
Study HIGH Quality CISA Free Study Guides and Exams Tutorials
Download ISACA CISA Exam Dumps to Pass Exam Easily
How to get CISA Certification on the basis of prior experience?
It is also possible to get the CISA certification through a combination of prior experience and an apprenticeship. There are over 300 Core Competency Domains (CCDs) in the CISA domain and another 200 CCDs in the Security Domain. Candidates with at least six years of experience as security specialists may attempt to complete core domain courses within six months.
NEW QUESTION 84
Which of the following activities performed by a database administrator (DBA) should be performed by a different person?
- A. Monitoring database usage
- B. Deleting database activity logs
- C. Defining backup and recovery procedures
- D. Implementing database optimization tools
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Since database activity logs record activities performed by the database administrator (DBA), deleting them should be performed by an individual other than the DBA. This is a compensating control to aid in ensuring an appropriate segregation of duties and is associated with the DBA's role. A DBA should perform the other activities as part of the normal operations.
NEW QUESTION 85
Which of the following is the BEST reason for an organization to develop a business continuity plan?
- A. To identify the users of information systems and processes
- B. To avoid the costs resulting from the failure of key systems and processes
- C. To establish business unit prioritization of systems, projects, and strategies
- D. To develop a detailed description of information systems and processes
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation/Reference: http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/Business-
Continuity-Management-Audit-Assurance-Program.aspx
NEW QUESTION 86
Integer overflow occurs primarily with:
- A. string formatting
- B. arithmetic operations
- C. input verifications
- D. debug operations
- E. output formatting
- F. None of the choices.
Answer: B
Explanation:
An integer overflow occurs when an arithmetic operation attempts to create a numeric value that is larger than can be represented within the available storage space. On some processors the result saturates - once the maximum value is reached attempts to make it larger simply return the maximum result.
NEW QUESTION 87
Which of the following acts as a decoy to detect active internet attacks?
- A. Trapdoors
- B. Honeypots
- C. Traffic analysis
- D. Firewalls
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
Honeypots are computer systems that are expressly set up to attract and trap individuals who attempt to
penetrate other individuals' computer systems. The concept of a honeypot is to learn from intruder's
actions. A properly designed and configured honeypot provides data on methods used to attack systems.
The data are then used to improve measures that could curb future attacks. A firewall is basically a
preventive measure. Trapdoors create a vulnerability that provides an opportunity for the insertion of
unauthorized code into a system. Traffic analysis is a type of passive attack.
NEW QUESTION 88
Which of the following is an object-oriented technology characteristic that permits an enhanced degree of security over data?
- A. Encapsulation
- B. inheritance
- C. Dynamic warehousing
- D. Polymorphism
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation
Explanation:
Encapsulation is a property of objects, and it prevents accessing either properties or methods that have not been previously defined as public. This means that any implementation of the behavior of an object is not accessible. An object defines a communication interface with the exterior and only that which belongs to that interface can be accessed.
NEW QUESTION 89
What is essential for the IS auditor to obtain a clear understanding of network management?
- A. Systems logs of all hosts providing application services
- B. Administrator access to systems
- C. A graphical map of the network topology
- D. Security administrator access to systems
Answer: C
Explanation:
Section: Protection of Information Assets
Explanation:
A graphical interface to the map of the network topology is essential for the IS auditor to obtain a clear
understanding of network management.
NEW QUESTION 90
.Fourth-Generation Languages (4GLs) are most appropriate for designing the application's graphical user interface (GUI). They are inappropriate for designing any intensive data-calculation procedures. True or false?
- A. True
- B. False
Answer: A
Explanation:
Fourth-generation languages (4GLs) are most appropriate for designing the application's graphical user interface (GUI). They are inappropriate for designing any intensive data-calculation procedures.
NEW QUESTION 91
Which of the following would be MOST effective when justifying the cost of adding security controls to an existing web application?
- A. Application security policy
- B. Internal audit reports
- C. Vulnerability assessment results
- D. A business case
Answer: D
Explanation:
Section: Governance and Management of IT
NEW QUESTION 92
Audit management has just completed the annual audit plan for the upcoming year, which consists entirely of high-risk processor. However it is determined that there are insufficient resources to execute the plan. What should be done NEXT?
- A. Remove audit from the annual plan to better match the number of resources available.
- B. Review the audit plan and defer some audits to the subsequent year
- C. Present the annual plan to the audit committee and ask for more resources
- D. Reduce the scope of the audit to better match the number of resources available
Answer: C
NEW QUESTION 93
During an audit of a data classification policy, an IS auditor finds that many documents are inappropriately classified as confidential. Which of the following is the GREATEST concern?
- A. Information may be underprotected.
- B. Information may generally be overprotected.
- C. Industry security best practices are violated.
- D. Data integrity issues may occur.
Answer: B
NEW QUESTION 94
Which of the following methods would BEST ensure that IT strategy is in line with business strategy?
- A. Critical path analysis
- B. IT value analysis
- C. Business impact analysis (BIA)
- D. Break-even-point analysis
Answer: B
Explanation:
Section: Governance and Management of IT
NEW QUESTION 95
Which of the following functions should be performed by the application owners to ensure an adequate segregation of duties between IS and end users?
- A. Application programming
- B. Data administration
- C. Authorization of access to data
- D. System analysis
Answer: C
Explanation:
The application owner is responsible for authorizing access to datA . Application development and programming are functions of the IS department. Similarly, system analysis should be performed by qualified persons in IS who have knowledge of IS and user requirements. Data administration is a specialized function related to database management systems and should be performed by qualified database administrators.
NEW QUESTION 96
At a project steering committee meeting, it is stated that adding controls to business processes undergoing re-engineering is an unnecessary cost. The IS auditor's BEST response is that the actual control overhead for a business process is:
- A. usually considerable, but the benefits of good controls always exceed the cost.
- B. the responsibility of the project manager, and the cost should have been included in the budget.
- C. usually difficult to ascertain but is justifiable, because controls are essential to doing business
- D. usually less than the potential cost of failure caused by lack of controls.
Answer: D
Explanation:
Section: Information System Acquisition, Development and Implementation
NEW QUESTION 97
Which of the following is the PRIMARY objective of a business impact analysis (BIA)?
- A. Determine recovery priorities.
- B. Analyze vulnerabilities.
- C. Define the recovery point objective (RPO).
- D. Confirm control effectiveness.
Answer: A
Explanation:
Section: Protection of Information Assets
NEW QUESTION 98
Which of the following is the BEST way for an IS auditor to validate that employees have been made aware of the organization's information security policy?
- A. Interview employees to determine their level of understanding of the policy
- B. Review HR records for employee violations of the information security policy.
- C. Compare the employee roster against a list of those who attended security training
- D. Review the training process to determine how policies are explained to employees
Answer: A
NEW QUESTION 99
An organization has an integrated development environment (IDE) on which the program libraries reside on the server, but modification/development and testing are done from PC workstations.
Which of the following would be a strength of an IDE?
- A. Increases program and processing integrity
- B. Expands the programming resources and aids available
- C. Prevents valid changes from being overwritten by other changes
- D. Controls the proliferation of multiple versions of programs
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A strength of an IDE is that it expands the programming resources and aids available. The other choices are IDE weaknesses.
NEW QUESTION 100
Which key is used by the sender of a message to create a digital signature for the message being sent?
- A. Receiver's public key
- B. Sender's public key
- C. Receiver's private key
- D. Sender's private key
Answer: D
Explanation:
Section: Protection of Information Assets
Explanation:
The sender private key is used to calculate the digital signature
The digital signature is used to achieve integrity, authenticity and non-repudiation. In a digital signature, the sender's private key is used to encrypt the message digest (signing) of the message and receiver need to decrypt the same using sender's public key to validate the signature.
A digital signature (not to be confused with a digital certificate) is an electronic signature that can be used to authenticate the identity of the sender of a message or the signer of a document, and possibly to ensure that the original content of the message or document that has been sent is unchanged. Digital signatures are easily transportable, cannot be imitated by someone else, and can be automatically time-stamped. The ability to ensure that the original signed message arrived means that the sender cannot easily repudiate it later.
A digital signature can be used with any kind of message, whether it is encrypted or not, simply so that the receiver can be sure of the sender's identity and that the message arrived intact. A digital certificate contains the digital signature of the certificate-issuing authority so that anyone can verify that the certificate is real.
How It Works
Assume you were going to send the draft of a contract to your lawyer in another town. You want to give your lawyer the assurance that it was unchanged from what you sent and that it is really from you.
You copy-and-paste the contract (it's a short one!) into an e-mail note.
Using special software, you obtain a message hash (mathematical summary) of the contract.
You then use a private key that you have previously obtained from a public-private key authority to encrypt the hash.
The encrypted hash becomes your digital signature of the message. (Note that it will be different each time you send a message.) At the other end, your lawyer receives the message:
To make sure it's intact and from you, your lawyer makes a hash of the received message.
Your lawyer then uses your public key to decrypt the message hash or summary.
If the hashes match, the received message is valid.
Below are some common reasons for applying a digital signature to communications:
Authentication
Although messages may often include information about the entity sending a message, that information may not be accurate. Digital signatures can be used to authenticate the source of messages. When ownership of a digital signature secret key is bound to a specific user, a valid signature shows that the message was sent by that user. The importance of high confidence in sender authenticity is especially obvious in a financial context. For example, suppose a bank's branch office sends instructions to the central office requesting a change in the balance of an account. If the central office is not convinced that such a message is truly sent from an authorized source, acting on such a request could be a grave mistake.
Integrity
In many scenarios, the sender and receiver of a message may have a need for confidence that the message has not been altered during transmission. Although encryption hides the contents of a message, it may be possible to change an encrypted message without understanding it. (Some encryption algorithms, known as nonmalleable ones, prevent this, but others do not.) However, if a message is digitally signed, any change in the message after signature invalidates the signature. Furthermore, there is no efficient way to modify a message and its signature to produce a new message with a valid signature, because this is still considered to be computationally infeasible by most cryptographic hash functions (see collision resistance).
Non-repudiation
Non-repudiation, or more specifically non-repudiation of origin, is an important aspect of digital signatures.
By this property, an entity that has signed some information cannot at a later time deny having signed it.
Similarly, access to the public key only does not enable a fraudulent party to fake a valid signature.
Note that these authentication, non-repudiation etc. properties rely on the secret key not having been revoked prior to its usage. Public revocation of a key-pair is a required ability, else leaked secret keys would continue to implicate the claimed owner of the key-pair. Checking revocation status requires an
"online" check, e.g. checking a "Certificate Revocation List" or via the "Online Certificate Status Protocol".
Very roughly this is analogous to a vendor who receives credit-cards first checking online with the credit- card issuer to find if a given card has been reported lost or stolen. Of course, with stolen key pairs, the theft is often discovered only after the secret key's use, e.g., to sign a bogus certificate for espionage purposes.
Tip for the exam:
Digital Signature does not provide confidentiality. The sender's private key is used for calculating digital signature Encryption provides only confidentiality. The receiver's public key or symmetric key is used for encryption The following were incorrect answers:
Sender's Public key - This is incorrect as receiver will require sender's private key to verify digital signature.
Receiver's Public Key - The digital signature provides non-repudiation. The receiver's public key is known to every one. So it can not be used for digital-signature. Receiver's public key can be used for encryption.
Receiver's Private Key - The sender does not know the receiver's private key. So this option is incorrect.
Reference:
CISA review manual 2014 Page number 348
http://upload.wikimedia.org/wikipedia/commons/2/2b/Digital_Signature_diagram.svg
http://en.wikipedia.org/wiki/Digital_signature
http://searchsecurity.techtarget.com/definition/digital-signature
NEW QUESTION 101
......
Get 100% Real Free Certified Information Systems Auditor CISA Sample Questions: https://www.passsureexam.com/CISA-pass4sure-exam-dumps.html
Accurate CISA Questions with Free and Fast Updates: https://drive.google.com/open?id=1aXzxdrT_Ne0jeyHJHjdj8d4m24adkcKf