Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27002-Foundation Exam - Topic 3 Question 9 Discussion

An organization uses an access control software that allows only authorized employees to access sensitive files. What type of control is this?
C) Preventive
A) Detective
B) Corrective

PECB ISO-IEC-27002-Foundation Exam - Topic 3 Question 9 Discussion

Actual exam question for PECB's ISO-IEC-27002-Foundation exam
Question #: 9
Topic #: 3
[All ISO-IEC-27002-Foundation Questions]

An organization uses an access control software that allows only authorized employees to access sensitive files. What type of control is this?

Show Suggested Answer Hide Answer
Suggested Answer: C

Access control software that allows only authorized employees to access sensitive files is a preventive control. Its purpose is to stop unauthorized access before it occurs by enforcing approved access rules. In ISO/IEC 27002, access control is implemented through policies, identity management, authentication, authorization, access rights review, privileged access control, and restrictions on information access. This type of software can prevent unauthorized disclosure, unauthorized modification, misuse of sensitive data, and violation of privacy or contractual obligations. It is not primarily detective because it does not merely discover an event after it has happened. It is not corrective because it does not restore damaged information or reverse the impact of an incident. Its security value is in blocking access attempts that do not meet authorization criteria. The principle behind the control is least privilege: users should receive only the access necessary for their role and responsibilities. For sensitive files, this is especially important because confidentiality, integrity, and accountability depend on correct authorization. Reference/Chapters: ISO/IEC 27002:2022, Control 5.15 Access control; Control 5.16 Identity management; Control 5.18 Access rights; Control 8.3 Information access restriction.


Contribute your Thoughts:

0/2000 characters
I could be wrong, but I feel like corrective controls are more about fixing issues after a breach, not preventing access.
upvoted 0 times
...
Fernanda
5 days ago
This seems similar to a practice question we did on access controls, and I believe it was classified as preventive too.
upvoted 0 times
...
Angelo
10 days ago
I'm not entirely sure, but I remember something about detective controls being more about monitoring access after it occurs.
upvoted 0 times
...
Lakeesha
15 days ago
I think this is a preventive control because it stops unauthorized access before it happens.
upvoted 0 times
...

Save Cancel