CISA Governance and Management of IT Practice Question
Exhibit
Refer to the exhibit. Access Control Policy (Excerpt): - All system access requests must be approved by the data owner. - Access reviews must be performed quarterly. - Non-compliant access will be revoked within 24 hours of detection.
An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?
⚠ Common exam trap
CISA often tests the difference between the risk itself (unauthorized access persisting) and the consequence (audit findings) — candidates pick the reporting outcome instead of the underlying security exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized access may be granted and persist
The most significant risk of missed access reviews is that unauthorized or excessive access rights remain in place undetected, allowing users to retain privileges they should no longer have (e.g., after role changes or terminations). This directly enables insider threats and privilege creep, which is the core control objective of periodic access reviews.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data integrity may be compromised
Why it's wrong here
Unreviewed access leaves stale entitlements in place, but the primary exposure is unauthorised access through excessive privileges, not corruption of stored data. Data integrity risk arises from modification or processing errors, which access reviews do not directly address.
- ✓
Unauthorized access may be granted and persist
Why this is correct
Missed quarterly reviews mean accumulated entitlement drift goes undetected, so accounts retain access after role changes or termination. The stem's two-quarter gap directly enables unauthorised access to be granted and to persist unchallenged, which is the most significant consequence.
- ✗
System performance may degrade
Why it's wrong here
Missed access reviews leave stale entitlements in place, so the real exposure is unauthorised or excessive access persisting undetected; performance degradation has no causal link to review completion. The option is tempting because periodic reviews do consume directory and reporting resources, so they would be the right concern when sizing Microsoft Entra ID access-review workloads or scheduling them against peak authentication traffic.
- ✗
Audit findings may be reported to management
Why it's wrong here
Reporting findings to management is the audit process working as intended, not a risk arising from missed reviews. Findings escalation is the correct outcome when control gaps are identified; the substantive exposure is the unreviewed access itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.