CPA · Question 19 · Area II: Risk Assessment
In an audit of an issuer, the auditor is testing the design effectiveness of User Access Controls within the IT environment. Which of the following observations would represent the MOST significant deficiency in design?
Answer options:
Passwords are required to be changed every 90 days.
Developers have access to migrate changes directly into the production environment.
Access requests for new employees are approved by the HR department.
The system automatically logs off users after 30 minutes of inactivity.
78 questions · hints · full answers · grading