Correct Answer: B
The correct answer is B. The last login to the user account was days after the last working date.
This is the greatest concern because it indicates the terminated employee's account may have remained active and may have been used after employment ended. That creates a direct risk of unauthorized access, data theft, fraud, sabotage, or misuse of organizational systems.
Option A is a concern because passwords should generally be subject to appropriate password controls, but it is less severe than evidence of post-termination account activity. Option C may indicate weak password management, but again it is not as serious as actual account use after termination. Option D is a governance weakness, but the strongest evidence of immediate risk is the login activity after the employee's last working date.
This maps to Protection of Information Assets because it relates to logical access control, identity and access management, and protection against unauthorized access. ISACA's CISA Exam Content Outline includes Domain 5, Protection of Information Assets, and the official outline includes identity and access management and information asset protection topics.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, access control and related control concepts.