nerdexam
Isaca

CISA · Question #492

Which of the following should be of MOST concern to an IS auditor when reviewing the protection of data?

The correct answer is C. Data is not properly classified. Proper data classification is the foundation for applying appropriate protection measures such as encryption, access control, and handling procedures. Without accurate classification, the organization cannot ensure that sensitive data receives the necessary level of protection…

Submitted by rachelw· Apr 18, 2026Protection of Information Assets

Question

Which of the following should be of MOST concern to an IS auditor when reviewing the protection of data?

Options

  • AClassified data is not encrypted.
  • BThe classification scheme is not published.
  • CData is not properly classified.
  • DPasswords are not changed regularly.

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    17% (5)
  • C
    45% (13)
  • D
    28% (8)

Explanation

Proper data classification is the foundation for applying appropriate protection measures such as encryption, access control, and handling procedures. Without accurate classification, the organization cannot ensure that sensitive data receives the necessary level of protection, making this the greatest concern.

Topics

#Data Classification#Data Protection#IS Audit Concerns#Security Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice