Courseiva

CISA Protection of Information Assets Practice Question

During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?

⚠ Common exam trap

CISA often tests the difference between frequency and coverage — candidates pick 'not quarterly' because it sounds like a control gap, but the real issue is that limited scenario coverage leaves the IR plan unvalidated for other incident types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IR plan may not address all relevant incident types

If tabletop exercises only cover malware outbreaks, the incident response plan may not be validated against other relevant incident types such as ransomware, insider threats, DDoS, or data breaches. The greatest concern is that the IR plan has untested gaps for scenarios the organization is likely to face. This is a coverage and validation issue, not a frequency or capability issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IR team may not have adequate forensic capabilities

    Why it's wrong here

    Forensic capability is unaddressed by the finding; tabletop discussions test decision-making and coordination, not evidence acquisition tooling. This concern arises when incident investigations lack artefacts or chain-of-custody, whereas the stem's issue is that non-malware scenarios such as insider or availability events go unpractised.

  • ✗

    The exercises are not conducted quarterly

    Why it's wrong here

    Frequency is not the deficiency here; annual exercises can satisfy many frameworks, and the stem identifies scenario limitation, not scheduling. Quarterly cadence matters where regulations or risk assessments mandate it, but the auditor's concern should target the untested threat types rather than the interval itself.

  • ✗

    The IR team is not following the defined procedures

    Why it's wrong here

    Nothing in the stem indicates the team deviates from documented procedures; the finding concerns scenario coverage, not procedural adherence. Auditors raise this concern when evidence shows steps skipped or runbooks ignored during an actual incident, which is a separate control failure from narrow exercise scope.

  • ✓

    The IR plan may not address all relevant incident types

    Why this is correct

    Restricting tabletop scenarios to malware outbreaks leaves the IR plan untested against other plausible incidents, such as insider misuse, denial of service or data breach. The plan's coverage of relevant incident types therefore remains unverified.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.