CISSP Security and Risk Management Practice Question
Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change management process for the financial system
IT general controls (ITGC) include access controls, change management, backup and recovery, and computer operations. Change management ensures that changes to financial systems are authorized and tested.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change management process for the financial system
Why this is correct
Under SOX, the integrity and reliability of financial reporting systems are paramount. A robust change management process for financial systems is a critical IT General Control (ITGC) because it ensures that all modifications to these systems are authorized, tested, and documented, preventing unauthorized changes that could compromise financial data accuracy. This control directly supports the reliability of financial statements by maintaining the stability and correctness of the applications processing financial transactions.
- ✗
Data encryption for customer PII
Why it's wrong here
While data encryption is a vital technical control for protecting the confidentiality of customer Personally Identifiable Information (PII), its primary focus is data privacy and security, not the integrity of financial reporting as mandated by SOX. SOX IT General Controls (ITGCs) are concerned with the overall reliability of the IT environment supporting financial data, whereas encryption is a specific technical mechanism primarily addressing data confidentiality and integrity at rest or in transit, rather than the foundational processes governing system operations.
- ✗
Firewall rule to block unauthorized traffic
Why it's wrong here
A firewall rule designed to block unauthorized network traffic is a crucial network security control that protects system perimeters from external threats. However, it is not typically classified as an IT General Control (ITGC) in the context of SOX. ITGCs focus on the overall integrity of the IT environment, including system development, program changes, computer operations, and logical access, rather than specific network traffic filtering mechanisms. While important for overall security, firewalls do not directly govern the processes that ensure the accuracy and reliability of financial data within the applications themselves.
- ✗
Automated calculation of interest on loans
Why it's wrong here
An automated calculation of interest on loans represents an application control, which is embedded within the specific functionality of a financial application to ensure the accuracy and completeness of transactions. This differs from an IT General Control (ITGC), which governs the overall IT environment and infrastructure supporting all applications, such as system development, access management, and operational processes. While critical for the accuracy of loan interest, this control's scope is limited to a specific business process within an application, rather than the foundational IT governance that SOX ITGCs address.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.