CPA · Question 42 · Area III: SOC Engagements
An auditor is testing the 'Logical Access' domain. They find that a terminated employee's account remained active for 3 weeks after departure. The policy requires removal within 24 hours. This is an example of:
Answer options:
A design deficiency.
A control deviation.
A material weakness.
Inherent risk.
82 questions · hints · full answers · grading