exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 483 discussion

Actual exam question from Isaca's CRISC
Question #: 483
Topic #: 1
[All CRISC Questions]

The compensating control that MOST effectively addresses the risk associated with piggybacking into a restricted area without a dead-man door is:

  • A. using two-factor authentication
  • B. using biometric door locks
  • C. requiring employees to wear ID badges
  • D. security awareness training
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Staanlee
9 months, 1 week ago
Selected Answer: B
B. using biometric door locks The compensating control that MOST effectively addresses the risk associated with piggybacking into a restricted area without a dead-man door is "B. using biometric door locks." Biometric door locks, such as fingerprint or retina scanners, provide a higher level of security compared to traditional access methods like ID badges. Biometric authentication ensures that only authorized individuals with matching biometric data can gain access, reducing the risk of unauthorized piggybacking.
upvoted 2 times
...
01010100
9 months, 3 weeks ago
Selected Answer: D
D. security awareness training Piggybacking, or tailgating, involves an unauthorized person following an authorized person into a restricted area. This risk often arises from employees' lack of awareness about the security implications of holding a door open for others. Security awareness training can teach employees about the risks associated with piggybacking and instruct them not to allow others to enter restricted areas without proper authentication. While options A, B, and C might enhance security to a certain extent, they may not effectively address piggybacking because even with advanced technology, a person can still follow an authenticated person through the door. Therefore, security awareness training is the most effective compensating control in this case.
upvoted 2 times
...
john_boogieman
1 year, 2 months ago
Selected Answer: D
Agree 'without a dead-man door'. If there is no physical control that responds effectively to the threat, the best thing to do is warn it so that an employee is attentive and prevents it from 'sneaking in'.
upvoted 2 times
...
deknow
1 year, 3 months ago
the correct answer is B
upvoted 1 times
...
Boubou480
1 year, 4 months ago
Selected Answer: D
Training always comes first
upvoted 1 times
...
Boubou480
1 year, 4 months ago
D. security awareness training Training always comes first
upvoted 1 times
...
Suchib
1 year, 4 months ago
I think B is direct control, whereas D is ocmpensating.
upvoted 2 times
...
Kozy
1 year, 8 months ago
Training employees are always the primary thing you can do to decrease human-based risks (eg.: phising).
upvoted 1 times
...
Khy
3 years, 1 month ago
not b?
upvoted 1 times
Raj1510
2 years, 4 months ago
Only B cannot address, concern. D is right answer
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...