ExamGecko
Question list
Search
Search

Related questions











Question 968 - CISA discussion

Report
Export

Several unattended laptops containing sensitive customer data were stolen from personnel offices Which of the following would be an IS auditor's BEST recommendation to protect data in case of recurrence?

A.
Encrypt the disk drive.
Answers
A.
Encrypt the disk drive.
B.
Require two-factor authentication
Answers
B.
Require two-factor authentication
C.
Enhance physical security
Answers
C.
Enhance physical security
D.
Require the use of cable locks
Answers
D.
Require the use of cable locks
Suggested answer: A

Explanation:

According to the CISA - Certified Information Systems Auditor Study Guide1, the correct answer to your question is A. Encrypt the disk drive. This is because encryption is a logical security measure that can protect data even if the physical device is stolen or lost. Encryption makes the data unreadable and inaccessible without the proper key or password. The other options are not as effective as encryption in this scenario. Two-factor authentication is a user authentication method that requires two pieces of evidence to verify the user's identity, such as a password and a code sent to a phone. However, this does not prevent unauthorized access to the data if the laptop is already logged in or if the attacker can bypass the authentication. Enhancing physical security is a preventive measure that can reduce the risk of theft, but it does not guarantee that theft will not occur or that the data will be safe if it does. Requiring the use of cable locks is another preventive measure that can deter thieves, but it can also be easily cut or removed by a determined attacker.

asked 18/09/2024
amy ashton
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first