ExamGecko
Question list
Search
Search

Related questions











Question 253 - CISA discussion

Report
Export

During an audit of a multinational bank's disposal process, an IS auditor notes several findings. Which of the following should be the auditor's GREATEST concern?

A.
Backup media are not reviewed before disposal.
Answers
A.
Backup media are not reviewed before disposal.
B.
Degaussing is used instead of physical shredding.
Answers
B.
Degaussing is used instead of physical shredding.
C.
Backup media are disposed before the end of the retention period
Answers
C.
Backup media are disposed before the end of the retention period
D.
Hardware is not destroyed by a certified vendor.
Answers
D.
Hardware is not destroyed by a certified vendor.
Suggested answer: C

Explanation:

During an audit of a multinational bank's disposal process, an IS auditor should be most concerned about backup media being disposed before the end of the retention period. This is because backup media contain sensitive and critical data that may be required for business continuity, legal compliance, or forensic purposes. Disposing backup media prematurely may result in data loss, unavailability, or corruption, which may have severe consequences for the bank's reputation, operations, and security. Backup media not being reviewed before disposal, degaussing being used instead of physical shredding, and hardware not being destroyed by a certified vendor are also findings that may pose some risks to the bank's disposal process, but they are not as critical as backup media being disposed before the end of the retention period.Reference:ISACA CISA Review Manual 27th Edition, page 302.

asked 18/09/2024
Nghia To Duc
53 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first