Courseiva
hardMultiple Choice

ISC2 CC Practice Question: During a security audit, it is discovered that a…

During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?

⚠ Common exam trap

ISC2 often tests the candidate's ability to prioritize containment over investigation or notification, trapping those who choose risk assessment or logging first instead of immediate access revocation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke the contractor's access immediately

The immediate priority is to revoke the contractor's access to the unauthorized customer databases to stop any potential data exfiltration or misuse. Access controls follow the principle of least privilege, and any discovered over-provisioning must be corrected instantly to contain the risk. Delaying revocation for notification, assessment, or logging leaves the sensitive data exposed to an unauthorized user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify the contractor's manager

    Why it's wrong here

    Notifying the manager raises awareness but leaves the contractor's live database access intact, so the risk persists during any investigation. Escalation is tempting because management should be informed, yet notification is a communication step, not the containment action that revoking the unneeded permissions provides.

  • ✓

    Revoke the contractor's access immediately

    Why this is correct

    Revoking the contractor's access immediately closes the excessive-permission exposure, satisfying least privilege before any investigation. Removing the unneeded database rights first eliminates the active risk; reviewing the contract or auditing logs afterwards addresses root cause without leaving the vulnerability open.

  • ✗

    Perform a risk assessment

    Why it's wrong here

    A risk assessment documents and prioritises the exposure but removes no access, so the contractor retains the databases. It is tempting because assessments normally precede remediation, yet the immediate first step is revoking the excessive permissions, with assessment following to determine scope and impact.

  • ✗

    Log the access for evidence

    Why it's wrong here

    Logging preserves evidence of the access but does not terminate it, so the contractor keeps reaching customer databases. Evidence capture is tempting because audits require documentation, yet it is a forensic step taken alongside containment, not the first mitigation, which is removing the unnecessary permissions.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.