
Certified Information Systems Auditor
Domain 5Objective 3
Identity and Access Management CISA Practice Questions (Page 4)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
23questions here
5free pages
8concepts
26%of the exam
Questions 16–20
- 16
A government agency handles classified documents. The agency requires that access to documents be determined by the document's classification level (e.g., Confidential, Secret, Top Secret) and the user's security clearance. Which access control model is most appropriate?
Select an answer first - 17
A financial services firm is implementing a new document management system. The compliance officer requires that access to customer records be granted based on the employee's role (e.g., 'Loan Officer', 'Compliance Auditor') and that no employee can both approve a loan and disburse funds. Which access control model best satisfies these requirements?
Select an answer first - 18
A multinational company has a policy that employee access to internal systems must be revoked within 24 hours of termination. The HR system updates the employee status in real time, but the IT team manually processes terminations during business hours. An auditor finds that a terminated employee's access remained active for three days. Which control would MOST effectively ensure timely revocation?
Select an answer first - 19
What is the primary purpose of segregation of duties (SoD) in IAM governance?
Select an answer first - 20
A mid-sized company has been managing user access rights locally within each application (e.g., HR system, finance system, file shares). An audit reveals inconsistent access rights and orphaned accounts. The company wants to improve consistency and reduce administrative overhead. Which approach should the company adopt?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.