Courseiva
mediumMultiple Select

CISA Practice Question: Which TWO of the following are effective controls…

Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)

⚠ Common exam trap

CISA often tests the distinction between fraud-specific controls (SoD, mandatory vacation, job rotation) and general security controls (passwords, SSO, background checks), tempting candidates to select broad security measures that do not directly address fraud concealment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory vacation policies

Mandatory vacation policies (A) are an effective anti-fraud control because they force another employee to perform the fraudster's duties, exposing schemes such as lapping, ghost vendors, or concealed transactions that depend on continuous, unmonitored access. Separation of duties (B) is effective because it splits critical functions (e.g., authorization, custody of assets, and record-keeping) among different people, so no single individual can both perpetrate and conceal a fraudulent act. Background checks (C) are a preventive screening measure for hiring, not an ongoing control that detects or blocks fraud once an employee is in place. Password complexity requirements (D) are an authentication control that reduces the risk of credential compromise, but they do not address the internal trust and collusion risks that enable fraud. Single sign-on (E) is a convenience and access-management mechanism that can even concentrate risk, and it does not by itself prevent fraudulent activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mandatory vacation policies

    Why this is correct

    Mandatory vacation policies force employees to step away from their duties, enabling colleagues to review transactions and uncover irregularities that continuous access would conceal. This directly satisfies the fraud-prevention constraint by removing the perpetrator's ability to sustain concealment, since most IT fraud schemes require ongoing manipulation of records to avoid detection.

  • ✓

    Separation of duties

    Why this is correct

    Separation of duties prevents fraud by ensuring no single individual controls an entire transaction lifecycle, splitting authorisation, custody and recording functions across different people. This directly satisfies the stem's fraud-prevention constraint, since collusion becomes necessary to conceal a fraudulent act, raising both the effort and detection risk.

  • ✗

    Background checks on new hires

    Why it's wrong here

    Background checks screen candidates before employment, addressing insider risk at onboarding, but they neither separate incompatible duties nor detect fraudulent transactions after hire. They are a legitimate personnel security control, yet fraud prevention in IT instead demands segregation of duties and independent review of privileged activity.

  • ✗

    Password complexity requirements

    Why it's wrong here

    Password complexity hardens authentication against guessing and credential theft, but it does not segregate duties or enforce transaction authorisation, so a single privileged user can still commit and conceal fraud. It is genuinely valuable for access security, yet fraud prevention instead requires dual control and independent reconciliation over financial or system transactions.

  • ✗

    Single sign-on (SSO) systems

    Why it's wrong here

    Single sign-on centralises authentication and simplifies access, but it consolidates credentials rather than separating incompatible duties, so one compromised identity can approve and execute a fraudulent transaction. It is genuinely an access-management convenience, yet fraud prevention instead requires segregation of duties and independent transaction authorisation.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.