โ† All CISA Flashcard Decks

Logical Access Controls Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Logical Access Controls flashcards as text
  1. An IS auditor reviewing a financial system finds that users can access any record regardless of their department. Which access control model is MOST appropriate to remediate this?

    Answer: Role-Based Access Control (RBAC)

    RBAC restricts access based on job roles, ensuring users only access data relevant to their department functions.

  2. Which of the following BEST describes the principle of least privilege in the context of logical access controls?

    Answer: Users receive only the minimum access rights necessary to perform their job

    Least privilege limits user access to only what is essential for their specific job duties, reducing the attack surface.

  3. During an access review, an auditor discovers that a terminated employee's account was not disabled for 30 days. Which control failure does this PRIMARILY represent?

    Answer: Inadequate access de-provisioning process

    Timely de-provisioning of access upon termination is a critical control; failure here creates unauthorized access risk.

  4. A company implements a system where a user's security clearance level must be equal to or greater than the data classification level to gain access. This BEST describes:

    Answer: Mandatory Access Control

    MAC enforces access based on security labels and clearances, typically used in government or highly sensitive environments.

  5. An IS auditor is evaluating single sign-on (SSO) implementation. What is the PRIMARY risk associated with SSO?

    Answer: Single point of failure for authentication

    If SSO credentials are compromised, an attacker gains access to all integrated systems simultaneously.

  6. Which access control technique would BEST prevent a database administrator from reading sensitive payroll data while still allowing them to perform administrative functions?

    Answer: Data masking or column-level encryption

    Data masking or column-level encryption restricts visibility of sensitive data even from privileged DBAs performing legitimate admin tasks.

  7. When auditing access control logs, an IS auditor should prioritize reviewing which of the following?

    Answer: Failed login attempts and after-hours access by privileged users

    Failed logins may indicate intrusion attempts, and after-hours privileged access is a key indicator of potential misuse or compromise.