CISA Practice Question: Information Systems Operations and Business Resilience
An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?
⚠ Common exam trap
CISA often tests the distinction between primary and secondary benefits — candidates pick cost reduction (a common outcome) instead of compliance, which is the stated primary purpose of SAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensuring compliance with software licensing agreements
The primary benefit of a software asset management (SAM) program is ensuring compliance with software licensing agreements, which mitigates legal, financial, and reputational risk from unlicensed or over-deployed software. SAM provides visibility into what software is installed, where, and under what license terms, enabling accurate reconciliation of entitlements versus deployments. While SAM can yield cost savings, compliance is the primary driver because non-compliance carries legal penalties and audit exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensuring compliance with software licensing agreements
Why this is correct
SAM maintains an accurate inventory of installed software against entitlements, so licensing compliance is the primary benefit. It directly satisfies the stem's constraint by reconciling deployed licences with purchased rights, preventing legal exposure and unbudgeted true-up costs.
- ✗
Reducing hardware costs
Why it's wrong here
SAM reconciles software licences, entitlements and usage; hardware cost reduction is a separate outcome of asset lifecycle management. It is tempting because SAM data can inform hardware refresh decisions, but the primary benefit is mitigating licence compliance risk and eliminating unnecessary software spend.
- ✗
Automating patch management
Why it's wrong here
Patch automation remediates vulnerabilities; SAM instead reconciles deployed software against licences and entitlements to control cost and compliance risk. It is tempting because SAM inventories feed patch tooling, so the two are often deployed together, but automating patching answers a vulnerability-management requirement, not the stem's licensing and usage visibility objective.
- ✗
Improving network performance
Why it's wrong here
SAM tracks software entitlements, installations and usage; network throughput is unrelated to licence reconciliation. It is tempting because inventory tools may collect device data, but the primary benefit is controlling software licence compliance and cost, not optimising network performance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.