mediumMultiple Select
CISA Practice Question: Which TWO of the following are examples of…
Which TWO of the following are examples of detective controls? (Choose two.)
⚠ Common exam trap
CISA often tests the confusion between preventive and detective controls, where candidates misclassify ACLs or encryption as detective because they involve security measures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regular review of security incident logs.
Option B (regular review of security incident logs) is a detective control because examining logs after events occur identifies suspicious or malicious activity that has already happened, enabling detection rather than prevention. Option C (intrusion detection system (IDS) alerts) is also detective because an IDS monitors network or host activity and raises alerts when it recognizes known attack signatures or anomalies, revealing incidents in progress or after the fact. By contrast, option A (firewall rules that block unauthorized traffic) is a preventive control, since it stops traffic before it reaches protected resources. Option D (encryption of sensitive data at rest) is preventive, protecting data confidentiality if storage is compromised. Option E (ACLs on network devices) is preventive, as it filters and permits or denies traffic to enforce access policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules that block unauthorized traffic.
Why it's wrong here
Firewall rules are preventive controls that block traffic at the boundary; they do not identify or record that an intrusion attempt succeeded or failed. They are tempting because firewall logs can feed detection, but the rule itself enforces policy, and detective controls such as IDS, SIEM correlation or log review are correct for discovering incidents.
- ✓
Regular review of security incident logs.
Why this is correct
Reviewing incident logs is a manual detective control: analysts examine recorded events to identify security incidents that automated tooling may have missed. Detection happens after the event, distinguishing it from preventive controls such as firewalls or access restrictions.
- ✓
Intrusion detection system (IDS) alerts.
Why this is correct
An IDS passively monitors network or host traffic and raises alerts when signatures or anomalies match known attack patterns. It detects and reports activity after it occurs rather than blocking it, which is precisely what defines a detective control.
- ✗
Encryption of sensitive data at rest.
Why it's wrong here
Encryption is a preventive control that renders data unreadable to unauthorised parties; it detects nothing because it takes no monitoring or comparison action. It is tempting because encryption features in many control frameworks alongside logging, but detective controls such as IDS, log review or file-integrity monitoring are correct when the objective is identifying that an event has occurred.
- ✗
Access control lists (ACLs) on network devices.
Why it's wrong here
ACLs are preventive: they permit or deny traffic before it reaches a resource, generating no detection of past or ongoing activity. They are tempting because they are configured on network devices that also host logging, but detective controls such as IDS alerts or audit-log analysis are correct when the requirement is to identify events after they occur.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Match each security control to its category.
medium- ✓ A.Firewall: Prevents unauthorized network access by filtering traffic.
- ✓ B.Intrusion Detection System (IDS): Monitors network traffic for suspicious activity and alerts.
- ✓ C.Data Backup: Restores lost or corrupted data from copies.
- D.Firewall: Monitors network traffic for suspicious activity and alerts.
- E.Intrusion Detection System (IDS): Restores lost or corrupted data from copies.
- F.Data Backup: Prevents unauthorized network access by filtering traffic.
Why A: Firewalls are preventive controls that block unauthorized access, IDS are detective controls that monitor and alert, and data backups are corrective controls that restore data after loss. The distractors swap these definitions.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.