ExamGecko
Question list
Search
Search

Related questions

Question 356 - CISA discussion

Report
Export

Which of the following is a corrective control?

A.
Separating equipment development testing and production
Answers
A.
Separating equipment development testing and production
B.
Verifying duplicate calculations in data processing
Answers
B.
Verifying duplicate calculations in data processing
C.
Reviewing user access rights for segregation
Answers
C.
Reviewing user access rights for segregation
D.
Executing emergency response plans
Answers
D.
Executing emergency response plans
Suggested answer: D

Explanation:

A corrective control is a control that aims to restore normal operations after a disruption or incident has occurred. Executing emergency response plans is an example of a corrective control, as it helps to mitigate the impact of an incident and resume business functions. Separating equipment development testing and production is a preventive control, as it helps to avoid errors or unauthorized changes in production systems. Verifying duplicate calculations in data processing is a detective control, as it helps to identify errors or anomalies in data processing. Reviewing user access rights for segregation is also a detective control, as it helps to detect any violations of segregation of duties principles.Reference:ISACA, CISA Review Manual, 27th Edition, 2018, page 64

asked 18/09/2024
Mauricio de Souza Penhalver Hollanda
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first