ISC2 CC Security Principles Practice Question
A retail chain wants to reduce the chance that a former employee can still access the point-of-sale system weeks after leaving the company. The security manager proposes a control that automatically disables accounts on the employee's last working day. Which type of control is this?
⚠ Common exam trap
Many exam-takers confuse timely deprovisioning with detective monitoring, when the control's defining feature is that it blocks access before any attempt occurs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventive
Automated account deactivation on the last working day stops unauthorized access before it can happen, which defines a preventive control. Detective controls would only reveal misuse after the fact, corrective controls would remediate damage already done, and compensating controls are alternate measures when a primary control is not feasible. Since the control blocks the event itself, preventive is the correct classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detective
Why it's wrong here
A detective control identifies that an event has already happened, such as an alert showing a terminated account was used. In this scenario, the goal is to stop access from occurring, not to discover it afterward. Automated account disabling acts before any login attempt, so labeling it detective mischaracterizes when and how the control functions.
- ✓
Preventive
Why this is correct
A preventive control stops an unwanted event before it occurs. Automatically disabling accounts on the last working day prevents the former employee from authenticating at all, closing off the possibility of unauthorized access. Because the control acts in advance of any attempted misuse, it is preventive in nature, even though it also supports other goals such as audit compliance.
- ✗
Compensating
Why it's wrong here
A compensating control substitutes for a primary control that cannot be implemented, often to satisfy a requirement in an alternative way. Automated deprovisioning is not a workaround; it is the primary control for terminating access. Calling it compensating would imply a different control was infeasible, which the scenario does not state.
- ✗
Corrective
Why it's wrong here
A corrective control repairs damage or restores normal operations after an incident, such as resetting a compromised account. Here, the control prevents the incident entirely rather than fixing it after the fact. Although disabling an account could be part of a corrective response, the scenario describes scheduled deprovisioning before any misuse occurs.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
Preventive control
A preventive control is a security measure designed to stop unauthorized access, attacks, or errors before they can occur.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.