Topic 5: Exam Pool E
When connecting to an organization's intranet from the Internet, security against unauthorized access is BEST
achieved by using:
A.
screening routers,
B.
virtual private networks (VPNs).
C.
proxy servers.
D.
encryption
screening routers,
Which of the following should an IS auditor expect to find when reviewing IT security policy?
A.
Virus protection Implementation strategies
B.
An inventory of information assets
C.
A risk-based classification of systems
D.
Assigned responsibility for safeguarding company assets
Assigned responsibility for safeguarding company assets
An IS auditor observed that most users do not comply with physical access controls. The business manager has
explained that the control design is inefficient. What is the auditor's BEST course of action?
A.
Work with management to design and implement a better control.
B.
Identify the impact of control failure and report the finding with a risk rating.
C.
Recommend changing the access control process to increase efficiency.
D.
Redesign and retest the physical access control.
Identify the impact of control failure and report the finding with a risk rating.
For a company that outsources payroll processing, which of the following is the BEST way to ensure that only
authorized employees are paid?
A.
Only payroll employees should be given the password for data entry and report retrieval.
B.
Employees should receive pay statements showing gross pay, net pay. and deductions.
C.
The company's bank reconciliations should be independently prepared and checked.
D.
Electronic payroll reports should be independently reviewed.
The company's bank reconciliations should be independently prepared and checked.
Which of the following is the BEST control to protect an organization's sensitive data when using a publicly
available cloud storage service?
A.
Transparent volume encryption offered by the cloud vendor
B.
Data encryption performed by the organization prior to uploading
C.
Transport layer security (TLS) between the cloud vendor and the organization
D.
Cryptographic hash function performed by the cloud vendor
Data encryption performed by the organization prior to uploading
Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?
A.
The scanning will be performed during non-peak hours.
B.
The scanning will be cost-effective.
C.
The scanning will be followed by penetration testing.
D.
The scanning will not degrade system performance.
The scanning will be followed by penetration testing.
When using a wireless device, which of the following BEST ensures confidential access to email via web
mail?
A.
Wired equivalent privacy (WEP)
B.
Hypertext transfer protocol secure (HTTPS)
C.
Simple object access protocol (SOAP)
D.
Extensible markup language (XML)
Hypertext transfer protocol secure (HTTPS)
A new regulatory standard for data privacy requires an organization to protect personally identifiable
information (Pll). Which of the following is MOST important to include in the audit engagement plan to assess
compliance with the new standard?
A.
Review of data protection procedures
B.
Review of data loss risk scenarios
C.
Identification of IT systems that host Pll
D.
Certification of unencrypted Pll
Review of data protection procedures
Which of the following is the MOST important reason to classify a disaster recovery plan (DRP) as
confidential?
A.
Comply with business continuity best practice.
B.
Protect the plan from unauthorized alteration.
C.
Ensure compliance with the data classification policy.
D.
Reduce the risk of data leakage that could lead to an attack.
Ensure compliance with the data classification policy.
Communicating which of the following would BEST encourage management to initiate appropriate actions
following the receipt of report findings?
A.
Statistical sampling used to derive observations
B.
Risk implications of the observations
C.
Strict deadlines to close all observations
D.
Recommendations that align with the business strategy
Recommendations that align with the business strategy
A small organization is experiencing rapid growth and plans to create a new information security policy.
Which of the following is MOST relevant to creating the policy?
A.
Industry standards
B.
The business objectives
C.
The business impact analysis
D.
Previous audit recommendations
The business impact analysis
When auditing the security architecture of an e-commerce environment, an IS auditor should FIRST review
the:
A.
criteria used for selecting the firewall.
B.
location of the firewall within the network.
C.
configuration of the firewall.
D.
alternate firewall arrangements.
criteria used for selecting the firewall.
| Page 55 out of 113 Pages |
| 38394041424344454647484950515253545556575859606162636465666768697071 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.