Which Control Best Detects Unauthorized Access to Personal Data in an HR System?
An organization is designing a new human resources (HR) system. Which of the following should be implemented to BEST enable detection of unauthorized access to personal data?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the ability to distinguish between preventive and detective controls; the common trap is selecting DLP because it is a data-protection tool, but detection of unauthorized access requires logging and event correlation, which SIEM provides.
For the CDPSE exam, choosing a SIEM solution is correct when the goal is to detect unauthorized access to personal data; community consensus confirms that SIEM enables monitoring and alerting, while DLP is preventive and other tools address different risks.
The most common wrong answer is A (DLP) because DLP is often associated with protecting personal data; however, DLP prevents data loss or exfiltration and does not primarily detect unauthorized access events, whereas SIEM collects and analyzes logs to identify such incidents.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
SIEM (Option B) is the best choice because its core function is centralized logging, real-time monitoring, and alerting on suspicious activities. In an HR system, unauthorized access to personal data would generate logs (e.g., failed logins, unusual data retrieval), and a SIEM correlates those events to enable detection. Comments confirm this: users specifically note that "if detection it should be SIEM, DLP preventive," aligning with the detective nature of SIEM.Why the Other Options Are Wrong
Option A (DLP) is primarily preventive—it is designed to block data exfiltration and enforce data-handling policies, not to detect unauthorized access after it occurs. Option C (vulnerability scanning) identifies weaknesses before an attack, not active unauthorized access. Option D (WAF) protects web applications from external attacks like SQL injection, but it is too narrow and is not the best overall tool for detecting unauthorized access within an HR system.Community Comment Notes
All comments indicate the correct answer is B. The most useful comment highlights the key distinction: "B if detection it should be SIEM, DLP preventive." Another simply votes for B. No comment disputes the answer, reinforcing that the question is straightforward once you recognize the difference between preventive and detective controls.Exam Strategy
When a question asks about 'detection of unauthorized access,' focus on the purpose of each control. SIEM is the classic detective control because it aggregates logs and generates alerts. Remember that DLP is preventive, vulnerability scanning is proactive, and WAF is application-specific—so choose the tool that explicitly supports monitoring and detection.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →