exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 569 discussion

Actual exam question from Isaca's CISA
Question #: 569
Topic #: 1
[All CISA Questions]

An IS auditor discovers a box of hard drives in a secured location that are overdue for physical destruction. The vendor responsible for this task was never made aware of these hard drives. Which of the following is the BEST course of action to address this issue?

  • A. Evaluate the corporate asset handling policy for potential gaps.
  • B. Examine the workflow to identify gaps in asset handling responsibilities.
  • C. Recommend the drives be sent to the vendor for destruction.
  • D. Escalate the finding to the asset owner for remediation.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pLulu
3 months, 3 weeks ago
B. By examining the workflow, the IS auditor can identify where the breakdown occurred that led to the hard drives not being sent for destruction. This approach helps in understanding the root cause of the issue and ensures that similar problems can be prevented in the future. Simply sending the drives for destruction (option C) addresses the immediate problem but does not resolve the underlying process gaps. Escalating the finding to the asset owner for remediation (option D) is a valid step, but it primarily addresses the immediate issue rather than preventing future occurrences.
upvoted 1 times
...
Infysenthil
8 months, 1 week ago
I believe B is correct. Before making any recommendation, the IS auditor should gain a good understanding of the scope of the problem and what factors caused this incident. The IS auditor should identify whether the issue was caused by managers not following procedures, or by a problem with the workflow of the automated system or a combination of the two.
upvoted 3 times
Swallows
8 months, 1 week ago
I agree with you. I change my selection.
upvoted 1 times
...
...
Swallows
9 months, 1 week ago
Selected Answer: D
While evaluating the corporate asset handling policy for potential gaps (option A) is also important, escalating the finding to the asset owner for remediation ensures swift and direct action to address the immediate issue while also facilitating improvements to prevent recurrence.
upvoted 1 times
...
3008
1 year, 3 months ago
Selected Answer: D
D is correct.
upvoted 1 times
...
Changwha
1 year, 7 months ago
D. Escalate the finding to the asset owner for remediation.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago