Courseiva
mediumMultiple ChoiceObjective-mapped

CISA Uses role-based access control (RBAC) Practice Question

An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?

⚠ Common exam trap

Candidates often think a grace period or logging is acceptable, but CISA emphasizes immediate revocation to maintain least privilege and prevent unauthorized access during role transitions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Immediately revoke all previous access and assign new role permissions.

RBAC mandates that access rights are strictly tied to job functions. When an employee changes departments, their previous role permissions are no longer applicable and must be immediately revoked to prevent unauthorized access, while new role permissions are granted to align with their new responsibilities. This follows the principle of least privilege and ensures that access rights are always current with the employee's role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remove access to the previous department's resources after a grace period.

    Why it's wrong here

    A grace period leaves a window of excessive privilege and security risk.

  • Keep all access but log usage.

    Why it's wrong here

    Logging does not prevent unauthorized access; privileges should be restricted.

  • Immediately revoke all previous access and assign new role permissions.

    Why this is correct

    Correct. This follows least privilege and prevents unauthorized access during transition.

  • Keep previous access and grant new role permissions.

    Why it's wrong here

    This would result in excessive privileges, violating least privilege.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.