Lack of Segregation of Duties in Privileged Account Approvals
Exhibit
Access Control Policy: - Users must be provisioned within 24 hours of request. - Access reviews are conducted quarterly. - Privileged accounts require manager approval. - Default deny for all new accounts. - Audit logs retained for 90 days.
Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?
Quick Answer
The correct answer is segregation of duties, as the finding that 20% of privileged accounts were approved by the same manager without secondary review directly violates this core control principle. Segregation of duties requires that no single individual has the authority to both request and approve a privileged account, ensuring checks and balances to prevent unauthorized access or abuse. On the CISM exam, this concept tests your understanding of preventive controls within identity and access management, often appearing in audit scenario questions where a lack of secondary review is the key deficiency. A common trap is confusing this with access review frequency or provisioning delays, but the core issue here is the absence of separation between the approval role and the requesting role. Remember the memory tip: “One person, one step—no approval, no trust.”
⚠ Common exam trap
The CISM exam often tests the distinction between a process control (like requiring a second approver) and a detective control (like access reviews or log retention), and candidates mistakenly choose access review frequency because they think 'review' solves the approval gap, but reviews happen after the fact and cannot prevent the initial improper approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Segregation of duties
The finding that 20% of privileged accounts were approved by the same manager without secondary review directly violates the principle of segregation of duties (SoD). In privileged access management (PAM), SoD requires that the approval of privileged account access be performed by a different individual than the requester or the manager who supervises the requester, to prevent a single point of failure and reduce the risk of unauthorized access or fraud. Without a secondary review, a single manager could approve accounts for themselves or their subordinates without independent oversight, undermining the control objective of preventing conflicts of interest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Segregation of duties
Why this is correct
One person approving without oversight is a segregation of duties deficiency.
- ✗
Access review frequency
Why it's wrong here
Quarterly reviews are stated; the issue is approval process.
- ✗
Provisioning delay
Why it's wrong here
The finding does not mention timing issues.
- ✗
Audit log retention
Why it's wrong here
Log retention is not relevant to the approval finding.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An information security manager reviews the suspicious activity log shown in the exhibit. The payroll file is supposed to be encrypted and only accessible internally. What is the MOST likely cause for the failed download?
hard- A.The user's encryption certificate has expired
- B.The file was not encrypted before being uploaded
- ✓ C.The user lacked permission to decrypt the file
- D.The external IP is blocked by the firewall
Why C: The status 'Encryption key not found' indicates that the user does not have the necessary decryption key, likely due to lack of permission. Option A is wrong because certificate expiry would show a different error. Option B is wrong because if the file were not encrypted, it would download successfully. Option D is wrong because if the external IP were blocked, the download would not initiate.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.