
Certified Information Systems Auditor
Domain 5Objective 3
Identity and Access Management CISA Practice Questions (Page 2)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
23questions here
5free pages
8concepts
26%of the exam
Questions 6–10
- 6
A multinational corporation has subsidiaries in different countries. Each subsidiary has its own IT team that manages user access to local systems. The corporate security team wants to ensure consistent access control policies across all subsidiaries while respecting local regulatory requirements. Which approach balances these needs?
Select an answer first - 7
Why is monitoring and recording privileged access sessions important?
Select an answer first - 8
A large enterprise has a team of database administrators (DBAs) who need full administrative access to production databases. The security team is concerned about insider threats and wants to ensure that DBA actions are monitored and that the DBA cannot cover their tracks. The company uses a PAM solution that provides session recording and password vaulting. Which additional control is MOST effective in preventing a DBA from hiding malicious activity?
Select an answer first - 9
What is the primary purpose of Identity and Access Management (IAM) in an organization?
Select an answer first - 10
A company wants to allow employees to access multiple SaaS applications (e.g., Salesforce, Office 365, Workday) with a single corporate login. The company also wants to enforce multi-factor authentication (MFA) for all access to these applications. Which solution should the company implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.