Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is assessing how an organization manages the risk of malicious code on employee workstations. The organization has deployed endpoint detection and response (EDR) agents on all workstations and maintains a centralized console. Which of the following is the MOST important factor in determining whether the EDR deployment effectively reduces malicious code risk?

⚠ Common exam trap

The trap here is treating vendor reputation or console placement as evidence of effectiveness, when detection currency through automatic updates is what determines whether the agent can actually identify malicious code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whether the EDR agents are configured to update their detection signatures and behavioral models automatically.

EDR reduces malicious code risk by detecting known and unknown threats through signatures and behavioral analysis. That capability degrades rapidly if the agent's detection logic is stale. Automatic updates keep both signature databases and behavioral models current, allowing the agent to recognize new variants and techniques. Configuration and response integration matter, but without current detection logic the agent cannot identify the threats it is deployed to stop, so update configuration is the most important factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Whether the EDR agents are installed on servers in addition to workstations.

    Why it's wrong here

    Extending coverage to servers broadens protection and is generally good practice, but the scenario is specifically about employee workstations. Server coverage does not determine whether workstation protection is effective. The auditor's question concerns the workstations already covered, so the decisive factor is how well those agents are maintained and configured, not whether additional platforms are protected.

  • ✗

    Whether the EDR vendor has a large market share among similar organizations.

    Why it's wrong here

    Vendor market share may indicate maturity and ecosystem support, but it does not establish that the deployment in this environment detects and responds to threats. A widely used product can still be misconfigured, unupdated, or poorly integrated. The auditor should evaluate the actual configuration and operational effectiveness rather than relying on popularity as a proxy for control strength.

  • ✓

    Whether the EDR agents are configured to update their detection signatures and behavioral models automatically.

    Why this is correct

    EDR effectiveness depends heavily on current detection logic. If agents do not receive automatic updates to signatures and behavioral models, they will fail to recognize new malware variants and evolving attack techniques. Automatic updating ensures the endpoint can detect threats that emerge after deployment. Without it, the organization retains coverage only for known, older threats, which materially weakens the control's ability to reduce malicious code risk.

  • ✗

    Whether the EDR console is hosted in the same data center as the workstations it monitors.

    Why it's wrong here

    Console location affects latency and network design but is not the primary determinant of detection capability. A cloud-hosted or remote console can manage endpoints effectively provided connectivity and security are maintained. Hosting proximity does not influence whether the agent recognizes malicious behavior. The auditor should focus on detection currency and response capability rather than on where the management console physically resides.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.