
Use Real CISA - 100% Cover Real Exam Questions [Oct-2021]
Dumps Brief Outline Of The CISA Exam - ActualTorrent
NEW QUESTION 504
Which of the following is the MOST important element when developing an information security strategy?
- A. Identifying information assets
- B. Determining the risk management methodology
- C. Identifying applicable laws and regulations
- D. Aligning security activities with organizational goals
Answer: D
Explanation:
Section: Governance and Management of IT
NEW QUESTION 505
Which of the following findings should hr of GREATEST concern for an IS auditor when auditing the effectiveness of a phishing simulation test administered for staff members?
- A. Staff members who failed the test did not receive follow-up education
- B. Test results were not communicated to staff members
- C. Staff members were not notified about the test beforehand
- D. Security awareness training was not provided poor to the test
Answer: A
NEW QUESTION 506
Which of the following Is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
- A. Implementation of segregation of duties
- B. Enforcement of the use of digital signatures
- C. Application of single sign-on for access control
- D. Enforcement of an internal data access policy
Answer: D
NEW QUESTION 507
Which significant risk is introduced by running the file transfer protocol (FTP) service on a server in a
demilitarized zone (DMZ)?
- A. FTP services could allow a user to download files from unauthorized sources.
- B. FTP could significantly reduce the performance of a DMZ server.
- C. A hacker may be able to use the FTP service to bypass the firewall.
- D. A user from within could send a file to an unauthorized person.
Answer: C
Explanation:
Section: Protection of Information Assets
Explanation:
Since file transfer protocol (FTP) is considered an insecure protocol, it should not be installed on a server in
a demilitarized zone (DMZ). FTP could allow an unauthorized user to gain access to the network. Sending
files to an unauthorized person and the risk of downloading unauthorized files are not as significant as
having a firewall breach. The presence of the utility does not reduce the performance of a DMZ server;
therefore, performance degradation is not a threat.
NEW QUESTION 508
Which of the following term describes a failure of an electric utility company to supply power within acceptable range?
- A. Sag
- B. EMI
- C. Brownout
- D. Blackout
Answer: C
Explanation:
Explanation/Reference:
The failure of an electric utility company to supply power within acceptable range. Such a failure places a strain on electronic equipment and may limit their operational life or even cause permanent damage.
For CISA exam you should know below information about power failure
Total Failure (Blackout) - A complete loss of electric power, which may span from a single building to an entire geographical are and is often caused by weather conditions or inability of an electric utility company to meet user demands Severely reduced voltage (brownout) - The failure of an electric utility company to supply power within acceptable range. Such a failure places a strain on electronic equipment and may limit their operational life or even cause permanent damage.
Sags, spike and surge - Temporary and rapid decreases (sag) or increases (spike and surges) in a voltage levels. These anomalies can cause loss of data, data corruption, network transmission errors or physical damage to hardware devices.
Electromagnetic interference (EMI) - The electromagnetic interference (EMI) caused by electrical storms or noisy electrical equipments. The interference may cause computer system to hang or crash as well as damages similar to those caused by sags, spike and surges.
The following were incorrect answers:
Sag - Temporarily rapid decrease in a voltage.
Total Failure (Blackout) - A complete loss of electric power, which may span from a single building to an entire geographical are and is often caused by weather conditions or inability of an electric utility company to meet user demands Severely reduced voltage (brownout) - The failure of an electric utility company to supply power within acceptable range. Such a failure places a strain on electronic equipment and may limit their operational life or even cause permanent damage.
Following reference(s) were/was used to create this question:
CISA review manual 2014 Page number372
NEW QUESTION 509
Which of the following is the BEST way to help ensure the security of privacy-related data stored by an organization?
- A. Classify privacy-related data as confidential
- B. Publish the data classification scheme.
- C. Inform data owners of the purpose of collecting information.
- D. Encrypt personally identifiable information.
Answer: A
NEW QUESTION 510
Codes from exploit programs are frequently reused in:
- A. None of the choices.
- B. OS patchers.
- C. trojan horses only.
- D. eavedroppers.
- E. computer viruses only.
- F. trojan horses and computer viruses.
Answer: F
Explanation:
Section: Protection of Information Assets
Explanation:
"The term ""exploit"" generally refers to small programs designed to take advantage of a software flaw that
has been discovered, either remote or local. The code from the exploit program is frequently reused in
trojan horses and computer viruses. In some cases, a vulnerability can lie in a certain programs processing
of a specific file type, such as a non-executable media file."
NEW QUESTION 511
An IS auditor conducting a review of disaster recovery planning (DRP) at a financial
processing organization has discovered the following:
The existing disaster recovery plan was compiled two years earlier by a systems analyst in the organization's IT department using transaction flow projections from the operations department.
The plan was presented to the deputy CEO for approval and formal issue, but it is still awaiting their attention.
The plan has never been updated, tested or circulated to key management and staff, though interviews show that each would know what action to take for its area in the event of a disruptive incident.
The IS auditor's report should recommend that:
- A. a manager coordinates the creation of a new or revised plan within a defined time limit.
- B. the deputy CEO be censured for their failure to approve the plan.
- C. a board of senior managers is set up to review the existing plan.
- D. the existing plan is approved and circulated to all key management and staff.
Answer: A
Explanation:
The primary concern is to establish a workable disaster recovery plan, which reflects current processing volumes to protect the organization from any disruptive incident. Censuring the deputy CEO will not achieve this and is generally not within the scope of an IS auditor to recommend. Establishing a board to review the plan, which is two years out of date, may achieve an updated plan, but is not likely to be a speedy operation, and issuing the existing plan would be folly without first ensuring that it is workable. The best way to achieve a disaster recovery plan in a short time is to make an experienced manager responsible for coordinating the knowledge of other managers into a single, formal document within a defined time limit.
NEW QUESTION 512
When developing a disaster recovery plan, the criteria for determining the acceptable downtime should be the:
- A. maximum tolerable outage.
- B. service delivery objective.
- C. quantity of orphan data.
- D. annualized loss expectancy (ALE).
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The recovery time objective is determined based on the acceptable downtime in case of a disruption of operations, it indicates the maximum tolerable outage that an organization considers to be acceptable before a system or process must resume following a disaster. Choice A is incorrect, because the acceptable downtime would not be determined by the annualized loss expectancy (ALE). Choices B and C are relevant to business continuity, but they are not determined by acceptable downtime.
NEW QUESTION 513
An IS auditor reviewing the implementation of an intrusion detection system (IDS) should be MOST concerned if:
- A. a behavior-based IDS is causing many false alarms.
- B. a signature-based IDS is weak against new types of attacks.
- C. IDS sensors are placed outside of the firewall.
- D. the IDS is used to detect encrypted traffic.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
An intrusion detection system (IDS) cannot detect attacks within encrypted traffic, and it would be a concern if someone was misinformed and thought that the IDS could detect attacks in encrypted traffic. An organization can place sensors outside of the firewall to detect attacks. These sensors are placed in highly sensitive areas and on extranets. Causing many false alarms is normal for a behavior-based IDS, and should not be a matter of concern. Being weak against new types of attacks is also expected from a signature-based IDS, because it can only recognize attacks that have been previously identified.
NEW QUESTION 514
To develop a robust data security program, the FIRST course of action should be to:
- A. perform an inventory of assets.
- B. implement data loss prevention controls.
- C. implement monitoring, controls
- D. interview IT senior management.
Answer: A
NEW QUESTION 515
An organization performs nightly backups but does not have a formal policy. An IS auditor should FIRST:
- A. document a policy for the organization
- B. recommend automated backup
- C. escalate to senior management
- D. evaluate current backup procedures
Answer: D
Explanation:
Section: The process of Auditing Information System
Explanation
NEW QUESTION 516
Which of the following is a continuity plan test that uses actual resources to simulate a system crash to cost-effectively obtain evidence about the plan's effectiveness?
- A. Preparedness test
- B. Post test
- C. Walk-through
- D. Paper test
Answer: A
Explanation:
A preparedness test is a localized version of a full test, wherein resources are expended in the simulation of a system crash. This test is performed regularly on different aspects of the plan and can be a cost-effective way to gradually obtain evidence about the plan's effectiveness. It also provides a means to improve the plan in increments. Incorrect answers:
A. A paper test is a walkthrough of the plan, involving major players in the plan's execution who attempt to determine what might happen in a particular type of service disruption. A paper test usually precedes the preparedness test.
B. A post-test is actually a test phase and is comprised of a group of activities, such as returning all resources to their proper place, disconnecting equipment, returning personnel and deleting all company data from third- party systems.
D. A walk-through is a test involving a simulated disaster situation that tests the preparedness and understanding of management and staff, rather than the actual resources.
NEW QUESTION 517
When auditing a proxy-based firewall, an IS auditor should:
- A. review Address Resolution Protocol (ARP) tables for appropriate mapping between media access control (MAC) and IP addresses.
- B. verify that the filters applied to services such as HTTP are effective.
- C. test whether routing information is forwarded by the firewall.
- D. verify that the firewall is not dropping any forwarded packets.
Answer: B
Explanation:
A proxy-based firewall works as an intermediary (proxy) between the service or application and the client, it makes a connection with the client and opens a different connection with the server and, based on specific filters and rules, analyzes all the traffic between the two connections. Unlike a packet-filtering gateway, a proxy-based firewall does not forward any packets. Mapping between media access control (MAC) and IP addresses is a task for protocols such as Address Resolution Protocol/Reverse Address Resolution Protocol (ARP/RARP).
NEW QUESTION 518
A legacy payroll application is migrated to a new application. Which of the following stakeholders should be PRIMARILY responsible for reviewing and signing-off on the accuracy and completeness of the data before going live?
- A. Data owner
- B. Project manager
- C. IS auditor
- D. Database administrator
Answer: A
Explanation:
During the data conversion stage of a project, the data owner is primarily responsible for reviewing and signing-off that the data are migrated completely, accurately and are valid. An IS auditor is not responsible for reviewing and signing-off on the accuracy of the converted datA . However, an IS auditor should ensure that there is a review and sign-off by the data owner during the data conversion stage of the project. A database administrator's primary responsibility is to maintain the integrity of the database and make the database available to users. A database administrator is not responsible for reviewing migrated datA . A project manager provides day-to-day management and leadership of the project, but is not responsible for the accuracy and integrity of the data.
NEW QUESTION 519
Which of the following would be the MOST secure firewall system?
- A. Screened-host firewall
- B. Screened-subnet firewall
- C. Stateful-inspection firewall
- D. Dual-homed firewall
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
A screened-subnet firewall, also used as a demilitarized zone (DMZ), utilizes two packet filtering routers
and a bastion host. This provides the most secure firewall system, since it supports both network- and
application-level security while defining a separate DMZ network. A screened-host firewall utilizes a packet
filtering router and a bastion host. This approach implements basic network layer security (packet filtering)
and application server security (proxy services). A dual- homed firewall system is a more restrictive form of
a screened-host firewall system, configuring one interface for information servers and another for private
network host computers. A stateful-inspection firewall working at the transport layer keeps track of the
destination IP address of each packet that leaves the organization's internal network and allows a reply
from the recorded IP addresses.
NEW QUESTION 520
Which of the following validation techniques would BEST prevent duplicate electronic vouchers?
- A. Sequence check
- B. Edit check
- C. Cyclic redundancy check
- D. Reasonless check
Answer: A
NEW QUESTION 521
A database administrator (DBA) extracts a user listing for an auditor as testing evidence. Which of the following will provide the GREATEST assurance that the user listing is reliable?
- A. Obtaining sign-off from the DBA to attest that the list is complete
- B. Witnessing the DBA running the query in-person
- C. Requesting a query that returns the count of the users
- D. Requesting a copy of the query that generated the user listing
Answer: A
NEW QUESTION 522
......
Certification Training for CISA Exam Dumps Test Engine: https://www.actualtorrent.com/CISA-questions-answers.html
CISA Training & Certification Get Latest Isaca Certification : https://drive.google.com/open?id=1kNZFlkCAoUykN444Kwi48D8PB_xdL_N_