CISA Protection of Information Assets • Timed 25 Questions
This is a timed practice session. You have 25 minutes to answer 25 questions — approximately 1 minute per question, matching real CISA exam pace. Answer every question before time expires.
Time remaining
25:00
Exam-pace drill
Allow 1 minute per question. On the real CISA exam you have approximately 72 seconds per question — this session trains you to maintain that pace under pressure.
An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?