Courseiva

CISA Protection of Information Assets Practice Question

During a review of a data center, an IS auditor observes that backup tapes containing customer records are transported nightly by a courier to an offsite vault. The tapes are placed in sealed containers, but the auditor learns that the courier contract does not require background checks for drivers and that no encryption is applied to the tape contents. Which of the following should the auditor recommend as the MOST effective compensating control?

⚠ Common exam trap

The trap here is choosing a physical or contractual control such as insurance or dual custody, which manages custody, instead of a control that protects the data itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement encryption of the backup data before it is written to tape.

The exposure is that unencrypted media leaves the controlled environment in the hands of personnel who have not been screened. Because the confidentiality risk travels with the data, the durable fix is to make the data unreadable to anyone who gains possession of the tape. Encryption at the source neutralizes the threat regardless of courier behavior, while insurance, counting, and dual custody only address custody or recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require two-person integrity for the nightly tape handover at the loading dock.

    Why it's wrong here

    Dual custody at the handover point strengthens physical control at one location but does nothing for the remainder of the route, where the container is in the courier's sole possession. The unvetted driver still has unsupervised access to unencrypted media for the duration of the trip. This control narrows a single window of exposure rather than eliminating the consequence of a lost or copied tape.

  • ✓

    Implement encryption of the backup data before it is written to tape.

    Why this is correct

    Encrypting backup data at the source renders the tapes unreadable if they are lost, stolen, or accessed in transit, directly mitigating the confidentiality risk that the missing courier vetting creates. This is the most effective compensating control because it protects the data itself rather than relying on physical custody. Key management must be handled separately, but the control addresses the exposure at its root.

  • ✗

    Increase the frequency of tape inventory counts at both the data center and the offsite vault.

    Why it's wrong here

    Inventory counts detect missing media after the fact but do not stop a driver or third party from reading or copying tape contents during transit. They improve accountability and chain-of-custody evidence, which is useful for investigation, yet they leave the underlying data exposed. Since the core weakness is unreadable-by-design media, counting tapes more often does not reduce the likelihood or impact of disclosure.

  • ✗

    Require the courier to provide a certificate of insurance covering the value of the tapes in transit.

    Why it's wrong here

    Insurance transfers financial loss but does not prevent disclosure of the customer records on the tapes. If a container is opened or a tape is copied, the data is already compromised regardless of any subsequent payout. Insurance also does not address regulatory notification obligations. As a compensating control for confidentiality, it is ineffective because it operates after the exposure rather than preventing unauthorized access to the media.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.