For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeCPA®CPA AUD Practice Exam 4Question 19
    Hard1 markMultiple Choice
    Area II: Risk AssessmentAUDIT ControlsSegregation of Duties

    CPA · Question 19 · Area II: Risk Assessment

    In an audit of an issuer, the auditor is testing the design effectiveness of User Access Controls within the IT environment. Which of the following observations would represent the MOST significant deficiency in design?

    Answer options:

    A.

    Passwords are required to be changed every 90 days.

    B.

    Developers have access to migrate changes directly into the production environment.

    C.

    Access requests for new employees are approved by the HR department.

    D.

    The system automatically logs off users after 30 minutes of inactivity.

    How to approach this question

    Identify IT General Controls (ITGC) principles. Segregation of Duties: Development vs. Production access is critical.

    Full Answer

    B.Developers have access to migrate changes directly into the production environment.✓ Correct
    Segregation of duties in IT requires separating the development/modification of programs from the authority to put them into production. If developers can move code to production, they can bypass testing and approval controls.

    Common mistakes

    Underestimating the risk of developer access to production.
    Question 18All questionsQuestion 20

    Practice the full CPA AUD Practice Exam 4

    78 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A CPA firm is performing an audit of a nonissuer, TechInnovate Inc. The engagement partner's spou...HardQ02An auditor is performing an audit of an issuer, Global Corp, in accordance with PCAOB standards. ...HardQ03A CPA is performing an audit of a county government entity that receives federal financial assist...HardQ04During the audit of an employee benefit plan subject to ERISA, the auditor discovers that the pla...HardQ05An auditor is evaluating the 'integrity' principle of the AICPA Code of Professional Conduct. Whi...Medium
    View all 78 questions →