CISA Protection of Information Assets Practice Question
An IS auditor is reviewing an organization's endpoint protection controls after several employees reported slow performance on their laptops. The auditor observes that the anti-malware solution performs a full disk scan every night, and the audit log shows that the last successful signature update was 47 days ago. Which of the following is the MOST significant concern the auditor should report?
⚠ Common exam trap
The trap here is focusing on the visible performance complaints from users instead of recognizing that stale signatures silently neutralize the anti-malware control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The anti-malware signature database has not been updated for 47 days, leaving endpoints exposed to recent threats.
The most significant concern is that endpoint protection is running with signatures that are 47 days old, which means the control cannot detect recently identified malware. A deployed but outdated anti-malware solution provides a false sense of security because it appears active yet fails against current threats. Performance and scheduling issues are secondary operational matters, while the stale signature database is a direct, measurable weakness in the protection of information assets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The nightly full disk scan consumes excessive endpoint resources and degrades user productivity.
Why it's wrong here
Full disk scans are resource-intensive, but performance degradation is an operational efficiency issue rather than a control failure. The far more serious problem is that the endpoint protection is operating with signatures that are 47 days old, meaning the solution cannot detect newly emerged malware variants. Reporting resource consumption would divert management attention from the actual loss of preventive capability.
- ✗
The organization has not implemented application whitelisting to complement the anti-malware solution.
Why it's wrong here
Application whitelisting is a valuable defense-in-depth control, but its absence is not the most urgent finding in this scenario. Many mature organizations rely on layered controls without whitelisting and still maintain adequate protection. The immediate, demonstrable failure is the stale signature database, which leaves a deployed control effectively blind to current threats.
- ✗
The full disk scan schedule conflicts with the organization's backup window and may cause backup failures.
Why it's wrong here
A scheduling conflict between scanning and backup is a plausible operational risk worth investigating, but the scenario does not state that backups are failing. The confirmed evidence is the 47-day signature gap, which is an actual control deficiency rather than a hypothetical scheduling concern. Auditors should report confirmed exposures over speculative ones.
- ✓
The anti-malware signature database has not been updated for 47 days, leaving endpoints exposed to recent threats.
Why this is correct
Signature files that are 47 days stale mean newly discovered malware families and variants cannot be detected by the endpoint control. This directly defeats the preventive purpose of the anti-malware solution and represents a material gap in the protection of information assets. The auditor should report this as the primary concern because it exposes the organization to known, circulating threats.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.