An access review finds that a terminated system administrator's privileged account remains enabled. Logs show no activity after termination. Which response best addresses the control risk?
- A.Close the finding because the logs show no use
- B.Disable the account, investigate the period of inappropriate access, and determine whether other access records need review
- C.Keep the account enabled for continuity and monitor it annually
- D.Delete the logs so the inactive account cannot be misunderstood
An enabled privileged account creates an avoidable unauthorized-access risk even when no activity is currently visible. The account should be disabled and the exposure period investigated.
Why the other answers are wrong
- A. Absence of observed use does not eliminate the risk created by an enabled privileged account.
- C. Continuity does not justify retaining inappropriate privileged access after termination.
- D. Logs are evidence and should be preserved, not deleted.