Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?

⚠ Common exam trap

CISA often tests the difference between preventive and detective controls, and candidates may select periodic reviews or shared accounts as effective controls when they actually weaken accountability and do not prevent real-time misuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session recording and monitoring of privileged activities

Option A is correct because session recording and monitoring of privileged activities creates a tamper-evident audit trail and real-time oversight, which deters misuse and enables detection and accountability for every privileged action. Option B is correct because just-in-time (JIT) privileged access grants elevated rights only for a limited, approved window and revokes them automatically, drastically shrinking the standing attack surface and the opportunity for misuse. Option C is not the most effective preventive control because a quarterly review is a detective, after-the-fact activity that can leave misuse undetected for up to three months. Option D is wrong because generic administrative accounts shared by multiple users destroy individual accountability and make attribution of actions impossible. Option E is wrong because shared passwords for emergency access eliminate non-repudiation and cannot be traced to a specific individual, increasing the risk of undetected misuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Session recording and monitoring of privileged activities

    Why this is correct

    Session recording and monitoring create attributable, tamper-evident evidence of every privileged action, deterring misuse and enabling detection after the fact. This satisfies the stem's prevention-of-misuse constraint by removing the anonymity that privileged accounts otherwise grant, since administrators know their sessions are captured and reviewed.

  • ✓

    Implementation of just-in-time (JIT) privileged access

    Why this is correct

    Just-in-time access grants privileged rights only for a defined window and task, then revokes them automatically. This satisfies the stem's misuse-prevention constraint by eliminating standing privileges, drastically shrinking the window in which compromised or malicious accounts can act, and forcing each elevation to be requested, approved and logged.

  • ✗

    Quarterly review of privileged account access

    Why it's wrong here

    A quarterly review is detective and retrospective; it identifies excessive privilege after misuse has already occurred rather than preventing it. It tempts because periodic access recertification is a recognised control, and it would be appropriate as a compensating check where automated provisioning is unavailable.

  • ✗

    Assignment of generic administrative accounts to multiple users

    Why it's wrong here

    Generic administrative accounts shared by multiple users destroy individual accountability, so misuse cannot be attributed or prevented through authorisation. They tempt as a convenience for reducing licence counts or simplifying handovers, but unique named accounts with just-in-time elevation are required instead.

  • ✗

    Use of shared passwords for emergency access

    Why it's wrong here

    Shared emergency passwords remove attribution and cannot be revoked per individual, so any holder can misuse them undetected. They tempt as a break-glass fallback when normal authentication fails, yet a vaulted, checked-out credential with session recording and rotation satisfies that need.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.