Free ISACA CISA Actual Exam Questions - Question 15 Discussion

Question No. 15
Which of the following findings from a database security audit presents the GREATEST risk
of critical security exposures?
Select all that apply, then reveal solution.
US
MG
Marco G.
2026-02-22

It’s B—non-expiring admin passwords are a clear, ongoing attack vector.

0
SP
Sohail P.
2026-02-18

B stands out to me because if admin passwords never expire, it’s easier for attackers to gain ongoing access once compromised. Does anyone think not expiring passwords pose a bigger immediate danger than legacy data or default settings?

0
SP
Sohail P.
2026-01-24

C/D? Default settings can open big vulnerabilities, but missing logs hide attacks too.

0
SP
Sohail P.
2026-01-23

Maybe C, because default settings often include weak security and can be exploited easily if left unchanged, leading to a bigger risk than just logging gaps or password policies.

0
FJ
Farhan J.
2026-01-15

Actually, D sounds the worst here since incomplete logging means you might not catch breaches or suspicious actions. Without proper tracking, a lot can slide under the radar.

0