Courseiva

CISA Protection of Information Assets Practice Question

An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?

⚠ Common exam trap

CISA often tests the distinction between PAM's primary purpose (centralized privileged account management and monitoring) and secondary benefits (reducing shared accounts, enabling password resets), causing candidates to select a true-but-not-primary answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Centralized management and monitoring of privileged account usage

The primary benefit of a PAM solution is centralized management and monitoring of privileged account usage — it vaults credentials, controls who can check out which privileged accounts, records sessions, and provides audit trails. This addresses the core risk that privileged accounts (root, admin, service accounts) are the most sought-after targets for attackers and the hardest to oversee when scattered across systems. While PAM can support the other options to varying degrees, centralized management and monitoring is the defining, primary purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Elimination of shared accounts by providing individual credentials

    Why it's wrong here

    Individual credentials remove shared-account ambiguity, yet accountability alone does not constrain what a privileged user can do once authenticated. It is tempting because shared accounts are a classic audit finding, but PAM's primary benefit is controlling, recording and time-limiting privileged sessions.

  • ✗

    Enforcement of segregation of duties between IT and security teams

    Why it's wrong here

    Segregation of duties is an organisational control achieved through process design and role assignment, not something a PAM tool enforces as its primary outcome. It is tempting because PAM supports separation, but its core benefit is vaulting and brokering privileged credentials with session monitoring.

  • ✗

    Automated password resets for user accounts

    Why it's wrong here

    Automated resets address routine credential hygiene, not the standing privileged access that PAM exists to control. It is tempting because password rotation is a genuine PAM capability, but the primary benefit is vaulting, session brokering and just-in-time elevation of administrative accounts.

  • ✓

    Centralized management and monitoring of privileged account usage

    Why this is correct

    Centralised management and monitoring consolidates privileged accounts into a controlled vault, enabling credential checkout, session recording and anomaly detection. This directly addresses the core PAM objective of curbing unmonitored, standing administrative access across the estate.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.