Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's core banking platform. During the walkthrough, the auditor notes that the mantrap entrance functions correctly, but the loading dock door is propped open for ventilation and the CCTV system records only the main corridor. Which TWO of the following findings should the auditor report as control weaknesses? (Choose two.)

⚠ Common exam trap

The trap here is reporting assumptions about controls that were not observed, such as missing biometrics or escort policies, instead of the two weaknesses actually seen during the walkthrough.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CCTV coverage does not include the loading dock or other areas outside the main corridor.

The walkthrough produced two concrete observations that weaken physical security: the loading dock door is propped open, bypassing the perimeter, and CCTV covers only the main corridor, leaving other areas unmonitored. Both conditions create opportunities for unauthorized entry and undetected activity. The functioning mantrap is not a weakness, and the scenario provides no evidence about biometric authentication or visitor escort policies, so those cannot be reported as findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The organization has not implemented a formal visitor escort policy for the data center.

    Why it's wrong here

    The scenario provides no information about visitor escort policies, so this finding is not supported by the walkthrough observations. Auditors must base findings on evidence gathered during the review, not on assumptions about controls that were not examined. The two observed deficiencies are the propped loading dock door and the incomplete CCTV coverage, both of which were directly noted during the walkthrough.

  • ✗

    The data center does not use biometric authentication at the mantrap entrance.

    Why it's wrong here

    The scenario does not state what authentication method the mantrap uses, so concluding that biometrics are absent is speculative. Biometric authentication is one option among several acceptable methods, including smart cards with PINs. Without evidence that the current method is inadequate, the auditor cannot report this as a weakness. The confirmed issues are the propped door and the limited camera coverage.

  • ✓

    CCTV coverage does not include the loading dock or other areas outside the main corridor.

    Why this is correct

    Video surveillance that covers only the main corridor leaves the loading dock and other sensitive areas unmonitored, creating blind spots where unauthorized activity could occur undetected. Because the loading dock is already identified as an uncontrolled entry point, the absence of camera coverage there compounds the risk. The auditor should report the incomplete CCTV coverage as a control weakness that limits detection and investigation capability.

  • ✓

    The loading dock door is propped open, bypassing the physical perimeter control.

    Why this is correct

    A propped-open loading dock door defeats the perimeter control by allowing unescorted entry into the facility, regardless of how well the mantrap functions. This is a concrete, observed weakness that undermines the entire physical access control layer. The auditor should report it because an attacker or unauthorized individual could enter through the dock and bypass the primary entrance controls entirely.

  • ✗

    The mantrap entrance allows only one person to enter at a time and slows authorized staff.

    Why it's wrong here

    A mantrap that admits one person at a time is functioning as designed to prevent tailgating. Slowing authorized staff is an expected trade-off of this control, not a weakness. Reporting it would mischaracterize a properly operating control as a deficiency. The auditor should focus on the loading dock and CCTV coverage, which are actual gaps in the physical protection of the data center.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.