Certified Internal Auditor (CIA) Part 1: Business Acumen — Question 194

During a review of data center physical security and environmental controls, an auditor should ensure that:
I. Visitors are accompanied by authorized personnel at all times.
II. Only developers and operators have access to the data center.
III. Fire suppression equipment is tested periodically.
IV. Fire and water detectors have been installed.

Answer options

Correct answer: C

Explanation

The correct answer is C because it includes essential measures such as ensuring visitors are always with authorized personnel, periodic testing of fire suppression systems, and the installation of fire and water detectors. Options A, B, and D are incorrect as they omit at least one critical aspect needed to maintain adequate security and safety in the data center.