Courseiva
mediumMultiple Choice

CISA Is considering outsourcing its IT help desk Practice Question

An organization is considering outsourcing its IT help desk. Which of the following is a key risk that should be addressed in the outsourcing contract?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inadequate data privacy and security measures

Data privacy and security are critical when outsourcing services that handle sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduced flexibility in service hours

    Why it's wrong here

    Reduced flexibility in service hours is an operational constraint, not a risk of losing control over the outsourced function, so it does not warrant specific contractual mitigation. It is tempting because service coverage is negotiated in contracts, and it would be the correct concern when the requirement is round-the-clock support.

  • ✗

    Lack of technical expertise in the outsourcing provider

    Why it's wrong here

    Provider expertise is assessed during due diligence and vendor selection, not mitigated by contract clauses. It tempts because a weak provider is a genuine operational concern, yet the stem targets risks arising after signing, such as data confidentiality, service continuity and regulatory compliance, which contractual controls must govern.

  • ✗

    Higher cost compared to in-house operations

    Why it's wrong here

    Cost escalation is a commercial concern managed through pricing schedules and benchmarking clauses, not a security risk requiring contractual control. It tempts because outsourcing often raises headline costs, but the stem asks about risk to the organisation's control over its service and data, which pricing terms do not address.

  • ✓

    Inadequate data privacy and security measures

    Why this is correct

    Outsourcing transfers customer and employee data to a third party, so the contract must impose confidentiality, access controls, breach notification and regulatory compliance obligations. Without these, the provider could expose or misuse data, creating legal and reputational risk for the organisation.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.