exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 983 discussion

Actual exam question from Isaca's CISA
Question #: 983
Topic #: 1
[All CISA Questions]

An organization has outsourced the maintenance of its customer database to an external vendor, and the vendor has requested live data to test the performance of the database. Which of the following is MOST important for the IS auditor to recommend?

  • A. Ensure sensitive field data is anonymized by random characters.
  • B. Ensure both parties agree the data will be destroyed after the testing is complete.
  • C. Ensure the data is backed up before providing it to the vendor.
  • D. Ensure data transfer details are specified in the service engagement contract.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Staanlee
Highly Voted 1 year, 8 months ago
The correct answer is D, Ensure data transfer details are specified in the service engagement contract. When an organization outsources the maintenance of its customer database to an external vendor, it is important for the IS auditor to ensure that the data transfer details are specified in the service engagement contract. This includes the specific types of data that will be shared with the vendor, the purpose of the data transfer, and any security measures that will be implemented to protect the data during the transfer. By specifying these details in the contract, the organization can ensure that the data transfer is conducted in a secure and transparent manner, and it can help to mitigate the risk of data breaches or unauthorized access to sensitive customer data.
upvoted 6 times
...
SayakSib
Most Recent 3 weeks, 3 days ago
Selected Answer: A
Chat GPT & Google bard is saying A
upvoted 1 times
...
Sibsankar
4 months ago
anonymizing sensitive field data (option A), backing up the data before providing it to the vendor (option C), and specifying data transfer details in the service engagement contract (option D), are important considerations, ensuring an agreement to destroy the data after testing (option B) takes precedence because it directly addresses the risk of data misuse and unauthorized retention. The most appropriate answer is B
upvoted 1 times
...
Swallows
5 months, 1 week ago
Selected Answer: D
Confidentiality of data provided to vendors should be defined.
upvoted 1 times
...
Rachy
7 months, 1 week ago
Selected Answer: D
D is the correct answer. Contract details should include transfer details which are details of what data it will be, the disposed method, the protection and every other details should be specified in the contract
upvoted 2 times
...
FAGFUR
9 months, 3 weeks ago
Selected Answer: B
The most important recommendation for the IS auditor in this scenario is to ensure that both parties agree that the data will be destroyed after the testing is complete. This is crucial to protect the confidentiality and privacy of the customer data. While multiple considerations are important, the most critical recommendation is to ensure a clear agreement that the data will be destroyed after the testing process is complete.
upvoted 1 times
...
galiou12
9 months, 3 weeks ago
Could the answer be A?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago