CIA-1 - Governance, Risk Management, and Control - Section C.7

Interpret internal control concepts and types of controls, including preventive, detective, and corrective controls, and recommend appropriate controls to mitigate risks.

Explain the purpose of internal control as providing reasonable assurance over the achievement of objectives, and classify controls by function into preventive controls that stop an event, detective controls that identify one that has occurred, and corrective controls that remediate its effects. Recommend a control, or mix of controls, proportionate to the risk being mitigated rather than defaulting to more control for its own sake.

Preventive controlDetective controlCorrective controlInternal control

Practice question for this objective

Free sampleGovernance, Risk Management, and Controlmedium

Corvus Publishing runs patching to keep systems current and monitoring tools that alert on suspicious activity, but the board accepts that a ransomware attack could still succeed and encrypt its production servers. The board asks internal audit for the control that would best remediate the effects and restore operations if an attack does get through. Which control should the auditor recommend?

  • AA recurring phishing-awareness programme so that staff are less likely to open the malicious attachments that carry ransomware.
  • BRegularly tested offline backups with a documented procedure to restore encrypted systems to a clean prior state. Correct
  • CIntrusion-detection tooling that raises an alert as soon as unusual bulk file-encryption behaviour is observed on the network.
  • DNetwork segmentation designed to stop malware from spreading laterally between the organisation's server environments.
Recommend a corrective control that remediates the effects of an event that has already occurred, distinct from preventive and detective controls. Corrective controls act after an event to restore the organisation to its intended state; tested offline backups recover encrypted systems, whereas training and segmentation prevent and detection tooling only signals that the event is under way.

Why A is wrong: Awareness training reduces the chance that an attack starts, which is preventive, so it does not remediate the damage once servers have already been encrypted.

Why B is correct: Restoring from tested backups repairs the effect of a successful attack and returns operations to normal, which is exactly the corrective control the board's stated aim requires.

Why C is wrong: Alerting on encryption in progress is a detective control that tells the organisation an event is happening, but it does not by itself restore the encrypted systems.

Why D is wrong: Segmentation limits how far an attack can travel, so it works to prevent wider compromise rather than to recover the systems that have already been encrypted.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Governance, Risk Management, and Control objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.