Medium1 markMultiple Choice
CPA · Question 40 · Area II: Security
An auditor is testing the 'Logical Access' controls for an ERP system. They select a sample of new employees and verify that their access rights were approved by a manager. This test is designed to validate which assertion?
An auditor is testing the 'Logical Access' controls for an ERP system. They select a sample of new employees and verify that their access rights were approved by a manager. This test is designed to validate which assertion?
Answer options:
A.
Authorization
B.
Authentication
C.
Accuracy
D.
Completeness
How to approach this question
Match 'Manager Approval' to 'Authorization'.
Full Answer
A.Authorization✓ Correct
A
Testing for manager approval ensures that access rights were properly authorized before being granted. Authentication verifies who you are; Authorization verifies what you are allowed to do.
Common mistakes
Confusing Authentication (Login) with Authorization (Permissions).
Practice the full CPA ISC Practice Exam 3
82 questions · hints · full answers · grading
More questions from this exam
Q01A CPA is advising a client who is migrating their legacy on-premise ERP system to a cloud-based s...MediumQ02During a review of a client's cloud governance structure, an auditor notes that the client uses a...MediumQ03An auditor is evaluating the 'Processing Integrity' principle for a financial institution's loan ...HardQ04A company uses a batch processing system to update inventory records overnight. The 'Grandfather-...HardQ05During a walkthrough of the change management process, an auditor observes that the 'Developer' r...Medium
Expert