Certified Information Systems Auditor CISA · Free Practice Question Medium
Question 12
You are auditing a company, and during the audit, you discover that employees are permitted to connect their personal devices to company-owned computers. As an auditor, what is the most effective method to validate that adequate security controls are implemented to prevent data loss?
- A A. Review the organization's acceptable use policy for personal devices.
- B B. Conduct an assessment of employee awareness and training programs on data loss prevention.
- C C. Verify that the organization has appropriately configured the data loss prevention (DLP) tool.
- D D. Evaluate the physical security measures implemented for company-owned computers.
Reveal correct answer
Correct answer: C
Explanation
Correct Answer: C. Verify that the organization has appropriately configured the data loss prevention (DLP) tool. Explanation: To validate that appropriate security controls are in place to prevent data loss resulting from employees connecting personal devices to company-owned computers, the IS auditor should focus on the configuration of the data loss prevention (DLP) tool (Option C). A data loss prevention (DLP) tool helps organizations monitor and control the movement of sensitive data, both internally and externally. By verifying that the organization has appropriately configured the DLP tool, the auditor can ensure that it is effectively detecting and preventing unauthorized data transfers or leakage through personal devices. Reviewing the organization's acceptable use policy for personal devices (Option A) is important for understanding the guidelines and restrictions in place. However, it may not provide direct evidence of the effectiveness of security controls and the actual implementation of data loss prevention measures. Conducting an assessment of employee awareness and training programs on data loss prevention (Option B) is valuable for ensuring that employees understand the risks associated with personal devices and the necessary security measures. However, it does not directly validate the implementation of security controls. Evaluating the physical security measures implemented for company-owned computers (Option D) is important for preventing unauthorized physical access. However, it does not specifically address the data loss risks associated with personal device connections. Therefore, the best way to validate that appropriate security controls are in place to prevent data loss in this scenario is to verify that the organization has appropriately configured the data loss prevention (DLP) tool. This ensures that the organization has implemented effective measures to detect and prevent unauthorized data transfers and leakage through personal devices.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
