CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?
⚠ Common exam trap
CISA often tests the difference between preventive and detective controls, and candidates may select periodic reviews or shared accounts as effective controls when they actually weaken accountability and do not prevent real-time misuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session recording and monitoring of privileged activities
Option A is correct because session recording and monitoring of privileged activities creates a tamper-evident audit trail and real-time oversight, which deters misuse and enables detection and accountability for every privileged action. Option B is correct because just-in-time (JIT) privileged access grants elevated rights only for a limited, approved window and revokes them automatically, drastically shrinking the standing attack surface and the opportunity for misuse. Option C is not the most effective preventive control because a quarterly review is a detective, after-the-fact activity that can leave misuse undetected for up to three months. Option D is wrong because generic administrative accounts shared by multiple users destroy individual accountability and make attribution of actions impossible. Option E is wrong because shared passwords for emergency access eliminate non-repudiation and cannot be traced to a specific individual, increasing the risk of undetected misuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Session recording and monitoring of privileged activities
Why this is correct
Session recording and monitoring create attributable, tamper-evident evidence of every privileged action, deterring misuse and enabling detection after the fact. This satisfies the stem's prevention-of-misuse constraint by removing the anonymity that privileged accounts otherwise grant, since administrators know their sessions are captured and reviewed.
- ✓
Implementation of just-in-time (JIT) privileged access
Why this is correct
Just-in-time access grants privileged rights only for a defined window and task, then revokes them automatically. This satisfies the stem's misuse-prevention constraint by eliminating standing privileges, drastically shrinking the window in which compromised or malicious accounts can act, and forcing each elevation to be requested, approved and logged.
- ✗
Quarterly review of privileged account access
Why it's wrong here
A quarterly review is detective and retrospective; it identifies excessive privilege after misuse has already occurred rather than preventing it. It tempts because periodic access recertification is a recognised control, and it would be appropriate as a compensating check where automated provisioning is unavailable.
- ✗
Assignment of generic administrative accounts to multiple users
Why it's wrong here
Generic administrative accounts shared by multiple users destroy individual accountability, so misuse cannot be attributed or prevented through authorisation. They tempt as a convenience for reducing licence counts or simplifying handovers, but unique named accounts with just-in-time elevation are required instead.
- ✗
Use of shared passwords for emergency access
Why it's wrong here
Shared emergency passwords remove attribution and cannot be revoked per individual, so any holder can misuse them undetected. They tempt as a break-glass fallback when normal authentication fails, yet a vaulted, checked-out credential with session recording and rotation satisfies that need.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.