Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 303

Mary Smith

Thu, 16 Apr 2026

CISA—Certified Information Systems Auditor - Part 303

1. Which of the following methods of suppressing a fire in a data center is the MOST effective and environmentally friendly?

A) Halon gas
B) Wet-pipe sprinklers
C) Dry-pipe sprinklers
D) Carbon dioxide gas



2. Which of the following environmental controls is appropriate to protect computer equipment against short-term reductions in electrical power?

A) Power line conditioners
B) Surge protective devices
C) Alternative power supplies
D) Interruptible power supplies



3. An IS auditor inspected a windowless room containing phone switching and networking equipment and documentation binders. The room was equipped with two handheld fire extinguishers-one filled with CO2, the other filled with halon. Which of the following should be given the HIGHEST priority in the auditor's report?

A) The halon extinguisher should be removed because halon has a negative impact on the atmospheric ozone layer.
B) Both fire suppression systems present a risk of suffocation when used in a closed room.
C) The CO2 extinguisher should be removed, because CO2 is ineffective for suppressing fires involving solid combustibles (paper).
D) The documentation binders should be removed from the equipment room to reduce potential risks.



4. Which of the following would be BEST prevented by a raised floor in the computer machine room?

A) Damage of wires around computers and servers
B) A power failure from static electricity
C) Shocks from earthquakes
D) Water flood damage.



5. A penetration test performed as part of evaluating network security:

A) provides assurance that all vulnerabilities are discovered.
B) should be performed without warning the organization's management.
C) exploits the existing vulnerabilities to gain unauthorized access.
D) would not damage the information assets when performed at network perimeters.



1. Right Answer: C
Explanation: Water sprinklers, with an automatic power shutoff system, are accepted as efficient because they can be set to automatic release without threat to life, and water is environmentally friendly.Sprinklers must be dry-pipe to prevent the risk of leakage. Halon is efficient and effective as it does not threaten human life and, therefore, can be set to automatic release, but it is environmentally damaging and very expensive. Water is an acceptable medium but the pipes should be empty to avoid leakage, so a full system is not a viable option. Carbon dioxide is accepted as an environmentally acceptable gas, but it is less efficient because it cannot be set to automatic release in a staffed site since it threatens life.

2. Right Answer: A
Explanation: Power line conditioners are used to compensate for peaks and valleys in the power supply and reduce peaks in the power flow to what is needed by the machine.Any valleys are removed by power stored in the equipment. Surge protection devices protect against high- voltage bursts. Alternative power supplies are intended for computer equipment running for longer periods and are normally coupled with other devices such as an uninterruptible power supply (UPS) to compensate for the power loss until the alternate power supply becomes available. An interruptible power supply would cause the equipment to come down whenever there was a power failure.

3. Right Answer: B
Explanation: Protecting people's lives should always be of highest priority in fire suppression activities. COz and halon both reduce the oxygen ratio in the atmosphere, which can induce serious personal hazards, in many countries installing or refilling halon fire suppression systems is not allowed. Although COz and halon are effective and appropriate for fires involving synthetic combustibles and electrical equipment, they are nearly totally ineffective on solid combustibles (wood and paper).Although not of highest priority, removal of the documentation would probably reduce some of the risks.

4. Right Answer: A
Explanation: The primary reason for having a raised floor is to enable power cables and data cables to be installed underneath the floor. This eliminates the safety and damage risks posed when cables are placed in a spaghetti-like fashion on an open floor. Static electricity should be avoided in the machine room; therefore, measures such as specially manufactured carpet or shoes would be more appropriate for static prevention than a raised floor. Raised floors do not address shocks from earthquakes. To address earthquakes, anti-seismic architecture would be required to establish a quake-resistant structural framework. Computer equipment needs to be protected against water. However, a raised floor would not prevent damage to the machines in the event of overhead water pipe leakage.

5. Right Answer: C
Explanation: Penetration tests are an effective method of identifying real-time risks to an information processing environment. They attempt to break into a live site in order to gain unauthorized access to a system. They do have the potential for damaging information assets or misusing information because they mimic an experienced hacker attacking a live system. On the other hand, penetration tests do not provide assurance that all vulnerabilities are discovered because they are based on a limited number of procedures. Management should provide consent for the test to avoid false alarms to IT personnel or to law enforcement bodies.

0 Comments

Leave a comment