CISA Protection of Information Assets Practice Question
An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?
⚠ Common exam trap
CISA often tests the distinction between PAM's primary purpose (centralized privileged account management and monitoring) and secondary benefits (reducing shared accounts, enabling password resets), causing candidates to select a true-but-not-primary answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Centralized management and monitoring of privileged account usage
The primary benefit of a PAM solution is centralized management and monitoring of privileged account usage — it vaults credentials, controls who can check out which privileged accounts, records sessions, and provides audit trails. This addresses the core risk that privileged accounts (root, admin, service accounts) are the most sought-after targets for attackers and the hardest to oversee when scattered across systems. While PAM can support the other options to varying degrees, centralized management and monitoring is the defining, primary purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Elimination of shared accounts by providing individual credentials
Why it's wrong here
Individual credentials remove shared-account ambiguity, yet accountability alone does not constrain what a privileged user can do once authenticated. It is tempting because shared accounts are a classic audit finding, but PAM's primary benefit is controlling, recording and time-limiting privileged sessions.
- ✗
Enforcement of segregation of duties between IT and security teams
Why it's wrong here
Segregation of duties is an organisational control achieved through process design and role assignment, not something a PAM tool enforces as its primary outcome. It is tempting because PAM supports separation, but its core benefit is vaulting and brokering privileged credentials with session monitoring.
- ✗
Automated password resets for user accounts
Why it's wrong here
Automated resets address routine credential hygiene, not the standing privileged access that PAM exists to control. It is tempting because password rotation is a genuine PAM capability, but the primary benefit is vaulting, session brokering and just-in-time elevation of administrative accounts.
- ✓
Centralized management and monitoring of privileged account usage
Why this is correct
Centralised management and monitoring consolidates privileged accounts into a controlled vault, enabling credential checkout, session recording and anomaly detection. This directly addresses the core PAM objective of curbing unmonitored, standing administrative access across the estate.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.