Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is examining how an organization classifies and handles its information assets. The auditor finds that the data classification policy defines four sensitivity levels and corresponding handling rules, but the asset inventory does not record a classification for most systems. Which of the following is the MOST likely consequence of this gap?

⚠ Common exam trap

The trap here is accepting the existence of a well-written classification policy as evidence of effective classification, when the inventory shows the labels were never actually assigned.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Handling rules cannot be consistently applied because protection requirements are not tied to specific assets.

A classification scheme only produces security value when each asset is labeled and the label drives the handling rules. Without classification recorded in the inventory, owners cannot determine which baseline applies, so encryption, access restrictions, and disposal methods are chosen inconsistently. The policy becomes documentation rather than an operating control, and the auditor cannot trace requirements to implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The organization will be unable to calculate the depreciated book value of its IT assets.

    Why it's wrong here

    Financial depreciation depends on acquisition cost and accounting policy, not on information classification. The scenario concerns sensitivity labeling, which drives security handling. Confusing asset management accounting with information classification would send the audit toward the fixed-asset register rather than the security control gap, and it does not explain why handling rules would fail to be applied.

  • ✗

    Software license compliance reports will be incomplete because unclassified systems are excluded.

    Why it's wrong here

    License reconciliation depends on installed software and entitlement records, not on classification. A system can be fully licensed and still be unclassified. This distractor substitutes a different inventory attribute for the missing one, and pursuing it would not close the gap between the classification policy and the safeguards actually applied to each system.

  • ✗

    Network bandwidth planning will be inaccurate because traffic volumes per system are unknown.

    Why it's wrong here

    Capacity planning relies on utilization metrics and growth projections, which are unrelated to whether an asset has been assigned a sensitivity level. The absence of classification labels does not impair the measurement of throughput or circuit sizing. Raising this as the consequence misidentifies the control objective and would not help management remediate the classification program.

  • ✓

    Handling rules cannot be consistently applied because protection requirements are not tied to specific assets.

    Why this is correct

    Classification is the mechanism that maps an asset to its required safeguards. If the inventory does not carry a classification label, owners and administrators have no authoritative basis for deciding encryption, access, retention, or disposal requirements, and controls become ad hoc. The policy exists but is inoperable at the asset level, which is the direct and most significant consequence of the missing data.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.