Courseiva

CISA Protection of Information Assets Practice Question

During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?

⚠ Common exam trap

CISA often tests the distinction between operational inconveniences (password complexity, provisioning overhead) and fundamental control failures (lack of accountability, unreliable audit trails); candidates may pick the more visible but less severe operational risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lack of individual accountability for actions performed

Option B is correct because shared accounts eliminate the one-to-one mapping between a user identity and an account, so when multiple administrators use the same credentials there is no way to attribute a specific action to a specific individual, destroying individual accountability. Option D is correct because the audit logs generated under a shared account record only the account name, not the actual person, so the resulting audit trail cannot reliably support forensic investigations or non-repudiation. Options A and C are operational inconveniences rather than the most significant risks, and option E describes a possible consequence of poor password hygiene rather than the core accountability and forensic integrity risks that an IS auditor would emphasize.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increased complexity in password management

    Why it's wrong here

    Password management complexity is an operational inconvenience, not a control failure. It tempts because shared credentials genuinely complicate rotation and distribution, but the significant risks are loss of individual accountability and non-repudiation, since activity cannot be traced to a specific administrator during incident response.

  • ✓

    Lack of individual accountability for actions performed

    Why this is correct

    Shared credentials remove the unique user identifier that links an action to a person, so no one can be held answerable for privileged changes. This directly undermines the accountability principle the audit is testing, since attribution becomes impossible when several administrators use one login.

  • ✗

    Increased overhead for account provisioning

    Why it's wrong here

    Provisioning overhead is an administrative cost, not a security risk arising from lost accountability. It tempts because shared accounts do reduce the number of credentials to manage, but the significant risks are non-repudiation loss and inability to attribute actions to an individual during incident response.

  • ✓

    Audit trails may not be reliable for forensic investigations

    Why this is correct

    Because every administrator authenticates as the same identity, logs record only the shared account, not the individual. Forensic reconstruction of who performed which action during an incident therefore becomes unreliable, defeating the evidential integrity the audit trail must provide.

  • ✗

    Higher likelihood of password sharing outside the authorized group

    Why it's wrong here

    While possible, the main risk is lack of accountability.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.