The best answer is A. There are shared administrator accounts on internet-facing routers.
Shared administrator accounts on internet-facing devices create a serious accountability, access control, and security exposure. ISACA access-control guidance stresses that access should be individually justified, authorized, logged, and monitored. Shared privileged accounts undermine attribution and make it much harder to determine who performed a change or malicious action. On internet-facing routers, this becomes especially serious because those devices sit at the network boundary and can be targeted directly.
Option B is a concern, but a test web page in the DMZ is usually less severe than weak privileged access on perimeter infrastructure. Option C and D both mention updates from within the last week. That timing matters: while prompt patching is important, the absence of updates released only last week is generally less risky than shared privileged accounts on external-facing network devices, especially when emergency testing and staged deployment may still be underway. ISACA patch guidance emphasizes risk assessment and testing before deployment.
Therefore, the correct answer is A, because shared privileged accounts on internet-facing routers present the greatest immediate security and audit risk.
References (Official ISACA):
ISACA, Audit Programs and Tools – Identity and Access Management Audit Program — access should be justified, authorized, logged, and monitored.
ISACA Journal, Selected COBIT 5 Processes for Essential Enterprise Security — supports strong identity and access governance. (Referenced through prior aligned ISACA IAM principles.)
ISACA Journal, Addressing Cybersecurity Vulnerabilities — patching and vulnerability management must be risk-based and timely.
ISACA, Protecting SAP Systems in the Cybersecurity Era — patch management should include risk and applicability assessment before deployment.
Submit