Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Change management process for the financial system

IT general controls (ITGC) include access controls, change management, backup and recovery, and computer operations. Change management ensures that changes to financial systems are authorized and tested.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Change management process for the financial system

    Why this is correct

    Under SOX, the integrity and reliability of financial reporting systems are paramount. A robust change management process for financial systems is a critical IT General Control (ITGC) because it ensures that all modifications to these systems are authorized, tested, and documented, preventing unauthorized changes that could compromise financial data accuracy. This control directly supports the reliability of financial statements by maintaining the stability and correctness of the applications processing financial transactions.

  • Data encryption for customer PII

    Why it's wrong here

    While data encryption is a vital technical control for protecting the confidentiality of customer Personally Identifiable Information (PII), its primary focus is data privacy and security, not the integrity of financial reporting as mandated by SOX. SOX IT General Controls (ITGCs) are concerned with the overall reliability of the IT environment supporting financial data, whereas encryption is a specific technical mechanism primarily addressing data confidentiality and integrity at rest or in transit, rather than the foundational processes governing system operations.

  • Firewall rule to block unauthorized traffic

    Why it's wrong here

    A firewall rule designed to block unauthorized network traffic is a crucial network security control that protects system perimeters from external threats. However, it is not typically classified as an IT General Control (ITGC) in the context of SOX. ITGCs focus on the overall integrity of the IT environment, including system development, program changes, computer operations, and logical access, rather than specific network traffic filtering mechanisms. While important for overall security, firewalls do not directly govern the processes that ensure the accuracy and reliability of financial data within the applications themselves.

  • Automated calculation of interest on loans

    Why it's wrong here

    An automated calculation of interest on loans represents an application control, which is embedded within the specific functionality of a financial application to ensure the accuracy and completeness of transactions. This differs from an IT General Control (ITGC), which governs the overall IT environment and infrastructure supporting all applications, such as system development, access management, and operational processes. While critical for the accuracy of loan interest, this control's scope is limited to a specific business process within an application, rather than the foundational IT governance that SOX ITGCs address.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.