Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Backup encryption at rest

Backup encryption at rest ensures that data stored offsite is protected from unauthorized access, which is a key control for offsite backups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Backup compression

    Why it's wrong here

    Backup compression reduces data volume for storage and transfer but applies no cryptographic transformation, so it cannot demonstrate encryption of offsite backups. Compression suits capacity and bandwidth optimisation where confidentiality is handled by a separate mechanism.

  • ✗

    Offsite transport log

    Why it's wrong here

    An offsite transport log records chain of custody and movement of media, not whether the backup data itself was encrypted before leaving the site. Transport logs suit verifying physical handling and delivery of tapes to the offsite facility.

  • ✓

    Backup encryption at rest

    Why this is correct

    Backup encryption at rest protects the transactional log and full backup files stored offsite, directly satisfying the auditor's verification objective. Because log backups occur every 15 minutes, each resulting file must be encrypted before leaving the environment, ensuring confidentiality of data at the offsite storage location.

  • ✗

    Backup verification logs

    Why it's wrong here

    Backup verification logs evidence that restore tests succeeded, confirming data integrity and recoverability rather than encryption of offsite copies. Verification logs suit proving backups are readable and complete, which is a separate control from confidentiality.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.