CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?
⚠ Common exam trap
The trap here is focusing on malware or network performance, which are secondary operational concerns, instead of the organization's inability to control or erase sensitive data on devices it does not manage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unmanaged devices may retain unencrypted copies of protected health information after a clinician leaves the organization.
The defining weakness is that personally owned devices are used for clinical work without enrollment, inspection, or technical controls. That means the organization cannot enforce encryption, remote wipe, or retention limits, so protected health information can persist on hardware it does not own or manage. Data remanence on unmanaged endpoints is the most consequential risk because it directly threatens confidentiality and creates reportable breach exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unmanaged devices may retain unencrypted copies of protected health information after a clinician leaves the organization.
Why this is correct
Without enrollment or inspection, the hospital cannot enforce encryption, remote wipe, or data-retention controls on personally owned devices. Clinical data cached locally on an unmanaged laptop or tablet survives the end of employment, and the organization has no technical means to erase it. This loss of control over protected health information is the most significant exposure because it creates both regulatory breach liability and direct patient-privacy harm.
- ✗
Personal devices may introduce malware that spreads to the EHR application servers.
Why it's wrong here
Malware propagation from an endpoint to a hardened application server is possible but requires additional failures such as missing patching or network segmentation, and server-side controls typically block it. The unmanaged-device gap more directly and reliably exposes data at rest on the endpoint itself. Treating malware spread as the primary risk overstates a conditional threat while understating the certain loss of data control.
- ✗
Clinicians may install unauthorized software that consumes excessive bandwidth on the hospital network.
Why it's wrong here
Bandwidth consumption and shadow IT are real concerns, but they are availability and support issues rather than the primary security consequence. Even significant performance degradation does not expose patient records or trigger regulatory penalties in the way that uncontrolled copies of protected health information do. An auditor would report this as a lower-priority operational finding once the data-loss exposure has been addressed.
- ✗
The acceptable-use agreement may be unenforceable because it was not signed by a witness.
Why it's wrong here
Witness signatures are not a general legal requirement for an acceptable-use agreement to be binding in most jurisdictions, and the scenario does not indicate any dispute over enforceability. The real weakness is the absence of technical controls behind the signed document, not the formality of its execution. Emphasizing contract form over missing device management would misdirect remediation effort.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.