Courseiva

CRISC Information Technology and Security Practice Question

A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?

⚠ Common exam trap

Watch out — candidates often confuse detective controls like logging with preventive controls, or assuming encryption at rest protects against all unauthorized access when it only protects data at the storage layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based access control (RBAC) with least privilege.

RBAC with least privilege is a preventive control that restricts access based on job roles, ensuring staff can only access the patient data necessary for their duties. This directly mitigates the risk of unauthorized internal access. While training, encryption, and monitoring are valuable, they do not prevent an authorized user from accessing data they should not see.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Logging and monitoring of all access to patient records.

    Why it's wrong here

    Logging and monitoring are detective controls that can identify unauthorized access after it occurs. While they are essential for incident detection and forensic investigation, they do not prevent the initial access. The risk of unauthorized access is better mitigated by preventive controls such as RBAC with least privilege, which stops the access before it happens.

  • ✓

    Role-based access control (RBAC) with least privilege.

    Why this is correct

    RBAC with least privilege ensures that staff members are granted only the access necessary to perform their job functions. This limits the potential for unauthorized access and reduces the attack surface. It is a preventive control that directly addresses the risk of internal staff accessing patient data they do not need, and it is a fundamental requirement of many healthcare regulations.

  • ✗

    Encryption of patient data at rest.

    Why it's wrong here

    Encryption at rest protects data if the storage media is physically stolen or improperly accessed at the storage layer, but it does not prevent an authorized user with valid credentials from accessing and misusing data through the application. Since the risk is unauthorized access by internal staff, encryption at rest does not address the primary threat vector of legitimate but excessive access.

  • ✗

    Annual security awareness training for all staff.

    Why it's wrong here

    Security awareness training is important for building a security culture and reducing human error, but it is a detective and educational control rather than a preventive one. It does not technically prevent a determined insider from accessing data they are authorized to see or from misusing their access. It should complement, not replace, access controls.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.