Free ISACA CISA Actual Exam Questions - Question 15 Discussion
Question No. 15
Which of the following findings from a database security audit presents the GREATEST risk
of critical security exposures?
of critical security exposures?
Select all that apply, then reveal solution.
US
MG
Marco G.
2026-02-22
It’s B—non-expiring admin passwords are a clear, ongoing attack vector.
0
SP
Sohail P.
2026-02-18
B stands out to me because if admin passwords never expire, it’s easier for attackers to gain ongoing access once compromised. Does anyone think not expiring passwords pose a bigger immediate danger than legacy data or default settings?
0
SP
Sohail P.
2026-01-24
C/D? Default settings can open big vulnerabilities, but missing logs hide attacks too.
0
SP
Sohail P.
2026-01-23
Maybe C, because default settings often include weak security and can be exploited easily if left unchanged, leading to a bigger risk than just logging gaps or password policies.
0
FJ
Farhan J.
2026-01-15
Actually, D sounds the worst here since incomplete logging means you might not catch breaches or suspicious actions. Without proper tracking, a lot can slide under the radar.
0