exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 5 discussion

Actual exam question from Isaca's CISA
Question #: 5
Topic #: 1
[All CISA Questions]

Which of the following issues associated with a data center's closed circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?

  • A. CCTV recordings are not regularly reviewed.
  • B. CCTV records are deleted after one year.
  • C. CCTV footage is not recorded 24 x 7.
  • D. CCTV cameras are not installed in break rooms.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cidigi
Highly Voted 1 year, 11 months ago
This is a typiclal ISACA thinking. : The most concerning issue with regards to CCTV surveillance cameras is that CCTV recordings are not regularly reviewed. It is essential for an IS auditor to ensure that recordings are frequently reviewed to ensure that the security of the data center is properly maintained. Additionally, the IS auditor should ensure that CCTV footage is recorded 24 x 7, and records should not be deleted until all necessary procedures are taken. Lastly, CCTV cameras should be installed in break rooms, as these are areas where confidential information may be discussed.
upvoted 6 times
...
I_Shall_Pass
Most Recent 2 weeks, 2 days ago
Selected Answer: A
I was torn between A and C. Then I remembered that often in data centres there are motion activated CCTV cameras, which only start recording if they've detected a motion. 1 year is sufficient time for maintaining the records. As for break rooms, I think it might not even be legal in some cases to have CCTV cameras there (e.g. under GDPR).
upvoted 1 times
...
Eiad1100
3 weeks, 6 days ago
Selected Answer: C
I think the answer is C. Since there is no incident, no one will review the record. So for me, recording everything first 24/7, then reviewing upon needs or incidents.
upvoted 1 times
...
scriptkiddie
5 months, 3 weeks ago
Selected Answer: A
The lack of regular review of CCTV recordings means that security incidents may not be detected in a timely manner​​.
upvoted 1 times
...
B1990
6 months, 1 week ago
Among the given options, the issue that should be of MOST concern to an IS auditor when reviewing a data center's closed circuit television (CCTV) surveillance cameras is: C. CCTV footage is not recorded 24 x 7. The continuous recording of CCTV footage is crucial for maintaining security and ensuring that any security incidents or breaches can be properly investigated. If the CCTV cameras are not recording 24 x 7, there can be significant gaps in the surveillance coverage, leaving the data center vulnerable to undetected security incidents or unauthorized access.
upvoted 3 times
choboanon
3 months, 3 weeks ago
Answer should be A What is worse, footage is recorded 24 x 7 but not reviewed or footage has gaps but a team watches and reviews what's available. Even if there's gaps, footage being at least looked at is more important than 24x7 recording if no one is looking at it.
upvoted 2 times
...
...
a84n
8 months, 2 weeks ago
Selected Answer: A
Answer: A
upvoted 1 times
...
5b56aae
8 months, 3 weeks ago
Selected Answer: A
not being reviewed is the most concern for me
upvoted 1 times
...
Olatoyimika
9 months ago
Answer is C
upvoted 1 times
...
Sibsankar
11 months, 4 weeks ago
recording 24 x 7 of course a concern, but have you ever reviewed the CCTV recording even if the recording is done 8 hours ?
upvoted 1 times
...
crowsaint
1 year, 1 month ago
Selected Answer: A
You don't need to record everything in your data center 24 hours a day. To reduce the amount of review, you can install a motion detector to record only when motion occurs. So the answer is A.
upvoted 3 times
...
Makacha
1 year, 1 month ago
Only if review of recordings means the live viewing by security can A be the correct answer. Otherwise, the correct answer is C.
upvoted 1 times
...
IsaacMyo
1 year, 2 months ago
Why is review more important than the records?
upvoted 1 times
VizVibhor
1 year, 2 months ago
because even if it is been recorded it has to be reviewed otherwise it wont hold any importance
upvoted 1 times
...
...
BA27
1 year, 2 months ago
C. CCTV footage is not recorded 24 x 7
upvoted 2 times
...
[Removed]
1 year, 3 months ago
Selected Answer: C
Who regulary revie recordings from CCTV? Only live viewing by security make sens and then 24/7 is crucial, or reviewing after incident when also 24/7 is crucial.
upvoted 2 times
...
victorchan
1 year, 3 months ago
Even I thought C is correct answer until I realized that without a monitor / review, recording 24 x 7 is of no use as it cannot detect any intrusions. At best it would be a deterrent without monitoring / review but not a detective control which is more effective form of control.
upvoted 2 times
...
PC2323
1 year, 3 months ago
24 X 7 recording if not available, reviews cannot take place
upvoted 1 times
...
fernz
1 year, 4 months ago
Selected Answer: C
I believe the answer is C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago