ExamGecko
Question list
Search
Search

Related questions











Question 353 - CISA discussion

Report
Export

Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?

A.
Disposal policies and procedures are not consistently implemented
Answers
A.
Disposal policies and procedures are not consistently implemented
B.
Evidence is not available to verify printer hard drives have been sanitized prior to disposal.
Answers
B.
Evidence is not available to verify printer hard drives have been sanitized prior to disposal.
C.
Business units are allowed to dispose printers directly to
Answers
C.
Business units are allowed to dispose printers directly to
D.
Inoperable printers are stored in an unsecured area.
Answers
D.
Inoperable printers are stored in an unsecured area.
Suggested answer: B

Explanation:

The greatest concern for an IS auditor reviewing a network printer disposal process is that evidence is not available to verify printer hard drives have been sanitized prior to disposal. This can expose sensitive data to unauthorized parties and cause data breaches. Disposal policies and procedures not being consistently implemented or business units being allowed to dispose printers directly to vendors are compliance issues, but not as critical as data protection. Inoperable printers being stored in an unsecured area is a physical security issue, but not as severe as data leakage.Reference:ISACA, CISA Review Manual, 27th Edition, 2018, page 387

asked 18/09/2024
Evelina Turco
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first