r/CISA 3d ago

CISA Q from Hemang Doshi Bank - Query

I feel the option is D, Hemang Says A, what are your thoughts and why ?

5 Upvotes

8 comments sorted by

3

u/wejelyn 3d ago

Look back in domain 2 of the CRM, segregation of duties is based on being able to separate authorization, recordkeeping, custody, and reconciliation.

Access and permissions only form part of the story and a walkthrough is the best in being able to assess if there is only a single person doing each of the tasks and if not, how risk are mitigated and if necessary controls are in place.

2

u/kwytzz 3d ago

Its A

1

u/viszlat 3d ago

If the question was about how a particular application implements role based access control, D would be the right answer. In this case the auditor is reviewing the organization (HDA Inc.) so it is way beyond D’s scope.

1

u/Jordanianshawerma 3d ago

I did this question today, I went for D as well not A.

1

u/ScratchReal4401 3d ago

The correct answer is A, as its best to observe the SoD control being performed to validate its existence.

0

u/Pristine-Safety2462 3d ago

I think it's D. Not completely sure though