hardMultiple Select
CISA Practice Question: Which TWO are primary objectives of an identity…
Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)
⚠ Common exam trap
Many candidates confuse IAM with general security controls like encryption or network monitoring, but IAM strictly deals with identity lifecycle, authentication, authorization, and access governance, not data protection or network-level defenses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensuring appropriate access to resources.
Option A, ensuring appropriate access to resources, is a core IAM objective because IAM governs who (identity) can access which resources (applications, data, systems) and under what conditions, typically through authentication, authorization, and provisioning/deprovisioning processes. Option B, enforcing the least privilege principle, is also a primary IAM objective since IAM implements least privilege by granting users only the minimum rights needed for their roles, often via role-based access control (RBAC), access reviews, and just-in-time elevation. The other options do not belong: C (encrypting data at rest and in transit) is a data protection/cryptography control, D (patching software vulnerabilities) is vulnerability and patch management, and E (monitoring network traffic for anomalies) is network security monitoring/IDS/IPS, none of which are primary IAM objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensuring appropriate access to resources.
Why this is correct
IAM's core purpose is granting the right users access to the right resources at the right times, supporting business operations securely. This provisioning objective is distinct from authentication, which merely verifies identity before access decisions are enforced.
- ✓
Enforcing least privilege principle.
Why this is correct
Least privilege restricts each identity to only the access needed for its role, limiting blast radius from compromised accounts or insider misuse. This authorisation principle is a primary IAM objective, enforced through role design and periodic access reviews.
- ✗
Encrypting data at rest and in transit.
Why it's wrong here
Encryption protects data confidentiality at rest and in transit; it neither establishes identity nor governs entitlements, which are IAM's objectives. Encryption is the correct control for a data protection programme, but it does not authenticate subjects or enforce access decisions.
- ✗
Patching software vulnerabilities.
Why it's wrong here
Vulnerability patching remediates software flaws; it neither verifies identity nor controls resource access, so it is not an IAM objective. Patching is correct within vulnerability and configuration management programmes, where reducing exploitable weaknesses is the aim.
- ✗
Monitoring network traffic for anomalies.
Why it's wrong here
Traffic anomaly monitoring detects threats on the network; it does not authenticate identities or administer entitlements, so it falls outside IAM's objectives. Such monitoring belongs to network security operations, where detecting intrusions and unusual flows is the goal.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.