Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is evaluating an organization's job scheduling practices for a critical batch process that updates the general ledger. The process runs nightly and must complete before the start of the business day. The auditor finds that the job scheduler uses a single service account with domain administrator privileges to run all jobs, and there are no alerts for job failures. Which of the following is the MOST significant risk arising from this configuration?

⚠ Common exam trap

The trap here is focusing on the security risk of excessive privileges and overlooking the operational risk of undetected job failures, which directly impacts data integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A failed job may go undetected, causing financial data to be incomplete or inaccurate.

The absence of job failure alerts is a critical control gap. For a nightly general ledger update, undetected failures can lead to incomplete financial data being used for reporting and decision-making. While the use of a domain administrator service account is a security concern, the immediate risk to data integrity and financial accuracy is more significant. Auditors should recommend implementing alerting and using least-privilege service accounts, but the most pressing risk is the potential for silent failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The job scheduler may not be able to run jobs if the service account password expires.

    Why it's wrong here

    Password expiration is a plausible operational risk, but it is not the most significant here. If the password expires, jobs would fail, and without alerts, the failure could go unnoticed. However, this is a subset of the broader risk of undetected job failures. The scenario does not indicate that password expiration is imminent or that the account is configured to expire, making it less likely than the systemic lack of monitoring.

  • ✗

    The batch process may not complete within the allotted time window due to resource contention.

    Why it's wrong here

    Resource contention could cause delays, but the scenario does not provide evidence of performance issues. The auditor's finding is about the use of a privileged service account and the absence of failure alerts. While timing is important, the lack of alerting is a more direct and severe control weakness because it allows any failure to go unnoticed, regardless of cause. Resource contention is speculative in this context.

  • ✓

    A failed job may go undetected, causing financial data to be incomplete or inaccurate.

    Why this is correct

    This is the most significant risk because the lack of failure alerts means that if the nightly general ledger update fails, no one is notified. The business day could start with incomplete or inaccurate financial data, leading to incorrect reporting, decisions, and potential regulatory issues. While excessive privileges are also a concern, the immediate impact on data integrity and financial reporting is more critical in this scenario.

  • ✗

    The service account's domain administrator privileges could be exploited by a malicious insider.

    Why it's wrong here

    While excessive privileges are a serious security risk, the scenario emphasizes the batch process's criticality and the absence of failure alerts. The domain administrator privileges increase the attack surface, but the direct and immediate risk to financial data integrity from an undetected job failure is more significant. The auditor should address both, but the most critical risk is the potential for undetected failures.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.