Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing a biometric access control system used to protect a data center. The system uses fingerprint recognition and is configured so that any single enrolled user who fails three consecutive attempts is locked out and must be re-enrolled by security staff. Which of the following is the MOST significant security concern with this configuration?

⚠ Common exam trap

The trap here is focusing on biometric accuracy metrics like false acceptance rate when the described lockout and manual re-enrollment process is the concrete availability and administration weakness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The lockout and re-enrollment process creates a denial-of-service and administrative burden risk.

The configuration described makes repeated lockouts easy to trigger and requires security staff to re-enroll affected users, which can deny access to legitimate personnel and create an administrative bottleneck. That operational and availability exposure is more significant than general biometric tuning questions such as false acceptance rate, skin variability, or the absence of a second factor, none of which are uniquely highlighted by the configuration as described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The system does not combine biometrics with a second authentication factor.

    Why it's wrong here

    Single-factor biometric authentication is weaker than multifactor authentication, and adding a second factor would strengthen the control. However, the scenario's specific configuration detail concerns lockout and re-enrollment, and that design choice creates a concrete availability and administration problem. The absence of a second factor is a general hardening opportunity rather than the most significant concern revealed by the described setup.

  • ✓

    The lockout and re-enrollment process creates a denial-of-service and administrative burden risk.

    Why this is correct

    Locking out any user after three failed attempts and requiring security staff to re-enroll means an attacker or a clumsy user can repeatedly trigger lockouts, denying access to legitimate staff and consuming administrative effort. The re-enrollment requirement also depends on staff availability, so the process itself becomes an availability and operational risk that outweighs the tuning concerns in this scenario.

  • ✗

    The false acceptance rate may be too high for a high-security environment.

    Why it's wrong here

    False acceptance rate is a genuine tuning parameter for biometric systems, and a high rate would be concerning. However, the described configuration does not reveal the acceptance threshold, so the auditor cannot conclude that this is the most significant issue. Other aspects of the configuration, particularly how lockout and re-enrollment are handled, present a clearer and more immediate control weakness.

  • ✗

    Fingerprint biometrics can be affected by changes in the user's skin condition.

    Why it's wrong here

    Skin condition, moisture, and minor injury can degrade fingerprint matching and cause false rejections, which is a well-known limitation of the technology. In this scenario, though, the described configuration compounds that limitation into a lockout and manual re-enrollment process, so the operational handling of failures is the more significant concern than the inherent variability of fingerprints.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.