CISA Protection of Information Assets Practice Question
An IS auditor is evaluating how an organization disposes of decommissioned hard drives that previously stored customer financial records. Management states that drives are physically destroyed by a third-party vendor, but no certificates of destruction are retained and the vendor's personnel perform the destruction at the organization's loading dock without supervision. Which of the following is the MOST important control weakness?
⚠ Common exam trap
The trap here is treating physical destruction as inherently sufficient and overlooking that without supervision and certificates the organization cannot prove the drives were actually destroyed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Destruction is performed without supervision and no certificates of destruction are retained to evidence the disposal.
When a third party destroys media containing customer financial records, the organization remains accountable for the confidentiality of that data. Unsupervised destruction at the loading dock allows drives to be diverted or inadequately destroyed, and the absence of certificates means the organization cannot prove disposal occurred. The auditor should report the lack of supervision and destruction evidence as the most important weakness because it removes both physical control and auditability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical destruction is less secure than software-based overwriting of the drives.
Why it's wrong here
Physical destruction, when properly performed and witnessed, is generally considered more reliable than overwriting because it eliminates the storage medium entirely. The problem in this scenario is not the choice of destruction method but the absence of supervision and documentation. Asserting that overwriting is superior misstates accepted practice and would lead management to abandon an appropriate method rather than fix the real control gap.
- ✗
The third-party vendor has not been assessed for financial stability.
Why it's wrong here
Vendor financial stability is a third-party risk consideration, but it has no bearing on whether data on the drives is securely destroyed. The relevant vendor risk here is the absence of supervision and documentation during destruction, not the vendor's balance sheet. Raising financial stability would misdirect the audit finding away from the data remanence and chain-of-custody risks created by the current disposal practice.
- ✓
Destruction is performed without supervision and no certificates of destruction are retained to evidence the disposal.
Why this is correct
Without supervision, drives could be diverted, swapped, or only partially destroyed, and without certificates there is no evidence that destruction occurred. This combination eliminates accountability and leaves the organization unable to demonstrate compliance with data disposal requirements. For media containing customer financial records, the auditor should report the lack of oversight and documentation as the most important weakness because it directly threatens data confidentiality.
- ✗
Drives should be degaussed before being released to the vendor.
Why it's wrong here
Degaussing is an accepted sanitization method for magnetic media, but the scenario states that the drives are physically destroyed, making pre-degaussing unnecessary if destruction is verified. The genuine weakness is that destruction occurs unsupervised with no certificates. Recommending degaussing would add a step without addressing the accountability and evidence problems that leave the organization unable to prove the drives were destroyed.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.