CISA Protection of Information Assets Practice Question
An IS auditor is evaluating how an organization detects unauthorized changes to the configuration of its internet-facing web servers. The organization runs a file integrity monitoring tool that hashes critical configuration files hourly and alerts on any hash mismatch. Which of the following is the MOST important factor in determining whether this control provides effective detection?
⚠ Common exam trap
The trap here is focusing on the technical strength of the hashing implementation when the decisive factor is whether anyone reviews and acts on the alerts it produces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alerts generated by the tool are routed to a monitored queue that is reviewed and acted upon.
Detection controls create value only when their alerts are reviewed and acted upon. A file integrity monitoring tool can hash files perfectly and still provide no protection if mismatches are logged to an unmonitored queue. Routing alerts to a staffed queue with defined response procedures connects detection to action, making it the most important factor. Algorithm strength, polling frequency, and baseline placement matter, but each is secondary to whether someone responds to the alert.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The tool uses a well-known cryptographic hash algorithm such as SHA-256.
Why it's wrong here
Using a strong, standard hash algorithm is necessary for the integrity comparison to be meaningful, but it is a baseline technical expectation rather than the factor that decides effectiveness. A properly implemented hash still delivers no protection if alerts are ignored, so algorithm choice is subordinate to whether the detection output is actually consumed and acted upon by the operations team.
- ✗
The baseline of approved file hashes is stored on the same server being monitored.
Why it's wrong here
Storing the approved baseline on the monitored host is a design weakness because an attacker who gains administrative control can alter the baseline to match a malicious change, suppressing the alert. This weakens detection, but the question asks for the most important factor in effectiveness, and a flawed baseline location is one of several possible weaknesses rather than the overarching determinant.
- ✗
The tool hashes files every hour rather than in real time.
Why it's wrong here
Hourly hashing introduces a detection window during which a change may go unnoticed, which is a genuine limitation. However, the scenario asks what most determines whether the control is effective, and a defined window with reliable alerting is generally acceptable for configuration monitoring. The absence of response to alerts is a more fundamental failure than the length of the polling interval.
- ✓
Alerts generated by the tool are routed to a monitored queue that is reviewed and acted upon.
Why this is correct
A detection control is only effective if its output leads to timely investigation and response. Routing alerts to a queue that is actively monitored and acted upon closes the loop between detection and response, ensuring that a hash mismatch actually triggers investigation. Without this, even a technically perfect integrity check produces no security value because no one responds.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.