Courseiva
hardMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: During a security audit, it is discovered that a…

During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?

⚠ Common exam trap

ISC2 often tests the candidate's ability to prioritize containment over investigation or notification, trapping those who choose risk assessment or logging first instead of immediate access revocation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Revoke the contractor's access immediately

The immediate priority is to revoke the contractor's access to the unauthorized customer databases to stop any potential data exfiltration or misuse. Access controls follow the principle of least privilege, and any discovered over-provisioning must be corrected instantly to contain the risk. Delaying revocation for notification, assessment, or logging leaves the sensitive data exposed to an unauthorized user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Notify the contractor's manager

    Why it's wrong here

    Notifying management is important but does not directly stop the ongoing access.

  • Revoke the contractor's access immediately

    Why this is correct

    Revoking access immediately stops the unauthorized access and reduces risk.

  • Perform a risk assessment

    Why it's wrong here

    Risk assessment should be done, but it is not the first step to mitigate immediate risk.

  • Log the access for evidence

    Why it's wrong here

    Logging is useful for forensic purposes but does not mitigate the current risk.

About these practice questions

This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.