Courseiva

CISA Governance and Management of IT Practice Question

Exhibit

Refer to the exhibit.

Access Control Policy (Excerpt):
- All system access requests must be approved by the data owner.
- Access reviews must be performed quarterly.
- Non-compliant access will be revoked within 24 hours of detection.

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

⚠ Common exam trap

CISA often tests the difference between the risk itself (unauthorized access persisting) and the consequence (audit findings) — candidates pick the reporting outcome instead of the underlying security exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unauthorized access may be granted and persist

The most significant risk of missed access reviews is that unauthorized or excessive access rights remain in place undetected, allowing users to retain privileges they should no longer have (e.g., after role changes or terminations). This directly enables insider threats and privilege creep, which is the core control objective of periodic access reviews.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data integrity may be compromised

    Why it's wrong here

    Unreviewed access leaves stale entitlements in place, but the primary exposure is unauthorised access through excessive privileges, not corruption of stored data. Data integrity risk arises from modification or processing errors, which access reviews do not directly address.

  • ✓

    Unauthorized access may be granted and persist

    Why this is correct

    Missed quarterly reviews mean accumulated entitlement drift goes undetected, so accounts retain access after role changes or termination. The stem's two-quarter gap directly enables unauthorised access to be granted and to persist unchallenged, which is the most significant consequence.

  • ✗

    System performance may degrade

    Why it's wrong here

    Missed access reviews leave stale entitlements in place, so the real exposure is unauthorised or excessive access persisting undetected; performance degradation has no causal link to review completion. The option is tempting because periodic reviews do consume directory and reporting resources, so they would be the right concern when sizing Microsoft Entra ID access-review workloads or scheduling them against peak authentication traffic.

  • ✗

    Audit findings may be reported to management

    Why it's wrong here

    Reporting findings to management is the audit process working as intended, not a risk arising from missed reviews. Findings escalation is the correct outcome when control gaps are identified; the substantive exposure is the unreviewed access itself.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.