CISA Protection of Information Assets Practice Question
An IS auditor is assessing the physical and environmental controls of a primary data center located in a region subject to seasonal flooding. Management has installed a raised floor, a water detection system, and a pre-action fire suppression system. Which TWO of the following findings would the auditor consider MOST significant? (Choose two.)
⚠ Common exam trap
The trap here is treating any deviation from a generic checklist as a finding, when the scenario's flood exposure makes water detection coverage and standby power siting the findings that actually matter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The generator and fuel storage are located in the basement level of the building.
In a flood-prone region, the dominant threats are water ingress and loss of standby power during the same event. Detection limited to the subfloor leaves overhead leaks unseen, and below-grade generators and fuel can be inundated precisely when they are needed. Both findings undermine continuity for the facility as a whole, whereas the suppression agent, floor rating, and badge access described are appropriate controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The generator and fuel storage are located in the basement level of the building.
Why this is correct
Placing standby power and fuel below grade in a region with seasonal flooding risks losing both the utility feed and the backup supply in the same event, defeating the purpose of redundancy. Floodwater can also make fuel unusable and delay refueling. This is a significant siting weakness that undermines the facility's ability to ride through an extended outage during the flood season.
- ✓
The water detection sensors are installed only under the raised floor and not in the ceiling plenum above the equipment.
Why this is correct
Leaks from chilled water piping, condensate drains, and roof penetrations typically originate above the equipment, so ceiling-plenum detection is essential in a flood-prone facility. Sensors confined to the subfloor leave the most common water entry path unmonitored, and a leak can reach live equipment before anyone is alerted. This is a significant gap in the environmental detection layer.
- ✗
The raised floor tiles are rated for a uniform load capacity that exceeds the weight of the installed racks.
Why it's wrong here
A load rating above the actual rack weight indicates the floor was specified with adequate margin, which is a positive condition rather than a concern. Auditors verify that point loads at rack corners and concentrated server weights remain within tolerance, but nothing in the scenario suggests an overload. This option describes a control working as intended and is not a finding.
- ✗
Access to the computer room is controlled by a badge reader with a documented visitor escort procedure.
Why it's wrong here
Badge-based entry with escorted visitors is a standard and effective physical access control for a data center. It supports individual accountability and prevents unescorted entry by non-personnel. Nothing in the scenario indicates the reader is unmonitored or that escort rules are ignored, so this is evidence of adequate control rather than a deficiency the auditor should report.
- ✗
The fire suppression system discharges a gaseous agent rather than water when activated.
Why it's wrong here
A gaseous agent is appropriate for occupied equipment spaces because it suppresses fire without the collateral damage of water on energized electronics. Pre-action design further reduces accidental discharge. Selecting this as a finding mistakes a sound control for a deficiency, and it does not relate to the flood exposure that the scenario establishes as the governing risk.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.