Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is assessing physical security at a data center that houses the organization's core transaction processing systems. The auditor observes that the main entrance uses a badge reader, but the door to the server hall is propped open with a box while staff move equipment. Which of the following is the auditor's GREATEST concern?

⚠ Common exam trap

The trap here is ranking a missing enhancement or a logging gap above an active control failure, when the propped door represents an immediate, realized exposure of the most critical assets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server hall door being propped open allows unauthorized physical access to critical systems.

Physical access to core transaction systems is a foundational control, and a door propped open removes that barrier entirely, allowing anyone nearby to reach the servers. Because physical proximity enables direct compromise, theft, or sabotage that logical controls cannot prevent, this observation carries the greatest risk. Missing logs, undocumented moves, and the absence of a mantrap are lesser issues by comparison.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The data center lacks a mantrap or interlocking double-door entry at the main entrance.

    Why it's wrong here

    A mantrap adds defense in depth by preventing tailgating, and its absence is worth noting, but it is a design improvement rather than an active breach of protection. The propped door represents a functioning control that has been defeated in practice, creating immediate risk. The auditor should prioritize the realized exposure over a missing enhancement.

  • ✓

    The server hall door being propped open allows unauthorized physical access to critical systems.

    Why this is correct

    A propped door defeats the entire physical access control for the server hall, letting anyone in the vicinity reach the core transaction systems. Physical access often leads to direct compromise, theft, or destruction that logical controls cannot stop. This is the greatest concern because the exposure is immediate, affects the most critical assets, and nullifies the badge-based control design.

  • ✗

    Equipment is being moved without a documented change management ticket.

    Why it's wrong here

    Undocumented equipment moves are a process weakness that could affect asset records and change control, but they do not by themselves expose the systems to unauthorized access. The propped door is a more direct and severe control failure because it removes the physical barrier protecting the transaction processing environment. The auditor should focus on the exposure with the greatest potential impact.

  • ✗

    The badge reader at the main entrance does not record access attempts for later review.

    Why it's wrong here

    Missing audit logs at the entrance is a real weakness because it hinders investigation of who entered, but it is less severe than an open door to the server hall. Logging records events after the fact; a propped door allows immediate unauthorized physical access to the systems themselves. The auditor should prioritize the control failure that directly exposes the assets.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.