nerdexam
Isaca

CISM · Question #773

Which of the following should be the PRIMARY focus for an information security manager when reviewing access controls for data stored in an off-premise cloud environment?

The correct answer is C. Ensuring access is granted to only those individuals whose job functions require it. Ensuring access is granted only to those whose job functions require it - the principle of least privilege - is the primary access control concern in any environment, and becomes especially critical in cloud settings where organizational boundaries are more porous and…

Submitted by ricky.ec· Apr 18, 2026Information Security Risk Management

Question

Which of the following should be the PRIMARY focus for an information security manager when reviewing access controls for data stored in an off-premise cloud environment?

Options

  • AReviewing and updating access controls in response to changes in organizational structure
  • BImplementing strong password policies and enforcing regular password changes
  • CEnsuring access is granted to only those individuals whose job functions require it
  • DImplementing strong encryption protocols to protect sensitive data

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    80% (41)
  • D
    12% (6)

Explanation

Ensuring access is granted only to those whose job functions require it - the principle of least privilege - is the primary access control concern in any environment, and becomes especially critical in cloud settings where organizational boundaries are more porous and misconfigurations are a leading cause of breaches. A (updating controls for org changes) is a valid operational task but is reactive and secondary to establishing the correct baseline policy. B (password policies) addresses authentication strength, not access control scope - it's a separate concern. D (encryption) protects data at rest/in transit but doesn't control who can access it; both are needed, but least privilege is the access control priority.

Memory tip: When a question asks about access controls, anchor to "who should have access?" - that points directly to least privilege (C). Encryption, passwords, and org updates are supporting concerns, not the primary access control principle.

Topics

#Access Control#Least Privilege#Cloud Security#Risk Mitigation

Community Discussion

No community discussion yet for this question.

Full CISM Practice