Hard1 markMultiple Choice
Area II: Risk AssessmentAUDIT ControlsSegregation of Duties

CPA · Question 19 · Area II: Risk Assessment

In an audit of an issuer, the auditor is testing the design effectiveness of User Access Controls within the IT environment. Which of the following observations would represent the MOST significant deficiency in design?

Answer options:

A.

Passwords are required to be changed every 90 days.

B.

Developers have access to migrate changes directly into the production environment.

C.

Access requests for new employees are approved by the HR department.

D.

The system automatically logs off users after 30 minutes of inactivity.

How to approach this question

Identify IT General Controls (ITGC) principles. Segregation of Duties: Development vs. Production access is critical.

Full Answer

B.Developers have access to migrate changes directly into the production environment.✓ Correct
Developers have access to migrate changes directly into the production environment.
Segregation of duties in IT requires separating the development/modification of programs from the authority to put them into production. If developers can move code to production, they can bypass testing and approval controls.

Common mistakes

Underestimating the risk of developer access to production.

Practice the full CPA AUD Practice Exam 4

78 questions · hints · full answers · grading

More questions from this exam