CISA Domain 5A-3 Practice Test 001

This practice test covers Domain 5 (Protection of Information Assets) Subdomain A-3 (Identity and Access Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 5A-3 Identity and Access Management Practice Test 001
10 questions • Single best answer
Question 1
A large retail bank completes its quarterly user access recertification, but the IS auditor finds that department managers approved all listed entitlements within minutes without any documented review of individual privileges. Several accounts retained access that is no longer required for the users' current roles. What should the IS auditor do FIRST?
    Question 2
    During an audit of a manufacturing company's identity and access management program, an IS auditor is assessing whether the access rights granted to newly hired employees align with the formally approved access requests. Which of the following provides the BEST evidence that access provisioning is properly authorized?
      Question 3
      During an audit of a hospital's identity and access management controls, an IS auditor compares the active directory account listing against human resources termination records covering the past twelve months. The organization's policy requires that accounts be disabled on an employee's final working day. Which of the following findings would be MOST significant?
        Question 4
        An IS auditor reviewing a cloud service provider's environment notes that several administrators use standing privileged accounts for both routine daily operations and sensitive administrative changes. These accounts remain active continuously, and privileged sessions are not currently recorded or reviewed. Which control would provide the BEST assurance that privileged access is used appropriately?
          Question 5
          During a review of an ERP system, an IS auditor finds that the same security administrator can create user accounts, assign entitlements, and approve the corresponding access requests. No compensating detective controls, such as independent monitoring of administrator activity, are in place. Which of the following should be the auditor's GREATEST concern?
            Question 6
            A financial services firm allows remote employees to access internal business applications over the public internet using only a username and password. Several of these applications process sensitive customer financial data, and no additional authentication factor is required. An IS auditor is evaluating the risk associated with this arrangement. Which recommendation is MOST appropriate?
              Question 7
              An IS auditor is evaluating the effectiveness of a government agency's periodic user access review across its critical applications. Testing shows all review campaigns were completed on the defined schedule. Which of the following would BEST indicate that the review control is operating effectively over the period?
                Question 8
                An IS auditor wants to determine whether dormant accounts on a critical application are being identified and disabled in accordance with the organization's policy. The policy requires accounts inactive for more than sixty days to be disabled. Which testing approach would provide the BEST assurance?
                  Question 9
                  During an audit of a large enterprise, an IS auditor finds that role definitions have accumulated excessive entitlements over time, granting many users more access than their current job functions require. This condition, known as privilege creep, has gone undetected for several review cycles. Which of the following is the auditor's BEST recommendation?
                    Question 10
                    An organization implements single sign-on across multiple critical business applications to streamline user authentication and reduce password fatigue. No compensating controls, such as multi-factor authentication, were added at the point of initial login. An IS auditor is assessing the security implications of this change. Which of the following represents the GREATEST risk introduced by this design?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top