Q: 11
An IS auditor is evaluating the access controls for a shared customer relationship
management (CRM) system. Which of the following would be the GREATEST concern?
Options
Discussion
Yeah, B looks right to me. No audit logging is a huge gap for any shared CRM system.
B not D. No audit logs means you can't trace or investigate anything, which is a bigger issue than just complex passwords in shared systems. Seen similar wording on other practice sets.
B tbh, not D. Audit logging missing is riskier here since you can't track or investigate unauthorized access at all.
C vs B for me. No security baseline is a problem, but if there's no audit logging at all (B), there's basically no way to trace anything bad that happens. I think B edges out C since you can't detect or investigate issues without logs. Might be missing something though, open to other takes.
B , no audit logging is a bigger deal than weak passwords for a shared CRM. Without logs nobody can trace access.
B
Exam reports show B is the main concern for this type of scenario.
B
Be respectful. No spam.
Question 11 of 35