Latest 2024 Realistic Verified CISA Dumps - 100% Free CISA Exam Dumps [Q505-Q521]

Share

Latest 2024 Realistic Verified CISA Dumps - 100% Free CISA Exam Dumps

Get 2024 Updated Free ISACA CISA Exam Questions and Answer


How to Schedule the ISACA CISA Exam?

After registration and paying the fee, you will get a confirmation email, you can schedule your exam by clicking that link in the email. You can also schedule by logging to your account. The CISA test is offered more than 50 times a year at various locations around the world, you can set time according to your ease, for example, Aug, Sep, Oct, Feb Apr, Jul whenever you want. You can also have a mid-year or quarterly break for better preparation for the exam. So it will not be much harder to find one that fits your schedule.

 

NEW QUESTION # 505
What is the difference between a threat and a vulnerability?

  • A. Vulnerabilities are a path that can be taken by a threat, resulting in a loss.
  • B. Vulnerability is a negative event that will cause a loss if it occurs.
  • C. Threats are risks and become a vulnerability if they occur.
  • D. Threats are the path that can be exploited by a vulnerability.

Answer: A

Explanation:
Assets are anything of value. Threats are negative events that cause a loss if they occur.
Vulnerabilities are paths that allow a threat to occur.


NEW QUESTION # 506
An organization's strategy to source certain IT functions from a Software as a Service (SaaS) provider should be approved by the:

  • A. chief financial officer (CFO).
  • B. IT steering committee
  • C. chief risk officer (CRO)
  • D. IT operations manager

Answer: D


NEW QUESTION # 507
Which of the following BEST facilitates the management of assets dunng the implementation of an information system?

  • A. Configuration management database (CMDB)
  • B. Quality management controls
  • C. Asset procurement system
  • D. Decision support system

Answer: A


NEW QUESTION # 508
A client/server configuration will:

  • A. enhance system performance through the separation of front-end and back-end processes.
  • B. keep track of all the clients using the IS facilities of a service organization.
  • C. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
  • D. optimize system performance by having a server on a front-end and clients on a host.

Answer: A


NEW QUESTION # 509
During a change control audit of a production system, an IS auditor finds that the change management process is not formally documented and that some migration procedures failed. What should the IS auditor do next?

  • A. Recommend redesigning the change management process.
  • B. Recommend that program migration be stopped until the change process is documented.
  • C. Gain more assurance on the findings through root cause analysis.
  • D. Document the finding and present it to management.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A change management process is critical to IT production systems. Before recommending that the organization take any other action (e.g., stopping migrations, redesigning the change management process), the IS auditor should gain assurance that the incidents reported are related to deficiencies in the change management process and not caused by some process other than change management.


NEW QUESTION # 510
Which of the following Confidentiality, Integrity, Availability (CIA) attribute supports the principle of least privilege by providing access to information only to authorized and intended users?

  • A. Availability
  • B. Integrity
  • C. Confidentiality
  • D. Accuracy

Answer: C

Explanation:
Explanation/Reference:
Confidentiality supports the principle of "least privilege" by providing that only authorized individuals, processes, or systems should have access to information on a need-to-know basis.
The level of access that an authorized individual should have is at the level necessary for them to do their job. In recent years, much press has been dedicated to the privacy of information and the need to protect it from individuals, who may be able to commit crimes by viewing the information.
Identity theft is the act of assuming one's identity through knowledge of confidential information obtained from various sources.
An important measure to ensure confidentiality of information is data classification. This helps to determine who should have access to the information (public, internal use only, or confidential). Identification, authentication, and authorization through access controls are practices that support maintaining the confidentiality of information.
A sample control for protecting confidentiality is to encrypt information. Encryption of information limits the usability of the information in the event it is accessible to an unauthorized person.
For your exam you should know the information below:
Integrity
Integrity is the principle that information should be protected from intentional, unauthorized, or accidental changes.
Information stored in files, databases, systems, and networks must be relied upon to accurately process transactions and provide accurate information for business decision making. Controls are put in place to ensure that information is modified through accepted practices.
Sample controls include management controls such as segregation of duties, approval checkpoints in the systems development life cycle, and implementation of testing practices that assist in providing information integrity. Well-formed transactions and security of the update programs provide consistent methods of applying changes to systems. Limiting update access to those individuals with a need to access limits the exposure to intentional and unintentional modification.
Availability
Availability is the principle that ensures that information is available and accessible to users when needed.
The two primary areas affecting the availability of systems are:
1. Denial-of-Service attacks and
2. Loss of service due to a disaster, which could be man-made (e.g., poor capacity planning resulting in system crash, outdated hardware, and poor testing resulting in system crash after upgrade) or natural (e.g., earthquake, tornado, blackout, hurricane, fire, and flood).
In either case, the end user does not have access to information needed to conduct business. The criticality of the system to the user and its importance to the survival of the organization will determine how significant the impact of the extended downtime becomes. The lack of appropriate security controls can increase the risk of viruses, destruction of data, external penetrations, or denial-of-service (DOS) attacks.
Such events can prevent the system from being used by normal users.
CIA
The following answers are incorrect:
Integrity- Integrity is the principle that information should be protected from intentional, unauthorized, or accidental changes.
Availability - Availability is the principle that ensures that information is available and accessible to users when needed.
Accuracy - Accuracy is not a valid CIA attribute.

Following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 314
Official ISC2 guide to CISSP CBK 3rd Edition Page number350


NEW QUESTION # 511
An organization is using tunneling over an extranet. Which or the following control objectives is BEST addressed by this process?

  • A. Availability
  • B. Completeness
  • C. Confidentially
  • D. Nonrepudiation

Answer: C


NEW QUESTION # 512
A project team has decided to switch to an agile approach to develop a replacement for an existing business application. Which of the following should an IS auditor do FIRST to ensure the effectiveness of the project audit?

  • A. Compare the agile process with previous methodology.
  • B. Understand the specific agile methodology that will be followed.
  • C. Identify and assess existing agile process controls.
  • D. Interview business process owners to compile a list of business requirements.

Answer: B


NEW QUESTION # 513
When reviewing the effectiveness of data center operations, the IS auditor would FIRST -stablish that system performance:

  • A. is within generally accepted reliability levels for that system.
  • B. is monitored and reported against agreed service levels.
  • C. reflects the expected usage levels established at implementation.
  • D. meets the expected targets specified by the manufacturer.

Answer: B


NEW QUESTION # 514
In an IT organization where many responsibilities are shared, which of the following is the BEST control for detecting unauthorized data changes?

  • A. Users are required to periodically rotate responsibilities.
  • B. Data changes are togged m an outside application
  • C. Data Ranges are independently reviewed by another group.
  • D. Segregation of duties contest are periodically reviewed

Answer: C


NEW QUESTION # 515
Which of the following BEST helps to ensure data integrity across system interfaces?

  • A. Reconciliations
  • B. Access controls
  • C. Environment segregation
  • D. System backups

Answer: B


NEW QUESTION # 516
Which of the following is a detective control that can be used to uncover unauthorized access to information systems?

  • A. Implementing a security information and event management (SIEM) system
  • B. Requiring internal audit to perform periodic reviews of system access logs
  • C. Protecting access to the data center with multif actor authentication
  • D. Requiring long and complex passwords for system access

Answer: A


NEW QUESTION # 517
Which of the following environment controls is MOST appropriate in an area where power outages lasting up to 8 hours are frequent?

  • A. A power generator
  • B. A surge protector
  • C. Data mirroring
  • D. An alternate power supply line

Answer: A


NEW QUESTION # 518
An IS auditor attempts to sample for variables in a population of items with wide differences in values but determines that an unreasonably large number of sample items must be selected to produce the desired confidence level. In this situation, which of the following is the BEST audit decision?

  • A. Allow more time and test the required sample
  • B. Select a judgmental sample
  • C. Select a stratified sample
  • D. Lower the desired confidence level

Answer: C


NEW QUESTION # 519
Which of the following is MOST important to ensure that electronic evidence collected during a forensic investigation will be admissible in future legal proceeding?

  • A. Restricting evidence access to professionally certified forensic investigation
  • B. Engaging an independent third party to perform the forensic investigation
  • C. Documentation evidence handling by personnel throughout the forensic investigation
  • D. Performing investigate procedures on the original hard drives rather than images of the hard drives

Answer: C


NEW QUESTION # 520
Which of the following attack redirects outgoing message from the client back onto the client, preventing outside access as well as flooding the client with the sent packets?

  • A. Brute force attack
  • B. Buffer overflow
  • C. Banana attack
  • D. Pulsing Zombie

Answer: C

Explanation:
Section: Protection of Information Assets
Explanation:
A "banana attack" is another particular type of DoS. It involves redirecting outgoing messages from the client back onto the client, preventing outside access, as well as flooding the client with the sent packets.
The Banana attack uses a router to change the destination address of a frame. In the Banana attack:
A compromised router copies the source address on an inbound frame into the destination address.
The outbound frame bounces back to the sender.
This sender is flooded with frames and consumes so many resources that valid service requests can no longer be processed.
The following answers are incorrect:
Brute force attack - Brute force (also known as brute force cracking) is a trial and error method used by application programs to decode encrypted data such as passwords or Data Encryption Standard (DES) keys, through exhaustive effort (using brute force) rather than employing intellectual strategies. Just as a criminal might break into, or "crack" a safe by trying many possible combinations, a brute force cracking application proceeds through all possible combinations of legal characters in sequence. Brute force is considered to be an infallible, although time-consuming, approach.
Buffer overflow - A buffer overflow occurs when a program or process tries to store more data in a buffer (temporary data storage area) than it was intended to hold. Since buffers are created to contain a finite amount of data, the extra information - which has to go somewhere - can overflow into adjacent buffers, corrupting or overwriting the valid data held in them. Although it may occur accidentally through programming error, buffer overflow is an increasingly common type of security attack on data integrity.
Pulsing Zombie - A Dos attack in which a network is subjected to hostile pinging by different attacker computer over an extended time period.
Reference:
CISA review manual 2014 Page number 321


NEW QUESTION # 521
......

CISA Dumps PDF and Test Engine Exam Questions: https://www.examslabs.com/ISACA/Certified-Information-Systems-Auditor/best-CISA-exam-dumps.html

Get New CISA Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1Sgh2mRM-4zzeQyM8deZ4r7QW5iAi6Yeo