Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 539 discussion

Actual exam question from Isaca's CISA
Question #: 539
Topic #: 1
[All CISA Questions]

Which of the following is the MOST reliable way for an IS auditor to evaluate the operational effectiveness of an organization's data loss prevention (DLP) controls?

  • A. Conduct interviews to identify possible data protection vulnerabilities.
  • B. Verify that confidential files cannot be transmitted to a personal USB device.
  • C. Verify that current DLP software is installed on all computer systems.
  • D. Review data classification levels based on industry best practice
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
starzuu
Highly Voted 1 year, 3 months ago
Selected Answer: B
Its B. One of the core functions of a DLP is preventing unauthorized data movements.
upvoted 5 times
...
PurpleParrot
Most Recent 3 months, 2 weeks ago
Selected Answer: B
Option B tests the operational effectiveness
upvoted 1 times
...
Infysenthil
4 months, 2 weeks ago
Testing samples helps to determine operational effectiveness
upvoted 1 times
...
Swallows
5 months, 1 week ago
Selected Answer: B
While verifying the installation of DLP software on all computer systems (option C) is important, it does not directly assess the functionality or effectiveness of the DLP controls in preventing data loss incidents. Testing specific functionalities, such as preventing data transfers to USB devices, provides more direct evidence of the operational effectiveness of the DLP controls.
upvoted 1 times
...
shalota2
5 months, 3 weeks ago
I think is B as it says operational effectiveness. C is more in design.
upvoted 1 times
...
001Yogesh
11 months, 1 week ago
Selected Answer: B
operational effectiveness of an organization's data loss prevention (DLP) controls ---- so it should be B
upvoted 2 times
ChaBum
8 months, 2 weeks ago
USB media storage is a very narrow area of DLP, most of the data happening by mistake are don by attaching the wrong doc in an email
upvoted 1 times
...
...
3008
11 months, 4 weeks ago
Selected Answer: D
D is correct. https://www.isaca.org/resources/isaca-journal/issues/2018/volume-1/data-loss-preventionnext-steps
upvoted 1 times
ChaBum
8 months, 2 weeks ago
there is nothing about Data Classification in the article behind your link
upvoted 1 times
...
NotJamesCharles
11 months, 2 weeks ago
why though?
upvoted 1 times
...
...
Staanlee
1 year, 11 months ago
Selected Answer: D
D is the right answer. Review data classification levels based on industry best practice
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...