Exam ISO-IEC-27001-Lead-Auditor Topic 2 Question 209 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 209
Topic #: 2
Question:
A cybersecurity company implemented an access control software that allows only authorized personnel to access sensitive files. Which type of control has the company implemented in this case?

Suggested Answer: A Vote an answer

Comprehensive and Detailed In-Depth Explanation:
* A. Preventive Control - Correct Answer. Access control software is designed to prevent unauthorized access by enforcing authentication and authorization mechanisms. This aligns with ISO/IEC 27001:
2022 Annex A Control A.5.18 (Access Rights).
* B. Detective controls identify and log unauthorized access attempts, but do not prevent them.
* C. Corrective controls take action after a security event has occurred.

by Hiram at Sep 17, 2026, 08:34 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10