An IS auditor learns of a new regulation which imposes penalties based on the number of individuals whose personally identifiable information (PII) is exposed by a security breach. What would be the BEST recommendation to help the organization limit the liability associated with a breach to its customer information database?
Correct Answer: A
The best recommendation is database segmentation. If liability depends on the number of individuals whose PII is exposed, the organization should reduce the amount of data that could be compromised in any single breach event. Segmenting databases or separating sensitive data domains limits blast radius and can reduce the number of records exposed in a single incident. ISACA guidance supports isolating high-value assets and tightening internal controls as a way to reduce exposure and improve resilience. Option A is correct because segmentation limits concentration risk. Instead of keeping all customer data in one broadly exposed logical store, segmentation helps confine access and reduce how many records a single compromise can reach. This directly supports limiting breach impact and, in this case, potential liability tied to the number of affected individuals. This conclusion is an inference from ISACA's risk-reduction principles around isolation, exposure control, and documenting exposure. Option B is incorrect because database normalization improves data structure and reduces redundancy; it is not primarily a breach-liability reduction control. Option C is incorrect because database harmonization is about consistency or integration across datasets, not limiting exposure in a breach. Option D is incorrect because database optimization focuses on performance and efficiency, not on minimizing the number of PII records exposed in a security incident. Therefore, A is the best answer because segmentation is the option that most directly reduces the scope of exposure in a breach and therefore helps limit liability based on affected individuals. References (Official ISACA): ISACA, Best Practices for Setting Up a Cybersecurity Operations Center - recommends prioritizing assets and isolating high-value asset networks. ISACA Journal, Reporting on GDPR Compliance to the Board - emphasizes documenting exposure and relevant risk controls for privacy risk reporting. ISACA Journal, Practical Data Security and Privacy for GDPR and CCPA - supports governance approaches to limiting privacy exposure. (Referenced conceptually from prior ISACA privacy guidance.)
CISA Exam Question 127
A vendor requires privileged access to a key business application. Which of the following is the BEST recommendation to reduce the risk of data leakage?
Correct Answer: A
A vendor requires privileged access to a key business application. The best recommendation to reduce the risk of data leakage is to implement real-time activity monitoring for privileged roles. This is because real-time activity monitoring can provide visibility and accountability for the actions performed by the vendor with privileged access, such as creating, modifying, deleting, or copying data. Real-time activity monitoring can also enable timely detection and response to any unauthorized or suspicious activities that may indicate data leakage. Including the right-to-audit in the vendor contract is a good practice, but it may not be sufficient to prevent or detect data leakage in a timely manner, as audits are usually performed periodically or on-demand. Performing a review of privileged roles and responsibilities is also a good practice, but it may not address the specific risk of data leakage by the vendor with privileged access. Requiring the vendor to implement job rotation for privileged roles may reduce the risk of collusion or fraud, but it may not prevent or detect data leakage by any individual with privileged access. References: CISA Review Manual (Digital Version), [ISACA Privacy Principles and Program Management Guide]
CISA Exam Question 128
Which of the following is MOST important for an IS auditor to verify when reviewing the use of an outsourcer for disposal of storage media?
Correct Answer: A
The most important thing for an IS auditor to verify when reviewing the use of an outsourcer for disposal of storage media is that the vendor's process appropriately sanitizes the media before disposal. As explained in the previous question, storage media may contain sensitive or confidential information that needs to be protected from unauthorized access, disclosure, or misuse. The IS auditor should verify that the vendor has a process that appropriately sanitizes the media before disposal, such as wiping, degaussing, shredding, or incinerating, and that the process is effective and compliant with the organization's policies and standards. The other options are not as important as verifying the vendor's process, because they either do not ensure the security and privacy of the information on the media, or they are secondary to the vendor's process. References: CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.7
CISA Exam Question 129
An organization uses an automated continuous integration/continuous deployment (CI/CD) tool to deploy changes to production. Which of the following would be an IS auditor ' s GREATEST concern in this situation?
Correct Answer: C
The greatest concern in a CI/CD environment is the accuracy of automated testing. Since code is deployed rapidly and often without manual intervention, weak or inaccurate test cases can allow vulnerabilities and defects to be pushed directly into production. Release frequency (A) and changing user requirements (D) are expected characteristics of agile/DevOps models and can be managed with governance. Delayed post- implementation reviews (B) may reduce oversight but do not directly undermine the core pipeline integrity. ISACA's DevOps guidance emphasizes that automated testing and validation of requirements must be thorough and reliable to ensure continuous deployment does not compromise quality or security. References (ISACA): COBIT Focus Area for DevOps; BAI06 Managed IT Changes.
CISA Exam Question 130
After delivering an audit report, the audit manager discovers that evidence was overlooked during the audit This evidence indicates that a procedural control may have failed and could contradict a conclusion of the audit Which of the following risks is MOST affected by this oversight?
Correct Answer: C
The risk that is most affected by this oversight is audit risk. Audit risk is the risk that the auditor may express an inappropriate opinion or conclusion based on the audit evidence obtained. Audit risk consists of inherent risk, control risk, and detection risk. Inherent risk is the risk that material errors or frauds exist in the audited area before considering the effectiveness of internal controls. Control risk is the risk that the internal controls fail to prevent or detect material errors or frauds. Detection risk is the risk that the auditor fails to identify material errors or frauds using the audit procedures performed. In this case, the auditor has overlooked evidence that could contradict a conclusion of the audit, which increases the detection risk and consequently the audit risk. References: * CISA Review Manual (Digital Version), Chapter 2, Section 2.31 * CISA Online Review Course, Domain 1, Module 1, Lesson 32