Courseiva
easyMultiple ChoiceObjective-mapped

CISA Practice Question: During an IT audit, the auditor finds that a…

During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Audit trails cannot attribute actions to a specific individual

Using a shared service account prevents attribution of actions to a specific individual, which is the primary risk from an audit perspective as it compromises accountability. Option B is not primarily a risk; password management is secondary. Option C is a possible operational risk but not primary. Option D is a risk but not the primary one; the main issue is lack of individual accountability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Audit trails cannot attribute actions to a specific individual

    Why this is correct

    Shared accounts break the link between an action and an individual, violating the principle of accountability.

  • Password changes become more difficult to manage

    Why it's wrong here

    Password management is a secondary concern compared to accountability.

  • The administrator may accidentally delete critical files

    Why it's wrong here

    This risk exists regardless of account type; accountability is more fundamental.

  • The shared account may be used by unauthorized personnel

    Why it's wrong here

    While possible, the main risk is lack of accountability, as any action cannot be attributed to a specific person.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.