[Apr 07, 2024] CISA Sample with Accurate & Updated Questions
CISA Exam Info and Free Practice Test | ExamsReviews
NEW QUESTION # 283
Which control type would provide the MOST useful input to a root cause analysis?
- A. Directive
- B. Corrective
- C. Compensating
- D. Detective
Answer: D
NEW QUESTION # 284
What supports data transmission through split cable facilities or duplicate cable facilities?
- A. Redundant routing
- B. Dual routing
- C. Alternate routing
- D. Diverse routing
Answer: D
Explanation:
Explanation/Reference:
Diverse routing supports data transmission through split cable facilities, or duplicate cable facilities.
NEW QUESTION # 285
In which of the following system development life cycle (SDLC) phases would an IS auditor expect to find that controls have been incorporated into system specifications?
- A. Feasibility
- B. Implementation
- C. Development
- D. Design
Answer: D
NEW QUESTION # 286
An IS auditor suspects an organization's computer may have been used to commit a crime. Which of the following is the auditor's BEST course of action?
- A. Examine the computer to search for evidence supporting the suspicions.
- B. Notify local law enforcement of the potential crime before further investigation.
- C. Advise management of the crime after the investigation.
- D. Contact the incident response team to conduct an investigation.
Answer: D
Explanation:
Section: Protection of Information Assets
NEW QUESTION # 287
To detect attack attempts that the firewall is unable to recognize, an IS auditor should recommend placing a network intrusion detection system (IDS) between the:
- A. Internet and the web server.
- B. Firewall and the organization's network.
- C. Internet and the firewall.
- D. Web server and the firewall.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Attack attempts that could not be recognized by the firewall will be detected if a network-based intrusion detection system is placed between the firewall and the organization's network. A network-based intrusion detection system placed between the internet and the firewall will detect attack attempts, whether they do or do not enter the firewall.
NEW QUESTION # 288
To address a maintenance problem, a vendor needs remote access to a critical network. The MOST secure and effective solution is to provide the vendor with a:
- A. Secure Shell (SSH-2) tunnel for the duration of the problem.
- B. virtual private network (VPN) account for the duration of the vendor support contract.
- C. two-factor authentication mechanism for network access.
- D. dial-in access.
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
For granting temporary access to the network, a Secure Shell (SSH-2) tunnel is the best approach. It has auditing features and allows restriction to specific access points. Choices B, C and D all give full access to the internal network. Two-factor authentication and virtual private network (VPN) provide access to the entire network and are suitable for dedicated users. Dial-in access would need to be closely monitored or reinforced with another mechanism to ensure authentication to achieve the same level of security as SSH-
2.
NEW QUESTION # 289
A client/server configuration will:
- A. optimize system performance by having a server on a front-end and clients on a host.
- B. enhance system performance through the separation of front-end and back-end processes.
- C. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
- D. keep track of all the clients using the IS facilities of a service organization.
Answer: B
NEW QUESTION # 290
Which of the following is the BEST defense against a brute force attack?
- A. Intruder detection lockout
- B. Time-of-day restrictions
- C. Discretionary access control
- D. Mandatory access control
Answer: B
Explanation:
Section: Information System Operations, Maintenance and Support
NEW QUESTION # 291
An organization is using symmetric encryption. Which of the following would be a valid reason for moving to asymmetric encryption? Symmetric encryption:
- A. provides authenticity.
- B. can cause key management to be difficult.
- C. requires a relatively simple algorithm.
- D. is faster than asymmetric encryption.
Answer: B
Explanation:
In a symmetric algorithm, each pair of users needs a unique pair of keys, so the number of keys grows and key management can become overwhelming. Symmetric algorithms do not provide authenticity, and symmetric encryption is faster than asymmetric encryption. Symmetric algorithms require mathematical calculations, but they are not as complex as asymmetric algorithms.
NEW QUESTION # 292
Which of the following is the PRIMARY concern when negotiating a contract for a hot site?
- A. Availability of the site in the event of multiple disaster declarations
- B. Reciprocal agreements with other organizations
- C. Complete testing of the recovery plan
- D. Coordination with the site staff in the event of multiple disaster declarations
Answer: A
Explanation:
Explanation
The primary concern when negotiating a contract for a hot site is the availability of the site in the event of multiple disaster declarations. A hot site is a fully equipped alternative facility that can be used to resume business operations in the event of a disaster. However, if multiple clients of the hot site provider declare a disaster at the same time, there may be a shortage of resources or capacity to accommodate all of them.
Therefore, the contract should specify the terms and conditions for ensuring the availability and priority of the hot site for the organization. The other options are not as important as availability, as they do not affect the ability to use the hot site in a disaster situation. Coordination with the site staff in the event of multiple disaster declarations is a logistical issue that can be resolved by communication and planning. Reciprocal agreements with other organizations are alternative arrangements that can be used to share resources or facilities in a disaster, but they may not be as reliable or suitable as a hot site. Complete testing of the recovery plan is a good practice that can help validate and improve the effectiveness of the recovery plan, but it is not a concern for negotiating a contract for a hot site. References: CISA Review Manual (Digital Version), Chapter 4, Section 4.2.3
NEW QUESTION # 293
Which of the following is the BEST performance indicator for the effectiveness of an incident management program?
- A. Incident resolution meantime
- B. Number of incidents reported
- C. Average time between incidents
- D. Incident alert meantime
Answer: A
Explanation:
Explanation
The best performance indicator for the effectiveness of an incident management program is the incident resolution meantime. This is the average time it takes to resolve an incident from the moment it is reported to the moment it is closed. The incident resolution meantime reflects how quickly and efficiently the incident management team can restore normal service and minimize the impact of incidents on the business operations and customer satisfaction.
The average time between incidents (option A) is not a good performance indicator for the effectiveness of an incident management program, as it does not measure how well the incidents are handled or resolved. It only shows how frequently the incidents occur, which may depend on various factors beyond the control of the incident management team, such as the complexity and reliability of the systems, the security threats and vulnerabilities, and the user behavior and expectations.
The incident alert meantime (option B) is the average time it takes to detect and report an incident. While this is an important metric for measuring the responsiveness and awareness of the incident management team, it does not indicate how effective the incident management program is in resolving the incidents and restoring normal service.
The number of incidents reported (option C) is also not a good performance indicator for the effectiveness of an incident management program, as it does not reflect how well the incidents are handled or resolved. It only shows how many incidents are identified and recorded, which may vary depending on the reporting channels, tools, and procedures used by the incident management team and the users.
Therefore, option D is the correct answer.
References:
Incident Management: Processes, Best Practices & Tools - Atlassian
What is backup and disaster recovery? | IBM
NEW QUESTION # 294
Loading of illegal software packages onto a network by an employee is MOST effectively detected by:
- A. diskless workstations
- B. maintaining current antivirus software
- C. regular scanning of hard drives
- D. logging of activity on network drives
Answer: D
NEW QUESTION # 295
Passwords should be:
- A. displayed on the screen so that the user can ensure that it has been entered properly.
- B. reused often to ensure the user does not forget the password.
- C. assigned by the security administrator for first time logon.
- D. changed every 30 days at the discretion of the user.
Answer: C
Explanation:
Section: Protection of Information Assets
Explanation:
Initial password assignment should be done discretely by the security administrator. Passwords should be
changed often (e.g., every 30 days); however, changing should not be voluntary, it should be required by
the system. Systems should not permit previous passwords to be used again. Old passwords may have
been compromised and would thus permit unauthorized access. Passwords should not be displayed in any
form.
NEW QUESTION # 296
In wireless communication, which of the following controls allows the device receiving the communications to verify that the received communications have not been altered in transit?
- A. Packet headers and trailers
- B. Wireless intrusion detection (IDS) and prevention systems (IPS)
- C. The use of cryptographic hashes
- D. Device authentication and data origin authentication
Answer: C
Explanation:
Calculating cryptographic hashes for wireless communications allows the device receiving the communications to verify that the received communications have not been altered in transit. This prevents masquerading and message modification attacks. Device authentication and data origin authentication is not the correct answer since authenticating wireless endpoints to each other prevents man-in-the-middle attacks and masquerading. Wireless iDS / lPSs is not the correct answer since wireless IDS/ lPSshave the ability to detect misconfigured devices and rogue devices, and detect and possibly stop certain types of attacks. Packet headers and trailers alone do not ensure that the content has not been altered.
NEW QUESTION # 297
Which of the following layer of an OSI model ensures that messages are delivered error-free, in sequence, and with no losses or duplications?
- A. Presentation layer
- B. Application layer
- C. Transport layer
- D. Session layer
Answer: C
Explanation:
Section: Information System Operations, Maintenance and Support
Explanation:
The transport layer ensures that messages are delivered error-free, in sequence, and with no losses or duplications. It relieves the higher layer protocols from any concern with the transfer of data between them and their peers.
The size and complexity of a transport protocol depends on the type of service it can get from the network layer. For a reliable network layer with virtual circuit capability, a minimal transport layer is required. If the network layer is unreliable and/or only supports datagram's, the transport protocol should include extensive error detection and recovery.
The transport layer provides:
Message segmentation: accepts a message from the (session) layer above it, splits the message into smaller units (if not already small enough), and passes the smaller units down to the network layer. The transport layer at the destination station reassembles the message.
Message acknowledgment: provides reliable end-to-end message delivery with acknowledgments.
Message traffic control: tells the transmitting station to "back-off" when no message buffers are available.
Session multiplexing: multiplexes several message streams, or sessions onto one logical link and keeps track of which messages belong to which sessions (see session layer).
For your exam you should know below information about OSI model:
The Open Systems Interconnection model (OSI) is a conceptual model that characterizes and standardizes the internal functions of a communication system by partitioning it into abstraction layers. The model is a product of the Open Systems Interconnection project at the International Organization for Standardization (ISO), maintained by the identification ISO/IEC 7498-1.
The model groups communication functions into seven logical layers. A layer serves the layer above it and is served by the layer below it. For example, a layer that provides error-free communications across a network provides the path needed by applications above it, while it calls the next lower layer to send and receive packets that make up the contents of that path. Two instances at one layer are connected by a horizontal.
OSI Model
PHYSICAL LAYER
The physical layer, the lowest layer of the OSI model, is concerned with the transmission and reception of the unstructured raw bit stream over a physical medium. It describes the electrical/optical, mechanical, and functional interfaces to the physical medium, and carries the signals for all of the higher layers. It provides:
Data encoding: modifies the simple digital signal pattern (1s and 0s) used by the PC to better accommodate the characteristics of the physical medium, and to aid in bit and frame synchronization. It determines:
What signal state represents a binary 1
How the receiving station knows when a "bit-time" starts
How the receiving station delimits a frame
DATA LINK LAYER
The data link layer provides error-free transfer of data frames from one node to another over the physical layer, allowing layers above it to assume virtually error-free transmission over the link. To do this, the data link layer provides:
Link establishment and termination: establishes and terminates the logical link between two nodes.
Frame traffic control: tells the transmitting node to "back-off" when no frame buffers are available.
Frame sequencing: transmits/receives frames sequentially.
Frame acknowledgment: provides/expects frame acknowledgments. Detects and recovers from errors that occur in the physical layer by retransmitting non-acknowledged frames and handling duplicate frame receipt.
Frame delimiting: creates and recognizes frame boundaries.
Frame error checking: checks received frames for integrity.
Media access management: determines when the node "has the right" to use the physical medium.
NETWORK LAYER
The network layer controls the operation of the subnet, deciding which physical path the data should take based on network conditions, priority of service, and other factors. It provides:
Routing: routes frames among networks.
Subnet traffic control: routers (network layer intermediate systems) can instruct a sending station to
"throttle back" its frame transmission when the router's buffer fills up.
Frame fragmentation: if it determines that a downstream router's maximum transmission unit (MTU) size is less than the frame size, a router can fragment a frame for transmission and re-assembly at the destination station.
Logical-physical address mapping: translates logical addresses, or names, into physical addresses.
Subnet usage accounting: has accounting functions to keep track of frames forwarded by subnet intermediate systems, to produce billing information.
Communications Subnet
The network layer software must build headers so that the network layer software residing in the subnet intermediate systems can recognize them and use them to route data to the destination address.
This layer relieves the upper layers of the need to know anything about the data transmission and intermediate switching technologies used to connect systems. It establishes, maintains and terminates connections across the intervening communications facility (one or several intermediate systems in the communication subnet).
In the network layer and the layers below, peer protocols exist between a node and its immediate neighbor, but the neighbor may be a node through which data is routed, not the destination station. The source and destination stations may be separated by many intermediate systems.
TRANSPORT LAYER
The transport layer ensures that messages are delivered error-free, in sequence, and with no losses or duplications. It relieves the higher layer protocols from any concern with the transfer of data between them and their peers.
The size and complexity of a transport protocol depends on the type of service it can get from the network layer. For a reliable network layer with virtual circuit capability, a minimal transport layer is required. If the network layer is unreliable and/or only supports datagram's, the transport protocol should include extensive error detection and recovery.
The transport layer provides:
Message segmentation: accepts a message from the (session) layer above it, splits the message into smaller units (if not already small enough), and passes the smaller units down to the network layer. The transport layer at the destination station reassembles the message.
Message acknowledgment: provides reliable end-to-end message delivery with acknowledgments.
Message traffic control: tells the transmitting station to "back-off" when no message buffers are available.
Session multiplexing: multiplexes several message streams, or sessions onto one logical link and keeps track of which messages belong to which sessions (see session layer).
Typically, the transport layer can accept relatively large messages, but there are strict message size limits imposed by the network (or lower) layer. Consequently, the transport layer must break up the messages into smaller units, or frames, pretending a header to each frame.
The transport layer header information must then include control information, such as message start and message end flags, to enable the transport layer on the other end to recognize message boundaries. In addition, if the lower layers do not maintain sequence, the transport header must contain sequence information to enable the transport layer on the receiving end to get the pieces back together in the right order before handing the received message up to the layer above.
End-to-end layers
Unlike the lower "subnet" layers whose protocol is between immediately adjacent nodes, the transport layer and the layers above are true "source to destination" or end-to-end layers, and are not concerned with the details of the underlying communications facility. Transport layer software (and software above it) on the source station carries on a conversation with similar software on the destination station by using message headers and control messages.
SESSION LAYER
The session layer allows session establishment between processes running on different stations. It provides:
Session establishment, maintenance and termination: allows two application processes on different machines to establish, use and terminate a connection, called a session.
Session support: performs the functions that allow these processes to communicate over the network, performing security, name recognition, logging, and so on.
PRESENTATION LAYER
The presentation layer formats the data to be presented to the application layer. It can be viewed as the translator for the network. This layer may translate data from a format used by the application layer into a common format at the sending station, then translate the common format to a format known to the application layer at the receiving station.
The presentation layer provides:
Character code translation: for example, ASCII to EBCDIC.
Data conversion: bit order, CR-CR/LF, integer-floating point, and so on.
Data compression: reduces the number of bits that need to be transmitted on the network.
Data encryption: encrypt data for security purposes. For example, password encryption.
APPLICATION LAYER
The application layer serves as the window for users and application processes to access network services. This layer contains a variety of commonly needed functions:
Resource sharing and device redirection
Remote file access
Remote printer access
Inter-process communication
Network management
Directory services
Electronic messaging (such as mail)
Network virtual terminals
The following were incorrect answers:
Application Layer - The application layer serves as the window for users and application processes to access network services.
Presentation layer - The presentation layer formats the data to be presented to the application layer. It can be viewed as the translator for the network. This layer may translate data from a format used by the application layer into a common format at the sending station, then translate the common format to a format known to the application layer at the receiving station.
Session layer - The session layer allows session establishment between processes running on different stations.
Reference:
CISA review manual 2014 Page number 260
NEW QUESTION # 298
Which of the following BEST ensures the integrity of a server's operating system?
- A. Setting a boot password
- B. Hardening the server configuration
- C. Protecting the server in a secure location
- D. Implementing activity logging
Answer: B
Explanation:
Hardening a system means to configure it in the most secure manner (install latest security patches, properly define the access authorization for users and administrators, disable insecure options and uninstall unused services) to prevent nonprivileged users from gaining the right to execute privileged instructions and thus take control of the entire machine, jeopardizing the OS's integrity. Protecting the server in a secure location and setting a boot password are good practices, but do not ensure that a user will not try to exploit logical vulnerabilities and compromise the OS. Activity logging has two weaknesses in this scenario-it is a detective control (not a preventive one), and the attacker who already gained privileged accesscan modify logs or disable them.
NEW QUESTION # 299
You should keep all computer rooms at reasonable temperatures, which is in between (choose all that apply):
- A. 20 - 35 degrees Fahrenheit
- B. 30 - 45 degrees Fahrenheit
- C. 60 - 75 degrees Fahrenheit
- D. 10 - 25 degrees Celsius
- E. 1 - 15 degrees Celsius
- F. 0 - 5 degrees Celsius
Answer: C,D
Explanation:
You should keep all computer rooms at reasonable temperatures, which is in between 60 - 75 degrees Fahrenheit or 10 - 25 degrees Celsius. You should also keep humidity levels at 20 - 70 percent.
NEW QUESTION # 300
The objective of a vulnerability identification step in a risk assessment process is to.
- A. determine the impact of compromise
- B. identify the compensating controls
- C. develop a list of weaknesses
- D. determine the likelihood of a threat
Answer: C
NEW QUESTION # 301
......
Pass ISACA CISA Premium Files Test Engine pdf - Free Dumps Collection: https://www.examsreviews.com/CISA-pass4sure-exam-review.html
New 2024 Realistic CISA Dumps Test Engine Exam Questions in here: https://drive.google.com/open?id=1tiWFLuq9CUlKeODxYOFw_-fBFGUr-lBL