Identity and Access Management (IAM)Medium

CISSP Practice Question: What would MOST likely happen if a company fails to enforce a…

Published July 24, 2026 · Free daily CISSP practice question
What would MOST likely happen if a company fails to enforce a comprehensive access policy across its cloud resources?
  1. A.Increased security breaches
  2. B.Higher employee productivity
  3. C.Lower operational costs
  4. D.Improved compliance
Correct answer: A. Increased security breaches

Correct Answer: A. Increased security breaches

Explanation (CISSP Manager Logic):

Failing to enforce a comprehensive access policy creates visibility gaps and unmanaged entry points across cloud infrastructure. Without centralized governance, unauthorized users can exploit over-privileged accounts, leading to data exfiltration and loss of organizational control.

By [enforcing a comprehensive access policy], you:

  • Reduce the attack surface by applying the principle of least privilege.
  • Ensure consistent identity governance across hybrid and multi-cloud environments.
  • Mitigate the risk of insider threats and external credential theft.

While the other options are relevant, they fall short because:

  • B: Unmanaged access leads to configuration drift and operational chaos rather than sustainable productivity.
  • C: Negligence results in massive financial liabilities from breach response, legal fees, and regulatory fines.
  • D: Compliance frameworks require documented and enforced controls; a lack of policy ensures audit failure.

Think like a manager:

Security is a business enabler that requires consistent policy enforcement to protect corporate assets. Effective governance ensures that access aligns with business needs while minimizing operational risk.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions