CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 31


An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider

MOST critical?

Show Answer
Correct Answer: D

When reviewing processes for importing market price data from external data providers, the most critical issue is that the transfer protocol is not encrypted. Encryption is essential to ensure the confidentiality and integrity of the data being transferred. Without encryption, the data could be intercepted and potentially altered or misused, leading to significant risks. While data quality and other considerations are important, they become secondary if the data can be compromised during transfer.

Discussion

22 comments
Sign in to comment
frisbg
May 25, 2023

You are importing data from external market provider which makes it authentic source, data quality doesnt need to be monitored as it may only be one source. But transfer protocol should be encrypted both for confidentiality and integrity. Authentication may not even be needed maybe its open to everyone. Answer is clearly D, in all cases you need encryption

Elikplim
Sep 5, 2022

I will go with A. If the quality is already compromised, encryption of the protocol will not be of any help.

BroesweeliesOption: D
Feb 21, 2023

D is the correct answer.

Alyussen
Sep 2, 2022

The answer is D not B because data from external need to be encrypted not monitored

maderon
Sep 7, 2022

I cannot be A. I am debating between B and D.

saado9
Mar 29, 2023

B. The transfer protocol does not require authentication.

Staanlee
Nov 28, 2022

I believe A is the right answer. Market price data is public information and not sensitive. Therefore, the quality of data is important.

saado9
Mar 29, 2023

B. The transfer protocol does not require authentication.

cidigi
Aug 14, 2023

this is public data available to anyone, why do they need to be encrypted?

SwallowsOption: A
Apr 6, 2024

The answer is A. Market prices are not confidential information and need not be encrypted.

Victor83516
Sep 6, 2022

I think B might also be the correct answer. If the transport protocol does not require authentication, how can you be sure that the source of the data stream is correct?

[Removed]Option: D
May 10, 2023

I though D is the answer. Am I wrong?

r9m5Option: A
Sep 13, 2023

In practice, the answer should be A. A is related to the SLA with the vendor and therefore has a direct financial impact and legal impact if it is escalated to a dispute. For option B and D, the party baring the risks and costs is actually the vendor, and hence for the auditor's client, the most concerning finding should be A.

CISA2021Option: D
Jan 14, 2024

The question remark "MOST critical", so it has to be D) rather than A)

crowsaintOption: A
Feb 15, 2024

I Though A is answer. Data quality is most important. There is no need for low quality data. If the data is of a quality appropriate for your business level, you must decide whether to encrypt it or not. This question is about the data brought in.

Pumeza
Nov 6, 2024

B FOR BRAVO

test5y7kq
Dec 19, 2022

Too much assumptions to deduce from these CISA-esque questions.

echo_certOption: B
Feb 23, 2024

The main consideration when relying on data from external source is authenticity of the source

5b56aaeOption: B
Apr 15, 2024

my answer is B

a84nOption: B
Apr 25, 2024

Answer: B

a84n
Apr 25, 2024

Sorry the correct answer is D

SwallowsOption: A
Jul 14, 2024

This is a key concern because if data quality is not monitored, there is a high chance that inaccurate data will enter the system and negatively impact decision-making.

roxannebadenhorstOption: B
Dec 23, 2024

The most critical finding is that the transfer protocol does not require authentication. If the data import process lacks authentication, it opens the system to potential risks such as unauthorized access, data manipulation, or spoofed data submissions from untrusted sources. This compromises the integrity and authenticity of the imported market price data, which could have significant financial and operational consequences.

yadavji12381
Jan 12, 2025

Auditor is reviewing process of "importing market price data from external data providers", if authentication is not in place it will make the organisation import data from unauthorized sources, which is unnecessary and critical since it may get the wrong data. However, transfer of unencrypted data from authorised sources on the network is the most critical as it may compromise the confidentiality.

IlationOption: B
Mar 3, 2025

Without authentication, an attacker can impersonate a legitimate data provider and send manipulated market prices. If authentication is missing, an attacker on the network could intercept the data transfer and insert fraudulent data.