Courseiva
easyMultiple Choice

CISA Practice Question: During an IT audit, the auditor finds that a…

During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?

⚠ Common exam trap

CISA often tests the difference between operational risks (password management, accidental deletion) and governance risks (accountability, non-repudiation) — candidates pick the operational-sounding answer when the audit-correct answer is the accountability one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit trails cannot attribute actions to a specific individual

When multiple administrators use a shared service account, system logs record the account name but cannot identify which individual performed an action. This destroys accountability and non-repudiation, which are core IT audit concerns. While the other issues are real, the inability to attribute actions to a specific person is the primary risk from a governance and audit perspective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Audit trails cannot attribute actions to a specific individual

    Why this is correct

    A shared service account means server logs record only the account name, never the individual administrator, so actions cannot be traced to a person. This destroys accountability and non-repudiation, the primary audit risk when local administrator rights are combined with shared credentials.

  • ✗

    Password changes become more difficult to manage

    Why it's wrong here

    Password rotation on a shared account is an operational nuisance, not the primary risk. The stem's concern is that shared credentials remove individual accountability, so actions cannot be traced to a person. Shared accounts would be considered only where no attribution requirement exists, which production administration never satisfies.

  • ✗

    The administrator may accidentally delete critical files

    Why it's wrong here

    Accidental deletion is a possible outcome of excessive rights, but the primary risk is loss of accountability: shared credentials mean no action can be attributed to a named administrator. Local admin rights would be acceptable where least privilege and individual accounts are enforced, which the shared service account prevents.

  • ✗

    The shared account may be used by unauthorized personnel

    Why it's wrong here

    Unauthorised use is a consequence of shared credentials, but the primary risk is that activity cannot be attributed to an individual, defeating accountability and audit trails. Shared accounts are tempting where multiple administrators need identical maintenance access, yet that scenario still requires individual named accounts with delegated rights.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.