CISA Protection of Information Assets Practice Question
An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?
⚠ Common exam trap
CISA often tests the distinction between preventive, detective, and corrective controls; candidates frequently choose a strong preventive control like RBAC or password policy when the question specifically asks for detection of unauthorized access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit logging of access attempts
Audit logging of access attempts is the most important control to detect unauthorized access because it creates a chronological record of who attempted to access what, when, and whether the attempt succeeded or failed. Detection requires evidence of events, and only logging provides that evidence after the fact. Strong passwords, recertification, and RBAC are preventive or administrative controls that reduce the likelihood of unauthorized access but do not detect it when it occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Strong password policy
Why it's wrong here
A strong password policy prevents weak credentials but does not detect unauthorised access after authentication succeeds. It is tempting because password controls are foundational logical access safeguards, yet detection requires logging and monitoring of actual access events. The question asks for detection, not prevention, so password policy addresses the wrong control objective.
- ✓
Audit logging of access attempts
Why this is correct
Audit logging records every authentication and authorisation event, including failed attempts, giving the auditor an independent trail to detect unauthorised access after the fact. This directly satisfies the stem's requirement for a detective control, unlike preventive measures such as passwords or Microsoft Entra ID conditional access, which block access but cannot reveal that an intrusion occurred.
- ✗
Monthly access recertification
Why it's wrong here
Monthly access recertification reviews whether existing entitlements remain appropriate; it cannot detect unauthorised access occurring between reviews. It is tempting because recertification is a key access governance control, but detection requires real-time logging and monitoring of access events. Recertification is periodic attestation, not continuous detection of unauthorised activity.
- ✗
Role-based access control (RBAC)
Why it's wrong here
RBAC restricts access based on roles, which prevents unauthorised access but does not detect it once it occurs. It is tempting because RBAC is a core logical access control for critical applications, but detection demands audit trails and monitoring. The stem asks for the control that detects unauthorised access, which RBAC does not provide.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.