mediumMultiple Choice
CISA Practice Question: An organization's IT security policy requires…
An organization's IT security policy requires background checks for all IT staff handling sensitive data. Which of the following is the PRIMARY reason for this requirement?
⚠ Common exam trap
CISA often tests the distinction between preventive controls and compliance drivers, and candidates select 'regulatory compliance' because it sounds authoritative — but the exam expects the risk-based PRIMARY reason, which is insider threat mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To reduce the risk of insider threats by verifying the trustworthiness of personnel
Background checks verify the integrity, identity, and criminal history of personnel before granting access to sensitive data, directly mitigating the risk that a trusted insider will misuse their privileges. Insider threats — whether malicious, negligent, or coerced — are among the hardest to detect because insiders already possess legitimate access. Pre-employment screening is a preventive control that reduces the likelihood of hiring individuals who pose an elevated trust risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To ensure employees have the necessary technical skills
Why it's wrong here
Background checks screen for criminal history, integrity and trustworthiness; they do not assess technical skills, which are verified through qualifications and interviews. It is tempting because screening staff who handle sensitive data is a personnel security control, which would be the primary reason if the policy aimed to confirm competency rather than trustworthiness.
- ✗
To reduce employee turnover
Why it's wrong here
Reducing turnover is a workforce-retention outcome, not a security control; background checks screen for prior criminal or fraudulent conduct before granting access to sensitive data. It tempts because vetting can improve trust and morale, but it would be the answer only if the stem asked how to lower attrition, not why policy mandates screening.
- ✓
To reduce the risk of insider threats by verifying the trustworthiness of personnel
Why this is correct
Background checks directly mitigate insider threat by screening personnel before granting access to sensitive data, satisfying the policy's requirement to verify trustworthiness. Unlike technical controls such as least privilege or monitoring, which limit or detect misuse after access is granted, pre-employment vetting addresses the human risk at the point of hiring, reducing the likelihood of malicious or negligent insiders.
- ✗
To comply with industry regulations
Why it's wrong here
While compliance may be a factor, the primary reason is risk mitigation through trust verification.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.