nerdexam
Isaca

CISA · Question #47

An IS auditor discovers a box of hard drives in a secured location that are overdue for physical destruction. The vendor responsible for this task was never made aware of these hard drives. Which of t

The correct answer is B. Examine the workflow to identify gaps in asset handling responsibilities.. The best course of action is to examine the workflow to identify why the hard drives were not sent for destruction, pinpointing process or responsibility gaps.

Submitted by jakub_pl· Apr 18, 2026Information System Auditing Process

Question

An IS auditor discovers a box of hard drives in a secured location that are overdue for physical destruction. The vendor responsible for this task was never made aware of these hard drives. Which of the following is the BEST course of action to address this issue?

Options

  • AEvaluate the corporate asset handling policy for potential gaps.
  • BExamine the workflow to identify gaps in asset handling responsibilities.
  • CRecommend the drives be sent to the vendor for destruction.
  • DEscalate the finding to the asset owner for remediation.

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    52% (17)
  • C
    30% (10)
  • D
    12% (4)

Why each option

The best course of action is to examine the workflow to identify why the hard drives were not sent for destruction, pinpointing process or responsibility gaps.

AEvaluate the corporate asset handling policy for potential gaps.

While a policy review might be a subsequent step if workflow issues point to policy deficiencies, the immediate problem is a process failure, so examining the workflow is a more targeted first action to diagnose the specific gap.

BExamine the workflow to identify gaps in asset handling responsibilities.Correct

The issue stems from the vendor not being made aware of the hard drives, indicating a breakdown in the established process or workflow for asset disposal. Examining the workflow helps identify where the communication failed or which responsible party missed a step, allowing for a systemic fix to prevent future occurrences of improperly handled assets.

CRecommend the drives be sent to the vendor for destruction.

Recommending sending the drives to the vendor addresses the symptom, not the root cause of why they were not sent in the first place, and thus does not prevent recurrence of the issue.

DEscalate the finding to the asset owner for remediation.

Escalating to the asset owner is appropriate for remediation once the root cause (workflow gap) has been identified, but it is not the initial diagnostic step to understand *why* the process failed.

Concept tested: IT asset disposal workflow audit

Source: https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final

Topics

#Asset destruction#Workflow analysis#Auditor's role#Process control gaps

Community Discussion

No community discussion yet for this question.

Full CISA Practice