Easy1 markMultiple Choice
Area II: SecuritySecurity MitigationArea II

CPA · Question 16 · Area II: Security

Which of the following is a detective control?

Answer options:

A.

Firewall

B.

Encryption

C.

Reviewing audit logs

D.

Multi-factor authentication

How to approach this question

Classify controls: Preventive (stops it), Detective (finds it), Corrective (fixes it).

Full Answer

C.Reviewing audit logs✓ Correct
Detective controls are designed to find errors or irregularities after they have occurred. Log review is a classic example.

Common mistakes

Classifying firewalls as detective (they prevent access).

Practice the full CPA ISC Practice Exam 2

82 questions · hints · full answers · grading

More questions from this exam