CISM Information Security Programme Practice Question
An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?
⚠ Common exam trap
CISM often tests the distinction between IAM components and authentication mechanisms, causing candidates to select biometrics or SSO as key components when they are merely supporting technologies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC) aligned with job functions.
Option B is correct because RBAC maps permissions to job functions rather than individuals, which enforces least privilege and makes entitlements manageable and auditable as roles change. Option C is correct because periodic access reviews (recertification) of critical systems ensure stale or excessive entitlements are detected and revoked, a core governance control in any mature IAM program. Option E is correct because automated provisioning and de-provisioning via lifecycle workflows (often driven by an identity governance platform or SCIM) ensures users receive and lose access promptly, especially at joiner/mover/leaver events. Option A does not belong because biometrics is only one authentication factor and is not required for all users in a mature IAM program. Option D does not belong because SSO is a valuable convenience and security enhancement, but it is not mandatory for every cloud application and is not itself a defining component of IAM maturity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Biometric authentication for all users.
Why it's wrong here
Biometrics authenticate identity strongly but address only one factor; they do not provide authorisation, provisioning, or access recertification. It is tempting because phishing-resistant authentication is valuable, yet mandating it for every user ignores availability, privacy and fallback requirements that mature IAM programmes must balance.
- ✓
Role-based access control (RBAC) aligned with job functions.
Why this is correct
RBAC ties entitlements to job functions, enforcing least privilege through structured role definitions rather than ad hoc grants. This satisfies the maturity requirement by making access decisions repeatable, auditable and aligned with organisational responsibilities, reducing entitlement drift.
- ✓
Quarterly access reviews for critical systems.
Why this is correct
Periodic access reviews verify that entitlements remain justified, catching privilege creep and orphaned accounts on critical systems. This satisfies the maturity requirement by providing recurring governance evidence that access is validated, not merely granted once at onboarding.
- ✗
Single sign-on (SSO) for all cloud applications.
Why it's wrong here
SSO is a convenience and federation mechanism, not a governance component; it authenticates users across applications but does not itself deliver entitlement review, role lifecycle management or privileged access controls. It would be the right answer where the requirement is reducing credential sprawl across cloud SaaS.
- ✓
Automated provisioning and de-provisioning of user accounts.
Why this is correct
Automated provisioning and de-provisioning synchronise account lifecycle with HR events, eliminating manual delays that leave orphaned or excessive access. This satisfies the maturity requirement by enforcing timely, consistent entitlement changes across systems, reducing standing privilege and human error.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.