Courseiva
hardMultiple Select

CISA Practice Question: Which TWO are primary objectives of an identity…

Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)

⚠ Common exam trap

Many candidates confuse IAM with general security controls like encryption or network monitoring, but IAM strictly deals with identity lifecycle, authentication, authorization, and access governance, not data protection or network-level defenses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensuring appropriate access to resources.

Option A, ensuring appropriate access to resources, is a core IAM objective because IAM governs who (identity) can access which resources (applications, data, systems) and under what conditions, typically through authentication, authorization, and provisioning/deprovisioning processes. Option B, enforcing the least privilege principle, is also a primary IAM objective since IAM implements least privilege by granting users only the minimum rights needed for their roles, often via role-based access control (RBAC), access reviews, and just-in-time elevation. The other options do not belong: C (encrypting data at rest and in transit) is a data protection/cryptography control, D (patching software vulnerabilities) is vulnerability and patch management, and E (monitoring network traffic for anomalies) is network security monitoring/IDS/IPS, none of which are primary IAM objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensuring appropriate access to resources.

    Why this is correct

    IAM's core purpose is granting the right users access to the right resources at the right times, supporting business operations securely. This provisioning objective is distinct from authentication, which merely verifies identity before access decisions are enforced.

  • ✓

    Enforcing least privilege principle.

    Why this is correct

    Least privilege restricts each identity to only the access needed for its role, limiting blast radius from compromised accounts or insider misuse. This authorisation principle is a primary IAM objective, enforced through role design and periodic access reviews.

  • ✗

    Encrypting data at rest and in transit.

    Why it's wrong here

    Encryption protects data confidentiality at rest and in transit; it neither establishes identity nor governs entitlements, which are IAM's objectives. Encryption is the correct control for a data protection programme, but it does not authenticate subjects or enforce access decisions.

  • ✗

    Patching software vulnerabilities.

    Why it's wrong here

    Vulnerability patching remediates software flaws; it neither verifies identity nor controls resource access, so it is not an IAM objective. Patching is correct within vulnerability and configuration management programmes, where reducing exploitable weaknesses is the aim.

  • ✗

    Monitoring network traffic for anomalies.

    Why it's wrong here

    Traffic anomaly monitoring detects threats on the network; it does not authenticate identities or administer entitlements, so it falls outside IAM's objectives. Such monitoring belongs to network security operations, where detecting intrusions and unusual flows is the goal.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.