CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?
⚠ Common exam trap
CISA often tests whether candidates can distinguish the direct technical risk (excessive privileges leading to unauthorized access) from secondary or related risks (compliance, detection, social engineering) when asked for the MOST significant risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized access to sensitive data due to excessive privileges
The most significant risk is unauthorized access to sensitive data due to excessive privileges, because the absence of manager confirmation means access rights may persist after role changes or terminations, accumulating unnecessary entitlements. Annual reviews by the application owner alone, without manager validation, fail to verify that each user still requires access for their current duties. This directly enables the accumulation of excessive privileges, which is the primary threat to data confidentiality in a financial application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unauthorized access to sensitive data due to excessive privileges
Why this is correct
Annual owner reviews without manager confirmation mean access is never validated against current job need, so transferred or terminated staff retain entitlements. Accumulated excessive privileges let users reach sensitive financial data beyond their remit, the specific risk the undocumented confirmation step leaves unmitigated.
- ✗
Increased likelihood of successful social engineering attacks
Why it's wrong here
Undocumented manager confirmation leaves stale or excessive entitlements in place, so the primary risk is unauthorised access through accumulated privileges, not deception of users. Social engineering targets human trust to obtain credentials. Manager recertification would be the correct control where reviewers must attest to continued access need.
- ✗
Non-compliance with regulatory requirements for access controls
Why it's wrong here
The finding is a documentation gap in the recertification process; it does not by itself evidence a breach of any specific regulation. The concrete risk is that access rights persist unverified, enabling unauthorised transactions. Regulatory non-compliance would be correct if the stem cited a mandated access-review requirement.
- ✗
Inability to detect insider threats in a timely manner
Why it's wrong here
Annual reviews without manager attestation leave stale entitlements in place, so misuse by a legitimate account holder persists undetected between cycles; insider activity is not the axis here, since the gap is ownership confirmation, not behavioural monitoring. Manager recertification would be the right control where segregation-of-duties attestation is the requirement.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.