Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?

⚠ Common exam trap

The trap here is selecting periodic access reviews or password policies, which are detective or irrelevant, instead of a preventive automated provisioning control triggered by HR events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Integrate the HR system with the IAM system to automatically revoke old roles and grant new roles upon a change in employee status or department.

The root cause of the incidents is that access rights are not updated when employees change roles. The most effective control is to automate the synchronization of role changes from HR to the IAM system, ensuring timely revocation of old access and assignment of new access. This preventive control addresses the issue at the source and reduces reliance on periodic reviews.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement mandatory password rotation every 30 days for all users.

    Why it's wrong here

    Password rotation does not address the issue of excessive access rights after a role change. The problem is that users retain permissions from their previous roles, not that their passwords are compromised. Frequent rotation can even lead to weaker passwords and increased help desk calls, without mitigating the risk of unauthorized access due to stale entitlements.

  • ✗

    Conduct periodic user access reviews with managers certifying that their direct reports have appropriate access.

    Why it's wrong here

    Access reviews are important, but they are detective and periodic. They may catch some excessive access, but the incidents described indicate a need for a more proactive, automated control that triggers upon role change. Relying solely on periodic reviews leaves a window of exposure between transfers and the next review cycle.

  • ✓

    Integrate the HR system with the IAM system to automatically revoke old roles and grant new roles upon a change in employee status or department.

    Why this is correct

    Automating role changes based on HR events ensures that access rights are updated immediately when an employee transfers, eliminating the lag that leads to retained access. This preventive control directly addresses the root cause: the lack of timely de-provisioning and re-provisioning of access when roles change. It reduces reliance on manual processes and periodic reviews.

  • ✗

    Require all employees to sign an acceptable use policy annually.

    Why it's wrong here

    An acceptable use policy is a deterrent and awareness control, but it does not enforce access revocation. Employees may still retain access unintentionally. Policy alone cannot prevent the technical issue of stale entitlements; a technical or process control integrated with HR is needed to ensure access is updated in real time.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.