Courseiva
Protection of Information AssetshardMultiple SelectObjective-mapped

CISA Protection of Information Assets Practice Question

During an audit of incident management processes, the IS auditor reviews past incident reports and conducts interviews. The organization recently experienced a ransomware attack that encrypted critical systems. The incident response team was able to contain the attack but struggled with forensic collection due to lack of pre-defined procedures. Which TWO of the following should the auditor recommend as the HIGHEST priority improvements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conducting tabletop exercises with the incident response team

Developing forensic procedures ensures proper evidence collection, and regular tabletop exercises improve team readiness. While backup restoration and malware analysis are important, the highest priority is to address the identified gaps in forensics and preparedness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conducting tabletop exercises with the incident response team

    Why this is correct

    Tabletop exercises test and improve the team's ability to respond effectively.

  • Acquiring advanced malware analysis tools

    Why it's wrong here

    Tools are helpful but not the highest priority compared to procedures and practice.

  • Implementing a more frequent backup schedule

    Why it's wrong here

    Backups are important but not the highest priority given the specific findings about forensics.

  • Establishing a formal chain of custody process

    Why it's wrong here

    Chain of custody is part of forensic procedures, but the broader need is for documented procedures.

  • Developing and documenting forensic investigation procedures

    Why this is correct

    Lack of forensic procedures was a key issue; documenting them is critical.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.