mediumMultiple Select
CISA Practice Question: Which TWO of the following are effective controls…
Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)
⚠ Common exam trap
CISA often tests the distinction between fraud-specific controls (SoD, mandatory vacation, job rotation) and general security controls (passwords, SSO, background checks), tempting candidates to select broad security measures that do not directly address fraud concealment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mandatory vacation policies
Mandatory vacation policies (A) are an effective anti-fraud control because they force another employee to perform the fraudster's duties, exposing schemes such as lapping, ghost vendors, or concealed transactions that depend on continuous, unmonitored access. Separation of duties (B) is effective because it splits critical functions (e.g., authorization, custody of assets, and record-keeping) among different people, so no single individual can both perpetrate and conceal a fraudulent act. Background checks (C) are a preventive screening measure for hiring, not an ongoing control that detects or blocks fraud once an employee is in place. Password complexity requirements (D) are an authentication control that reduces the risk of credential compromise, but they do not address the internal trust and collusion risks that enable fraud. Single sign-on (E) is a convenience and access-management mechanism that can even concentrate risk, and it does not by itself prevent fraudulent activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mandatory vacation policies
Why this is correct
Mandatory vacation policies force employees to step away from their duties, enabling colleagues to review transactions and uncover irregularities that continuous access would conceal. This directly satisfies the fraud-prevention constraint by removing the perpetrator's ability to sustain concealment, since most IT fraud schemes require ongoing manipulation of records to avoid detection.
- ✓
Separation of duties
Why this is correct
Separation of duties prevents fraud by ensuring no single individual controls an entire transaction lifecycle, splitting authorisation, custody and recording functions across different people. This directly satisfies the stem's fraud-prevention constraint, since collusion becomes necessary to conceal a fraudulent act, raising both the effort and detection risk.
- ✗
Background checks on new hires
Why it's wrong here
Background checks screen candidates before employment, addressing insider risk at onboarding, but they neither separate incompatible duties nor detect fraudulent transactions after hire. They are a legitimate personnel security control, yet fraud prevention in IT instead demands segregation of duties and independent review of privileged activity.
- ✗
Password complexity requirements
Why it's wrong here
Password complexity hardens authentication against guessing and credential theft, but it does not segregate duties or enforce transaction authorisation, so a single privileged user can still commit and conceal fraud. It is genuinely valuable for access security, yet fraud prevention instead requires dual control and independent reconciliation over financial or system transactions.
- ✗
Single sign-on (SSO) systems
Why it's wrong here
Single sign-on centralises authentication and simplifies access, but it consolidates credentials rather than separating incompatible duties, so one compromised identity can approve and execute a fraudulent transaction. It is genuinely an access-management convenience, yet fraud prevention instead requires segregation of duties and independent transaction authorisation.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.