[Nov 22, 2022] Prepare For The CISA Question Papers In Advance
CISA PDF Dumps Real 2022 Recently Updated Questions
NEW QUESTION 173
Which of the following is MOST important for an organization to complete prior to developing its disaster recovery plan (DRP)?
- A. Support staff skills gap analysis
- B. Risk assessment
- C. Business impact analysis (BIA)
- D. Comprehensive IT inventory
Answer: C
NEW QUESTION 174
An IS audit reveals that an organization is not proactively addressing known vulnerabilities. Which of the following should the IS auditor recommend the organization do FIRST?
- A. Ensure the intrusion prevention system (IPS) is effective.
- B. Assess the security risks to the business.
- C. Verify the disaster recovery plan (DRP) has been tested.
- D. Confirm the incident response team understands the issue.
Answer: B
NEW QUESTION 175
The FIRST step in managing the risk of a cyber-attack is to:
- A. estimate potential damage.
- B. identify critical information assets.
- C. evaluate the likelihood of threats.
- D. assess the vulnerability impact.
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
The first step in the managing risk is the identification and classification of critical information resources
(assets). Once the assets have been identified, the process moves onto the identification of threats,
vulnerabilities and calculation of potential damages.
NEW QUESTION 176
Which of the following network components is PRIMARILY set up to serve as a security measure by preventing unauthorized traffic between different segments of the network?
- A. VLANs
- B. Firewalls
- C. Routers
- D. Layer 2 switches
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Firewall systems are the primary tool that enable an organization to prevent unauthorized access between networks. An organization may choose to deploy one or more systems that function as firewalls. Routers can filter packets based on parameters, such as source address, but are not primarily a security tool.
Based on Media Access Control (MAC) addresses, layer 2 switches separate traffic in a port as different segments and without determining if it is authorized or unauthorized traffic. A virtual LAN (VLAN) is a functionality of some switches that allows them to switch the traffic between different ports as if they are in the same LAN. Nevertheless, they do not deal with authorized vs. unauthorized traffic.
NEW QUESTION 177
The quality of the metadata produced from a data warehouse is _______________ in the warehouse's design. Choose the BEST answer.
- A. Of secondary importance to data warehouse content
- B. Often hard to determine because the data is derived from a heterogeneous data environment
- C. The most important consideration
- D. Independent of the quality of the warehoused databases
Answer: C
Explanation:
Explanation/Reference:
The quality of the metadata produced from a data warehouse is the most important consideration in the warehouse's design.
NEW QUESTION 178
Which of the following is a dynamic analysis tool for the purpose of testing software modules?
- A. Structured walk-through
- B. Desk checking
- C. Design and code
- D. Blackbox test
Answer: D
Explanation:
Explanation/Reference:
Explanation:
A blackbox test is a dynamic analysis tool for testing software modules. During the testing of software modules, a blackbox test works first in a cohesive manner as one single unit/entity, consisting of numerous modules and second, with the user data that flows across software modules. In some cases, this even drives the software behavior. In choices B, C and D, the software (design or code) remains static and someone closely examines it by applying their mind, without actually activating the software. Therefore, these cannot be referred to as dynamic analysis tools.
NEW QUESTION 179
Which of the following is the protocol data unit (PDU) of application layer in TCP/IP model?
- A. Packet
- B. Segment
- C. Data
- D. Frame
Answer: C
Explanation:
Explanation/Reference:
Application layer's PDU is data.
For your exam you should know below information about TCP/IP model:
Network models
Layer 4. Application Layer
Application layer is the top most layer of four layer TCP/IP model. Application layer is present on the top of the Transport layer. Application layer defines TCP/IP application protocols and how host programs interface with Transport layer services to use the network.
Application layer includes all the higher-level protocols like DNS (Domain Naming System), HTTP (Hypertext Transfer Protocol), Telnet, SSH, FTP (File Transfer Protocol), TFTP (Trivial File Transfer Protocol), SNMP (Simple Network Management Protocol), SMTP (Simple Mail Transfer Protocol) , DHCP (Dynamic Host Configuration Protocol), X Windows, RDP (Remote Desktop Protocol) etc.
Layer 3. Transport Layer
Transport Layer is the third layer of the four layer TCP/IP model. The position of the Transport layer is between Application layer and Internet layer. The purpose of Transport layer is to permit devices on the source and destination hosts to carry on a conversation. Transport layer defines the level of service and status of the connection used when transporting data.
The main protocols included at Transport layer are TCP (Transmission Control Protocol) and UDP (User Datagram Protocol).
Layer 2. Internet Layer
Internet Layer is the second layer of the four layer TCP/IP model. The position of Internet layer is between Network Access Layer and Transport layer. Internet layer pack data into data packets known as IP datagram's, which contain source and destination address (logical address or IP address) information that is used to forward the datagram's between hosts and across networks. The Internet layer is also responsible for routing of IP datagram's.
Packet switching network depends upon a connectionless internetwork layer. This layer is known as Internet layer. Its job is to allow hosts to insert packets into any network and have them to deliver independently to the destination. At the destination side data packets may appear in a different order than they were sent. It is the job of the higher layers to rearrange them in order to deliver them to proper network applications operating at the Application layer.
The main protocols included at Internet layer are IP (Internet Protocol), ICMP (Internet Control Message Protocol), ARP (Address Resolution Protocol), RARP (Reverse Address Resolution Protocol) and IGMP (Internet Group Management Protocol).
Layer 1. Network Access Layer
Network Access Layer is the first layer of the four layer TCP/IP model. Network Access Layer defines details of how data is physically sent through the network, including how bits are electrically or optically signaled by hardware devices that interface directly with a network medium, such as coaxial cable, optical fiber, or twisted pair copper wire.
The protocols included in Network Access Layer are Ethernet, Token Ring, FDDI, X.25, Frame Relay etc.
The most popular LAN architecture among those listed above is Ethernet. Ethernet uses an Access Method called CSMA/CD (Carrier Sense Multiple Access/Collision Detection) to access the media, when Ethernet operates in a shared media. An Access Method determines how a host will place data on the medium.
IN CSMA/CD Access Method, every host has equal access to the medium and can place data on the wire when the wire is free from network traffic. When a host wants to place data on the wire, it will check the wire to find whether another host is already using the medium. If there is traffic already in the medium, the host will wait and if there is no traffic, it will place the data in the medium. But, if two systems place data on the medium at the same instance, they will collide with each other, destroying the data. If the data is destroyed during transmission, the data will need to be retransmitted. After collision, each host will wait for a small interval of time and again the data will be retransmitted.
Protocol Data Unit (PDU) :
Protocol Data Unit - PDU
The following answers are incorrect:
Segment - Transport layer PDU
Packet - Network interface layer PDU
Frame/bit - LAN or WAN interface layer PDU
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 272
NEW QUESTION 180
Passwords should be:
- A. reused often to ensure the user does not forget the password.
- B. assigned by the security administrator for first time logon.
- C. displayed on the screen so that the user can ensure that it has been entered properly.
- D. changed every 30 days at the discretion of the user.
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
Initial password assignment should be done discretely by the security administrator. Passwords should be
changed often (e.g., every 30 days); however, changing should not be voluntary, it should be required by
the system. Systems should not permit previous passwords to be used again. Old passwords may have
been compromised and would thus permit unauthorized access. Passwords should not be displayed in any
form.
NEW QUESTION 181
Which of the following should an IS auditor be MOST concerned with when a system uses ratio frequency identification (RFID)?
- A. nonrepudiations
- B. Maintainability
- C. Scalability
- D. Privacy
Answer: C
NEW QUESTION 182
Which of the following ensures a sender's authenticity and an e-mail's confidentiality?
- A. Encrypting the hash of the message with the sender's private key and thereafter encrypting the hash of the message with the receiver's public key
- B. Encrypting the message with the sender's private key and encrypting the message hash with the receiver's public key.
- C. Encrypting the hash of the message with the sender's private key and thereafter encrypting the message with the receiver's public key
- D. The sender digitally signing the message and thereafter encrypting the hash of the message with the sender's private key
Answer: C
Explanation:
To ensure authenticity and confidentiality, a message must be encrypted twice: first with the sender's private key, and then with the receiver's public key. The receiver can decrypt the message, thus ensuring confidentiality of the message. Thereafter, the decrypted message can be decrypted with the public key of the sender, ensuring authenticity of the message. Encrypting the message with the sender's private key enables anyone to decrypt it.
NEW QUESTION 183
The MOST significant reason for using key performance indicators (KPIs) to track the progress of IT
projects against initial targets is that they:
- A. provide timely indication of when corrective actions need to be taken
- B. identify which projects may require additional funding
- C. influence management decisions to outsource IT projects
- D. identify instances where increased stakeholder engagement is required
Answer: D
Explanation:
Section: Information System Acquisition, Development and Implementation
NEW QUESTION 184
When reviewing the procedures for the disposal of computers, which of the following should be the
GREATEST concern for the IS auditor?
- A. All files and folders on hard disks are separately deleted, and the hard disks are formatted before
leaving the organization. - B. Hard disks are overwritten several times at the sector level, but are not reformatted before leaving the
organization. - C. Hard disks are rendered unreadable by hole-punching through the platters at specific positions before
leaving the organization. - D. The transport of hard disks is escorted by internal security staff to a nearby metal recycling company,
where the hard disks are registered and then shredded.
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
Deleting and formatting does not completely erase the data but only marks the sectors that contained files
as being free. There are tools available over the Internet which allow one to reconstruct most of a hard
disk's contents. Overwriting a hard disk at the sector level would completely erase data, directories, indices
and master file tables. Reformatting is not necessary since all contents are destroyed. Overwriting several
times makes useless some forensic measures which are able to reconstruct former contents of newly
overwritten sectors by analyzing special magnetic features of the platter's surface. While hole-punching
does not delete file contents, the hard disk cannot be used anymore, especially when head parking zones
and track zero information are impacted. Reconstructing data would be extremely expensive since all
analysis must be performed under a clean room atmosphere and is only possible within a short time frame
or until the surface is corroded. Data reconstruction from shredded hard disks is virtually impossible,
especially when the scrap is mixed with other metal parts. If the transport can be secured and the
destruction be proved as described in the option, this is a valid method of disposal.
NEW QUESTION 185
When should application controls be considered within the system-development process?
- A. After application unit testing
- B. After application module testing
- C. As early as possible, even in the development of the project's functional specifications
- D. After applications systems testing
Answer: C
Explanation:
Explanation/Reference:
Application controls should be considered as early as possible in the system-development process, even in the development of the project's functional specifications.
NEW QUESTION 186
Which of the following cloud deployment models would BEST meet the needs of a startup software
development organization with limited initial capital?
- A. Public
- B. Private
- C. Community
- D. Hybrid
Answer: A
Explanation:
Section: Protection of Information Assets
NEW QUESTION 187
Which of the following would be an appropriate role of internal audit in helping to establish an organization's privacy program?
- A. Defining roles within the organization related to privacy
- B. Developing procedures to monitor the use of personal data
- C. Designing controls to protect personal data
- D. Analyzing risks posed by new regulations
Answer: B
NEW QUESTION 188
Which of the following audit procedures would be MOST conclusive in evaluating the effectiveness of an e- commerce application system's edit routine?
- A. Interviews with knowledgeable users
- B. Review of source code
- C. Use of test transactions
- D. Review of program documentation
Answer: C
Explanation:
Section: The process of Auditing Information System
Explanation/Reference:
NEW QUESTION 189
Which of the following is the BEST method for uncovering shadow IT within an organization?
- A. Use a cloud access security broker (CASB).
- B. Review business processes.
- C. Review secondary approval thresholds.
- D. Analyze help desk tickets.
Answer: B
NEW QUESTION 190
In a public key infrastructure, a registration authority:
- A. verifies information supplied by the subject requesting a certificate.
- B. issues the certificate after the required attributes are verified and the keys are generated.
- C. digitally signs a message to achieve nonrepudiation of the signed message.
- D. registers signed messages to protect them from future repudiation.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
A registration authority is responsible for verifying information supplied by the subject requesting a certificate, and verifies the requestor's right to request certificate attributes and that the requestor actually possesses the private key corresponding to the public key being sent. Certification authorities, not registration authorities, actually issue certificates once verification of the information has been completed; because of this, choice B is incorrect. On the other hand, the sender who has control of their private key signs the message, not the registration authority. Registering signed messages is not a task performed by registration authorities.
NEW QUESTION 191
What is the BEST way is evaluate a control environment where the organization and a third party have shared responsibility?
- A. Review complementary user entity controls.
- B. Review the service level agreement (SLA).
- C. Perform an onsite evaluation
- D. Conduct a control self-assessment (CSA).
Answer: B
NEW QUESTION 192
The control that MOST effectively addresses the risk of piggybacking/tailgating into a restricted area without a dead man door is:
- A. security awareness training.
- B. requiring employees to wear ID badges.
- C. using two-factor authentication.
- D. using biometric door locks.
Answer: A
Explanation:
Section: Protection of Information Assets
NEW QUESTION 193
An effective implementation of security roles and responsibilities is BEST evidenced across an enterprise when:
- A. policies are signed off by users.
- B. reviews and updates of policies are regularly performed
- C. operational activities are aligned with policies.
- D. policies are rolled out and disseminated
Answer: C
NEW QUESTION 194
......
Further Certification Path after Passing CISA Exam
Once IT specialists manage to get the passing score in the CISA certification exam they can move forward to leverage their skills with more advanced ISACA certificates. Therefore, they can take the CRISC certification exam that helps them become certified professionals in Risk and Information Systems Control. Another certification that successful ISACA CISA certified specialists can take is the CISM or Certified Information Security Manager.
What are the language, duration, and format of the ISACA CISA Certification Exam?
The Language, span, and format of the ISACA CISA Certification Exam are as follows:
Language: The CISA exam is being administered in 11 languages. Those languages are Chinese Traditional, Chinese Simplified, English, French, German, Hebrew, Italian, Japanese, Korean, Spanish, and Turkish.
Time Duration: Candidates will have 240 min (04 hours) to attempt his/her CISA exam.
A number of questions: There will be 150 questions in the CISA exam. You have to answer all the questions. Questions of the CISA exam will be in the form of multiple choice.
How to Schedule the ISACA CISA Exam?
After registration and paying the fee, you will get a confirmation email, you can schedule your exam by clicking that link in the email. You can also schedule by logging to your account. The CISA test is offered more than 50 times a year at various locations around the world, you can set time according to your ease, for example, Aug, Sep, Oct, Feb Apr, Jul whenever you want. You can also have a mid-year or quarterly break for better preparation for the exam. So it will not be much harder to find one that fits your schedule.
CISA Dumps and Practice Test (361 Exam Questions): https://www.passsureexam.com/CISA-pass4sure-exam-dumps.html
Released ISACA CISA Updated Questions PDF: https://drive.google.com/open?id=1kReYeA0tbg3zq9o2pKq1MbWBhrC1Sxdp