hardMultiple Choice
ISC2 CC Practice Question: During a security audit, it is discovered that a…
During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?
⚠ Common exam trap
ISC2 often tests the candidate's ability to prioritize containment over investigation or notification, trapping those who choose risk assessment or logging first instead of immediate access revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the contractor's access immediately
The immediate priority is to revoke the contractor's access to the unauthorized customer databases to stop any potential data exfiltration or misuse. Access controls follow the principle of least privilege, and any discovered over-provisioning must be corrected instantly to contain the risk. Delaying revocation for notification, assessment, or logging leaves the sensitive data exposed to an unauthorized user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify the contractor's manager
Why it's wrong here
Notifying the manager raises awareness but leaves the contractor's live database access intact, so the risk persists during any investigation. Escalation is tempting because management should be informed, yet notification is a communication step, not the containment action that revoking the unneeded permissions provides.
- ✓
Revoke the contractor's access immediately
Why this is correct
Revoking the contractor's access immediately closes the excessive-permission exposure, satisfying least privilege before any investigation. Removing the unneeded database rights first eliminates the active risk; reviewing the contract or auditing logs afterwards addresses root cause without leaving the vulnerability open.
- ✗
Perform a risk assessment
Why it's wrong here
A risk assessment documents and prioritises the exposure but removes no access, so the contractor retains the databases. It is tempting because assessments normally precede remediation, yet the immediate first step is revoking the excessive permissions, with assessment following to determine scope and impact.
- ✗
Log the access for evidence
Why it's wrong here
Logging preserves evidence of the access but does not terminate it, so the contractor keeps reaching customer databases. Evidence capture is tempting because audits require documentation, yet it is a forensic step taken alongside containment, not the first mitigation, which is removing the unnecessary permissions.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.