Certified Information Systems Auditor CISA · Free Practice Question Easy
Question 94
You are the information system auditor of HDA Inc. You are assessing different controls in place for managing incidents. Which of the following is a corrective control?
- A A. Conducting vulnerability assessments
- B B. Implementing access controls
- C C. Implementing an incident response plan
- D D. Performing regular data backups
Reveal correct answer
Correct answer: C
Explanation
Correct Answer: C. Implementing an incident response plan Explanation: A corrective control is a type of control that is implemented after an incident has occurred to correct or mitigate the effects of the incident. It focuses on the timely response and remediation of the incident. Implementing an incident response plan is an example of a corrective control. An incident response plan outlines the actions to be taken in the event of a security incident, such as a data breach or system compromise. It includes steps for containment, eradication, and recovery, as well as communication and reporting procedures. By implementing an incident response plan, an organization can effectively respond to incidents, minimize the impact, and restore normal operations in a timely manner. Option A, conducting vulnerability assessments, is an example of a preventive control. Vulnerability assessments are proactive measures that identify vulnerabilities in systems and networks. They help organizations identify and address weaknesses before they are exploited by attackers, thus preventing incidents from occurring in the first place. Option B, implementing access controls, is also a preventive control. Access controls restrict and manage user access to systems, applications, and data. By enforcing authentication, authorization, and other access control mechanisms, organizations can prevent unauthorized access and reduce the risk of incidents. Option D, performing regular data backups, is an example of a detective control. Data backups are created to recover data in case of data loss or system failures. While backups can help in restoring data after an incident, they do not actively correct or mitigate the effects of the incident. They are primarily used for recovery purposes. Therefore, the correct answer is C. Implementing an incident response plan, as it is a control that is specifically designed to respond to and correct incidents that have occurred.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
