mediumMultiple Choice
CISA Practice Question: After a security incident, an organization…
After a security incident, an organization discovers that an employee accessed sensitive files without authorization. Which of the following is the most effective preventive control to reduce the risk of such unauthorized access?
⚠ Common exam trap
Many exam-takers confuse preventive controls with detective or deterrent controls, selecting DLP (a detective/corrective control) or strong passwords (an authentication control) instead of recognizing that access recertification directly prevents unauthorized access by removing excessive permissions before they can be exploited.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting regular access reviews and recertification.
Regular access reviews and recertification (Option C) are the most effective preventive control because they ensure that user permissions are periodically validated against current job roles and business needs. By systematically revoking excessive or outdated entitlements, this process directly reduces the attack surface for unauthorized access, addressing the root cause of privilege creep rather than merely detecting or deterring misuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying a data loss prevention (DLP) solution.
Why it's wrong here
DLP detects and blocks data exfiltration or sharing, not the act of opening files an employee is not entitled to view. It is tempting because DLP protects sensitive data, but it would be the right control against leakage via email or USB. Preventing unauthorised access requires access controls enforcing least privilege.
- ✗
Implementing background checks on all employees.
Why it's wrong here
Background checks screen candidates before hiring and cannot revoke file permissions once someone is employed. It is tempting because vetting reduces insider risk generally, but it would be correct for roles involving financial or privileged trust. Preventing this access requires least-privilege authorisation applied to the sensitive files themselves.
- ✓
Conducting regular access reviews and recertification.
Why this is correct
Regular access reviews and recertification verify that each user's entitlements remain justified, revoking accumulated or stale permissions before misuse occurs. This addresses the root cause of unauthorised access, satisfying the requirement for a preventive control rather than a detective one.
- ✗
Enforcing strong password policies.
Why it's wrong here
Strong password policies protect against credential compromise, not against an authenticated employee opening files they were never granted rights to. It is tempting because authentication feels like access control, but it would be correct against brute-force or password-guessing attacks. Restricting file permissions by role addresses this insider access directly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.