easyMultiple Choice
CISA Practice Question: An IS auditor is reviewing the logical access…
An IS auditor is reviewing the logical access controls of an enterprise resource planning (ERP) system. The auditor finds that terminated employees' accounts are disabled but not deleted. What is the PRIMARY risk associated with this practice?
⚠ Common exam trap
ISACA often tests the misconception that 'disabled accounts are safe because they cannot log in,' but the trap here is that the account's privileges remain intact, making re-enablement the primary risk over performance or audit concerns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disabled accounts could be re-enabled without proper authorization
The primary risk of disabling rather than deleting terminated employees' accounts is that a disabled account retains its existing privileges and can be re-enabled by an attacker or insider with sufficient access (e.g., a system administrator with compromised credentials). In an ERP system, this could allow unauthorized re-activation of accounts with elevated roles, bypassing the intended termination process and leading to data theft, fraud, or system compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disabled accounts could be re-enabled without proper authorization
Why this is correct
Disabled accounts retain their permissions and group memberships, so anyone who re-enables the account, whether through administrative error or misuse, restores the terminated employee's full access. Deletion removes the entitlement entirely, eliminating that residual exposure.
- ✗
Segregation of duties controls may be compromised
Why it's wrong here
Disabling accounts preserves the audit trail and prevents login, so segregation of duties is unaffected; the risk is dormant accounts being re-enabled or shared. Segregation of duties concerns conflicting access rights within active roles, which is a different control objective from account lifecycle management.
- ✗
System performance may degrade due to accumulation of disabled accounts
Why it's wrong here
Disabled accounts consume negligible resources, so performance degradation is not a realistic risk; the actual exposure is unauthorised reactivation or credential reuse. Performance concerns relate to active session load or database growth, not dormant directory objects.
- ✗
Audit trail completeness may be affected
Why it's wrong here
Disabling rather than deleting accounts actually preserves audit trail completeness, since historical transaction attribution remains intact. Deleting accounts would sever that linkage. Audit trail integrity is the reason to retain disabled accounts, not a risk arising from the practice.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.