Courseiva
easyMultiple Choice

CISA Practice Question: Wants to ensure that its backup tapes are…

An organization wants to ensure that its backup tapes are protected from unauthorized access. Which of the following is the MOST effective control?

⚠ Common exam trap

CISA often tests the distinction between physical, logical, and data-level controls; candidates may choose physical locks or offsite storage because they seem tangible, but the most effective control for protecting data confidentiality is encryption, as it renders the data useless even if other controls fail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encryption of the backup data

Encryption of the backup data is the most effective control because it protects the data itself, regardless of where the tapes are stored or who physically possesses them. Even if tapes are stolen, lost, or accessed without authorization, the data remains unreadable without the encryption keys. This directly addresses the confidentiality of backup data at rest, which is the core requirement. Physical and logical controls can be bypassed, but strong encryption provides a last line of defense.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Physical locks on the tape library

    Why it's wrong here

    Physical locks on the tape library secure tapes only while inside that library; once tapes are removed for transport or offsite rotation, the locks provide no protection. They suit a fixed, single-location library, whereas the scenario requires protection across the tapes' full lifecycle.

  • ✓

    Encryption of the backup data

    Why this is correct

    Encryption renders tape contents unreadable without the decryption key, protecting data even if physical media is lost, stolen or accessed by unauthorised staff. This directly satisfies the requirement to prevent unauthorised access to backup tapes.

  • ✗

    Access control lists on the backup server

    Why it's wrong here

    Access control lists on the backup server govern logical access to data while it resides there; they do not protect tapes once removed and transported, where physical theft is the threat. ACLs suit restricting who can read or restore backups on the server, not safeguarding removable media in transit or storage.

  • ✗

    Offsite storage of tapes

    Why it's wrong here

    Offsite storage relocates tapes but does not itself restrict access; without encryption or physical controls, anyone reaching the offsite facility can read them. It is tempting because offsite placement addresses environmental risk, and it would be correct for disaster recovery, not for preventing unauthorised access.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.