CISSP Identity and Access Management Practice Question
A multinational bank must enforce least privilege across 4,000 roles that change frequently as employees move between trading, compliance, and IT functions. Auditors found that access reviews are performed manually and that role definitions drift from actual job duties. The identity team proposes a role mining and management program. Which approach best aligns with identity and access management governance objectives while reducing role explosion?
⚠ Common exam trap
The trap here is treating role mining as purely technical and skipping governance approval, or assuming that eliminating roles removes the need for access reviews.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform bottom-up role mining to derive candidate roles from existing entitlement data, then normalize and approve them through a role governance board.
Bottom-up role mining derives roles from observed entitlement patterns, which exposes drift between documented and actual access and produces a smaller, business-relevant role set. Normalizing and approving candidates through a governance board keeps roles controlled and auditable, reducing role explosion while supporting least privilege and repeatable access reviews across the bank's diverse functions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a unique role for every employee based on their current entitlements and assign it during onboarding.
Why it's wrong here
Creating a role per employee produces thousands of near-duplicate roles and defeats the purpose of role-based access control. It worsens role explosion, makes access reviews harder, and does not establish a governance model that maps job functions to a controlled set of entitlements, so it fails the stated objective.
- ✗
Eliminate all roles and assign entitlements directly to each user through workflow-based access requests.
Why it's wrong here
Removing roles and assigning entitlements individually increases administrative overhead and makes it far harder to enforce least privilege consistently. Auditors would see unstructured, user-specific access with no role baseline, which typically produces more excessive permissions rather than fewer, so this approach contradicts the governance objective.
- ✓
Perform bottom-up role mining to derive candidate roles from existing entitlement data, then normalize and approve them through a role governance board.
Why this is correct
Bottom-up role mining analyzes actual entitlement assignments to identify common access patterns and proposes candidate roles, which are then refined and approved by business owners. This reduces role sprawl, aligns roles with real job functions, and creates a governed, reviewable role catalog, directly addressing the drift and manual review problems.
- ✗
Adopt a top-down role engineering approach that defines roles solely from the organizational chart and job descriptions.
Why it's wrong here
Top-down role engineering based only on org charts and job descriptions often misses the granular entitlements people actually need, leading to either over-privileged roles or constant exception requests. It does not leverage existing entitlement data to detect drift, so it is weaker than mining actual assignments for this scenario.
Go deeper
Related to this question
Learn chapter
Legal, Regulatory, and Compliance Issues
Key term
Identity and access management
Identity and access management (IAM) is the security discipline that ensures the right individuals access the right resources at the right times for the right reasons.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.