CISA Protection of Information Assets Practice Question
An IS auditor is evaluating a cloud service provider's (CSP) security posture before the organization migrates a customer-facing application to the provider's infrastructure as a service (IaaS) environment. The auditor is reviewing the shared responsibility model and the provider's assurance documentation. Which TWO of the following are the auditor's MOST important considerations? (Choose two.)
⚠ Common exam trap
The trap here is treating a provider's marketing claims or certifications at face value without confirming the scope and the split of responsibilities under the shared responsibility model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirming which security controls remain the organization's responsibility under the shared responsibility model.
Under the IaaS shared responsibility model, the provider secures the underlying infrastructure while the customer remains accountable for the guest operating system, applications, data, and identities. The auditor must therefore establish exactly where the responsibility boundary lies and obtain independent assurance, such as a SOC 2 Type II report, that the provider's controls operated effectively over time. Together these give the organization a reliable basis for relying on the provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confirming which security controls remain the organization's responsibility under the shared responsibility model.
Why this is correct
In an IaaS engagement the provider secures the physical facilities, hosts, and hypervisor, while the customer remains responsible for guest operating systems, applications, data, and identity management. If the auditor does not clearly establish the boundary, controls may fall into a gap where each party assumes the other is responsible. Mapping responsibilities explicitly is therefore essential before relying on the provider's certifications or contractual commitments.
- ✗
Confirming that the provider offers the lowest price among competing CSPs for equivalent compute capacity.
Why it's wrong here
Price comparison is a procurement activity and does not address security posture or control effectiveness. The auditor's role is to assess whether the provider can protect the organization's information assets and meet compliance obligations. While cost is a legitimate business factor, it is outside the scope of a security posture evaluation and would not help the auditor determine whether risks have been adequately mitigated by the provider's controls.
- ✗
Reviewing the provider's marketing materials describing its security certifications and awards.
Why it's wrong here
Marketing materials are unaudited and selectively presented, so they cannot substitute for independent assurance. An auditor needs to examine the actual certification scope and the underlying audit report, not promotional summaries. A provider may hold a certification that does not cover the specific services the organization will consume. Relying on marketing content would give the auditor a false sense of assurance and is not a valid audit evidence source.
- ✗
Verifying that the provider's data center is located in a country with lower operating costs.
Why it's wrong here
Cost efficiency is a business consideration, not a security assurance objective. The auditor's focus should be on control effectiveness, data protection, and regulatory compliance. A lower-cost location may even introduce additional legal or privacy risks, such as conflicting data protection regimes. While location matters for data residency and legal jurisdiction, framing it as a cost advantage misstates the auditor's security evaluation objective.
- ✓
Obtaining and evaluating an independent assurance report such as SOC 2 Type II covering the provider's control environment.
Why this is correct
A SOC 2 Type II report provides independent evidence that the provider's controls operated effectively over a period of time, which is far stronger than a self-attestation or marketing claim. The auditor should examine the scope, the period covered, the testing performed, and any exceptions noted. This gives the organization a basis to rely on the provider's controls and to identify areas where additional customer-side controls are needed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.