Certified Information Systems Auditor CISA · Free Practice Question Medium

Question 96

You are an information system auditor of HDA Inc. You are auditing the threat assessment for a data center. In this context, what specific factor or aspect would be of the highest concern to you?
  • A A. The data center has redundant power supply.
  • B B. Physical access controls are in place and monitored.
  • C C. Only external threats are identified.
  • D D. The data center has fire suppression systems.
Reveal correct answer

Correct answer: C

Explanation

Correct Answer: C. Only external threats are identified. Explanation: When conducting a threat assessment for a data center, it is crucial to consider both internal and external threats. Internal threats refer to potential risks arising from individuals within the organization, such as employees, contractors, or vendors, who may have unauthorized access or malicious intent. External threats, on the other hand, originate from outside the organization and include factors like natural disasters, cyber attacks, or physical breaches. Identifying and addressing both internal and external threats is essential for a comprehensive threat assessment. If only external threats are identified, it raises concerns about overlooking potential risks posed by internal individuals who may have access to critical systems, data, or infrastructure. Internal threats can be just as damaging as external threats, and failing to consider them increases the organization's vulnerability to insider threats, data breaches, or unauthorized access. While options A, B, and D highlight important security measures such as redundant power supply, physical access controls, and fire suppression systems, they do not directly address the concern of only identifying external threats. These controls help mitigate risks associated with power outages, unauthorized physical access, and fire incidents, respectively. However, a comprehensive threat assessment should encompass a broader scope that includes both internal and external threats. Therefore, the IS auditor would be most concerned if only external threats are identified in the threat assessment, as it indicates a potential blind spot in addressing internal threats and may leave the organization vulnerable to insider risks and unauthorized activities.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need