mediumMultiple ChoiceObjective-mapped
CISA Practice Question: After a security incident, an organization…
After a security incident, an organization discovers that an employee accessed sensitive files without authorization. Which of the following is the most effective preventive control to reduce the risk of such unauthorized access?
⚠ Common exam trap
Many exam-takers confuse preventive controls with detective or deterrent controls, selecting DLP (a detective/corrective control) or strong passwords (an authentication control) instead of recognizing that access recertification directly prevents unauthorized access by removing excessive permissions before they can be exploited.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting regular access reviews and recertification.
Regular access reviews and recertification (Option C) are the most effective preventive control because they ensure that user permissions are periodically validated against current job roles and business needs. By systematically revoking excessive or outdated entitlements, this process directly reduces the attack surface for unauthorized access, addressing the root cause of privilege creep rather than merely detecting or deterring misuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying a data loss prevention (DLP) solution.
Why it's wrong here
DLP monitors and prevents data exfiltration but is a detective/deterrent control, not a preventive control for access.
- ✗
Implementing background checks on all employees.
Why it's wrong here
Background checks are pre-employment controls but do not prevent authorized users from exceeding their access rights.
- ✓
Conducting regular access reviews and recertification.
Why this is correct
Access reviews help identify and revoke unnecessary permissions, directly reducing the risk of unauthorized access.
- ✗
Enforcing strong password policies.
Why it's wrong here
Strong passwords help prevent credential theft but do not control what an authorized user can access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.