Which Control Best Prevents Unapproved Emergency Changes to a Critical System?
A business area received an audit finding because an administrator made unapproved emergency changes to a critical system. Which of the following would BEST prevent unapproved changes in the future?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests selecting a preventive control over a detective or administrative one: dual control physically blocks unilateral changes, while the trap is choosing procedure updates, which guide behavior but do not enforce approval.
This CISA question contrasts preventive and detective controls in emergency change management, where dual-control temporary emergency access accounts stop any single administrator from acting unilaterally on a critical system. The community favors D over updated procedures by roughly a two-to-one margin, consistent with ISACA's preference for enforced preventive controls.
About a third of voters chose B (updated emergency change management procedures), reasoning that controls fail without a defined process; however, procedures alone are administrative guidance that cannot stop an administrator from bypassing approval, so they do not BEST prevent recurrence.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Dual-control temporary emergency access accounts implement two-person integrity, meaning no single administrator can invoke emergency access and push changes to a critical system without a second authorized individual authorizing and executing the action. This is a preventive control that directly removes the root cause identified in the audit finding — one administrator acting unilaterally. Because the accounts are temporary, standing privileged access is also minimized, shrinking the window for misuse. ISACA consistently ranks technical preventive controls above procedural guidance when a question asks what BEST prevents recurrence.Why the Other Options Are Wrong
Two-factor authentication (A) verifies identity but does nothing to restrict what an authenticated administrator can do, so an approved admin can still make unapproved changes alone. Updated emergency change management procedures (B) are valuable but purely administrative; a policy statement cannot physically stop an administrator from bypassing approval, which is exactly what already happened. Regular emergency change-control log reviews (C) are detective controls that surface violations only after changes have occurred, failing the explicit "prevent" requirement. Only D inserts an enforcement checkpoint before a change can be executed.Community Comment Notes
Comments [3] and [4] articulate the winning logic — dual control "requires two individuals to authorize and execute actions," which significantly reduces the risk of unapproved changes. The minority camp, represented by comments [1] and [5], argues procedures must first define how emergency work is performed, but even comment [1] concedes D functions as an added control on top of process. The vote distribution (D: 67, B: 33) shows a clear two-to-one community consensus for the enforcement-based option. This split mirrors a classic CISA debate between documented process and enforced control, with ISACA favoring enforcement for preventive questions.Official Reference
Exam Strategy
When a CISA question asks which control BEST prevents something, pick the option that technically enforces the desired behavior rather than one that documents or detects it. Dual control (two-person integrity) physically requires a second person before an emergency change can execute. Procedure updates and log reviews support the control environment but operate around or after the event.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →