Courseiva
mediumMultiple Choice

CISA Practice Question: A company's backup policy requires that backup…

A company's backup policy requires that backup tapes be stored offsite for at least one year. During an audit, the auditor finds that the offsite storage facility is not access-controlled and backup tapes are not encrypted. Which of the following is the auditor's BEST recommendation?

⚠ Common exam trap

The trap here is that candidates often focus on physical security controls (like logs or moving tapes) rather than recognizing that data confidentiality is the paramount risk, and encryption is the only option that directly protects the data itself regardless of physical security failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt all backup tapes before sending them offsite

The core issue is that backup tapes contain sensitive data and are stored in an uncontrolled environment. Encrypting the tapes before transport ensures that even if the physical security of the offsite facility is compromised, the data remains confidential. This directly addresses the risk of unauthorized access to the data, which is the primary concern, and is a cost-effective, immediate control that does not disrupt operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Negotiate a new contract with a different offsite storage provider

    Why it's wrong here

    Swapping providers does not guarantee the new facility enforces access control or that tapes are encrypted; the control deficiencies would persist. It is tempting because the current facility is at fault, but remediation must specify access control and encryption regardless of which provider stores the tapes.

  • ✗

    Move the tapes back to the primary site until the offsite facility is secured

    Why it's wrong here

    Returning tapes on site violates the policy requirement for one-year offsite retention, trading one control gap for a policy breach. It is tempting as an immediate risk-reduction step, but the correct recommendation must restore offsite storage while adding access control and encryption.

  • ✗

    Implement a check-in/check-out log for the offsite facility

    Why it's wrong here

    A check-in/check-out log records access after the fact but does not restrict it; the finding is absent access control and absent encryption, so the recommendation must add physical access restriction and encryption. Logging suits environments where access is already controlled and only accountability is missing.

  • ✓

    Encrypt all backup tapes before sending them offsite

    Why this is correct

    Encryption renders tape contents unreadable if the offsite facility is breached, directly mitigating the exposure created by the missing access controls. It is the strongest control available for data at rest in transit to and within third-party storage.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.