Courseiva
mediumMultiple Select

CISA Practice Question: Which TWO of the following are essential controls…

Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?

⚠ Common exam trap

A common mix-up: candidates confuse encryption with confidentiality and overlook its role in integrity, or they assume that a single post-migration validation (Option E) is sufficient, ignoring the need for ongoing reconciliation checks (Option D) to detect incremental data loss or corruption during the transfer process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing encryption at rest and in transit

Option B is correct because implementing encryption at rest and in transit protects data from unauthorized modification or interception during transfer and storage, directly preserving integrity throughout the migration. Option D is correct because reconciliation checks that compare source and target data counts (and ideally checksums or hashes) detect any data loss, duplication, or corruption introduced during migration, verifying that the transferred data matches the original. Option A is wrong because granting all team members full database access violates least privilege and increases the risk of accidental or malicious data alteration. Option C is wrong because a phased migration without rollback capability removes the ability to revert corrupted or incomplete transfers, undermining integrity safeguards. Option E is wrong because a single full validation only after migration is too late and too coarse; integrity must be verified continuously or at multiple checkpoints, not once at the end.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Granting all migration team members full database access

    Why it's wrong here

    Granting every migration team member full database access removes least-privilege segregation, letting any member alter or delete records undetected during transfer. It is tempting because broad access speeds up migration tasks, and it would be correct only for a small, fully trusted team working on non-production data.

  • ✓

    Implementing encryption at rest and in transit

    Why this is correct

    Encryption at rest and in transit protects data confidentiality and integrity throughout the migration, satisfying the stem's data-integrity requirement. It prevents tampering or interception while data moves between source and cloud environments, ensuring transferred records remain unaltered and trustworthy.

  • ✗

    Using a phased migration approach without rollback capability

    Why it's wrong here

    Phasing migration without rollback capability leaves no tested path to restore data if a phase corrupts records, undermining integrity assurance. It is tempting because phased cutovers reduce risk exposure per stage, and would be correct when each phase is independently reversible and verified.

  • ✓

    Running reconciliation checks comparing source and target data counts

    Why this is correct

    Reconciliation checks comparing source and target record counts detect any data loss or corruption introduced during transfer, directly verifying the integrity the stem demands. This detective control confirms completeness after migration, catching discrepancies that encryption alone would not reveal.

  • ✗

    Performing a single full data validation after migration

    Why it's wrong here

    A single post-migration validation cannot detect corruption introduced mid-transfer, since no baseline or in-flight reconciliation exists for comparison. It is tempting because it minimises validation effort and downtime, and would be correct for small, static datasets where full re-verification is genuinely feasible.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.