-Implementation Audit of Job Scheduler

IT Auditing & Access Controls
Answer Correct answer: D — The IT team accesses the scheduler admin panel via a generic account, which eliminates individual accountability and compromises audit trails.

A post-implementation audit has been completed for the deployment of a sophisticated job scheduling tool. Which of the following observations would be of GREATEST concern?

  1. The IT team customized tool settings without seeking approval from the provider.
  2. The overall project took longer to complete than planned.
  3. The data encryption setting is not enabled in the scheduling tool.
  4. The IT team accesses the scheduler admin panel via a generic account. Correct Answer

Community Votes

C
50%
D
50%

50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests prioritization of audit findings by contrasting a configuration gap against a fundamental access control violation that destroys non-repudiation.

This CISA question evaluates your ability to prioritize audit findings, highlighting why shared administrative credentials pose a higher risk than unencrypted data or project delays. It establishes that unique user accountability for privileged access is the paramount concern in IT audits.

Candidates frequently choose the missing encryption option because it appears as an obvious security flaw, overlooking that CISA prioritizes individual accountability for administrative functions over general data protection settings in this context.

Community Discussion (3 comments)

46080f2 👍 1 Selected: D
Based on the CISA Official Review Manual 28th Edition, the observation of greatest concern is D. The IT team accesses the scheduler admin panel via a generic account. This finding aligns with the manual’s strong stance against shared privileged accounts, as evidenced by Section 5.3.14 and the self-assessment, due to its significant risks to accountability, integrity, and availability - crucial for a job scheduling tool’s operation.
pLulu 👍 1
D. The IT team accesses the scheduler admin panel via a generic account. Using a generic account for accessing the scheduler admin panel poses significant security risks. It makes it difficult to track individual user actions, which can lead to accountability issues and complicate incident response. Additionally, it increases the risk of unauthorized access, as generic accounts are often less secure and more prone to misuse.
blehbleh 👍 1 Selected: C
I'm leaning toward C on this due to this being an audit certificate. One would think they would care most about security and encryption out of the options provided. Not to say that option A and D aren't concerns as well. Just C seems to be more concerning.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D represents the greatest concern because using a generic account for administrative access fundamentally violates core IT audit principles of individual accountability and non-repudiation. Without unique credentials, it becomes impossible to trace specific actions to an individual, severely compromising incident investigation and forensic auditing capabilities. CISA doctrine consistently ranks the absence of unique privileged access controls above many configuration gaps because it undermines the entire audit trail.

Why the Other Options Are Wrong

Option A involves vendor customization protocols, which are operational concerns but do not immediately compromise system integrity or security. Option B reflects standard project management variance and carries no direct security or compliance impact for an audit. Option C highlights a missing encryption feature, which is a valid security risk, but job schedulers often process internal system tasks where encryption may be handled at the infrastructure level, making the loss of administrative accountability a more critical and immediate audit failure.

Community Comment Notes

Several learners initially leaned toward the encryption option due to its apparent security severity, but experienced auditors emphasize that administrative credential sharing completely breaks the audit chain. As user pLulu noted, generic accounts "makes it difficult to track individual user actions," which directly contradicts mandatory logging requirements for privileged systems. The consensus correctly identifies that while data protection matters, losing the ability to track who modified the scheduler is a definitive audit failure.

Exam Strategy

Always prioritize findings that destroy audit trails or eliminate individual accountability when asked for the "greatest concern" in an audit scenario. Evaluate options through the lens of non-repudiation and privileged access management before selecting configuration or procedural gaps.

Frequently Asked Questions

Why is missing encryption less concerning than a generic account?

Encryption protects data confidentiality, but a generic account destroys accountability and breaks the audit trail for all administrative actions. CISA prioritizes non-repudiation for privileged access.

Does customizing a tool without provider approval matter?

It creates support and compliance issues, but lacks the immediate security and accountability risks of shared privileged credentials. Vendor approval workflows are secondary to core access controls.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide