Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: A medium-sized financial services company…

A medium-sized financial services company recently deployed a new identity governance and administration (IGA) solution to manage user access across on-premises Active Directory and cloud-based SaaS applications. The IGA system uses a role-based access control (RBAC) model with hundreds of roles defined. The company has a policy that all access certifications must be completed quarterly. During the first quarterly certification, the access reviewers complain that they are overwhelmed by the number of entitlements they need to review, and many certifications are not completed on time. The security team also notices that some users have accumulated excessive privileges because role assignments were not properly reviewed. The company wants to streamline the certification process without sacrificing security. Which of the following is the BEST course of action?

⚠ Common exam trap

Many exam-takers choose option D (automate all certifications) because it seems efficient, but they overlook the critical requirement for human oversight in high-risk access decisions, which is a core principle of identity governance and audit compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a risk-based certification approach that focuses on high-risk access and uses automated certification for low-risk access

A risk-based certification approach prioritizes high-risk entitlements for manual review while automating the certification of low-risk access, reducing reviewer fatigue and ensuring critical privileges are scrutinized. This aligns with the principle of 'defense in depth' and addresses the core issue of overwhelming certification volume without compromising security, as low-risk access can be certified based on predefined policies and automated workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase the certification frequency to monthly and assign more reviewers

    Why it's wrong here

    Increasing certification frequency to monthly and assigning more reviewers directly exacerbates the problem of entitlement overload rather than solving it. This approach multiplies the operational burden by requiring more frequent reviews of an already unmanageable volume of entitlements, leading to reviewer fatigue and potential rubber-stamping without genuine scrutiny. It fails to address the root cause of excessive or inappropriate access, making it an unsustainable and ineffective strategy for improving security posture or compliance.

  • Eliminate role-based access and assign permissions directly to users

    Why it's wrong here

    Eliminating role-based access control (RBAC) and assigning permissions directly to individual users would catastrophically worsen entitlement management. This 'many-to-many' mapping creates an exponential increase in the number of unique entitlements to review, making the certification process far more complex, error-prone, and time-consuming for reviewers. It destroys the efficiency and clarity that RBAC provides for managing access at scale, leading to an unmanageable audit burden and significantly increased security risks.

  • Implement a risk-based certification approach that focuses on high-risk access and uses automated certification for low-risk access

    Why this is correct

    Implementing a risk-based certification approach is the most effective strategy for managing extensive entitlement reviews by intelligently prioritizing human effort. High-risk access, such as privileged accounts or access to sensitive data, receives thorough manual scrutiny, ensuring critical security controls are meticulously maintained. Conversely, low-risk, routine access can be efficiently certified through automated processes, significantly reducing reviewer fatigue and operational costs while still meeting compliance requirements for regular access reviews and maintaining overall security.

  • Automate all certifications by using scripts that approve access if no violations are detected

    Why it's wrong here

    Automating *all* certifications without any human oversight, even with violation detection, carries significant risks and typically fails to meet stringent audit and compliance standards for access reviews. Scripts might miss subtle context-dependent risks, emergent threats, or business policy violations that only human judgment can reliably identify. Completely removing human accountability from the certification process can lead to a false sense of security, potentially allowing inappropriate or excessive access to persist undetected and increasing the organization's attack surface.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.