CISA Protection of Information Assets Practice Question
During an audit of incident management processes, the IS auditor reviews past incident reports and conducts interviews. The organization recently experienced a ransomware attack that encrypted critical systems. The incident response team was able to contain the attack but struggled with forensic collection due to lack of pre-defined procedures. Which TWO of the following should the auditor recommend as the HIGHEST priority improvements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting tabletop exercises with the incident response team
Developing forensic procedures ensures proper evidence collection, and regular tabletop exercises improve team readiness. While backup restoration and malware analysis are important, the highest priority is to address the identified gaps in forensics and preparedness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conducting tabletop exercises with the incident response team
Why this is correct
Tabletop exercises test and improve the team's ability to respond effectively.
- ✗
Acquiring advanced malware analysis tools
Why it's wrong here
Tools are helpful but not the highest priority compared to procedures and practice.
- ✗
Implementing a more frequent backup schedule
Why it's wrong here
Backups are important but not the highest priority given the specific findings about forensics.
- ✗
Establishing a formal chain of custody process
Why it's wrong here
Chain of custody is part of forensic procedures, but the broader need is for documented procedures.
- ✓
Developing and documenting forensic investigation procedures
Why this is correct
Lack of forensic procedures was a key issue; documenting them is critical.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.