Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the antivirus and endpoint protection deployment across a hospital's clinical workstations. The auditor finds that signature updates are delivered daily, real-time scanning is enabled on all workstations, but the endpoint protection console shows that 40 of 600 workstations have not checked in for more than 30 days. Which of the following should the auditor do FIRST?

⚠ Common exam trap

The trap here is treating a management console gap as conclusive proof that endpoints are unprotected without first validating whether the devices are still in service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine whether the 40 unmanaged workstations are still in service and whether they have compensating controls.

The missing check-ins could indicate unprotected endpoints, but they could equally reflect decommissioned hardware or devices covered by other controls. An auditor must validate the condition before reporting it, since the characterization of risk depends entirely on whether those 40 workstations are active and what protection they have. Confirming asset status and compensating controls is the logical first step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report a critical finding that 40 workstations are unprotected and could spread malware throughout the hospital network.

    Why it's wrong here

    Reporting immediately without validation risks an inaccurate finding. The devices may no longer be in service, may be isolated, or may run a different endpoint protection product that reports to a separate console. An auditor must gather sufficient appropriate evidence before characterizing the issue as critical. Jumping to a conclusion based on console data alone is premature and could damage the auditor's credibility if the devices turn out to be retired assets.

  • ✗

    Recommend that the organization purchase additional endpoint protection licenses to cover the 40 unmanaged devices.

    Why it's wrong here

    Licensing is not the identified problem. The console shows devices that have not checked in, which may reflect decommissioned hardware, network isolation, or agent failures rather than missing licenses. Recommending a purchase before understanding the root cause would not address the actual condition and could waste resources. The auditor should first determine why the endpoints are not reporting and whether they represent a genuine control gap.

  • ✗

    Verify that the antivirus signature update frequency meets the organization's policy of daily updates.

    Why it's wrong here

    The scenario already states that signature updates are delivered daily, so this is not the gap. The auditor's attention should shift to the endpoints that are not communicating with the management console, since those devices may not be receiving any updates or policy at all. Re-checking a control that is already confirmed to be operating correctly would not address the actual risk indicated by the missing check-ins.

  • ✓

    Determine whether the 40 unmanaged workstations are still in service and whether they have compensating controls.

    Why this is correct

    Before concluding that a control failure exists, the auditor must establish whether those endpoints are still active and what protection they actually have. The 40 devices may be decommissioned, in storage, or covered by an alternate solution, in which case the finding changes significantly. Confirming asset status and compensating controls is the appropriate first step to validate the observation and avoid reporting an inaccurate finding.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.