Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's primary transaction processing systems. The auditor observes that the data center uses a single-factor proximity card reader at the main entrance, the server room door is propped open during a vendor maintenance visit, and CCTV cameras record continuously but recordings are retained for only seven days. Which of the following should the auditor identify as the MOST significant control weakness?

⚠ Common exam trap

The trap here is gravitating toward technology gaps such as missing biometrics while overlooking an active physical control failure happening during the audit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server room door was propped open during the vendor visit, defeating the access control boundary.

The propped server room door during a vendor visit is an active failure of the physical access control boundary protecting the transaction processing systems. While single-factor entry, short CCTV retention, and lack of biometrics are all valid observations, none of them currently allows uncontrolled access to the most sensitive area. The auditor should prioritize the real-time breach and require escorted vendor procedures and door alarms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The main entrance uses a single-factor proximity card reader instead of multifactor authentication.

    Why it's wrong here

    Single-factor access at the outer entrance is a legitimate weakness because a lost or cloned card grants entry, but it is a layered control that can be compensated by interior controls such as mantraps, guards, and server room authentication. It is less severe than an open door into the server room itself, since an attacker must still pass additional controls. The auditor should note it as an improvement opportunity rather than the most significant finding.

  • ✗

    CCTV recordings are retained for only seven days rather than the organization's 90-day standard.

    Why it's wrong here

    Short retention limits the ability to investigate incidents discovered after a week, which is a real deficiency in monitoring and evidence preservation. However, it does not enable unauthorized physical access in the way an open server room door does. Retention is a detective and investigative control, whereas the propped door is a preventive control failure. The auditor should report the retention gap but rank it below the active breach of the physical boundary.

  • ✗

    The data center lacks biometric authentication at the server room entrance.

    Why it's wrong here

    Biometrics can strengthen authentication by tying access to a physical characteristic, but their absence is not itself a control failure if other compensating controls such as card plus PIN, guards, or mantraps are present and enforced. The scenario does not state that server room access is unauthenticated, only that the door was propped open. The active bypass of whatever control exists is the more pressing issue for the auditor to report.

  • ✓

    The server room door was propped open during the vendor visit, defeating the access control boundary.

    Why this is correct

    A propped door during a vendor visit directly compromises the physical access control boundary and allows unescorted or unauthorized entry into the area housing critical transaction systems. Unlike the other observations, this is an active control failure occurring in real time that exposes the most sensitive assets. Vendor visits are a known risk period, and the door being held open means the access control system is not actually enforcing who enters the server room, making this the most significant weakness observed.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.