Isaca Certified in Risk and Information Systems Control CRISC Question # 42 Topic 5 Discussion
CRISC Exam Topic 5 Question 42 Discussion:
Question #: 42
Topic #: 5
An organization requires data owners to perform a quarterly review of all privileged users on key financial systems. What type of control does this represent?
The correct answer is D . A quarterly privileged-user review is a detective control because it identifies inappropriate, excessive, or unauthorized privileged access after access has been granted. The uploaded CRISC notes state that a supervisor’s review of firewall logs is an administrative control and that regularly testing information system controls helps identify design flaws, failures, and redundancies. The same principle applies here: periodic review detects whether access remains appropriate.
A preventive control stops an event before it occurs. B directs behavior through policy or guidance. C restores or fixes after an issue. The quarterly access review is primarily detective.
===========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit