CRISC Information Technology and Security Practice Question
A hospital is implementing a new electronic health record (EHR) system. The risk practitioner is concerned about the risk of unauthorized access to patient data by internal staff. Which of the following controls is MOST effective in mitigating this risk?
⚠ Common exam trap
Watch out — candidates often confuse detective controls like logging with preventive controls, or assuming encryption at rest protects against all unauthorized access when it only protects data at the storage layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC) with least privilege.
RBAC with least privilege is a preventive control that restricts access based on job roles, ensuring staff can only access the patient data necessary for their duties. This directly mitigates the risk of unauthorized internal access. While training, encryption, and monitoring are valuable, they do not prevent an authorized user from accessing data they should not see.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Logging and monitoring of all access to patient records.
Why it's wrong here
Logging and monitoring are detective controls that can identify unauthorized access after it occurs. While they are essential for incident detection and forensic investigation, they do not prevent the initial access. The risk of unauthorized access is better mitigated by preventive controls such as RBAC with least privilege, which stops the access before it happens.
- ✓
Role-based access control (RBAC) with least privilege.
Why this is correct
RBAC with least privilege ensures that staff members are granted only the access necessary to perform their job functions. This limits the potential for unauthorized access and reduces the attack surface. It is a preventive control that directly addresses the risk of internal staff accessing patient data they do not need, and it is a fundamental requirement of many healthcare regulations.
- ✗
Encryption of patient data at rest.
Why it's wrong here
Encryption at rest protects data if the storage media is physically stolen or improperly accessed at the storage layer, but it does not prevent an authorized user with valid credentials from accessing and misusing data through the application. Since the risk is unauthorized access by internal staff, encryption at rest does not address the primary threat vector of legitimate but excessive access.
- ✗
Annual security awareness training for all staff.
Why it's wrong here
Security awareness training is important for building a security culture and reducing human error, but it is a detective and educational control rather than a preventive one. It does not technically prevent a determined insider from accessing data they are authorized to see or from misusing their access. It should complement, not replace, access controls.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.