Identity and Access Management (IAM)Easy

CISSP Practice Question: In a growing fintech company, what would MOST likely happen if user…

Published September 18, 2026 · Free daily CISSP practice question
In a growing fintech company, what would MOST likely happen if user access is not reviewed regularly?
  1. A.Increased productivity due to quicker access
  2. B.Reduced operational costs
  3. C.Higher risk of unauthorized access
  4. D.Improved compliance posture
Correct answer: C. Higher risk of unauthorized access

Correct Answer: C. Higher risk of unauthorized access

Explanation (CISSP Manager Logic):

Neglecting regular access reviews leads to privilege creep and the accumulation of "ghost accounts" for terminated employees. This failure expands the organization's attack surface and increases the likelihood of a breach by allowing users to retain permissions that no longer align with their current business roles.

By performing regular access reviews, you:

  • Enforce the principle of least privilege across the enterprise.
  • Mitigate insider threats and the risk of unauthorized data exfiltration.
  • Maintain an accurate audit trail for accountability and regulatory requirements.

While the other options are relevant, they fall short because:

  • A: Prioritizing speed over security controls creates unacceptable residual risk for the business.
  • B: Minor administrative savings are negligible compared to the catastrophic costs of a data breach.
  • D: Compliance posture actually degrades as most frameworks mandate periodic access certification.

Think like a manager:

Access control is a dynamic lifecycle process that requires continuous oversight. Managers must ensure security controls evolve alongside organizational changes to maintain an acceptable level of risk.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions Next question →