CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the logical access controls of a legacy payroll application that authenticates users directly against its own internal user table rather than the corporate directory. Management states that this was a deliberate design choice by the vendor. Which of the following is the MOST significant audit concern with this arrangement?
⚠ Common exam trap
The trap here is treating a vendor design decision as automatically acceptable and focusing on support or usability rather than on the loss of centralized provisioning and de-provisioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password policy enforcement may be inconsistent with the corporate standard and orphaned accounts may persist.
A locally maintained user table sits outside the corporate directory, so provisioning, modification, and timely revocation depend on manual processes that frequently fail. The result is inconsistent password standards and accounts that survive termination or role change. Auditors should focus on whether identity lifecycle controls still cover the application, since that determines whether access remains authorized, least-privileged, and auditable over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Password policy enforcement may be inconsistent with the corporate standard and orphaned accounts may persist.
Why this is correct
When an application maintains its own credential store, corporate password complexity, lockout, rotation, and expiry settings are not automatically inherited, and accounts are not disabled when the employee leaves or transfers. The directory's joiner-mover-leaver process no longer governs access, so orphaned and excessive rights accumulate silently. This is the most material concern because it breaks centralized identity governance for a financially sensitive system.
- ✗
The application's database may not be able to support concurrent user sessions at peak payroll processing times.
Why it's wrong here
Session concurrency is a performance and capacity consideration, not an access control deficiency. The scenario describes where credentials are stored, not how many users connect or how the database scales. Even if concurrency were limited, that would affect availability rather than the completeness and revocation of user authorization, which is the control objective relevant to an access control review of a payroll system.
- ✗
Users may need to remember an additional password, which could increase help desk call volume.
Why it's wrong here
Usability friction and help desk cost are secondary operational effects, not the audit concern. Auditors should not let convenience arguments obscure a segregation and revocation weakness. Increased calls are a symptom that could be mitigated with single sign-on or federation, but the underlying issue remains that the application's user table is outside the control of the corporate identity lifecycle processes.
- ✗
Vendor support for the authentication module may lapse if the application is not upgraded to the current release.
Why it's wrong here
Patch and support lifecycle is a valid IT operations concern, but it is not the primary access control risk raised by a local credential store. The scenario does not indicate that the application is unsupported or out of warranty. Framing the finding as a support issue would distract from the actual control gap, which is the loss of centralized provisioning, de-provisioning, and password governance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.