Identity and Access Management (IAM)Medium

CISSP Practice Question: In a financial services firm with strict regulatory requirements, what would MOST…

Published October 4, 2026 · Free daily CISSP practice question
In a financial services firm with strict regulatory requirements, what would MOST likely happen if user provisioning processes are not regularly audited?
  1. A.Increased risk of insider threats
  2. B.Improved user satisfaction
  3. C.Reduced compliance costs
  4. D.Enhanced system performance
Correct answer: A. Increased risk of insider threats

Correct Answer: A. Increased risk of insider threats

Explanation (CISSP Manager Logic):

Failure to audit provisioning creates "privilege creep" and leaves orphaned accounts active, providing a playground for malicious insiders or compromised credentials. From a risk management perspective, lack of oversight breaks the principle of least privilege and obscures visibility into who has access to sensitive financial data.

By auditing user provisioning, you:

  • Ensure access remains aligned with current business roles.
  • Identify and revoke unauthorized or redundant permissions.
  • Maintain a defensible security posture for regulatory compliance.

While the other options are relevant, they fall short because:

  • B: Poorly managed access often leads to help desk bottlenecks and confusion, decreasing user satisfaction.
  • C: Neglecting audits increases the likelihood of massive regulatory fines and expensive remediation efforts.
  • D: Provisioning audits focus on security and compliance rather than technical system throughput or latency.

Think like a manager:

Trust but verify; without periodic formal reviews, your technical controls will inevitably drift from your security policy and legal obligations.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions