exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 769 discussion

Actual exam question from Isaca's CISA
Question #: 769
Topic #: 1
[All CISA Questions]

Which of the following would BEST help to support an auditor's conclusion about the effectiveness of an implemented data classification program?

  • A. Access rights provisioned according to scheme
  • B. Detailed data classification scheme
  • C. Purchase of information management tools
  • D. Business use cases and scenarios
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
maxson69
1 month, 3 weeks ago
Selected Answer: A
Effectiveness is about real-world enforcement, and access rights based on classification is the clearest sign that the program is functioning as intended.
upvoted 1 times
maxson69
1 month, 3 weeks ago
Change my mind, the answer should be D because D shows that business units are applying classification in practice that making the program effective across the organization. A is necessary but may only reflect IT enforcement, not broader organizational usage and understanding. It's the best evidence of practical, real-world effectiveness, especially from a business-integrated audit perspective. So, D is the best option.
upvoted 1 times
...
...
9967be3
3 months, 2 weeks ago
Selected Answer: A
Access controls as it show the classification scheme in action.
upvoted 1 times
...
Swallows
1 year, 2 months ago
Selected Answer: D
While having access rights provisioned according to the classification scheme (option A) is important, it alone may not provide a comprehensive view of the program's effectiveness. Business use cases and scenarios offer tangible evidence of how the data classification program contributes to achieving organizational goals and protecting sensitive information, making them the best choice for supporting an auditor's conclusion.
upvoted 2 times
Swallows
1 year ago
Business use cases and scenarios provide insight into how real-world operations use data and what the risks are. These case studies allow auditors to assess whether your data classification program meets real-world business needs.
upvoted 1 times
...
...
shiowbah
1 year, 9 months ago
B. Detailed data classification scheme
upvoted 2 times
shiowbah
1 year, 8 months ago
D. Business use cases and scenarios
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...