Logical Access Controls Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Logical Access Controls flashcards as text
An IS auditor is reviewing a healthcare organization's EHR system. Which logical access control would BEST address the HIPAA minimum necessary standard?
Answer: Implementing context-based access that limits record visibility to treating clinicians
Context-based access ensures clinicians only see records for patients under their direct care, aligning with HIPAA's minimum necessary requirement.
During a review of an application's authentication mechanism, an IS auditor finds session tokens that never expire. What is the PRIMARY risk?
Answer: Captured session tokens can be reused indefinitely by attackers
Non-expiring session tokens allow session hijacking attacks to persist indefinitely, granting long-term unauthorized access.
Which of the following BEST describes an access control matrix?
Answer: A table defining what operations each subject can perform on each object
An access control matrix is a formal model that maps subjects (users/processes) to objects (resources) and their permitted operations.
An organization uses OAuth 2.0 for API access delegation. Which security concern should an IS auditor PRIMARILY evaluate?
Answer: Scope limitations on access tokens and token revocation capabilities
Overly broad token scopes and lack of revocation mechanisms are primary OAuth security risks that can lead to excessive API access.
An IS auditor finds that a legacy system cannot enforce password complexity requirements. What is the MOST appropriate recommendation?
Answer: Implement compensating controls such as additional authentication factors
When a system cannot enforce a technical control, compensating controls such as MFA or enhanced monitoring should be implemented to offset the risk.
Which logical access control approach would BEST prevent an insider from exfiltrating bulk customer records from a database?
Answer: Implementing query result row-count limits and data loss prevention controls
Row-count limits on query results and DLP controls detect and restrict bulk data extraction, targeting the exfiltration method directly.
An IS auditor is assessing a federated identity management system. Which of the following represents the GREATEST advantage from a logical access control perspective?
Answer: Centralized identity governance across multiple organizations without sharing credentials
Federated identity allows users to authenticate once with a trusted provider while accessing resources across organizations without transmitting actual credentials.