CISSP Security and Risk Management Practice Question
Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?
⚠ Common exam trap
CISSP often tests the distinction between IT general controls (which govern the IT environment and support financial reporting under SOX) and application/business controls (which operate within a specific application) — candidates frequently pick the automated business calculation (Option D) because it sounds financial, missing that it is an application control, not an ITGC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change management process for the financial system
Under SOX, IT general controls (ITGCs) are the foundational controls that ensure the reliability, integrity, and security of the IT environment supporting financial reporting. A change management process for the financial system is a classic ITGC because it ensures that modifications to applications affecting financial data are authorized, tested, approved, and documented — directly protecting the accuracy and completeness of financial statements. SOX Section 404 requires management to assess and auditors to attest to the effectiveness of these internal controls over financial reporting (ICFR), and ITGCs like change management are a core part of that assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change management process for the financial system
Why this is correct
Under SOX, the integrity and reliability of financial reporting systems are paramount. A robust change management process for financial systems is a critical IT General Control (ITGC) because it ensures that all modifications to these systems are authorized, tested, and documented, preventing unauthorized changes that could compromise financial data accuracy. This control directly supports the reliability of financial statements by maintaining the stability and correctness of the applications processing financial transactions.
- ✗
Data encryption for customer PII
Why it's wrong here
While data encryption is a vital technical control for protecting the confidentiality of customer Personally Identifiable Information (PII), its primary focus is data privacy and security, not the integrity of financial reporting as mandated by SOX. SOX IT General Controls (ITGCs) are concerned with the overall reliability of the IT environment supporting financial data, whereas encryption is a specific technical mechanism primarily addressing data confidentiality and integrity at rest or in transit, rather than the foundational processes governing system operations.
- ✗
Firewall rule to block unauthorized traffic
Why it's wrong here
A firewall rule designed to block unauthorized network traffic is a crucial network security control that protects system perimeters from external threats. However, it is not typically classified as an IT General Control (ITGC) in the context of SOX. ITGCs focus on the overall integrity of the IT environment, including system development, program changes, computer operations, and logical access, rather than specific network traffic filtering mechanisms. While important for overall security, firewalls do not directly govern the processes that ensure the accuracy and reliability of financial data within the applications themselves.
- ✗
Automated calculation of interest on loans
Why it's wrong here
An automated calculation of interest on loans represents an application control, which is embedded within the specific functionality of a financial application to ensure the accuracy and completeness of transactions. This differs from an IT General Control (ITGC), which governs the overall IT environment and infrastructure supporting all applications, such as system development, access management, and operational processes. While critical for the accuracy of loan interest, this control's scope is limited to a specific business process within an application, rather than the foundational IT governance that SOX ITGCs address.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.