Primary Preventive Method for Privileged Account Risks
Which of the following is the PRIMARY preventive method to mitigate risks associated with privileged accounts?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question distinguishes between preventive and detective controls, trapping candidates who confuse periodic access reviews with proactive risk mitigation.
This CISM question tests the application of least privilege as the primary preventive control for privileged access management. Community consensus strongly favors restricting access based on business need over periodic reviews or monitoring.
Option B (periodic certification) is frequently chosen because it sounds compliant, but it functions as a detective or corrective measure rather than a preventive control.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Implementing the principle of least privilege directly prevents unauthorized access before it occurs, making it the strongest preventive control for privileged accounts. By granting elevated permissions only to users who explicitly require them for their job functions, organizations inherently reduce the attack surface and potential insider threats. This aligns with ISACA’s guidance that prevention must precede detection in security control frameworks.Why the Other Options Are Wrong
Eliminating privileged accounts entirely is operationally impossible since system administration and critical business processes require elevated rights. Periodic access certification serves as a detective or administrative control that identifies existing risks after they have been established. Continuous activity monitoring provides real-time visibility but acts as a detective control rather than preventing the initial authorization or misuse.Community Comment Notes
Multiple high-voted comments correctly identify least privilege as a fundamental security principle that must be applied proactively. Users note that option B resembles corrective or detective measures, which explains the vote split between B and C. The consensus reinforces that preventive strategies should focus on access justification rather than retrospective validation.Official Reference
Exam Strategy
Always classify controls by their timing—preventive stops incidents before they happen, while detective and corrective controls respond after the fact. When options include both access restriction and auditing mechanisms, prioritize the restriction for prevention-focused questions.
Frequently Asked Questions
Why is periodic access certification not preventive?
Periodic certification reviews existing permissions retrospectively, classifying it as a detective or corrective control rather than a proactive prevention measure.
How does least privilege differ from monitoring?
Least privilege restricts initial authorization to prevent misuse, while activity monitoring detects unauthorized actions after they occur.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →