Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?

⚠ Common exam trap

CISA often tests the distinction between authentication controls (biometrics, SSO) and authorization/governance controls (recertification, data-owner approval), luring candidates toward technically impressive but governance-irrelevant options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Quarterly recertification of access by managers

Option C is correct because quarterly recertification of access by managers ensures that users' privileges are periodically reviewed and revoked when no longer needed, directly supporting the principle of least privilege and preventing privilege creep in a sensitive financial application. Option E is correct because access requests approved by the data owner enforce proper authorization by the individual accountable for the data, ensuring that only legitimate business needs grant access to sensitive financial information. Biometric authentication (A) strengthens identity verification but does not by itself ensure that access rights are appropriate or authorized. Single sign-on (B) improves convenience and can centralize authentication, but it can also broaden exposure if not tightly controlled and does not validate the appropriateness of access. Automatic provisioning upon hire (D) speeds onboarding but risks granting excessive or unauthorized access without proper approval, making it a weaker control for ensuring appropriate access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use of biometric authentication

    Why it's wrong here

    Biometric authentication strengthens identity verification at login but does not govern which financial application entitlements a user receives or whether those are approved and reviewed. It is tempting because it is a strong authentication factor, and would be correct if the concern were credential sharing or password weakness rather than inappropriate access rights.

  • ✗

    Single sign-on for all applications

    Why it's wrong here

    Single sign-on centralises authentication but does not itself enforce least privilege or segregation of duties on the financial application; access requests still need owner approval and periodic review. It is tempting because it improves the login experience, and would be correct if the audit objective were reducing credential sprawl rather than ensuring appropriate access.

  • ✓

    Quarterly recertification of access by managers

    Why this is correct

    Quarterly recertification forces managers to confirm each user's continued business need for financial application access, catching privilege creep and stale entitlements between joiner-mover-leaver events. This directly satisfies the stem's requirement for controls ensuring access remains appropriate over time.

  • ✗

    Automatic provisioning upon employee hire

    Why it's wrong here

    Automatic provisioning grants access without validating role-based need, so it cannot enforce least privilege or segregation of duties for a sensitive financial application. It is tempting because automation suits high-volume, low-risk onboarding, where standardised birthright access genuinely reduces administrative effort.

  • ✓

    Access requests approved by the data owner

    Why this is correct

    Data owner approval ensures each access request is authorised by the party accountable for the financial information itself, not merely the system custodian. This satisfies the stem's need for appropriate access by tying grants to data classification and business need before provisioning occurs.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.