easyMultiple ChoiceObjective-mapped
CISA Practice Question: During an IT audit, the auditor finds that a…
During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit trails cannot attribute actions to a specific individual
Using a shared service account prevents attribution of actions to a specific individual, which is the primary risk from an audit perspective as it compromises accountability. Option B is not primarily a risk; password management is secondary. Option C is a possible operational risk but not primary. Option D is a risk but not the primary one; the main issue is lack of individual accountability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Audit trails cannot attribute actions to a specific individual
Why this is correct
Shared accounts break the link between an action and an individual, violating the principle of accountability.
- ✗
Password changes become more difficult to manage
Why it's wrong here
Password management is a secondary concern compared to accountability.
- ✗
The administrator may accidentally delete critical files
Why it's wrong here
This risk exists regardless of account type; accountability is more fundamental.
- ✗
The shared account may be used by unauthorized personnel
Why it's wrong here
While possible, the main risk is lack of accountability, as any action cannot be attributed to a specific person.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.