Courseiva
Protection of Information AssetsmediumMultiple SelectObjective-mapped

CISA Protection of Information Assets Practice Question

An IS auditor is evaluating the privacy controls of an e-commerce company that collects and processes personal data from customers in multiple jurisdictions, including the European Union (GDPR). The company has a data inventory but has not conducted a privacy impact assessment (PIA) for a new customer analytics platform that processes sensitive data. Which THREE of the following are the MOST critical deficiencies that the auditor should report?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Lack of a privacy impact assessment (PIA) for the new platform

Under GDPR, a PIA is required for high-risk processing. Cross-border transfers without safeguards violate GDPR. Consent management is also a key requirement. Data minimization is a principle, but not necessarily a critical deficiency without context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Inadequate data minimization practices in the platform design

    Why it's wrong here

    While important, it is not as critical as the missing PIA or consent issues.

  • Lack of a privacy impact assessment (PIA) for the new platform

    Why this is correct

    PIA is mandatory for high-risk processing under GDPR.

  • Lack of an up-to-date privacy notice on the website

    Why it's wrong here

    Important but not the most critical deficiency given the scenario.

  • Absence of cross-border data transfer mechanisms such as Standard Contractual Clauses (SCCs)

    Why this is correct

    Cross-border transfers without safeguards violate GDPR.

  • Insufficient consent management processes for data processing

    Why this is correct

    Consent must be obtained and managed properly under GDPR.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.