IsacaIsaca
CISA · Question #627
CISA Question #627: Real Exam Question with Answer & Explanation
Sign in or unlock CISA to reveal the answer and full explanation for question #627. The question stem and answer options stay visible for context.
Submitted by saadiq_pk· Apr 18, 2026Governance and Management of IT
Question
An international organization collects customer data through internet-enabled fitness devices. Which of the following would be of GREATEST concern to an IS auditor reviewing the organization's privacy policy?
Options
- AThe policy does not mention third-party audits performed for assurance purposes.
- BThe policy does not include the technical details of security measures to protect customer data.
- CThe policy does not mention the jurisdiction under which the organization collects personal data.
- DThe policy does not offer clear mechanisms for users to opt out of data sharing.
Unlock CISA to see the answer
You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Privacy Policy#International Data Regulations#Jurisdiction#IS Audit Concerns