Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is evaluating a data loss prevention (DLP) deployment intended to stop sensitive customer records from leaving a bank's network. Management wants assurance that the solution is operating effectively. Which TWO of the following are the MOST important factors for the auditor to assess? (Choose two.)

⚠ Common exam trap

The trap here is selecting infrastructure or vendor assurance items, such as patching or certifications, that feel like controls but do not demonstrate that the DLP rules detect the right data or that alerts are actually acted upon.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whether alerts generated by the DLP solution are investigated and resolved through a defined incident process.

To judge whether DLP stops sensitive records from leaving, the auditor must confirm the rules reflect the bank's data classifications and workflows, and that generated alerts are investigated and resolved through a defined incident process. These two factors together establish that the control both detects the right events and triggers action. Platform patching, endpoint encryption, and vendor certifications address adjacent concerns but not the operational effectiveness of the DLP control itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Whether alerts generated by the DLP solution are investigated and resolved through a defined incident process.

    Why this is correct

    A DLP tool only reduces risk if alerts lead to investigation and action. Without a defined process that assigns, tracks, and closes alerts, the solution is purely decorative and violations go unaddressed. Assessing the handling process verifies the detective control is actually operational, which is essential before the auditor can conclude the deployment prevents sensitive records from leaving.

  • ✗

    Whether the DLP solution supports encryption of data at rest on endpoint devices.

    Why it's wrong here

    Endpoint encryption is a separate control that protects data if a device is lost or stolen; it does not determine whether DLP detects and blocks exfiltration attempts. The bank's stated objective is stopping records from leaving the network, so endpoint encryption capability is tangential. Focusing on it would divert the audit from the DLP rules and alert handling that actually govern the outcome.

  • ✗

    Whether the DLP vendor is certified to an internationally recognized quality management standard.

    Why it's wrong here

    Vendor quality certifications may inform procurement due diligence, but they say nothing about whether this bank's DLP rules catch its data or whether alerts are acted upon. A certified vendor's product can still be misconfigured or ignored. This factor assesses the supplier, not the effectiveness of the deployed control, and therefore is not among the most important for the auditor's conclusion.

  • ✓

    Whether the DLP rules are tuned to the bank's actual data classifications and business workflows.

    Why this is correct

    DLP effectiveness depends on rules matching the organization's real data classifications and legitimate workflows. If rules are generic or misaligned, the tool will either miss sensitive records or flood analysts with false positives that get ignored. Assessing rule alignment tests whether the control is designed for the specific data and processes it is meant to protect, which is central to concluding the deployment works.

  • ✗

    Whether the DLP server's operating system has the latest vendor-recommended patch level.

    Why it's wrong here

    Patching the DLP server is good infrastructure hygiene, but it is not one of the two most important factors for judging whether DLP stops data exfiltration. A fully patched server with untuned rules and unhandled alerts still fails to protect sensitive records. Patch status addresses the platform's vulnerability exposure, not the control's ability to detect and prevent data loss.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.