CISA Exam Dumps Free Test Engine Verified By Certified Information Systems Auditor Certified Experts [Q175-Q197]

Share

CISA Exam Dumps Free Test Engine Verified By Certified Information Systems Auditor Certified Experts

Use Real ISACA Achieve the CISA Dumps - 100% Exam Passing Guarantee


What Are Details of CISA Certification Exam?

All certification tests developed by ISACA have a standard structure. They include 150 questions that have a multiple-choice format. Candidates will have 240 minutes to answer as many questions as possible correctly. The exam fees are different and based on the applicants' membership. For instance, an ISACA member will pay $575 to register for the CISA exam. In case they are non-members, the registration fee becomes $760. It is essential to mention that all exam fees are non-refundable. To know more, this exam is available in different languages. Thus, examinees can take it in Chinese Traditional or Simplified, German, English, French, Italian, Japanese, Italian, Korean, Spanish, and Turkish. Before registering for the CISA, candidates need to know that this test is computer-based and is administered by PSI testing centers anywhere in the world. The registration process is continuous, which allows candidates to register without restrictions anytime. Also, the vendor recommends that applicants should schedule a testing appointment 48 hours after the candidate finalized the registration process. Once the registration is complete, exam-takers can take their test within one year after they register. Besides, an important step that examinees shouldn't forget is checking which is the nearest PSI test site to their home place.

 

NEW QUESTION # 175
An organization is planning to replace its wired networks with wireless networks. Which
of the following would BEST secure the wireless network from unauthorized access?

  • A. Implement Wired Equivalent Privacy (WEP)
  • B. Disable open broadcast of service set identifiers (SSID)
  • C. Permit access to only authorized Media Access Control (MAC) addresses
  • D. Implement Wi-Fi Protected Access (WPA) 2

Answer: D

Explanation:
Wi-Fi Protected Access (WPA) 2 implements most of the requirements of the IEEE 802.11i standard. The Advanced Encryption Standard (AESJ used in WPA2 provides better security. Also, WPA2 supports both the Extensible Authentication Protocol and the preshared secret key authentication model. Implementing Wired Equivalent Privacy (WEP) is incorrect since it can be cracked within minutes. WEP uses a static key which has to be communicated to all authorized users, thus management is difficult. Also, there is a greater vulnerability if the static key is not changed at regular intervals. The practice of allowing access based on Media Access Control (MAC) is not a solution since MAC addresses can be spoofed by attackers to gain access to the network. Disabling open broadcast of service set identifiers (SSID) is not the correct answer as they cannot handle access control.


NEW QUESTION # 176
An IS auditor reviewing an organization's IT strategic plan should FIRST review:

  • A. the present IT budget.
  • B. the business plan.
  • C. the existing IT environment.
  • D. current technology trends.

Answer: B

Explanation:
Section: Protection of Information Assets
Explanation:
The IT strategic plan exists to support the organization's business plan. To evaluate the IT strategic plan, an IS auditor would first need to familiarize themselves with the business plan.


NEW QUESTION # 177
Which of the following would BEST indicate the independence of the internal audit function?

  • A. Audit chatter
  • B. Engagement letter
  • C. Organizational structure
  • D. Dedicated chief internal auditor

Answer: C


NEW QUESTION # 178
An organization is considering replacing physical backup tapes stored offsite with real-time on-line backup to a storage area network (SAN) located in the primary data center. Which of the following is the GREATEST risk?

  • A. Backups may require excessive storage space.
  • B. Implementation could cause significant cost increases.
  • C. A single disaster could cause significant data loss
  • D. Archived data may not satisfy data retention requirements.

Answer: C


NEW QUESTION # 179
In an organization, the responsibilities for IT security are clearly assigned and enforced and an IT security risk and impact analysis is consistently performed. This represents which level of ranking in the information security governance maturity model?

  • A. Optimized
  • B. Managed
  • C. Repeatable
  • D. Defined

Answer: B

Explanation:
Boards of directors and executive management can use the information security governance maturity model to establish rankings for security in their organizations. The ranks are nonexistent, initial, repeatable, defined, managed and optimized. When the responsibilities for IT security in an organization are clearly assigned and enforced and an IT security risk and impact analysis is consistently performed, it is said to be 'managed and measurable.'


NEW QUESTION # 180
Which of the following is a passive attack method used by intruders to determine potential network
vulnerabilities?

  • A. Denial of service (DoS)
  • B. Distributed denial of service (DoS)
  • C. Traffic analysis
  • D. SYN flood

Answer: C

Explanation:
Section: Protection of Information Assets
Explanation:
Traffic analysis is a passive attack method used by intruders to determine potential network vulnerabilities.
All others are active attacks.


NEW QUESTION # 181
Which of the following uses a prototype that can be updated continually to meet changing user or business requirements?

  • A. GANTT
  • B. Function point analysis (FPA)
  • C. PERT
  • D. Rapid application development (RAD)

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Rapid application development (RAD) uses a prototype that can be updated continually to meet changing user or business requirements.


NEW QUESTION # 182
An IS auditor found that a company executive is encouraging employee use of social networking sites for business purposes. Which of the following recommendations would BEST help to reduce the risk of data leakage?

  • A. Providing education and guidelines to employees on use of social networking sites
  • B. Monitoring employees social networking usage
  • C. Requiring policy acknowledgment and nondisclosure agreements signed by employees

Answer: A


NEW QUESTION # 183
The GREATEST risk when end users have access to a database at its system level, instead of through the application, is that the users can:

  • A. update data without authentication.
  • B. remotely access the database.
  • C. make use of a system query language (SQL) to access information.
  • D. make unauthorized changes to the database directly, without an audit trail.

Answer: D

Explanation:
Having access to the database could provide access to database utilities, which can update the database without an audit trail and without using the application. Using SQL only provides read access to information, in a networked environment, accessing the database remotely does not make a difference. What is critical is what is possible or completed through this access. To access a database, it is necessary that a user is authenticated using a user ID.


NEW QUESTION # 184
Which of the following ensures a sender's authenticity and an e-mail's confidentiality?

  • A. Encrypting the hash of the message with the sender's private key and thereafter encrypting the message with the receiver's public key
  • B. Encrypting the message with the sender's private key and encrypting the message hash with the receiver's public key.
  • C. The sender digitally signing the message and thereafter encrypting the hash of the message with the sender's private key
  • D. Encrypting the hash of the message with the sender's private key and thereafter encrypting the hash of the message with the receiver's public key

Answer: A

Explanation:
To ensure authenticity and confidentiality, a message must be encrypted twice: first with the sender's private key, and then with the receiver's public key. The receiver can decrypt the message, thus ensuring confidentiality of the message. Thereafter, the decrypted message can be decrypted with the public key of the sender, ensuring authenticity of the message. Encrypting the message with the sender's private key enables anyone to decrypt it.


NEW QUESTION # 185
A medium-sized organization, whose IT disaster recovery measures have been in place and regularly tested for years, has just developed a formal business continuity plan (BCP). A basic BCP tabletop exercise has been performed successfully. Which testing should an IS auditor recommend be performed NEXT to verify the adequacy of the new BCP?

  • A. Full-scale test with relocation of all departments, including IT, to the contingency site
  • B. Functional test of a scenario with limited IT involvement
  • C. IT disaster recovery test with business departments involved in testing the critical applications
  • D. Walk-through test of a series of predefined scenarios with all critical personnel involved

Answer: B

Explanation:
Explanation/Reference:
Explanation:
After a tabletop exercise has been performed, the next step would be a functional test, which includes the mobilization of staff to exercise the administrative and organizational functions of a recovery. Since the IT part of the recovery has been tested for years, it would be more efficient to verify and optimize the business continuity plan (BCP) before actually involving IT in a full-scale test. The full-scale test would be the last step of the verification process before entering into a regular annual testing schedule. A full-scale test in the situation described might fail because it would be the first time that the plan is actually exercised, and a number of resources (including IT) and time would be wasted. The walk-through test is the most basic type of testing. Its intention is to make key staff familiar with the plan and discuss critical plan elements, rather than verifying its adequacy. The recovery of applications should always be verified and approved by the business instead of being purely IT-driven. A disaster recovery test would not help in verifying the administrative and organizational parts of the BCP which are not IT-related.


NEW QUESTION # 186
A message is being sent with a hash. The risk of an attacker changing the message and generating an authentic hash value can be mitigated by:

  • A. using the sender's public key to encrypt the message.
  • B. generating hash output that is the same size as the original message.
  • C. requiring the recipient to use a different hash algorithm.
  • D. using a secret key in conjunction with the hash algorithm.

Answer: D

Explanation:
Section: Information System Operations, Maintenance and Support


NEW QUESTION # 187
An organization is developing a web portal using some external components. Which of the following should be of MOST concern to an IS auditor?

  • A. Some of the developers are located in another country.
    The organization has not reviewed the components for known exploits.
  • B. Open-source components were integrated during development.
  • C. Staff require additional training in order to perform cede review.

Answer: B


NEW QUESTION # 188
Which of the following should an IS auditor expect to find when reviewing IT security policy?

  • A. Virus protection implementation strategies
  • B. An inventory of information assets
  • C. Assigned responsibility for safeguarding company assets
  • D. A risk-based classification of systems

Answer: C

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 189
A LAN administrator normally would be restricted from:

  • A. having end-user responsibilities.
  • B. being responsible for LAN security administration.
  • C. having programming responsibilities.
  • D. reporting to the end-user manager.

Answer: C

Explanation:
A LAN administrator should not have programming responsibilities but may have end- user responsibilities. The LAN administrator may report to the director of the IPF or, in a decentralized operation, to the end-user manager. In small organizations, the LAN administrator also may be responsible for security administration over the LAN.


NEW QUESTION # 190
The use of digital signatures:

  • A. ensures message confidentiality.
  • B. provides encryption to a message.
  • C. requires the use of a one-time password generator.
  • D. validates the source of a message.

Answer: D

Explanation:
The use of a digital signature verifies the identity of the sender, but does not encrypt the whole message, and hence is not enough to ensure confidentiality. A one-time password generator is an option, but is not a requirement for using digital signatures.


NEW QUESTION # 191
An IS auditor performing a review of the backup processing facilities should be MOST concerned that:

  • A. adequate fire insurance exists.
  • B. regular hardware maintenance is performed.
  • C. offsite storage of transaction and master files exists.
  • D. backup processing facilities are fully tested.

Answer: C

Explanation:
Adequate fire insurance and fully tested backup processing facilities are important elements for recovery, but without the offsite storage of transaction and master files, it is generally impossible to recover. Regular hardware maintenance does not relate to recovery.


NEW QUESTION # 192
Which of the following is a standard secure email protection protocol?

  • A. S/MIME
  • B. SET
  • C. S/HTTP
  • D. SSH

Answer: A

Explanation:
Explanation/Reference:
Secure Multipurpose Internet Mail Extension (S/MIME) is a standard secure email protocol that authenticates the identity of the sender and receiver, verifies message integrity, and ensures the privacy of message's content's, including attachments.
The following were incorrect answers:
SSH -A client server program that opens a secure, encrypted command-line shell session from the Internet for remote logon. Similar to a VPN, SSH uses strong cryptography to protect data, including password, binary files and administrative commands, transmitted between system on a network. SSH is typically implemented between two parties by validating each other's credential via digital certificates. SSH is useful in securing Telnet and FTP services, and is implemented at the application layer, as opposed to operating at network layer (IPSec Implementation) SET - SET is a protocol developed jointly by VISA and Master Card to secure payment transaction among all parties involved in credit card transactions among all parties involved in credit card transactions on behalf of cardholders and merchants. As an open system specification, SET is a application-oriented protocol that uses trusted third party's encryption and digital-signature process, via PKI infrastructure of trusted third party institutions, to address confidentiality of information, integrity of data, cardholders authentication, merchant authentication and interoperability.
Secure Hypertext Transfer Protocol (S/HTTP) -As an application layer protocol, S/HTTP transmits individual messages or pages securely between a web client and server by establishing SSL-type connection. Using the https:// designation in the URL, instead of the standard http://, directs the message to a secure port number rather than the default web port address. This protocol utilizes SSL secure features but does so as a message rather than the session-oriented protocol.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 352 and 353


NEW QUESTION # 193
When reviewing an organization's information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:

  • A. a risk management process.
  • B. an information security framework.
  • C. industry best practices.
  • D. past information security incidents.

Answer: A


NEW QUESTION # 194
.What often results in project scope creep when functional requirements are not defined as well as they could be?

  • A. Inadequate softwarebaselining
  • B. Inaccurate resource allocation
  • C. Insufficient strategic planning
  • D. Project delays

Answer: A

Explanation:
Inadequate software baselining often results in project scope creep because functional requirements are not defined as well as they could be.


NEW QUESTION # 195
An IS auditor is reviewing a recent security incident and is seeking information about the approval of a recent modification to a database system's security settings Where would the auditor MOST likely find this information?

  • A. Database log
  • B. Change log
  • C. System event correlation report
  • D. Security incident and event management (SIEM) report

Answer: B


NEW QUESTION # 196
When reviewing input controls, an IS auditor observes that, in accordance with corporate policy, procedures allow supervisory override of data validation edits. The IS auditor should:

  • A. ensure that overrides are automatically logged and subject to review.
  • B. not be concerned since there may be other compensating controls to mitigate the risks.
  • C. verify whether all such overrides are referred to senior management for approval.
  • D. recommend that overrides not be permitted.

Answer: A

Explanation:
If input procedures allow overrides of data validation and editing, automatic logging should occur. A management individual who did not initiate the override should review this log. An IS auditor should not assume that compensating controls exist. Aslong as the overrides are policy-compliant, there is no need for senior management approval or a blanket prohibition.


NEW QUESTION # 197
......

Check the Free demo of our CISA Exam Dumps with 690 Questions: https://www.pass4leader.com/ISACA/CISA-exam.html

Verified CISA Q&As - Pass Guarantee CISA Exam Dumps: https://drive.google.com/open?id=1jzXe6GnSp2_Zj8uN6i9atjYZBNtgdDcF