Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?

⚠ Common exam trap

Many exam-takers confuse recertification's primary purpose (validating appropriateness of access) with its incidental benefits (finding inactive accounts), causing candidates to select the tempting but secondary answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To verify that users' access rights remain appropriate for their roles

The primary purpose of user access recertification is to verify that each user's access rights remain appropriate for their current role and responsibilities (B). It is a detective governance control that catches privilege creep, role changes, and orphaned entitlements that accumulate over time. While recertification can surface inactive accounts, that is a byproduct rather than the primary objective; the core intent is validating the ongoing business need for access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To identify inactive user accounts

    Why it's wrong here

    Recertification's primary purpose is confirming that each user's current entitlements remain justified for their present role, not merely flagging dormant accounts. Inactive-account detection is a by-product, handled by separate dormancy reviews. It tempts because dormant accounts often surface during recertification, but that is not the control's objective.

  • ✓

    To verify that users' access rights remain appropriate for their roles

    Why this is correct

    Recertification forces managers to periodically revalidate each user's entitlements against current job duties, catching privilege creep and stale accounts created by transfers or role changes. This directly satisfies the control objective of confirming access remains appropriate for users' roles.

  • ✗

    To ensure compliance with password policies

    Why it's wrong here

    Recertification validates entitlement appropriateness against job duties; password policy compliance is enforced through authentication configuration and technical controls, not access reviews. It tempts because both sit within identity governance, but recertification examines who holds which permissions, not credential strength or rotation settings.

  • ✗

    To enforce segregation of duties

    Why it's wrong here

    Segregation of duties is enforced through role design and conflict rules at provisioning; recertification confirms existing access remains appropriate, and may detect SoD conflicts incidentally. It tempts because reviewers can spot toxic combinations, but the control's primary purpose is entitlement attestation, not preventive SoD enforcement.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.