Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

In an information systems security audit, which control is a preventive control designed to stop unauthorised persons from entering a payroll application?

Unique user IDs with passwords and role-based access rights are the preventive control, because they stop unauthorised entry before it happens. Failed-login reports and log reviews only detect misuse afterwards, while backup restoration is corrective, repairing damage after the event.

  1. AUnique user IDs protected by passwords and role-based access rightsCorrect
  2. BA daily exception report of failed login attempts reviewed by the manager
  3. CRestoration of data from a backup tape after a crash
  4. DA post-incident forensic review of server logs

Explanation

Preventive controls act before a violation occurs. Unique IDs with passwords and role-based rights block unauthorised entry. Exception reports of failed logins are detective, backup restoration is corrective, and log forensics after an incident is also detective.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions