Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?

⚠ Common exam trap

The trap here is choosing a preventive control (disable emergency access, add MFA) when the scenario already accepts that emergency access must exist; CISA expects a compensating detective control (break-glass with post-event review) that balances availability and accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a break-glass procedure with post-event review

A break-glass procedure with post-event review directly addresses the lack of segregation between request and approval for emergency access by allowing immediate access while ensuring independent retrospective review. This compensates for the missing preventive segregation with a detective control that validates the emergency was legitimate. It preserves the ability to respond to incidents without waiting for standard approvals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a break-glass procedure with post-event review

    Why this is correct

    A break-glass procedure grants emergency access under predefined conditions with logging, then mandates post-event review to validate and revoke it. This restores the missing segregation between request and approval by introducing independent retrospective scrutiny, mitigating the risk created when the system owner alone both requests and approves.

  • ✗

    Require two-factor authentication for emergency access

    Why it's wrong here

    Two-factor authentication verifies the identity of the person requesting emergency access, but the same individual still both raises and approves the request, so the segregation-of-duties gap persists. It is tempting because MFA genuinely strengthens authentication for privileged accounts, and it would be the right control where the risk is credential compromise rather than unverified approval.

  • ✗

    Disable emergency access and require standard approval

    Why it's wrong here

    Disabling emergency access removes the compensating route for genuine outages, pushing staff to shared or bypass accounts and worsening the risk. It would be correct only where no break-glass access is required; here the gap is unverified approval, which independent review addresses.

  • ✗

    Log all emergency access activities without review

    Why it's wrong here

    Logging without review creates records nobody examines, so misuse of emergency access stays undetected and the missing approval separation remains. Logging with independent review would be correct where detective evidence, not preventive authorisation, is the control objective.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.