Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?

⚠ Common exam trap

CISA often tests the difference between a control's existence and its effectiveness; candidates pick operational issues (missed deadlines) over the substantive failure (blind approval) because the former sounds more concrete.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managers approve all access requests without verifying job requirements

Managers approving all access requests without verifying job requirements is the most concerning finding because it defeats the purpose of recertification: access is rubber-stamped rather than validated against least privilege. This creates a systemic risk of privilege creep and unauthorized access that no amount of process formality can offset. The other findings are either positive or minor operational issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The recertification report includes all users with active accounts

    Why it's wrong here

    Including all active users in the recertification report is completeness, which strengthens the review rather than weakening it. The auditor's concern is reviewers approving access without scrutiny, or privileged accounts being excluded. Full population coverage supports effective recertification.

  • ✗

    Reviews are performed quarterly instead of annually

    Why it's wrong here

    Quarterly reviews exceed the annual minimum, so frequency itself does not weaken recertification; the concern lies in whether reviewers actually validate each entitlement. Annual cycles suit low-risk, static environments where change volume is minimal, making quarterly cadence unnecessary overhead rather than a control failure.

  • ✗

    Some users did not respond to the recertification request within the deadline

    Why it's wrong here

    Non-responses are handled by escalation and default revocation, so they do not by themselves indicate ineffective reviews. It is tempting because missed deadlines look like process failure, but the real concern is reviewers approving access without evidence of verification.

  • ✓

    Managers approve all access requests without verifying job requirements

    Why this is correct

    Managers rubber-stamping approvals defeats the review's purpose: recertification exists to confirm each user's access still matches current job requirements. Without that verification, excessive or stale entitlements persist, violating least privilege and undermining the control's effectiveness. This directly addresses the stem's concern about review effectiveness, unlike process timing or documentation issues.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.