CRISC Information Technology and Security Practice Question
A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The organization uses role-based access control (RBAC) but has experienced several incidents where employees retained access to systems after transferring to different departments. Which of the following is the MOST effective control to address this risk?
⚠ Common exam trap
The trap here is selecting periodic access reviews or password policies, which are detective or irrelevant, instead of a preventive automated provisioning control triggered by HR events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate the HR system with the IAM system to automatically revoke old roles and grant new roles upon a change in employee status or department.
The root cause of the incidents is that access rights are not updated when employees change roles. The most effective control is to automate the synchronization of role changes from HR to the IAM system, ensuring timely revocation of old access and assignment of new access. This preventive control addresses the issue at the source and reduces reliance on periodic reviews.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement mandatory password rotation every 30 days for all users.
Why it's wrong here
Password rotation does not address the issue of excessive access rights after a role change. The problem is that users retain permissions from their previous roles, not that their passwords are compromised. Frequent rotation can even lead to weaker passwords and increased help desk calls, without mitigating the risk of unauthorized access due to stale entitlements.
- ✗
Conduct periodic user access reviews with managers certifying that their direct reports have appropriate access.
Why it's wrong here
Access reviews are important, but they are detective and periodic. They may catch some excessive access, but the incidents described indicate a need for a more proactive, automated control that triggers upon role change. Relying solely on periodic reviews leaves a window of exposure between transfers and the next review cycle.
- ✓
Integrate the HR system with the IAM system to automatically revoke old roles and grant new roles upon a change in employee status or department.
Why this is correct
Automating role changes based on HR events ensures that access rights are updated immediately when an employee transfers, eliminating the lag that leads to retained access. This preventive control directly addresses the root cause: the lack of timely de-provisioning and re-provisioning of access when roles change. It reduces reliance on manual processes and periodic reviews.
- ✗
Require all employees to sign an acceptable use policy annually.
Why it's wrong here
An acceptable use policy is a deterrent and awareness control, but it does not enforce access revocation. Employees may still retain access unintentionally. Policy alone cannot prevent the technical issue of stale entitlements; a technical or process control integrated with HR is needed to ensure access is updated in real time.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.