Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Information Systems

In an information system, which control is classified as a preventive control?

Requiring a unique user ID and password before accessing the payroll module is a preventive control because it stops unauthorised access before it happens. Log reviews and exception reports detect problems afterwards, and restoring backups corrects damage after an incident.

  1. AReviewing system logs after a month-end close
  2. BRequiring a unique user ID and password before access to the payroll moduleCorrect
  3. CRestoring data from backup after a server crash
  4. DInvestigating an unexplained transaction flagged by an exception report

Explanation

Preventive controls stop an unwanted event before it occurs. Authentication at login blocks unauthorised access. Log review and exception reports are detective controls, while restoring from backup is a corrective control.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems shows your real accuracy, how long you take and where you lose marks.

More Information Systems questions