Courseiva
mediumMultiple Choice

CISA Uses role-based access control (RBAC) Practice Question

An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?

⚠ Common exam trap

Candidates often think a grace period or logging is acceptable, but CISA emphasizes immediate revocation to maintain least privilege and prevent unauthorized access during role transitions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately revoke all previous access and assign new role permissions.

RBAC mandates that access rights are strictly tied to job functions. When an employee changes departments, their previous role permissions are no longer applicable and must be immediately revoked to prevent unauthorized access, while new role permissions are granted to align with their new responsibilities. This follows the principle of least privilege and ensures that access rights are always current with the employee's role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove access to the previous department's resources after a grace period.

    Why it's wrong here

    Retaining previous-department access during a grace period leaves stale entitlements active, violating least privilege and segregation of duties after the role change. Access should be revoked immediately on transfer; a grace period is defensible only for temporary, formally approved handover duties.

  • ✗

    Keep all access but log usage.

    Why it's wrong here

    Keeping all prior access and merely logging usage leaves accumulated entitlements that violate least privilege and enable toxic combinations across departments. Logging supports monitoring but does not remediate. Access should be revoked on transfer, with only the new role's permissions granted.

  • ✓

    Immediately revoke all previous access and assign new role permissions.

    Why this is correct

    RBAC grants permissions through roles, so a transfer creates risk of accumulated privileges. Revoking all prior access and assigning only the new department's role permissions enforces least privilege and prevents the employee retaining unnecessary rights from the previous position.

  • ✗

    Keep previous access and grant new role permissions.

    Why it's wrong here

    Retaining previous access alongside new permissions violates least privilege and creates toxic combinations that auditors flag. It is tempting because the employee may still cover old duties during transition, but best practice is to remove the old role's rights and grant only the new role.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.