Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is assessing how an organization classifies and handles its information assets. The auditor finds that a data classification policy exists but is inconsistently applied across business units. Which TWO of the following are the MOST important elements the auditor should verify are present to support effective data classification? (Choose two.)

⚠ Common exam trap

The trap here is selecting a technology such as a DLP tool or an unrelated assurance activity instead of the governance elements that make classification consistent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A documented mapping of classification levels to specific handling and protection requirements.

Effective classification depends on two foundational elements: an accountable owner for each information asset and a documented mapping from classification levels to specific handling requirements. Ownership drives consistent labeling and review, while the mapping translates labels into enforceable controls. Absent either element, business units interpret classification differently, which explains the inconsistency the auditor observed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A documented mapping of classification levels to specific handling and protection requirements.

    Why this is correct

    A classification scheme must translate labels into concrete handling rules such as encryption, retention, and access restrictions. Without that mapping, users cannot know what a given label requires, producing the inconsistent application the auditor found. Mapping levels to controls is the mechanism that converts a classification decision into measurable, auditable protection.

  • ✗

    Use of a commercial data loss prevention tool to enforce labels.

    Why it's wrong here

    A DLP tool can enforce handling rules once a classification program is mature, but it is a technical enabler rather than a foundational element. Deploying tooling before ownership and handling mappings exist simply automates inconsistency. This option confuses a supporting technology with the core program components the auditor should verify first.

  • ✗

    Annual penetration testing of systems that store classified data.

    Why it's wrong here

    Penetration testing evaluates technical vulnerabilities in systems, not whether data is properly classified and handled across the organization. It is a valuable assurance activity in its own right, but it does not establish the ownership and handling rules that make classification work. This option addresses a different control domain than the classification program under review.

  • ✓

    Defined ownership and accountability for each information asset.

    Why this is correct

    Classification is meaningless without an accountable owner who assigns and maintains the label and the associated handling rules. Ownership ensures that assets are inventoried, classified consistently, and reviewed as their sensitivity changes. Without clear ownership, labels drift and controls become inconsistent, which is exactly the symptom the auditor observed across business units.

  • ✗

    A requirement that all data be stored in a single centralized repository.

    Why it's wrong here

    Centralizing all data in one repository is neither necessary nor practical for effective classification, and it may conflict with business, legal, or performance requirements. Classification governs how data is handled regardless of where it resides. This option imposes an architectural constraint that does not address the inconsistent labeling and handling the auditor identified.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.