exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 21 discussion

Actual exam question from Isaca's CISA
Question #: 21
Topic #: 1
[All CISA Questions]

Which of the following is the PRIMARY role of the IS auditor in an organization's information classification process?

  • A. Securing information assets in accordance with the classification assigned
  • B. Validating that assets are protected according to assigned classification
  • C. Ensuring classification levels align with regulatory guidelines
  • D. Defining classification levels for information assets within the organization
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
2 months, 3 weeks ago
Selected Answer: B
The IS auditor does not define classification levels (Option D) or directly secure the assets (Option A). Ensuring regulatory alignment (Option C) may be a part of the audit scope, but it is not the primary focus in the context of classification.
upvoted 1 times
10 months, 2 weeks ago
Selected Answer: B
Answer: B
upvoted 1 times
10 months, 3 weeks ago
Selected Answer: C
regulatory is the keyword for me
upvoted 2 times
1 year ago
Selected Answer: D
Primary role is to define
upvoted 1 times
1 year, 1 month ago
Selected Answer: B
Primary role is to validate
upvoted 1 times
1 year, 8 months ago
The main function of the IS (Information Systems) auditor in an organization's information classification process is to ensure that information assets are protected according to the assigned classification. Therefore, the correct option is B. The IS auditor is in charge of evaluating and verifying that adequate security measures are implemented to protect the organization's information assets in accordance with their classification. This involves reviewing existing policies and controls, as well as testing and auditing to ensure assets are effectively protected. While the other options may be additional functions of the IS auditor in relation to the classification of information, the primary function is to ensure that assets are adequately protected based on their assigned classification.
upvoted 2 times
1 year, 8 months ago
La función principal del auditor de SI (Sistemas de Información) en el proceso de clasificación de la información de una organización es asegurar que los activos de información estén protegidos según la clasificación asignada. Por lo tanto, la opción correcta es la B. El auditor de SI se encarga de evaluar y verificar que se implementen las medidas de seguridad adecuadas para proteger los activos de información de la organización de acuerdo con su clasificación. Esto implica revisar las políticas y controles existentes, así como realizar pruebas y auditorías para asegurarse de que los activos estén protegidos de manera efectiva. Si bien las otras opciones pueden ser funciones adicionales del auditor de SI en relación con la clasificación de la información, la función principal es garantizar que los activos estén protegidos adecuadamente según su clasificación asignada.
upvoted 2 times
1 year, 8 months ago
Selected Answer: B
I thought B is better answer than C
upvoted 2 times
1 year, 9 months ago
Selected Answer: C
The IS auditor plays a crucial role in ensuring that an organization's information classification process aligns with regulatory guidelines and industry best practices. They are responsible for assessing the effectiveness and appropriateness of the classification levels assigned to information assets within the organization.
upvoted 3 times
2 years, 6 months ago
Selected Answer: B
The assigned classification may also contain regulatory requirements, so answer B is correct.
upvoted 4 times
2 years, 6 months ago
Why the answer is not C?
upvoted 2 times
2 years, 5 months ago
auditors do not ensure.... its board or top mgt. so B
upvoted 1 times
2 years, 5 months ago
IS auditor should first check the classification criterias (incl regulatory requiremnets) and there after check compliance with such classification. if classification is inappropriate, then complinace with such classification is of no use. Both options C and D are interrelated.. but since there would be other criterias also to ensure whether classification i scorrect or not other than regulatory requiremnets, option to be selected cab be B..
upvoted 2 times
2 years, 5 months ago
i have went with c as of now
upvoted 3 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago