CISSP Practice Question: In a multinational corporation with limited IT budget, what would MOST likely…
Correct Answer: B. Higher risk of unauthorized access
Explanation (CISSP Manager Logic):
Failure to conduct regular access reviews leads to "privilege creep," where users retain permissions they no longer require for their current roles. From a business perspective, this creates a significant security debt that increases the likelihood of internal data breaches and non-compliance with regulatory mandates.
By implementing regular reviews, you:
- Enforce the principle of least privilege across the enterprise.
- Identify and revoke stale accounts belonging to terminated employees or contractors.
- Reduce the organization's attack surface and potential liability.
While the other options are relevant, they fall short because:
- A: Productivity is not improved by maintaining excessive or unauthorized permissions.
- C: While skipping reviews reduces short-term tasks, it creates massive long-term administrative and legal overhead during an incident.
- D: User satisfaction is driven by access availability, not the absence of security governance.
Think like a manager:
Security is a continuous lifecycle, not a one-time event. Managers must balance operational efficiency with rigorous oversight to ensure that access rights always align with current business needs.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial