CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?
⚠ Common exam trap
CISA often tests the difference between a control's existence and its effectiveness; candidates pick operational issues (missed deadlines) over the substantive failure (blind approval) because the former sounds more concrete.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managers approve all access requests without verifying job requirements
Managers approving all access requests without verifying job requirements is the most concerning finding because it defeats the purpose of recertification: access is rubber-stamped rather than validated against least privilege. This creates a systemic risk of privilege creep and unauthorized access that no amount of process formality can offset. The other findings are either positive or minor operational issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The recertification report includes all users with active accounts
Why it's wrong here
Including all active users in the recertification report is completeness, which strengthens the review rather than weakening it. The auditor's concern is reviewers approving access without scrutiny, or privileged accounts being excluded. Full population coverage supports effective recertification.
- ✗
Reviews are performed quarterly instead of annually
Why it's wrong here
Quarterly reviews exceed the annual minimum, so frequency itself does not weaken recertification; the concern lies in whether reviewers actually validate each entitlement. Annual cycles suit low-risk, static environments where change volume is minimal, making quarterly cadence unnecessary overhead rather than a control failure.
- ✗
Some users did not respond to the recertification request within the deadline
Why it's wrong here
Non-responses are handled by escalation and default revocation, so they do not by themselves indicate ineffective reviews. It is tempting because missed deadlines look like process failure, but the real concern is reviewers approving access without evidence of verification.
- ✓
Managers approve all access requests without verifying job requirements
Why this is correct
Managers rubber-stamping approvals defeats the review's purpose: recertification exists to confirm each user's access still matches current job requirements. Without that verification, excessive or stale entitlements persist, violating least privilege and undermining the control's effectiveness. This directly addresses the stem's concern about review effectiveness, unlike process timing or documentation issues.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.