mediumMultiple ChoiceObjective-mapped
CISA Uses role-based access control (RBAC) Practice Question
An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?
⚠ Common exam trap
Candidates often think a grace period or logging is acceptable, but CISA emphasizes immediate revocation to maintain least privilege and prevent unauthorized access during role transitions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately revoke all previous access and assign new role permissions.
RBAC mandates that access rights are strictly tied to job functions. When an employee changes departments, their previous role permissions are no longer applicable and must be immediately revoked to prevent unauthorized access, while new role permissions are granted to align with their new responsibilities. This follows the principle of least privilege and ensures that access rights are always current with the employee's role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove access to the previous department's resources after a grace period.
Why it's wrong here
A grace period leaves a window of excessive privilege and security risk.
- ✗
Keep all access but log usage.
Why it's wrong here
Logging does not prevent unauthorized access; privileges should be restricted.
- ✓
Immediately revoke all previous access and assign new role permissions.
Why this is correct
Correct. This follows least privilege and prevents unauthorized access during transition.
- ✗
Keep previous access and grant new role permissions.
Why it's wrong here
This would result in excessive privileges, violating least privilege.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.