CISA Protection of Information Assets Practice Question
An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?
⚠ Common exam trap
Many exam-takers confuse recertification's primary purpose (validating appropriateness of access) with its incidental benefits (finding inactive accounts), causing candidates to select the tempting but secondary answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To verify that users' access rights remain appropriate for their roles
The primary purpose of user access recertification is to verify that each user's access rights remain appropriate for their current role and responsibilities (B). It is a detective governance control that catches privilege creep, role changes, and orphaned entitlements that accumulate over time. While recertification can surface inactive accounts, that is a byproduct rather than the primary objective; the core intent is validating the ongoing business need for access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To identify inactive user accounts
Why it's wrong here
Recertification's primary purpose is confirming that each user's current entitlements remain justified for their present role, not merely flagging dormant accounts. Inactive-account detection is a by-product, handled by separate dormancy reviews. It tempts because dormant accounts often surface during recertification, but that is not the control's objective.
- ✓
To verify that users' access rights remain appropriate for their roles
Why this is correct
Recertification forces managers to periodically revalidate each user's entitlements against current job duties, catching privilege creep and stale accounts created by transfers or role changes. This directly satisfies the control objective of confirming access remains appropriate for users' roles.
- ✗
To ensure compliance with password policies
Why it's wrong here
Recertification validates entitlement appropriateness against job duties; password policy compliance is enforced through authentication configuration and technical controls, not access reviews. It tempts because both sit within identity governance, but recertification examines who holds which permissions, not credential strength or rotation settings.
- ✗
To enforce segregation of duties
Why it's wrong here
Segregation of duties is enforced through role design and conflict rules at provisioning; recertification confirms existing access remains appropriate, and may detect SoD conflicts incidentally. It tempts because reviewers can spot toxic combinations, but the control's primary purpose is entitlement attestation, not preventive SoD enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.