CISA Practice Question: Information Systems Operations and Business Resilience
An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?
⚠ Common exam trap
Test-takers frequently confuse operational lifecycle tasks (warranty, tagging, benchmarking) with security-specific disposition controls, overlooking that only sanitization and authorized policy directly address data confidentiality and disposal governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure sanitization of storage media
Option C (Secure sanitization of storage media) is correct because decommissioned servers often retain sensitive data on HDDs, SSDs, or NVMe drives, and the auditor must verify that media are wiped using approved methods such as NIST SP 800-88 purge/clear or cryptographic erase, or physically destroyed, before the hardware leaves organizational control. Option D (Formal disposal policy with authorization) is correct because secure disposition requires a documented, approved process that defines roles, disposal methods, chain-of-custody, and management sign-off, ensuring decommissioning is authorized and auditable rather than ad hoc. The unmarked options do not belong: A (Hardware warranty tracking) relates to maintenance and support entitlements, not data-bearing disposition; B (Performance benchmarking) measures system capability and has no bearing on secure disposal; and E (Asset tagging during procurement) is an intake/inventory control that supports tracking but does not itself ensure secure sanitization or authorized disposal at end of life.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardware warranty tracking
Why it's wrong here
Warranty tracking records entitlement dates and support coverage, revealing nothing about data sanitisation or disposal authorisation before a server leaves the estate. It is tempting because warranty data genuinely supports refresh budgeting and vendor claim scheduling, which is where an auditor would correctly test it.
- ✗
Performance benchmarking
Why it's wrong here
Benchmarking measures throughput and latency against baselines, so it produces no evidence about sanitisation, media destruction or chain-of-custody records for retired servers. It is tempting because performance monitoring legitimately supports capacity planning and hardware refresh decisions, where it would be the right control to verify.
- ✓
Secure sanitization of storage media
Why this is correct
Sanitisation destroys residual data on decommissioned server drives, preventing recovery of sensitive information before the hardware leaves organisational control. Verifying this control confirms the confidentiality constraint in the disposition process is met, since disposal without media cleansing exposes data to unauthorised parties.
- ✓
Formal disposal policy with authorization
Why this is correct
A formal disposal policy with documented authorisation ensures decommissioned servers are retired only through approved, accountable channels. Auditors verify this control because it enforces the governance and traceability requirement of the disposition process, preventing asset loss or unauthorised removal.
- ✗
Asset tagging during procurement
Why it's wrong here
Asset tagging at procurement establishes ownership and tracking during the server's working life; it does nothing to sanitise, verify, or document data removal at disposal. It is tempting as an inventory control, and would be correct when auditing acquisition and assignment records instead.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.