Which term describes an internal control used to avoid undesirable events that could have a negative material effect on a process?

Master ISACA's IT Risk Fundamentals with our comprehensive test preparation. Dive into flashcards and multiple choice questions, complete with hints and explanations, and ensure you're fully prepared for your certification success.

Multiple Choice

Which term describes an internal control used to avoid undesirable events that could have a negative material effect on a process?

Explanation:
Preventive controls are designed to stop problems before they occur, reducing the likelihood that an undesirable event will happen and cause material damage to a process. This proactive approach fits the idea of an internal control used to avoid negative outcomes, with examples such as access controls to prevent unauthorized actions, input validation to catch errors before processing, and separation of duties to reduce opportunities for fraud. In contrast, an IT risk register is simply a record of risks, not a control; qualitative risk analysis and risk analysis are methods for assessing risk, not mechanisms that prevent harm. So the term described is preventive control.

Preventive controls are designed to stop problems before they occur, reducing the likelihood that an undesirable event will happen and cause material damage to a process. This proactive approach fits the idea of an internal control used to avoid negative outcomes, with examples such as access controls to prevent unauthorized actions, input validation to catch errors before processing, and separation of duties to reduce opportunities for fraud. In contrast, an IT risk register is simply a record of risks, not a control; qualitative risk analysis and risk analysis are methods for assessing risk, not mechanisms that prevent harm. So the term described is preventive control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy