nerdexam
PECB

LEAD-AUDITOR · Question #258

A cybersecurity company implemented an access control software that allows only authorized personnel to access sensitive files. Which type of control has the company implemented in this case?

The correct answer is A. Preventive control. Access control software is designed to prevent unauthorized access by enforcing authentication and authorization mechanisms. This aligns with ISO/IEC 27001:2022 Annex A Control A.5.18 (Access Rights).

Information Security Controls

Question

A cybersecurity company implemented an access control software that allows only authorized personnel to access sensitive files. Which type of control has the company implemented in this case?

Options

  • APreventive control
  • BDetective control
  • CCorrective control

How the community answered

(36 responses)
  • A
    89% (32)
  • B
    3% (1)
  • C
    8% (3)

Explanation

Access control software is designed to prevent unauthorized access by enforcing authentication and authorization mechanisms. This aligns with ISO/IEC 27001:2022 Annex A Control A.5.18 (Access Rights).

Topics

#access control#preventive control#control classification#authorization

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice