Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?

⚠ Common exam trap

CISA often tests whether candidates can distinguish risks directly caused by the described control gap (no approval, no SoD) from generic security risks (password policy, lockout) that are not implicated by the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

There is no audit trail of who granted access and why

Option A is correct because provisioning without a formal access request or approval process means there is no documented record of who authorized or granted each user's access, eliminating the audit trail needed to trace accountability for access decisions. Option B is correct because HR performing user provisioning without IT involvement removes the segregation of duties between the department that owns the employee data and the function that administers system access, allowing a single group to both request and grant privileges. Option D is correct because without a formal request and approval workflow, there is no validation against job roles, so users can be provisioned with rights exceeding their job requirements (excessive privileges). Options C and E are not among the most significant risks here because password policy enforcement and account lockout after failed logins are authentication controls configured within the system itself, and nothing in the scenario indicates these controls are absent or affected by the HR provisioning process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    There is no audit trail of who granted access and why

    Why this is correct

    Absent formal requests or approvals, no record exists linking an account to an authoriser or business justification. This defeats accountability and non-repudiation, leaving the auditor unable to reconstruct who granted access, when, or why — undermining investigation, disciplinary action and regulatory evidence.

  • ✓

    Segregation of duties between HR and IT is not maintained

    Why this is correct

    HR staff provisioning accounts in the HR system they also administer means one function both authorises and implements access. That collapses the segregation of duties control, enabling unauthorised or fraudulent access to sensitive employee data without independent IT review or detection.

  • ✗

    Password policies may not be enforced

    Why it's wrong here

    Password policy enforcement is a platform configuration control, not an outcome of HR-led provisioning. The missing approval process risks users receiving inappropriate entitlements or orphaned accounts, whereas password complexity and expiry are set in the system's authentication settings regardless of provisioning ownership.

  • ✓

    Users may be granted excessive privileges beyond their job requirements

    Why this is correct

    Without an approval process assessing job requirements, provisioning defaults to whatever HR requests, so accounts accumulate permissions exceeding actual duties. This violates least privilege, widening the attack surface and increasing the impact of any compromised HR account holding sensitive employee data.

  • ✗

    User accounts may not be locked after multiple failed login attempts

    Why it's wrong here

    Account lockout thresholds are configured within the application or identity platform's authentication settings, independent of who provisions users. The absence of approval workflow creates risks of excessive or unauthorised access rights, not failed-login lockout gaps, which would be the concern if authentication configuration were unmanaged.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.