Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 869 discussion

Actual exam question from Isaca's CISA
Question #: 869
Topic #: 1
[All CISA Questions]

Which of the following management decisions presents the GREATEST risk associated with data leakage?

  • A. Staff is allowed to work remotely.
  • B. There is no requirement for desktops to be encrypted.
  • C. Security awareness training is not provided to staff.
  • D. Security policies have not been updates in the past year.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Vima234
2 months, 2 weeks ago
Selected Answer: C
You're correct in highlighting that without security awareness training, employees might inadvertently cause data leakage in various ways, even if desktop encryption is in place. For instance, they might fall victim to phishing attacks, mishandle sensitive data, use insecure communication channels, or neglect other critical security practices. Lack of security awareness training can lead to a wide range of risks, including data leakage through multiple vectors beyond just unencrypted devices. Employees who are unaware of security best practices are more likely to make mistakes that can compromise data security, regardless of whether their desktops are encrypted. Given this perspective, Option C: Security awareness training is not provided to staff could indeed be considered the greatest risk, as it affects the overall security behavior and practices of the entire organization, potentially leading to data leakage in numerous ways.
upvoted 1 times
...
Swallows
4 months ago
Selected Answer: A
B. Desktop encryption is not required. The decision to not encrypt desktops can also pose significant security risks, but it does not immediately increase the risk of a data breach compared to the ability to work remotely. Encryption is an important security measure, but remote work management may have a greater impact when balancing security measures with the flexibility of remote work.
upvoted 1 times
...
RS66
4 months ago
Selected Answer: A
I say A B would be correct if it was a laptop instead of a desktop. They tricked us. Desktops are not a great concern as there are compensating controls like physical security, cctv, censors and so on ..
upvoted 4 times
...
SuperMax
1 year, 1 month ago
Selected Answer: B
B. There is no requirement for desktops to be encrypted. Not requiring desktops to be encrypted can pose a significant risk because if a laptop or desktop computer is lost or stolen, the data stored on it can be easily accessed by unauthorized individuals. Encryption helps protect the data even if the physical device falls into the wrong hands. Without encryption, sensitive information could be exposed, potentially leading to data leakage, data breaches, and compliance violations. While the other options also present security risks, such as remote work without proper security measures (Option A), lack of security awareness training (Option C), and outdated security policies (Option D), not encrypting desktops can have more immediate and direct consequences in terms of data leakage.
upvoted 2 times
...
007Georgeo
1 year, 6 months ago
Selected Answer: B
B is correct, security awareness training can educate staff about the risks of data leakage and how to prevent it. However, failing to encrypt desktops leaves data vulnerable to theft, and this risk cannot be fully mitigated without encryption.
upvoted 1 times
...
BabaP
1 year, 6 months ago
Selected Answer: B
B is correct, this is about Data leakage
upvoted 1 times
BabaP
1 year, 6 months ago
Not sure but A and C are risks too
upvoted 2 times
...
...
saado9
1 year, 8 months ago
A. Staff is allowed to work remotely.
upvoted 2 times
...
kertyce
1 year, 9 months ago
C is the answer
upvoted 4 times
...
Staanlee
1 year, 10 months ago
The answer should be C. I'm trying to understand how B is the answer.
upvoted 1 times
007Georgeo
1 year, 6 months ago
security awareness training can educate staff about the risks of data leakage and how to prevent it. However, failing to encrypt desktops leaves data vulnerable to theft, and this risk cannot be fully mitigated without encryption.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...