データベース管理の評価中に、情報システム監査人は、データベース管理者 (DBA) 権限を持つ一部のアカウントに、ログイン試行の失敗回数が無制限のデフォルト パスワードが割り当てられていることを発見しました。監査人にとって最善の対応策は次のどれですか。
正解:C
The auditor's best course of action is to document the finding and explain the risk of having administrator accounts with inappropriate security settings. This is because the auditor's role is to identify and report the issues, not to fix them or request others to fix them. The auditor should also communicate the impact of the finding, such as the possibility of unauthorized access, data tampering, or denial of service attacks. The auditor should not assume the responsibility of the IT manager or the DBA, who are in charge of changing the security parameters or disabling the accounts. References:
* CISA Review Manual (Digital Version), Chapter 4, Section 4.2.21
* CISA Online Review Course, Domain 1, Module 3, Lesson 32