Courseiva
Information Security ProgramhardMultiple ChoiceObjective-mapped

Lack of Segregation of Duties in Privileged Account Approvals

Exhibit

Access Control Policy:
- Users must be provisioned within 24 hours of request.
- Access reviews are conducted quarterly.
- Privileged accounts require manager approval.
- Default deny for all new accounts.
- Audit logs retained for 90 days.

Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?

Quick Answer

The correct answer is segregation of duties, as the finding that 20% of privileged accounts were approved by the same manager without secondary review directly violates this core control principle. Segregation of duties requires that no single individual has the authority to both request and approve a privileged account, ensuring checks and balances to prevent unauthorized access or abuse. On the CISM exam, this concept tests your understanding of preventive controls within identity and access management, often appearing in audit scenario questions where a lack of secondary review is the key deficiency. A common trap is confusing this with access review frequency or provisioning delays, but the core issue here is the absence of separation between the approval role and the requesting role. Remember the memory tip: “One person, one step—no approval, no trust.”

⚠ Common exam trap

The CISM exam often tests the distinction between a process control (like requiring a second approver) and a detective control (like access reviews or log retention), and candidates mistakenly choose access review frequency because they think 'review' solves the approval gap, but reviews happen after the fact and cannot prevent the initial improper approval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Segregation of duties

The finding that 20% of privileged accounts were approved by the same manager without secondary review directly violates the principle of segregation of duties (SoD). In privileged access management (PAM), SoD requires that the approval of privileged account access be performed by a different individual than the requester or the manager who supervises the requester, to prevent a single point of failure and reduce the risk of unauthorized access or fraud. Without a secondary review, a single manager could approve accounts for themselves or their subordinates without independent oversight, undermining the control objective of preventing conflicts of interest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Segregation of duties

    Why this is correct

    One person approving without oversight is a segregation of duties deficiency.

  • Access review frequency

    Why it's wrong here

    Quarterly reviews are stated; the issue is approval process.

  • Provisioning delay

    Why it's wrong here

    The finding does not mention timing issues.

  • Audit log retention

    Why it's wrong here

    Log retention is not relevant to the approval finding.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An information security manager reviews the suspicious activity log shown in the exhibit. The payroll file is supposed to be encrypted and only accessible internally. What is the MOST likely cause for the failed download?

hard
  • A.The user's encryption certificate has expired
  • B.The file was not encrypted before being uploaded
  • C.The user lacked permission to decrypt the file
  • D.The external IP is blocked by the firewall

Why C: The status 'Encryption key not found' indicates that the user does not have the necessary decryption key, likely due to lack of permission. Option A is wrong because certificate expiry would show a different error. Option B is wrong because if the file were not encrypted, it would download successfully. Option D is wrong because if the external IP were blocked, the download would not initiate.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.