CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 80


Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?

Show Answer
Correct Answer: D

The greatest concern when reviewing a network printer disposal process is ensuring that any sensitive information is not exposed. Network printers often store sensitive documents, user credentials, and network configurations on their internal hard drives. If the hard drives are not properly sanitized before disposal, this information could be accessed by unauthorized individuals, posing significant security risks. Therefore, the absence of evidence verifying that printer hard drives have been sanitized prior to disposal is the most critical issue.

Discussion

14 comments
Sign in to comment
survivalkitOption: D
Feb 10, 2023

An IS auditor reviewing a network printer disposal process should be most concerned with the evidence available to verify that the hard drives of the printers have been sanitized prior to disposal. The hard drives of network printers may contain sensitive and confidential information, such as confidential documents, user credentials, or network configurations. If this information is not properly sanitized prior to disposal, it could be accessed by unauthorized individuals and potentially used for malicious purposes.

NAJ_88Option: B
Sep 5, 2022

should be C. because the question asking on the process. so to confirm on the p&p is compliance and implemented.

Victor83516
Oct 6, 2022

but you choose the ansewer B...Please resubmit your chose

MunaMOption: D
Sep 4, 2022

can some please confirm which is correct C or D? I think D

srisai_tOption: D
Nov 16, 2022

Whats the right answer? it should be "D" because there is no evidence to support C

katyakOption: C
Nov 15, 2023

I think correct answer is C: not following the disposal policy consistently. All other answers actually shows that policy has not been followed and bears the risk with integrity and confidentiality of information that could be contained on hard drives.

OD1NOption: C
Dec 3, 2023

C is Correct

akosigengenOption: C
Feb 29, 2024

C. is correct

lingtianx1127Option: D
Mar 27, 2024

D is correct

SwallowsOption: D
Apr 6, 2024

Without a disposal certificate, there can be no assurance that the data has been disposed of correctly.

5b56aaeOption: C
Apr 22, 2024

C for me

a84nOption: C
Apr 25, 2024

Answer: C Addressing the consistency of disposal policies and procedures would likely address various risks associated with the printer disposal process, including ensuring the proper sanitization of printer hard drives.

sleekdungaOption: C
May 15, 2024

The answer is C in my opinion, because disposal policies and procedures being inconsistent not only tells the auditor about the printer in question but other printers and devices that have been disposed or that will require disposal in the future. Its easy to think the answer is D, but it C is the best bet, opening the auditor's eyes to what is obtainable with this one printer and several other devices.

HengaOption: C
Jun 11, 2024

Answer is C, and D is the subset of C

46080f2Option: C
Jun 12, 2024

First of all policies and procedures have to be implemented consistently. If A., B. or D. is an issue depends on what has been defined in the policies and procedures afterwards.