CISA · Question #226
At the end of each business day, a business-critical application generates a report of financial transactions greater than a certain value, and an employee then checks these transactions for errors. W
The correct answer is D. Detective. This scenario describes a detective control, as it identifies errors after they have occurred.
Question
At the end of each business day, a business-critical application generates a report of financial transactions greater than a certain value, and an employee then checks these transactions for errors. What type of control is in place?
Options
- ADeterrent
- BPreventive
- CCorrective
- DDetective
How the community answered
(16 responses)- C6% (1)
- D94% (15)
Why each option
This scenario describes a detective control, as it identifies errors after they have occurred.
A deterrent control aims to discourage undesirable acts from occurring in the first place, such as security warnings or policies.
A preventive control stops errors or unauthorized actions from happening, such as input validation or segregation of duties, before the transaction is finalized.
A corrective control aims to reverse the impact of an error once it has been detected, for example, by restoring data from backups or fixing a corrupted record, which happens after detection.
A detective control is designed to identify and report errors, omissions, or unauthorized transactions that have already happened. In this case, the control generates a report of specific transactions (greater than a certain value) after they are processed, and an employee then checks for errors, aiming to discover issues rather than prevent them upfront.
Concept tested: Types of IT controls
Source: https://learn.microsoft.com/en-us/azure/architecture/guide/security/security-controls
Topics
Community Discussion
No community discussion yet for this question.