nerdexam
Isaca

CISA · Question #623

An IS auditor has identified that as users change departments or leave the company, their access is not adjusted. Which of the following would BEST help to address this situation?

The correct answer is B. Perform periodic access recertification. Periodic access recertification requires managers to regularly review and formally validate that each user's access rights are still appropriate for their current role. This directly addresses the problem of stale or excessive access accumulating over time as employees change…

Submitted by obi.ng· Apr 18, 2026Protection of Information Assets

Question

An IS auditor has identified that as users change departments or leave the company, their access is not adjusted. Which of the following would BEST help to address this situation?

Options

  • APublish user access management policies.
  • BPerform periodic access recertification.
  • CAssign user administration rights to line management.
  • DMandate periodic password changes.

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    83% (15)
  • D
    11% (2)

Explanation

Periodic access recertification requires managers to regularly review and formally validate that each user's access rights are still appropriate for their current role. This directly addresses the problem of stale or excessive access accumulating over time as employees change departments or leave. Publishing policies (A) creates awareness but does not enforce action. Delegating admin rights to line managers (C) may help but without a recertification process, access still may not be removed promptly. Password changes (D) address authentication strength, not authorization scope.

Topics

#Access Management#User Access Review#Identity and Access Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice