CISA Practice Question: Information Systems Operations and Business Resilience
An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Backup encryption at rest
Backup encryption at rest ensures that data stored offsite is protected from unauthorized access, which is a key control for offsite backups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Backup compression
Why it's wrong here
Backup compression reduces data volume for storage and transfer but applies no cryptographic transformation, so it cannot demonstrate encryption of offsite backups. Compression suits capacity and bandwidth optimisation where confidentiality is handled by a separate mechanism.
- ✗
Offsite transport log
Why it's wrong here
An offsite transport log records chain of custody and movement of media, not whether the backup data itself was encrypted before leaving the site. Transport logs suit verifying physical handling and delivery of tapes to the offsite facility.
- ✓
Backup encryption at rest
Why this is correct
Backup encryption at rest protects the transactional log and full backup files stored offsite, directly satisfying the auditor's verification objective. Because log backups occur every 15 minutes, each resulting file must be encrypted before leaving the environment, ensuring confidentiality of data at the offsite storage location.
- ✗
Backup verification logs
Why it's wrong here
Backup verification logs evidence that restore tests succeeded, confirming data integrity and recoverability rather than encryption of offsite copies. Verification logs suit proving backups are readable and complete, which is a separate control from confidentiality.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.