nerdexam
Isaca

CISA · Question #639

What would be an IS auditor's BEST recommendation upon discovering that customer records in a database have not been protected?

The correct answer is A. Encrypt the data in the database. Encrypting the data in the database provides the most effective protection for customer records by ensuring confidentiality even if unauthorized access occurs, directly addressing the lack of data protection at rest.

Submitted by olafpl· Apr 18, 2026Protection of Information Assets

Question

What would be an IS auditor’s BEST recommendation upon discovering that customer records in a database have not been protected?

Options

  • AEncrypt the data in the database.
  • BPerform periodic access reviews.
  • CEnsure database patches are installed.
  • DImplement audit logging.

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    4% (1)
  • C
    13% (3)
  • D
    9% (2)

Explanation

Encrypting the data in the database provides the most effective protection for customer records by ensuring confidentiality even if unauthorized access occurs, directly addressing the lack of data protection at rest.

Topics

#Data protection#Encryption#Database security#Confidentiality

Community Discussion

No community discussion yet for this question.

Full CISA Practice