nerdexam
Isaca

CISA · Question #625

Which of the following should be an IS auditor's PRIMARY focus when auditing a file-sharing system used for collaboration among remote teams?

The correct answer is A. Evaluating the encryption and access control mechanisms of the file-sharing system. For a file-sharing system used by remote teams, the primary IS audit concern is whether data is protected through encryption (in transit and at rest) and whether access controls ensure only authorized users can read, write, or share files. These controls directly govern the…

Submitted by brentm· Apr 18, 2026Protection of Information Assets

Question

Which of the following should be an IS auditor’s PRIMARY focus when auditing a file-sharing system used for collaboration among remote teams?

Options

  • AEvaluating the encryption and access control mechanisms of the file-sharing system
  • BEnsuring communications and records are stored according to the organization's data retention
  • CReviewing the integration of the file-sharing system with external communication tools
  • DAssessing the bandwidth consumption of the file-sharing system

How the community answered

(67 responses)
  • A
    94% (63)
  • B
    3% (2)
  • C
    1% (1)
  • D
    1% (1)

Explanation

For a file-sharing system used by remote teams, the primary IS audit concern is whether data is protected through encryption (in transit and at rest) and whether access controls ensure only authorized users can read, write, or share files. These controls directly govern the confidentiality and integrity of organizational data. Data retention (B), integrations (C), and bandwidth (D) are secondary operational considerations, not the core security risk.

Topics

#Data Security#Access Control#Encryption#Audit Focus

Community Discussion

No community discussion yet for this question.

Full CISA Practice