CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the data backup strategy for a hospital's electronic health record (EHR) system. The auditor finds that full backups are performed weekly, with daily incremental backups, but the backup tapes are stored in the same server room as the production system. Which of the following is the MOST significant finding?
⚠ Common exam trap
The trap here is focusing on backup frequency or encryption while overlooking the fundamental physical security principle that backups must be stored separately from the source data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The backup tapes are stored in the same location as the production system, creating a single point of failure.
Storing backup media in the same physical location as the production system creates a single point of failure. A disaster such as a fire or flood could destroy both the original data and the backups, rendering recovery impossible. Best practice requires that backups be stored offsite or in a geographically separate location to ensure availability and support disaster recovery objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The backup tapes are stored in the same location as the production system, creating a single point of failure.
Why this is correct
Storing backups in the same room as the production system means that a fire, flood, or other physical disaster could destroy both the original data and its backups, making recovery impossible. This is a critical control weakness because it defeats the purpose of backups. Offsite storage is a fundamental requirement for disaster recovery, especially for critical systems like an EHR.
- ✗
The backup process lacks a documented restoration testing procedure.
Why it's wrong here
The absence of restoration testing is a valid concern, but the scenario does not mention whether testing is performed or documented. The explicit finding is the co-location of backups with production. While testing is important, the immediate and undeniable risk is that a single disaster could eliminate both data copies, which is a more severe and certain finding.
- ✗
The backup schedule does not meet the recovery point objective (RPO) for the EHR system.
Why it's wrong here
The RPO defines the maximum acceptable data loss. Daily incremental backups may or may not meet the RPO; the scenario does not specify the RPO, so the auditor cannot conclude this is the most significant finding. The critical issue is the lack of offsite storage, which jeopardizes recovery from a site-wide disaster, not the backup frequency itself.
- ✗
The backup tapes are not encrypted, exposing sensitive patient data.
Why it's wrong here
While encryption of backup media is important for protecting PHI, the scenario does not state that the tapes are unencrypted. The auditor's finding is about physical storage location, not encryption. Even if encryption were absent, the lack of offsite storage is a more fundamental threat to availability and recovery, which are primary concerns for an EHR system.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.