CISA · Question #625
Which of the following should be an IS auditor's PRIMARY focus when auditing a file-sharing system used for collaboration among remote teams?
The correct answer is A. Evaluating the encryption and access control mechanisms of the file-sharing system. For a file-sharing system used by remote teams, the primary IS audit concern is whether data is protected through encryption (in transit and at rest) and whether access controls ensure only authorized users can read, write, or share files. These controls directly govern the…
Question
Which of the following should be an IS auditor’s PRIMARY focus when auditing a file-sharing system used for collaboration among remote teams?
Options
- AEvaluating the encryption and access control mechanisms of the file-sharing system
- BEnsuring communications and records are stored according to the organization's data retention
- CReviewing the integration of the file-sharing system with external communication tools
- DAssessing the bandwidth consumption of the file-sharing system
How the community answered
(67 responses)- A94% (63)
- B3% (2)
- C1% (1)
- D1% (1)
Explanation
For a file-sharing system used by remote teams, the primary IS audit concern is whether data is protected through encryption (in transit and at rest) and whether access controls ensure only authorized users can read, write, or share files. These controls directly govern the confidentiality and integrity of organizational data. Data retention (B), integrations (C), and bandwidth (D) are secondary operational considerations, not the core security risk.
Topics
Community Discussion
No community discussion yet for this question.