Courseiva
easyMultiple ChoiceObjective-mapped

CISA Practice Question: An IS auditor is reviewing the logical access…

An IS auditor is reviewing the logical access controls of an enterprise resource planning (ERP) system. The auditor finds that terminated employees' accounts are disabled but not deleted. What is the PRIMARY risk associated with this practice?

⚠ Common exam trap

ISACA often tests the misconception that 'disabled accounts are safe because they cannot log in,' but the trap here is that the account's privileges remain intact, making re-enablement the primary risk over performance or audit concerns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disabled accounts could be re-enabled without proper authorization

The primary risk of disabling rather than deleting terminated employees' accounts is that a disabled account retains its existing privileges and can be re-enabled by an attacker or insider with sufficient access (e.g., a system administrator with compromised credentials). In an ERP system, this could allow unauthorized re-activation of accounts with elevated roles, bypassing the intended termination process and leading to data theft, fraud, or system compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disabled accounts could be re-enabled without proper authorization

    Why this is correct

    If account management is weak, re-enabling could lead to unauthorized access.

  • Segregation of duties controls may be compromised

    Why it's wrong here

    Segregation is about role assignment, not account disablement.

  • System performance may degrade due to accumulation of disabled accounts

    Why it's wrong here

    Performance impact is minimal and not the primary risk.

  • Audit trail completeness may be affected

    Why it's wrong here

    Disabled accounts can still be logged; deletion might lose history.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.