Courseiva

CCNA Protection of Information Assets Questions

75 of 114 questions · Page 1/2 · Protection of Information Assets · Answers revealed

1
Multi-Selecthard

An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?

Select 3 answers
A.Standard Contractual Clauses (SCCs)
B.Data Protection Impact Assessment (DPIA)
C.Adequacy decision by the European Commission
D.Binding Corporate Rules (BCRs)
E.Data encryption at rest
AnswersA, C, D

SCCs are the European Commission's approved contractual template that imposes GDPR-equivalent safeguards on a data importer in a third country lacking an adequacy decision. They provide the lawful transfer mechanism the privacy program requires for such restricted jurisdictions.

Why this answer

Standard Contractual Clauses (SCCs) (A) are a core GDPR transfer mechanism under Article 46, providing pre-approved contractual terms that legally safeguard personal data when it moves to a third country lacking an adequacy finding. An adequacy decision by the European Commission (C) is essential because under Article 45 it declares a third country's data protection regime essentially equivalent to the EU's, allowing transfers without additional safeguards. Binding Corporate Rules (BCRs) (D) are another Article 47 mechanism, essential for multinational groups to legitimize intra-group cross-border transfers through internally binding data protection policies approved by supervisory authorities.

The unmarked options do not belong: a DPIA (B) is a risk assessment tool for high-risk processing, not a transfer mechanism, and encryption at rest (E) is a security control that may supplement but does not by itself legalize a cross-border transfer.

Exam trap

The trap is selecting security measures like encryption or risk assessments as legal transfer mechanisms. Candidates might think encryption alone suffices, but GDPR requires a legal basis for transfer. The exam tests knowledge of the specific legal instruments (SCCs, adequacy, BCRs) that are explicitly recognized.

2
MCQmedium

During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?

A.Test whether the rule is actually being used.
B.Escalate the finding to senior management.
C.Determine if the rule has a documented business justification.
D.Recommend immediate removal of the rule.
AnswerC

Before judging the any-any port 443 rule as a finding, the auditor must establish whether a documented business justification exists. Determining intent and approval first distinguishes an authorised exception from an undocumented, unjustified exposure, directing subsequent audit action appropriately.

Why this answer

When an IS auditor identifies a potentially risky firewall rule, the first step is to determine whether the rule has a documented business justification before taking any action. Auditors must gather evidence and understand the context — a rule allowing TCP 443 from any source may be legitimate for a public-facing web server. Only after establishing whether the rule is justified can the auditor decide on escalation or remediation.

Exam trap

The trap is jumping to remediation or escalation — CISA questions frequently test whether candidates understand that auditors must first gather evidence and assess justification before recommending action, reflecting the 'audit, don't fix' principle.

How to eliminate wrong answers

Option A is wrong because testing whether the rule is used is a technical validation step, but it does not establish whether the rule is authorized or justified — usage alone does not imply approval. Option B is wrong because escalating to senior management is premature before the auditor has gathered facts and assessed the rule's justification. Option D is wrong because recommending immediate removal without understanding the business context could disrupt legitimate services and violates the auditor's role of assessing rather than unilaterally acting.

3
MCQmedium

An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?

A.Privileged access is granted without approval from the system owner
B.Privileged accounts are not monitored in real-time
C.Privileged access is reviewed quarterly
D.There is no segregation of duties for privileged users
AnswerA

Without system owner approval, privileged access bypasses the authorisation control that ensures rights are granted only when a legitimate business need exists. This is the most serious finding because unapproved rights enable unauthorised changes and cannot be traced to an accountable approver.

Why this answer

Granting privileged access without approval from the system owner is the most serious finding because it removes the fundamental authorization control that ensures only legitimate, accountable requests receive elevated rights. Without owner approval, there is no business justification, no accountability trail, and no way to verify that the access is appropriate for the user's role. This directly undermines the principle of least privilege and creates an uncontrolled pathway to critical systems.

Exam trap

CISA often tests the distinction between preventive and detective controls — candidates may pick 'no real-time monitoring' because it sounds alarming, but the absence of an approval control is the more fundamental governance failure.

How to eliminate wrong answers

Option B is wrong because lack of real-time monitoring is a detective-control weakness, but it is less severe than an absent preventive control — monitoring gaps can be remediated with tooling, whereas unapproved access grants are already a governance failure. Option C is wrong because quarterly review of privileged access is actually a reasonable periodic control; while more frequent reviews may be desirable, quarterly is not inherently a finding of concern. Option D is wrong because lack of segregation of duties is a concern, but it is a design issue that can be mitigated with compensating controls; the absence of any approval process is a more fundamental breakdown of the access governance framework.

4
MCQeasy

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?

A.To document the data processing activities
B.To obtain consent from data subjects
C.To ensure compliance with data protection laws
D.To identify privacy risks and recommend mitigations
AnswerD

A privacy impact assessment systematically examines a processing activity to identify privacy risks and recommend mitigations before harm occurs. This proactive risk identification and treatment is its primary purpose, distinguishing it from breach response, consent collection or regulatory notification.

Why this answer

The PRIMARY purpose of a Privacy Impact Assessment (PIA) is to systematically identify and assess privacy risks associated with a project, system, or process, and to recommend mitigation measures. It is a proactive risk management tool that helps organizations understand how personal information is collected, used, shared, and retained, and to address potential privacy harms before they occur. While compliance with laws and documenting processing activities are outcomes or components, the core objective is risk identification and mitigation.

Exam trap

CISA often tests the distinction between the primary purpose of a PIA (risk identification and mitigation) and secondary outcomes like compliance or documentation, causing candidates to select a broader or more familiar concept such as legal compliance.

How to eliminate wrong answers

Option A is wrong because documenting data processing activities is a component of a PIA (e.g., data mapping) but not its primary purpose; documentation supports the risk assessment. Option B is wrong because obtaining consent from data subjects is a separate legal basis for processing and is not the purpose of a PIA; consent may be one mitigation if required, but it is not the primary goal. Option C is wrong because ensuring compliance with data protection laws is a benefit or driver of conducting a PIA, but the primary purpose is to identify and mitigate privacy risks; compliance is an outcome, not the core objective.

5
MCQmedium

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's primary transaction processing systems. The auditor observes that the data center uses a single-factor proximity card reader at the main entrance, the server room door is propped open during a vendor maintenance visit, and CCTV cameras record continuously but recordings are retained for only seven days. Which of the following should the auditor identify as the MOST significant control weakness?

A.The main entrance uses a single-factor proximity card reader instead of multifactor authentication.
B.CCTV recordings are retained for only seven days rather than the organization's 90-day standard.
C.The data center lacks biometric authentication at the server room entrance.
D.The server room door was propped open during the vendor visit, defeating the access control boundary.
AnswerD

A propped door during a vendor visit directly compromises the physical access control boundary and allows unescorted or unauthorized entry into the area housing critical transaction systems. Unlike the other observations, this is an active control failure occurring in real time that exposes the most sensitive assets. Vendor visits are a known risk period, and the door being held open means the access control system is not actually enforcing who enters the server room, making this the most significant weakness observed.

Why this answer

The propped server room door during a vendor visit is an active failure of the physical access control boundary protecting the transaction processing systems. While single-factor entry, short CCTV retention, and lack of biometrics are all valid observations, none of them currently allows uncontrolled access to the most sensitive area. The auditor should prioritize the real-time breach and require escorted vendor procedures and door alarms.

Exam trap

The trap here is gravitating toward technology gaps such as missing biometrics while overlooking an active physical control failure happening during the audit.

6
MCQmedium

An IS auditor is reviewing an organization's network segmentation design. The organization states that its cardholder data environment is isolated from the corporate network. During testing, the auditor discovers that a management VLAN can reach both environments and that the firewall permits administrative protocols from the management VLAN to any host. Which of the following is the auditor's BEST conclusion?

A.Segmentation is effective because administrative traffic is trusted and exempt from segmentation controls.
B.The finding is not significant because the management VLAN is internal to the organization.
C.Segmentation is ineffective because the management VLAN provides a path that bypasses the intended isolation.
D.The finding is acceptable if management traffic is encrypted with strong ciphers.
AnswerC

A management VLAN that can reach both the cardholder data environment and the corporate network, with administrative protocols permitted to any host, creates a bridge that defeats the purpose of segmentation. The intended isolation no longer holds because an attacker compromising a management workstation could pivot between environments, so the auditor should conclude the control objective is not met.

Why this answer

Segmentation depends on preventing any path between environments that should not communicate. A management VLAN with administrative protocol access to any host in both the cardholder data environment and the corporate network creates exactly such a path, so the isolation claim fails. Encryption, internal origin, and presumed trust of administrative traffic do not remove the reachability that allows lateral movement, and the auditor should report the design as ineffective.

Exam trap

The trap here is treating management traffic as inherently trusted, when a management VLAN that spans both environments is itself the bypass that breaks segmentation.

7
Multi-Selectmedium

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's core banking platform. During the walkthrough, the auditor notes that the mantrap entrance functions correctly, but the loading dock door is propped open for ventilation and the CCTV system records only the main corridor. Which TWO of the following findings should the auditor report as control weaknesses? (Choose two.)

Select 2 answers
A.The organization has not implemented a formal visitor escort policy for the data center.
B.The data center does not use biometric authentication at the mantrap entrance.
C.CCTV coverage does not include the loading dock or other areas outside the main corridor.
D.The loading dock door is propped open, bypassing the physical perimeter control.
E.The mantrap entrance allows only one person to enter at a time and slows authorized staff.
AnswersC, D

Video surveillance that covers only the main corridor leaves the loading dock and other sensitive areas unmonitored, creating blind spots where unauthorized activity could occur undetected. Because the loading dock is already identified as an uncontrolled entry point, the absence of camera coverage there compounds the risk. The auditor should report the incomplete CCTV coverage as a control weakness that limits detection and investigation capability.

Why this answer

The walkthrough produced two concrete observations that weaken physical security: the loading dock door is propped open, bypassing the perimeter, and CCTV covers only the main corridor, leaving other areas unmonitored. Both conditions create opportunities for unauthorized entry and undetected activity. The functioning mantrap is not a weakness, and the scenario provides no evidence about biometric authentication or visitor escort policies, so those cannot be reported as findings.

Exam trap

The trap here is reporting assumptions about controls that were not observed, such as missing biometrics or escort policies, instead of the two weaknesses actually seen during the walkthrough.

8
MCQmedium

An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?

A.Increased complexity of password management
B.Lack of individual accountability and audit trail
C.Violation of segregation of duties
D.Higher risk of password sharing outside the team
AnswerB

Shared administrative accounts mean activity cannot be attributed to a named individual, so the audit trail cannot support investigation, least-privilege enforcement or disciplinary action. This loss of individual accountability is the most significant concern because it undermines every other administrative control.

Why this answer

Shared administrative accounts break the fundamental audit principle of individual accountability because multiple administrators operate under one identity, making it impossible to attribute a specific action to a specific person. Without unique user IDs, the audit trail (logs, change records, access reviews) cannot reliably identify who performed which action, undermining non-repudiation and forensic investigation. This is the most significant concern because it defeats the purpose of logging and monitoring controls that auditors rely on.

Exam trap

CISA often tests the distinction between operational inconvenience (password complexity) and control failure (loss of accountability), so candidates who focus on the 'sharing' risk rather than the audit trail principle pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because password management complexity is an operational inconvenience, not a control failure — it can be mitigated with a privileged access management (PAM) vault and does not by itself destroy auditability. Option C is wrong because segregation of duties is a related but distinct concern; shared accounts do not automatically violate SoD if duties are otherwise separated, and SoD can still be enforced through other controls. Option D is wrong because password sharing outside the team is a symptom of the same root problem (no individual accountability) and is a risk rather than the core audit concern; the fundamental issue is the loss of attributable audit trails.

9
Multi-Selecthard

An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?

Select 3 answers
A.Defined roles and responsibilities for the incident response team
B.Procedures for evidence collection and chain of custody
C.Communication procedures for internal and external stakeholders
D.A list of all employees and their contact information
E.A detailed technical guide for each software application
AnswersA, B, C

Clearly defined roles and responsibilities assign each team member specific duties during an incident, preventing duplicated effort, gaps and confusion under pressure. This structure is essential for the plan to execute coordinated containment, eradication and recovery actions.

Why this answer

Option A is correct because an effective incident response plan must clearly define roles and responsibilities for the incident response team, ensuring each member knows their specific duties and authority during an incident. Option B is correct because procedures for evidence collection and chain of custody are essential to preserve forensic integrity, support potential legal or disciplinary actions, and ensure evidence is admissible. Option C is correct because communication procedures for internal and external stakeholders are critical for timely notification, coordination, regulatory compliance, and managing public relations during and after an incident.

Option D is not correct because a list of all employees and their contact information, while useful for general administration, is not an essential component of an incident response plan and may be maintained separately in a business continuity or crisis communication plan. Option E is not correct because a detailed technical guide for each software application is an operational or application-specific document, not a core component of an incident response plan, which should focus on processes, roles, and communication rather than exhaustive technical manuals.

10
MCQeasy

An IS auditor is reviewing the physical security controls at a data center. The auditor observes that the data center has a single entrance with a biometric scanner, but the door is propped open by a cleaning cart while the cleaning staff works inside. Which of the following is the MOST appropriate action for the auditor to take?

A.Ignore the observation because the cleaning staff are authorized personnel who have undergone background checks.
B.Recommend replacing the biometric scanner with a more robust access control system.
C.Report the issue to the cleaning supervisor and consider the matter resolved.
D.Document the observation as a finding because the propped door defeats the access control and allows unauthorized entry.
AnswerD

A propped door bypasses the biometric access control, allowing anyone to enter without authentication. This is a clear physical security weakness that undermines the entire access control objective. The auditor should document it as a finding because it represents a real risk of unauthorized access. Observing and reporting the issue is the appropriate audit action, not ignoring or downplaying it.

Why this answer

A propped door completely bypasses the biometric access control, creating a path for unauthorized entry. The auditor should document this as a finding because it represents a failure of the physical access control objective. The appropriate recommendation would be to implement compensating controls such as door alarms, mantrap entrances, or strict policy enforcement to prevent doors from being held open.

Exam trap

The trap here is assuming that because the individuals present are authorized, the propped door is acceptable, when in fact the open door allows anyone to enter without authentication.

11
Multi-Selecthard

An IS auditor is reviewing an organization's implementation of a security information and event management (SIEM) system. The auditor wants to assess whether the SIEM is effectively supporting incident detection and response. Which TWO of the following are the MOST important factors for the auditor to evaluate? (Choose two.)

Select 2 answers
A.The completeness of log sources and the timeliness of log ingestion from critical systems.
B.The brand reputation of the SIEM vendor and the number of industry awards it has received.
C.The physical security of the SIEM server room and the biometric access controls at the data center.
D.The process for tuning correlation rules and the procedures for investigating and escalating alerts.
E.The total storage capacity of the SIEM and the compression ratio of archived logs.
AnswersA, D

A SIEM's detection capability depends on the breadth and timeliness of the data it ingests. If critical systems such as firewalls, domain controllers, and databases are not forwarding logs, or if ingestion is delayed, the SIEM cannot correlate events or alert on emerging threats in real time. Evaluating log source coverage and ingestion latency is therefore fundamental to assessing whether the SIEM can effectively support incident detection.

Why this answer

The effectiveness of a SIEM for incident detection and response hinges on two operational pillars: comprehensive, timely log ingestion from critical systems, and well-tuned correlation rules supported by defined investigation and escalation procedures. Without complete and timely data, detection is blind; without tuning and response processes, alerts are noise. Storage capacity, vendor reputation, and physical security are secondary considerations for this specific audit objective.

Exam trap

The trap here is focusing on technical specifications such as storage or vendor reputation instead of the operational factors that determine whether the SIEM actually detects and enables response to incidents.

12
MCQeasy

An IS auditor is reviewing the physical security controls at a data center. The auditor observes that entry to the data center requires a smart card and a PIN, and that the door is a single-leaf door with a standard lock. Which of the following is the MOST important physical security control that the auditor should recommend?

A.Require employees to sign a logbook upon entry and exit.
B.Implement a mantrap or double-door entry system to prevent tailgating.
C.Replace the standard lock with a biometric lock for all employees.
D.Install security cameras inside the data center to monitor activity.
AnswerB

A mantrap, or access control vestibule, uses two interlocking doors to ensure that only one person can enter at a time, effectively preventing tailgating. Tailgating is a common physical security breach where an unauthorized person follows an authorized person through a secure door. Given that the data center uses smart cards and PINs, the next logical enhancement is to control physical passage to prevent unauthorized entry via tailgating, which is a critical control for high-security areas.

Why this answer

The most important physical security control to recommend is a mantrap or double-door entry system to prevent tailgating. While the data center uses smart card and PIN for authentication, a single door allows multiple people to enter on one authentication. A mantrap ensures that each person is individually authenticated and prevents unauthorized individuals from following authorized personnel.

This is a fundamental control for high-security areas like data centers.

Exam trap

The trap here is focusing on strengthening authentication methods when the real vulnerability is the lack of anti-tailgating controls, which authentication alone cannot address.

13
Multi-Selectmedium

An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?

Select 2 answers
A.Checking for default passwords on firewall
B.Verifying that each rule has a business justification
C.Comparing actual rules to documented rules
D.Testing firewall failover capabilities
E.Reviewing firewall performance metrics
AnswersB, C

Each firewall rule must map to a documented business need; rules lacking justification are candidates for removal, reducing attack surface. This satisfies the stem's rule-review element by confirming every permitted flow is authorised rather than merely technically functional.

Why this answer

A firewall rule review is fundamentally about validating the rulebase itself, so option B is correct: verifying that each rule has a business justification ensures no unnecessary, stale, or overly permissive rules remain, directly supporting least-privilege and reducing the attack surface. Option C is also correct because comparing the actual running rulebase against the documented/approved rules detects unauthorized changes, configuration drift, and shadowed or redundant rules, which is the core purpose of a rule review. Option A is not a rule-review element but a configuration/hardening check for default credentials, which is a separate control.

Option D concerns resilience and availability testing (failover), not rule correctness, and option E addresses capacity/performance monitoring rather than the appropriateness of the rules themselves.

Exam trap

CISA often tests the difference between rule review (policy and documentation validation) and firewall operational testing (failover, performance, password checks); candidates who pick operational tasks miss the 'rule review' scope.

14
MCQhard

During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?

A.Add an intrusion prevention system (IPS) to monitor the traffic
B.Require all traffic to go through a proxy server
C.Implement a more restrictive rule set based on specific IP addresses and ports
D.Accept the risk because there is a business justification
AnswerC

Any-to-any internal-to-Internet access grants unrestricted egress, enabling data exfiltration and command-and-control. Restricting to specific IP addresses and ports enforces least privilege while preserving the justified business need, satisfying the stem's requirement for a more granular, auditable rule set.

Why this answer

An any-to-any rule from internal to Internet is overly permissive and violates the principle of least privilege, even if a business justification exists. The auditor's best recommendation is to implement a more restrictive rule set based on specific IP addresses, ports, and protocols, which enforces least privilege while still meeting business needs. A business justification does not make an overly broad rule acceptable; the control should be tightened to the minimum necessary access.

Exam trap

The trap is accepting a business justification as sufficient for an overly broad rule; CISA tests that auditors must still recommend least-privilege restrictions even when a justification exists.

How to eliminate wrong answers

Option A is wrong because adding an IPS to monitor traffic is a compensating detective control, not a corrective measure; it does not reduce the attack surface created by the any-any rule and leaves the overly permissive rule in place. Option B is wrong because requiring all traffic to go through a proxy server is an architectural change that may not be feasible or necessary; it is not the auditor's first recommendation and does not directly address the rule specificity issue. Option D is wrong because accepting the risk solely due to a business justification ignores the principle of least privilege; a justification explains why access is needed, but the rule should still be as restrictive as possible.

15
MCQmedium

An IS auditor is assessing how an organization manages the risk of malicious code on employee workstations. The organization has deployed endpoint detection and response (EDR) agents on all workstations and maintains a centralized console. Which of the following is the MOST important factor in determining whether the EDR deployment effectively reduces malicious code risk?

A.Whether the EDR agents are installed on servers in addition to workstations.
B.Whether the EDR vendor has a large market share among similar organizations.
C.Whether the EDR agents are configured to update their detection signatures and behavioral models automatically.
D.Whether the EDR console is hosted in the same data center as the workstations it monitors.
AnswerC

EDR effectiveness depends heavily on current detection logic. If agents do not receive automatic updates to signatures and behavioral models, they will fail to recognize new malware variants and evolving attack techniques. Automatic updating ensures the endpoint can detect threats that emerge after deployment. Without it, the organization retains coverage only for known, older threats, which materially weakens the control's ability to reduce malicious code risk.

Why this answer

EDR reduces malicious code risk by detecting known and unknown threats through signatures and behavioral analysis. That capability degrades rapidly if the agent's detection logic is stale. Automatic updates keep both signature databases and behavioral models current, allowing the agent to recognize new variants and techniques.

Configuration and response integration matter, but without current detection logic the agent cannot identify the threats it is deployed to stop, so update configuration is the most important factor.

Exam trap

The trap here is treating vendor reputation or console placement as evidence of effectiveness, when detection currency through automatic updates is what determines whether the agent can actually identify malicious code.

16
MCQhard

During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?

A.Compute the aggregate risk score using a vulnerability management tool.
B.Review the risk acceptance documentation approved by the system owner and CISO.
C.Recommend immediate application of all missing patches.
D.Verify that the patches are not applicable to the environment.
AnswerB

Documented risk acceptance approved by the system owner and CISO evidences that the business knowingly accepted the unpatched vulnerabilities within its risk appetite. Reviewing that documentation lets the auditor evaluate whether acceptance was authorised, justified and consistent with policy.

Why this answer

The question asks how to evaluate the risk acceptance of unpatched vulnerabilities. Risk acceptance is a formal management decision that must be documented and approved by the appropriate authorities—typically the system owner and the CISO. Reviewing this documentation provides direct evidence that the organization has consciously accepted the risk, which is exactly what the auditor needs to evaluate.

Computing a risk score or recommending patching does not address whether the risk has been formally accepted.

Exam trap

CISA often tests the distinction between evaluating risk acceptance (reviewing documentation) and performing risk assessment or remediation (computing scores or patching), so candidates may incorrectly choose a technical action over a governance review.

How to eliminate wrong answers

Option A is wrong because computing an aggregate risk score quantifies the risk but does not evaluate whether that risk has been formally accepted by management. Option C is wrong because recommending immediate patching is a remediation action, not an evaluation of risk acceptance; it also ignores the possibility that the risk was deliberately accepted. Option D is wrong because verifying patch applicability is a technical validation step that determines if the patches are needed, but it does not assess whether the risk of not applying them has been accepted.

17
MCQmedium

An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?

A.Implement a break-glass procedure with post-event review
B.Require two-factor authentication for emergency access
C.Disable emergency access and require standard approval
D.Log all emergency access activities without review
AnswerA

A break-glass procedure grants emergency access under predefined conditions with logging, then mandates post-event review to validate and revoke it. This restores the missing segregation between request and approval by introducing independent retrospective scrutiny, mitigating the risk created when the system owner alone both requests and approves.

Why this answer

A break-glass procedure with post-event review directly addresses the lack of segregation between request and approval for emergency access by allowing immediate access while ensuring independent retrospective review. This compensates for the missing preventive segregation with a detective control that validates the emergency was legitimate. It preserves the ability to respond to incidents without waiting for standard approvals.

Exam trap

The trap here is choosing a preventive control (disable emergency access, add MFA) when the scenario already accepts that emergency access must exist; CISA expects a compensating detective control (break-glass with post-event review) that balances availability and accountability.

How to eliminate wrong answers

Option B is wrong because two-factor authentication strengthens authentication but does not compensate for the absence of segregation of duties between requesting and approving emergency access. Option C is wrong because disabling emergency access entirely could prevent timely response to critical incidents, creating an availability risk that outweighs the control benefit. Option D is wrong because logging without any review provides no assurance that emergency access was justified, so the risk remains unmitigated.

18
MCQmedium

An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?

A.Changing the shared account password after each use.
B.Logging all commands executed by the shared account.
C.Requiring two-factor authentication for the shared account.
D.Implementing a privileged access management (PAM) solution with session recording.
AnswerD

Shared accounts destroy individual accountability, so non-repudiation requires attributing each privileged action to a named person. PAM with session recording achieves this by brokering access through unique credentials while capturing activity, letting administrators act without sharing passwords and enabling forensic attribution.

Why this answer

A PAM solution with session recording uniquely ties each privileged session to an authenticated individual, even when a shared account is used, because users check out credentials and their keystrokes/commands are captured under their own identity. This provides the attribution needed for non-repudiation, which is the ability to prove who performed a specific action. Password changes, logging, and MFA on the shared account do not identify which individual used it.

Exam trap

CISA often tests the distinction between authentication, logging, and accountability; candidates incorrectly assume that logging commands or adding MFA to a shared account provides non-repudiation, when only per-user attribution (e.g., PAM session recording) does.

How to eliminate wrong answers

Option A is wrong because rotating a shared password after each use only limits the window of exposure; it does not identify which individual used the account, so non-repudiation is not achieved. Option B is wrong because logging commands executed under a shared account records actions but cannot attribute them to a specific person, defeating non-repudiation. Option C is wrong because two-factor authentication on a shared account authenticates the account, not the individual, and the second factor may be shared or bypassed, so it still cannot prove who acted.

19
MCQeasy

An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?

A.Percentage of employees who completed the training
B.Average score on post-training quiz
C.Number of reported phishing emails
D.Reduction in the number of successful phishing attacks
AnswerD

Successful phishing attacks measure actual security outcomes rather than activity. Completion rates and quiz scores reflect attendance, not behaviour change; a sustained fall in employees falling for simulated or real phishing demonstrates the training altered real-world susceptibility, which is the program's purpose.

Why this answer

A reduced number of successful phishing attacks indicates that employees are applying the training to recognize and avoid threats. The other metrics are useful but less direct indicators of behavioral change.

20
MCQeasy

An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?

A.Conducting periodic access recertification
B.Implementing single sign-on (SSO)
C.Enforcing password complexity rules
D.Using role-based access control (RBAC)
AnswerA

Periodic access recertification requires managers to confirm each user's rights remain necessary, catching privilege creep, transfers and stale accounts that accumulate over time. It directly satisfies the requirement that access rights stay appropriate, which provisioning-time approvals alone cannot guarantee.

Why this answer

Periodic access recertification is the most important control to ensure user access rights remain appropriate over time because it forces business owners to review and confirm each user's entitlements on a scheduled basis. It detects and removes accumulated privileges from role changes, transfers, or terminations. Other controls like SSO, password rules, and RBAC support access management but do not verify ongoing appropriateness.

Exam trap

CISA often tests the difference between access provisioning controls (RBAC, SSO) and access governance controls (recertification); candidates pick RBAC because it sounds like it manages access over time, but only recertification validates that rights remain appropriate.

How to eliminate wrong answers

Option B is wrong because single sign-on improves user convenience and centralizes authentication but does not verify that each user's access rights are still appropriate. Option C is wrong because password complexity rules protect against credential compromise but have no bearing on whether entitlements match current job roles. Option D is wrong because role-based access control provides a structured way to assign rights, but without periodic recertification, users can retain stale or excessive roles over time.

21
MCQmedium

An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?

A.Certificate authorities may lose their root key
B.Compromised certificates could still be used to establish trust
C.Certificates may expire without renewal
D.Users may not be able to verify certificate signatures
AnswerB

CRLs are the mechanism relying parties use to learn that a certificate is revoked. If they are stale, a compromised certificate's serial number is absent, so systems continue trusting it and attackers can still authenticate or decrypt traffic until the CRL is refreshed.

Why this answer

If CRLs are not updated in a timely manner, a certificate that has been revoked due to compromise or misuse will still appear valid to relying parties, allowing it to be used to establish trust. This defeats the purpose of revocation and can enable man-in-the-middle or impersonation attacks. Timely CRL publication is essential for the integrity of the PKI trust model.

Exam trap

The trap is confusing revocation with expiration or signature verification; candidates may pick 'certificates may expire' or 'users may not verify signatures' when the real risk is that revoked certificates continue to be trusted.

How to eliminate wrong answers

Option A is wrong because CRL updates have no relationship to the security of the CA's root private key; root key compromise is a separate, catastrophic event managed by offline storage and HSMs. Option C is wrong because certificate expiration is governed by the certificate's validity period and renewal processes, not by CRL update frequency. Option D is wrong because signature verification uses the certificate's public key and the CA's certificate, not the CRL; CRLs are used for revocation status checking, not signature validation.

22
MCQeasy

An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?

A.Separating key management duties
B.Storing keys in a hardware security module (HSM)
C.Regular key rotation
D.Encrypting keys with a master key
AnswerB

An HSM generates, stores and uses keys inside tamper-resistant hardware, so plaintext key material never enters general memory or storage. This satisfies the programme's core requirement to protect keys from extraction, unlike software storage or file-based encryption, where compromise of the host exposes the keys.

Why this answer

Storing keys in a hardware security module (HSM) is the most important control because HSMs provide tamper-resistant hardware that protects keys from extraction, ensures cryptographic operations occur inside a secure boundary, and enforces access controls. This directly addresses the core security objective of key protection. Other controls like separation of duties, rotation, and key wrapping are important but secondary to secure storage.

Exam trap

CISA often tests the hierarchy of key protection controls; candidates may choose key rotation or separation of duties because they sound like strong controls, but the question asks for the MOST important control to ensure key security, which is hardware-based protection (HSM).

How to eliminate wrong answers

Option A is wrong because separating key management duties reduces insider fraud risk but does not protect keys from technical compromise or extraction if they are stored in software. Option C is wrong because regular key rotation limits the impact of a compromised key but does not prevent the key from being stolen in the first place. Option D is wrong because encrypting keys with a master key (key wrapping) protects keys at rest but the master key itself must be protected, and software-based wrapping is weaker than hardware-based protection.

23
MCQmedium

An IS auditor is reviewing the logical access controls of a legacy payroll application that authenticates users directly against its own internal user table rather than the corporate directory. Management states that this was a deliberate design choice by the vendor. Which of the following is the MOST significant audit concern with this arrangement?

A.Password policy enforcement may be inconsistent with the corporate standard and orphaned accounts may persist.
B.The application's database may not be able to support concurrent user sessions at peak payroll processing times.
C.Users may need to remember an additional password, which could increase help desk call volume.
D.Vendor support for the authentication module may lapse if the application is not upgraded to the current release.
AnswerA

When an application maintains its own credential store, corporate password complexity, lockout, rotation, and expiry settings are not automatically inherited, and accounts are not disabled when the employee leaves or transfers. The directory's joiner-mover-leaver process no longer governs access, so orphaned and excessive rights accumulate silently. This is the most material concern because it breaks centralized identity governance for a financially sensitive system.

Why this answer

A locally maintained user table sits outside the corporate directory, so provisioning, modification, and timely revocation depend on manual processes that frequently fail. The result is inconsistent password standards and accounts that survive termination or role change. Auditors should focus on whether identity lifecycle controls still cover the application, since that determines whether access remains authorized, least-privileged, and auditable over time.

Exam trap

The trap here is treating a vendor design decision as automatically acceptable and focusing on support or usability rather than on the loss of centralized provisioning and de-provisioning.

24
Multi-Selecthard

An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)

Select 2 answers
A.Ensuring the hypervisor is kept up to date with the latest security patches.
B.Using a host-based intrusion detection system (HIDS) on each VM.
C.Regularly backing up VM images to a separate storage system.
D.Enabling promiscuous mode on the virtual switch to monitor all traffic.
E.Implementing strict isolation between VMs by disabling unnecessary virtual hardware and shared folders.
AnswersA, E

Keeping the hypervisor patched is critical because VM escape vulnerabilities are often due to bugs in the hypervisor code. Patches address known exploits that could allow an attacker to break out of a VM and compromise the host. This is a fundamental security practice for any software, and especially for the hypervisor, which is the foundation of the virtualized environment. Regular patching reduces the attack surface and mitigates known escape techniques.

Why this answer

The most effective controls to mitigate VM escape are patching the hypervisor and hardening VM configurations by disabling unnecessary virtual hardware and shared folders. Patching addresses known vulnerabilities that could be exploited for escape, while reducing the attack surface limits the vectors an attacker can use. Together, these preventive measures significantly reduce the risk of a VM compromising the hypervisor.

Exam trap

The trap here is selecting controls that detect or recover from an attack, such as HIDS or backups, instead of preventive controls that directly reduce the likelihood of VM escape.

25
MCQhard

During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?

A.Certificate authorities may become unavailable
B.Revoked certificates may be accepted as valid
C.Increased network traffic due to large CRLs
D.Users may experience delays in certificate validation
AnswerB

Weekly CRL publication creates a window in which a revoked certificate remains absent from the list, so relying parties continue to treat it as valid. Until the next update, compromised or misissued certificates can still authenticate, undermining the PKI's revocation assurance.

Why this answer

If CRLs are only updated weekly, revoked certificates may still be accepted as valid during the interval between revocation and CRL publication, allowing compromised or misused certificates to be trusted. This is the most significant risk because it undermines the revocation mechanism and can enable impersonation or man-in-the-middle attacks. Timely revocation is critical to PKI trust.

Exam trap

CISA often tests the difference between availability/performance impacts and security impacts; candidates may pick network traffic or validation delays because they sound like consequences of large CRLs, but the most significant risk is that revoked certificates remain trusted.

How to eliminate wrong answers

Option A is wrong because CRL update frequency does not affect CA availability; CA availability depends on infrastructure and redundancy. Option C is wrong because increased network traffic from large CRLs is an operational concern, not a security risk, and can be mitigated with delta CRLs or OCSP. Option D is wrong because delays in certificate validation are a performance issue, not a security risk; the security risk is accepting revoked certificates.

26
Multi-Selectmedium

An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?

Select 2 answers
A.The encryption algorithm used to protect the data
B.The location (systems and physical) where PII is stored
C.The cost of storing the data
D.The retention period for each type of PII
E.The names of all employees who process the data
AnswersB, D

Recording where PII resides, both in systems and physical premises, is essential because privacy obligations attach to every storage location. Without this, the institution cannot scope subject access requests, cross-border transfer restrictions or breach notification, leaving copies of personal data unaccounted for during compliance assessments.

Why this answer

Option B is correct because a data inventory must record where PII resides—both the systems (applications, databases, cloud services) and physical locations—so the organization can apply appropriate safeguards and respond to access, breach, or deletion requests under privacy regulations. Option D is correct because documenting the retention period for each type of PII ensures data is kept only as long as legally or operationally necessary and is securely disposed of when that period ends, which is a core privacy compliance requirement. Option A is not essential to the inventory itself; encryption algorithms are security controls recorded in system documentation, not identifying attributes of a data inventory.

Option C is irrelevant to privacy compliance, as storage cost is a financial metric rather than a data-governance attribute. Option E is unnecessary and impractical, since the inventory should identify processing activities and roles, not list every individual employee who handles the data.

Exam trap

CISA often tests the distinction between privacy-compliance metadata (location, retention) and security or financial metadata (encryption algorithm, cost), tempting candidates to pick controls that sound important but are not inventory essentials.

27
MCQmedium

An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?

A.Secure key storage (e.g., HSM)
B.Key rotation policy
C.Key generation in a secure environment
D.Key destruction procedures
AnswerA

Secure key storage in a hardware security module protects keys at rest within tamper-resistant hardware, preventing extraction or disclosure. Since compromise of the key itself defeats every cryptographic protection built upon it, this control is the most critical safeguard.

Why this answer

Secure key storage, typically in a hardware security module (HSM), is the most critical control because it protects keys at rest from extraction, tampering, and unauthorized access throughout their lifecycle. If keys can be stolen from storage, every other control — generation, rotation, destruction — is undermined, since the attacker gains the key material itself. HSMs provide tamper resistance, cryptographic isolation, and access controls that software storage cannot match.

Exam trap

CISA often tests the hierarchy of key management controls — candidates pick rotation or generation because they sound proactive, but the exam expects recognition that secure storage is foundational because compromised keys nullify all other controls.

How to eliminate wrong answers

Option B is wrong because key rotation limits the window of exposure if a key is compromised, but it is a mitigating control, not the foundational one — a stolen key is still usable until rotation occurs. Option C is wrong because secure key generation ensures keys have sufficient entropy and are not predictable, which is important, but a well-generated key is worthless if it can be extracted from weak storage. Option D is wrong because key destruction procedures prevent residual key material from being recovered after retirement, which addresses end-of-life risk, not the ongoing protection of active keys.

28
Multi-Selecteasy

An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?

Select 2 answers
A.Use of biometric authentication
B.Single sign-on for all applications
C.Quarterly recertification of access by managers
D.Automatic provisioning upon employee hire
E.Access requests approved by the data owner
AnswersC, E

Quarterly recertification forces managers to confirm each user's continued business need for financial application access, catching privilege creep and stale entitlements between joiner-mover-leaver events. This directly satisfies the stem's requirement for controls ensuring access remains appropriate over time.

Why this answer

Option C is correct because quarterly recertification of access by managers ensures that users' privileges are periodically reviewed and revoked when no longer needed, directly supporting the principle of least privilege and preventing privilege creep in a sensitive financial application. Option E is correct because access requests approved by the data owner enforce proper authorization by the individual accountable for the data, ensuring that only legitimate business needs grant access to sensitive financial information. Biometric authentication (A) strengthens identity verification but does not by itself ensure that access rights are appropriate or authorized.

Single sign-on (B) improves convenience and can centralize authentication, but it can also broaden exposure if not tightly controlled and does not validate the appropriateness of access. Automatic provisioning upon hire (D) speeds onboarding but risks granting excessive or unauthorized access without proper approval, making it a weaker control for ensuring appropriate access.

Exam trap

CISA often tests the distinction between authentication controls (biometrics, SSO) and authorization/governance controls (recertification, data-owner approval), luring candidates toward technically impressive but governance-irrelevant options.

29
MCQeasy

An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?

A.To identify inactive user accounts
B.To verify that users' access rights remain appropriate for their roles
C.To ensure compliance with password policies
D.To enforce segregation of duties
AnswerB

Recertification forces managers to periodically revalidate each user's entitlements against current job duties, catching privilege creep and stale accounts created by transfers or role changes. This directly satisfies the control objective of confirming access remains appropriate for users' roles.

Why this answer

The primary purpose of user access recertification is to verify that each user's access rights remain appropriate for their current role and responsibilities (B). It is a detective governance control that catches privilege creep, role changes, and orphaned entitlements that accumulate over time. While recertification can surface inactive accounts, that is a byproduct rather than the primary objective; the core intent is validating the ongoing business need for access.

Exam trap

The trap here is confusing recertification's primary purpose (validating appropriateness of access) with its incidental benefits (finding inactive accounts), causing candidates to select the tempting but secondary answer.

How to eliminate wrong answers

Option A is wrong because identifying inactive accounts is a secondary benefit of recertification, not its primary purpose; dedicated dormancy reports or last-login analysis handle that more directly. Option C is wrong because password policy compliance is enforced through technical controls such as complexity rules, expiration, and lockout thresholds, not through access reviews. Option D is wrong because segregation of duties is enforced through role design, conflict-of-interest rules, and preventive controls at provisioning time; recertification may detect SoD conflicts but does not enforce them.

30
MCQeasy

An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?

A.CCTV cameras
B.Visitor log
C.Mantrap
D.Biometric readers
AnswerC

A mantrap admits one person at a time through interlocking doors, so a second individual cannot follow on the first person's valid credential. This physically enforces single-person entry, directly preventing the unauthorised tailgating the stem asks about.

Why this answer

A mantrap (C) is the most effective control for preventing tailgating because it physically admits only one person at a time through an interlocking door system, using weight sensors, biometrics, or access cards to verify each individual before the second door opens. It enforces one-person-per-entry at the physical layer, which no camera or log can do. CCTV and visitor logs are detective controls, and biometric readers authenticate individuals but do not by themselves prevent a second person from slipping through behind an authorized user.

Exam trap

The trap is confusing authentication controls (biometric readers) with anti-tailgating controls, leading candidates to pick a device that verifies identity but does not physically prevent multiple people from entering.

How to eliminate wrong answers

Option A is wrong because CCTV cameras are detective controls that record activity for later review; they do not physically prevent a person from following an authorized user through a door. Option B is wrong because a visitor log is an administrative, detective control that documents entry after the fact and does nothing to stop unauthorized physical entry. Option D is wrong because biometric readers authenticate the person presenting the credential but, without an interlocking physical barrier, an unauthorized person can still tailgate behind the authenticated individual.

31
MCQhard

An IS auditor is evaluating a wireless network deployed in a corporate headquarters. The auditor discovers that the network uses WPA2-Enterprise with 802.1X authentication, but the RADIUS server accepts any client presenting a valid domain user account, including accounts belonging to recently terminated employees that have not yet been disabled. Which of the following is the GREATEST risk arising from this configuration?

A.Rogue access points could be introduced without detection by the wireless intrusion prevention system.
B.Former employees with still-valid accounts could authenticate to the internal network and access resources.
C.Wireless traffic could be decrypted by anyone monitoring the radio frequency spectrum.
D.Attackers could capture and crack the pre-shared key used for wireless encryption.
AnswerB

The core weakness is that terminated users retain working credentials that the RADIUS server accepts. An ex-employee who remembers those credentials can pass 802.1X authentication and reach internal network resources as an authorized user. This is a logical access failure, and it directly enables unauthorized entry into the protected environment through the wireless infrastructure.

Why this answer

The finding is that authentication succeeds for accounts belonging to terminated employees, meaning the RADIUS server does not enforce timely deprovisioning. Because 802.1X grants network access on successful authentication, a former employee can re-enter the internal network using valid credentials. The primary risk is unauthorized internal access through a logical access control failure, not encryption weakness or rogue devices.

Exam trap

The trap here is focusing on wireless encryption strength when the actual exposure is a logical access control gap caused by stale, still-valid credentials.

32
MCQhard

An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?

A.Accept the decision as business risk acceptance
B.Escalate to senior management as a critical finding
C.Recommend immediate decommissioning of the application
D.Verify that the risk has been formally accepted and compensating controls are implemented
AnswerD

Verifying formal risk acceptance and compensating controls confirms the residual risk is documented, authorised by accountable management and mitigated, satisfying the auditor's duty to ensure the unfixed vulnerability is consciously owned rather than silently ignored before decommissioning.

Why this answer

The auditor's proper action is to verify that the risk has been formally accepted by the appropriate authority and that compensating controls are implemented (D). Risk acceptance is a legitimate management decision, but it must be documented, approved at the right level, and supported by mitigating controls given the criticality of the vulnerability. The auditor's role is to validate that this governance process occurred, not to unilaterally accept, escalate, or demand decommissioning.

Exam trap

The trap is the auditor's role confusion — candidates either overstep by escalating or recommending decommissioning, or understep by accepting the risk themselves, instead of verifying formal acceptance and compensating controls.

How to eliminate wrong answers

Option A is wrong because the auditor cannot simply accept the decision; acceptance is management's prerogative, and the auditor must verify that it was formally documented and approved by the appropriate authority. Option B is wrong because escalation to senior management is premature if the risk has been properly accepted and compensating controls exist; escalation is warranted only when acceptance is undocumented or outside the approver's authority. Option C is wrong because recommending immediate decommissioning is a business decision beyond the auditor's mandate and ignores the possibility of compensating controls and the planned six-month decommissioning timeline.

33
MCQmedium

An IS auditor is reviewing the network segmentation of a retail company's cardholder data environment (CDE). The auditor finds that the CDE and the corporate user VLAN are separated by a firewall, but the same flat Layer 2 domain spans both segments, and no internal segmentation firewall exists between the CDE web tier and the CDE database tier. Which of the following findings should the auditor report as the GREATEST risk?

A.The CDE and corporate VLAN share a flat Layer 2 domain, allowing lateral movement without passing through the firewall.
B.The corporate VLAN should be moved into the CDE so that all traffic is inspected by the same firewall policy.
C.The firewall separating the CDE and corporate VLAN is a single point of failure and should be deployed in a high-availability pair.
D.The absence of an internal segmentation firewall between the web tier and the database tier is the greatest risk.
AnswerA

A shared Layer 2 domain means hosts in the corporate VLAN and the CDE can communicate at the data-link layer, bypassing the firewall that was intended to be the sole control point. An attacker on a compromised workstation could reach CDE hosts directly via ARP and MAC-level traffic, defeating the segmentation the organization believes is in place. This is the most severe issue because the compensating control does not actually enforce the separation it claims to provide.

Why this answer

The critical issue is that the CDE and corporate network share a flat Layer 2 domain, so hosts can communicate via ARP and MAC-level traffic without traversing the firewall. This silently defeats the intended segmentation and enables lateral movement from a compromised corporate workstation into the cardholder data environment. Eliminating the shared broadcast domain and forcing all inter-segment traffic through the firewall restores the control the organization believes is operating.

Exam trap

The trap here is assuming that a firewall between VLANs guarantees isolation, when a shared Layer 2 domain allows traffic to bypass the firewall entirely.

34
MCQmedium

An IS auditor is reviewing the physical security controls for a data center. The auditor observes that the data center has a raised floor, a fire suppression system, and biometric access controls. The auditor also notes that the data center is located in a region prone to flooding. Which of the following controls is MOST important to mitigate the risk of flooding?

A.Elevating the data center floor above the expected flood level.
B.A sump pump system in the basement.
C.Water detection sensors under the raised floor.
D.A fire suppression system that also removes water.
AnswerA

Elevating the data center floor above the expected flood level is a preventive physical control that directly reduces the risk of floodwater reaching the equipment. By placing the data center on a higher floor or raising the entire facility, water from a flood would need to rise significantly before affecting operations. This is the most effective way to mitigate flood risk, as it addresses the threat at its source by keeping water out.

Why this answer

Elevating the data center floor above the expected flood level is the most important control because it prevents floodwater from reaching critical equipment. It is a preventive measure that directly addresses the flood risk, whereas other options like sensors or pumps are detective or mitigating. In flood-prone areas, physical elevation is a fundamental design consideration for data center resilience.

Exam trap

The trap here is confusing detective controls like water sensors with preventive controls, when the question asks for the best mitigation of flood risk.

35
MCQmedium

An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?

A.Reviewing security camera footage of office areas
B.Reviewing the policy document and employee acknowledgments
C.Interviewing employees about the policy
D.Conducting unannounced inspections of workstations
AnswerD

Unannounced inspections provide direct, first-hand evidence of whether sensitive documents and media are actually secured when staff leave workstations, satisfying the need to verify real compliance rather than assumed adherence. Announced checks or policy reviews only confirm intent, not operational practice.

Why this answer

Surprise walkthroughs provide a realistic view of daily compliance, unlike scheduled inspections.

36
MCQhard

During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?

A.Conduct a penetration test to assess the risk
B.Remove the rule immediately and verify no impact
C.Document the rule with a risk acceptance signed by management
D.Modify the rule to allow only specific ports and protocols
AnswerB

The any-any rule grants broad internal-to-DMZ access with no business justification, violating least privilege and expanding the attack surface. Removing it and verifying no impact eliminates the exposure while confirming that no legitimate dependency remains.

Why this answer

The rule is overly permissive, no longer justified by business need, and poses an unnecessary risk. The best recommendation is to remove the rule immediately and verify no impact, as it aligns with the principle of least privilege and reduces the attack surface.

Exam trap

The trap is choosing 'modify the rule' because it seems less disruptive, but the rule is no longer needed, so removal is the best practice; also, 'any-any' is too broad to simply modify without understanding requirements.

How to eliminate wrong answers

Option A is wrong because a penetration test is a point-in-time assessment and does not address the immediate risk; it also does not remove the rule. Option C is wrong because documenting the rule with risk acceptance is inappropriate when the rule is no longer needed; risk acceptance should be a last resort after risk mitigation. Option D is wrong because modifying the rule to allow specific ports is a mitigation, but the rule is no longer required, so removal is better; also, 'any-any' includes all ports, so modifying might still leave unnecessary access.

37
MCQeasy

Which of the following is the BEST indicator of the effectiveness of a security awareness program?

A.Reduction in the number of successful phishing attacks.
B.Positive feedback from employees about the training.
C.Number of employees who completed the training.
D.Average test scores on post-training assessments.
AnswerA

Successful phishing attacks measure actual user behaviour under real adversarial conditions, directly evidencing whether awareness training changed outcomes. Completion rates and quiz scores reflect attendance, not resistance, so a sustained reduction in successful phishing satisfies the stem's effectiveness indicator by demonstrating transferred vigilance rather than passive knowledge.

Why this answer

A decrease in successful phishing attacks demonstrates behavioral change.

38
MCQmedium

An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?

A.A rule that has not been reviewed for 18 months
B.A rule that permits traffic from a specific IP to a database server on port 1433
C.A rule that allows any source IP to access a critical server on port 443
D.A rule that allows any service from the Internet to the internal network
AnswerD

A rule permitting any service from the Internet to the internal network exposes every internal host and port to unrestricted external access, effectively bypassing perimeter segmentation. This is the most severe finding because it enables broad exploitation, far exceeding risks from individual permissive rules.

Why this answer

A rule that allows any service from the Internet to the internal network is the most concerning because it effectively bypasses the firewall's purpose, permitting unrestricted inbound access to internal systems. This exposes the entire internal network to external threats, including malware, unauthorized access, and exploitation of any vulnerable service. Such a rule violates the principle of least privilege and is a critical misconfiguration that auditors flag as a severe control weakness.

Exam trap

The trap is equating 'any source IP' with 'any service'; candidates see 'any source' in option C and pick it, missing that the protocol and destination are restricted, whereas option D allows any service to the entire internal network.

How to eliminate wrong answers

Option A is wrong because a rule not reviewed for 18 months is a hygiene issue and a policy violation, but it is less severe than an any-service rule that actively exposes the internal network. Option B is wrong because permitting a specific IP to a database server on port 1433 (SQL Server) is a narrow, targeted rule that may be legitimate for application access, though it should be reviewed for necessity. Option C is wrong because allowing any source IP to access a critical server on port 443 (HTTPS) is common for public-facing web servers and is not inherently dangerous if the service is hardened and intended to be public.

39
MCQhard

An IS auditor is assessing the security of an organization's virtualization environment. The auditor finds that the hypervisor management interface is accessible from the general corporate network and uses default credentials. Which of the following is the MOST critical risk associated with this finding?

A.An attacker could cause a denial of service by overwhelming the hypervisor with management requests.
B.An attacker could exploit a vulnerability in the hypervisor to escape to the host operating system.
C.An attacker could gain control of the hypervisor and compromise all hosted virtual machines.
D.An attacker could intercept network traffic between virtual machines on the same host.
AnswerC

The hypervisor management interface is a high-value target because it controls the entire virtual infrastructure. If an attacker accesses it with default credentials, they can potentially shut down, modify, or create virtual machines, and even move laterally to other systems. This could lead to a complete compromise of all hosted workloads, data breaches, and service outages. This is the most critical risk because it affects the entire virtual environment, not just a single VM.

Why this answer

The most critical risk is that an attacker could gain control of the hypervisor and compromise all hosted virtual machines. The hypervisor management interface is a privileged access point; if exposed and using default credentials, it can be easily exploited. An attacker with administrative control can manipulate all VMs, access sensitive data, and disrupt services across the entire virtual infrastructure.

This represents a single point of failure with catastrophic potential.

Exam trap

The trap here is focusing on specific technical attacks like VM escape or traffic sniffing while underestimating the immediate and severe impact of unauthorized administrative access to the hypervisor.

40
Multi-Selecteasy

During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?

Select 2 answers
A.Deploy additional CCTV cameras
B.Conduct security awareness training
C.Implement a clean desk policy
D.Implement a visitor management system
E.Install motion detectors
AnswersB, C

Security awareness training addresses the human behaviour behind documents left on desks, teaching staff classification handling and the clean desk requirement. It complements procedural controls by changing the culture that causes the exposure the auditor observed.

Why this answer

Option B (Conduct security awareness training) is correct because the root cause of documents being left out overnight is employee behavior, and awareness training directly educates staff on their security responsibilities, the risks of leaving confidential information exposed, and proper handling and storage procedures. Option C (Implement a clean desk policy) is correct because it establishes a formal, enforceable requirement that all sensitive documents be secured or locked away at the end of the workday, directly addressing the observed weakness and providing a basis for audits and disciplinary action. Option A (Deploy additional CCTV cameras) is not appropriate because cameras only provide detective/monitoring capability and do not prevent employees from leaving documents on desks.

Option D (Implement a visitor management system) does not belong because the issue involves employees, not visitors, and visitor control does not address internal document handling. Option E (Install motion detectors) is not relevant because motion detection is an intrusion-detection control for after-hours physical access, not a control over how employees handle confidential documents.

Exam trap

The trap is choosing physical detection controls (CCTV, motion detectors) because they sound security-related, when the question asks for controls that directly address the observed behavior of leaving documents on desks.

41
MCQhard

An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?

A.Pseudonymisation eliminates the need for data subject rights
B.Pseudonymisation is not recognized by GDPR
C.Pseudonymisation cannot be applied to structured data
D.Pseudonymised data is still considered personal data under GDPR
AnswerD

Pseudonymisation replaces direct identifiers but retains a key enabling re-identification, so the data remains personal data under GDPR and its protections still apply. This limits the control: it reduces risk but does not remove the organisation's compliance obligations.

Why this answer

Under GDPR Article 4(5), pseudonymisation is a technique where personal data can no longer be attributed to a specific data subject without additional information kept separately. However, because re-identification remains possible with that additional information, pseudonymised data is still legally considered personal data under GDPR, meaning data subject rights, breach notification, and other obligations continue to apply. This is the most important limitation an IS auditor must recognize when assessing the control's effectiveness.

Exam trap

CISA often tests the misconception that pseudonymisation equals anonymisation — candidates incorrectly assume pseudonymised data falls outside GDPR scope, when in fact it remains personal data subject to full regulatory obligations.

How to eliminate wrong answers

Option A is wrong because pseudonymisation does not eliminate data subject rights — GDPR Articles 15-22 rights (access, erasure, portability, etc.) still apply to pseudonymised data since it remains personal data. Option B is wrong because GDPR explicitly recognizes pseudonymisation in Article 4(5) and encourages it as a safeguard under Article 32 and Recital 28. Option C is wrong because pseudonymisation can absolutely be applied to structured data — it is commonly implemented via tokenization, hashing, or key-value substitution in relational databases and data warehouses.

42
MCQmedium

An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?

A.Elimination of shared accounts by providing individual credentials
B.Enforcement of segregation of duties between IT and security teams
C.Automated password resets for user accounts
D.Centralized management and monitoring of privileged account usage
AnswerD

Centralised management and monitoring consolidates privileged accounts into a controlled vault, enabling credential checkout, session recording and anomaly detection. This directly addresses the core PAM objective of curbing unmonitored, standing administrative access across the estate.

Why this answer

The primary benefit of a PAM solution is centralized management and monitoring of privileged account usage — it vaults credentials, controls who can check out which privileged accounts, records sessions, and provides audit trails. This addresses the core risk that privileged accounts (root, admin, service accounts) are the most sought-after targets for attackers and the hardest to oversee when scattered across systems. While PAM can support the other options to varying degrees, centralized management and monitoring is the defining, primary purpose.

Exam trap

CISA often tests the distinction between PAM's primary purpose (centralized privileged account management and monitoring) and secondary benefits (reducing shared accounts, enabling password resets), causing candidates to select a true-but-not-primary answer.

How to eliminate wrong answers

Option A is wrong because while PAM can reduce shared accounts by issuing individual credentials, that is a secondary benefit, not the primary purpose — PAM's core value is centralized control and visibility over privileged access, not merely credential individualization. Option B is wrong because segregation of duties between IT and security teams is an organizational governance decision, not something a PAM tool enforces by itself; PAM can support SoD but does not establish it. Option C is wrong because automated password resets for regular user accounts is a helpdesk/identity management function (often handled by IAM or self-service password reset tools), not the primary benefit of PAM, which focuses on privileged accounts.

43
MCQmedium

An IS auditor is reviewing an organization's endpoint protection controls after several employees reported slow performance on their laptops. The auditor observes that the anti-malware solution performs a full disk scan every night, and the audit log shows that the last successful signature update was 47 days ago. Which of the following is the MOST significant concern the auditor should report?

A.The nightly full disk scan consumes excessive endpoint resources and degrades user productivity.
B.The organization has not implemented application whitelisting to complement the anti-malware solution.
C.The full disk scan schedule conflicts with the organization's backup window and may cause backup failures.
D.The anti-malware signature database has not been updated for 47 days, leaving endpoints exposed to recent threats.
AnswerD

Signature files that are 47 days stale mean newly discovered malware families and variants cannot be detected by the endpoint control. This directly defeats the preventive purpose of the anti-malware solution and represents a material gap in the protection of information assets. The auditor should report this as the primary concern because it exposes the organization to known, circulating threats.

Why this answer

The most significant concern is that endpoint protection is running with signatures that are 47 days old, which means the control cannot detect recently identified malware. A deployed but outdated anti-malware solution provides a false sense of security because it appears active yet fails against current threats. Performance and scheduling issues are secondary operational matters, while the stale signature database is a direct, measurable weakness in the protection of information assets.

Exam trap

The trap here is focusing on the visible performance complaints from users instead of recognizing that stale signatures silently neutralize the anti-malware control.

44
MCQeasy

An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?

A.Security guards at the entrance
B.CCTV cameras at the entrance
C.Mantrap
D.Biometric readers at all entrances
AnswerC

A mantrap permits only one person through an interlocking door sequence at a time, physically preventing an unauthorised individual from following an authenticated person. This directly satisfies the stem's constraint by eliminating the single-entry tailgating vector that badge readers alone cannot address.

Why this answer

A mantrap is a physical security control consisting of a small vestibule with two interlocking doors, where the first door must close and the person must be authenticated before the second door opens. This design physically prevents tailgating because only one person can occupy the space at a time, and unauthorized individuals cannot slip through behind an authorized person. It is the most effective preventive control specifically engineered to defeat tailgating.

Exam trap

CISA often tests the difference between preventive and detective physical controls — candidates pick CCTV or guards (detective/deterrent) when the question asks for the MOST effective control to PREVENT tailgating, which requires a physical interlock like a mantrap.

How to eliminate wrong answers

Option A is wrong because security guards are a deterrent and detective control — they can observe and challenge tailgaters, but human attention lapses and a determined tailgater can still slip past, especially during high-traffic periods. Option B is wrong because CCTV cameras are purely detective and after-the-fact — they record tailgating but do nothing to prevent it in real time. Option D is wrong because biometric readers authenticate the person presenting credentials but do not prevent a second person from following closely behind through the same door — biometrics alone do not stop tailgating without a physical interlock.

45
MCQeasy

An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?

A.Checking the availability of forensic tools
B.Interviewing the IR team
C.Conducting a tabletop exercise
D.Reviewing IR policies and procedures
AnswerC

A tabletop exercise walks participants through a simulated incident, testing decision-making, roles, communication and plan completeness without production disruption. This validates the IR plan's effectiveness against the stem's requirement, unlike reviewing documentation, which only confirms the plan exists.

Why this answer

A tabletop exercise is the best way to test the effectiveness of an incident response plan because it simulates a realistic incident scenario and requires the IR team to walk through their roles, decisions, and communications in a facilitated discussion. This reveals gaps in the plan, unclear responsibilities, and coordination breakdowns without the risk or cost of a live simulation. It directly tests whether the plan works in practice, not just whether it exists on paper.

Exam trap

CISA often tests the difference between reviewing documentation (policies, procedures) and actually testing a plan — candidates pick 'reviewing IR policies' because it sounds thorough, but the question asks for the BEST way to TEST effectiveness, which requires an exercise like a tabletop.

How to eliminate wrong answers

Option A is wrong because checking the availability of forensic tools only verifies that tools exist and are accessible — it does not test whether the IR team can use them effectively during an actual incident or whether the plan's procedures are sound. Option B is wrong because interviewing the IR team gathers opinions and stated knowledge but does not validate that the plan functions under pressure or that team members can execute their roles in a coordinated way. Option D is wrong because reviewing IR policies and procedures is a documentation review that confirms the plan exists and is written correctly, but it provides no evidence that the plan works when executed.

46
MCQeasy

An IS auditor is reviewing how a data center protects its backup tapes while they are in transit to an offsite storage facility. Management states that tapes are encrypted before shipment and that a courier transports them in sealed containers. Which of the following is the MOST appropriate evidence to confirm that the tapes are protected in transit?

A.Review the encryption algorithm and key length used for the backup tapes.
B.Interview the backup administrator about the tape pickup schedule.
C.Examine the offsite storage vendor's SOC 2 report.
D.Inspect the courier's chain-of-custody logs and verify the sealed-container handoff signatures.
AnswerD

Chain-of-custody logs with signed handoffs demonstrate that the sealed containers were tracked from pickup to delivery, providing direct evidence that physical protection was maintained during transit. This is the strongest audit evidence available for the transit leg of the media lifecycle, since the auditor can trace each tape shipment and confirm no unaccounted gaps or broken seals occurred.

Why this answer

The scenario tests physical media protection during transit, so the auditor needs evidence covering the movement of tapes between sites. Signed chain-of-custody documentation with sealed-container handoffs directly evidences that custody was maintained and containers stayed intact from pickup to delivery, which is the specific control objective. Encryption, interviews, and vendor-side reports each address different phases of the media lifecycle and cannot substitute for transit custody records.

Exam trap

The trap here is assuming that encrypting backup tapes removes the need for physical transit controls, when custody documentation is still required to prove the media was protected and accounted for in transit.

47
MCQeasy

Which of the following is the PRIMARY reason for implementing network segmentation?

A.To comply with licensing requirements.
B.To simplify IP address management.
C.To contain security breaches and limit lateral movement.
D.To improve network performance.
AnswerC

Segmentation places enforcement points between network zones, so a compromised host cannot freely reach other systems. This directly satisfies the containment constraint: it restricts lateral movement, limiting blast radius and buying incident responders time before the attacker pivots to critical assets.

Why this answer

The primary reason for network segmentation is to contain security breaches and limit lateral movement — by dividing the network into isolated zones, an attacker who compromises one segment cannot freely move to others. This is a foundational defense-in-depth control that reduces the blast radius of a breach and protects critical assets. While segmentation can have secondary benefits, security containment is its primary purpose in modern network design.

Exam trap

CISA often tests the distinction between primary and secondary benefits — candidates pick 'improve network performance' because segmentation can reduce broadcast traffic, but the PRIMARY reason is security containment and limiting lateral movement.

How to eliminate wrong answers

Option A is wrong because licensing compliance is unrelated to network segmentation — licensing is a legal/procurement matter, not a network architecture driver. Option B is wrong because simplifying IP address management is a potential administrative side effect of good network design, but it is not the primary reason organizations invest in segmentation. Option D is wrong because improving network performance can be a secondary benefit (by reducing broadcast domains and congestion), but it is not the primary reason — security containment is the driving rationale, especially given regulatory and threat-landscape pressures.

48
MCQhard

An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?

A.Encryption keys are stored on the same server as the encrypted data.
B.The encryption algorithm used is not FIPS 140-2 validated.
C.Encryption is not applied to all ePHI in transit.
D.The encryption key rotation policy is not documented.
AnswerA

Storing keys alongside ciphertext collapses the two-party separation encryption depends on: anyone gaining server access obtains both data and keys, rendering encryption ineffective. This defeats HIPAA's safe harbour premise, which assumes keys remain protected and separate, so a single compromise exposes all protected health information.

Why this answer

HIPAA's encryption safe harbor only applies if ePHI is rendered unusable, unreadable, or indecipherable to unauthorized persons. If the encryption keys are stored on the same server as the encrypted data, an attacker who compromises that server obtains both the ciphertext and the keys, effectively defeating the encryption. This is the most significant risk because it nullifies the safe harbor protection entirely.

Exam trap

CISA often tests the misconception that any encryption satisfies the safe harbor, when the real trap is key management: storing keys with the data defeats encryption and is the most severe risk.

How to eliminate wrong answers

Option B is wrong because although FIPS 140-2 validation is a recognized standard, using a non-validated algorithm is a compliance weakness rather than an immediate defeat of the safe harbor; the data may still be encrypted with a strong algorithm. Option C is wrong because failing to encrypt all ePHI in transit is a gap in coverage, but it does not undermine the encryption that is applied; it is a scope issue, not a key-management failure. Option D is wrong because an undocumented key rotation policy is a documentation and governance weakness, not an immediate compromise of the encryption's effectiveness.

49
Multi-Selectmedium

An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?

Select 2 answers
A.CCTV cameras at entry points.
B.Security guards checking badges.
C.Mantrap with interlocking doors.
D.Turnstiles that allow only one person per authentication.
E.Biometric authentication.
AnswersC, D

A mantrap with interlocking doors physically admits one person per cycle, so a second individual cannot follow through before the first door closes. This directly satisfies the stem's requirement to prevent unauthorised tailgating, unlike detective controls such as CCTV, which record the breach only after entry has occurred.

Why this answer

Option C, a mantrap with interlocking doors, is correct because it creates a controlled vestibule where the first door must close and the person must be authenticated before the second door opens, physically preventing a second individual from following through. Option D, turnstiles that allow only one person per authentication, is correct because the physical barrier permits exactly one authenticated entry at a time, so a tailgater cannot pass without their own valid credential. Option A, CCTV cameras, is only a detective control that records events after the fact and does not stop tailgating.

Option B, security guards checking badges, is a deterrent and detective measure but is subject to human error, distraction, and social-engineering bypass. Option E, biometric authentication, verifies the identity of the person authenticating but does not by itself prevent a second person from walking through the opened door behind them.

50
MCQmedium

An organization's security team proposes deploying a network-based intrusion prevention system (IPS) inline at the internet perimeter. Management asks the IS auditor to comment on the operational implications before approving the purchase. Which of the following should the auditor identify as the MOST significant operational risk of the inline placement?

A.The IPS will be unable to inspect encrypted traffic without additional decryption capability.
B.A false positive or device failure could block legitimate business traffic and cause an outage.
C.The IPS will not be able to correlate events with host-based logs from servers.
D.Signature updates will consume WAN bandwidth and degrade branch office performance.
AnswerB

Because inline prevention sits directly in the traffic path, a misclassified signature, a capacity limit, or a hardware fault can drop legitimate sessions for every user behind it. Availability of business services becomes dependent on the IPS tuning and resilience. This is the most significant operational risk and explains why fail-open design, bypass, and staged tuning are essential before enforcement mode is enabled.

Why this answer

Inline prevention changes the device from a passive observer into a component whose failure or misconfiguration directly affects service delivery. Every packet traverses it, so latency, throughput limits, and false positives translate into user-visible outages. The auditor should therefore focus on fail-open behavior, bypass paths, change control for signature updates, and a tuning period in detection mode before blocking is enabled.

Exam trap

The trap here is evaluating the IPS primarily as a detection tool and overlooking that inline enforcement makes the device a single point of failure for business traffic.

51
MCQhard

An IS auditor is reviewing an organization's security monitoring architecture. The organization uses a SIEM to collect logs from servers, firewalls, and applications. Management reports that the SIEM is functioning as designed and alerts are generated. Which of the following findings would be of MOST concern to the auditor?

A.Log retention is set to 30 days, and the organization's incident response procedure requires investigating events up to 90 days old.
B.Log sources use different time zone settings and the SIEM normalizes timestamps at ingestion.
C.The SIEM is deployed on-premises rather than as a cloud-hosted service.
D.The SIEM generates more alerts than the security team can review in a shift.
AnswerA

If the retention period is shorter than the investigation window defined by policy, evidence required to investigate incidents will be unavailable. Detection may occur, but without 90 days of logs the team cannot reconstruct the scope, timeline, or root cause of events that surface late. This is a direct conflict between a configured control and a documented requirement, making it the most concerning finding because it undermines incident response and forensic capability.

Why this answer

A monitoring system is only as useful as the evidence it retains. When the configured retention period is shorter than the period the incident response process requires for investigation, the organization cannot reconstruct events that are discovered late. This misalignment between a technical setting and a documented requirement directly impairs detection follow-up and forensic analysis, making it the finding that most threatens the effectiveness of security monitoring.

Exam trap

The trap here is focusing on alert volume or architecture, when the decisive issue is whether retained evidence matches the investigation timeline defined by policy.

52
MCQmedium

An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?

A.The recertification report includes all users with active accounts
B.Reviews are performed quarterly instead of annually
C.Some users did not respond to the recertification request within the deadline
D.Managers approve all access requests without verifying job requirements
AnswerD

Managers rubber-stamping approvals defeats the review's purpose: recertification exists to confirm each user's access still matches current job requirements. Without that verification, excessive or stale entitlements persist, violating least privilege and undermining the control's effectiveness. This directly addresses the stem's concern about review effectiveness, unlike process timing or documentation issues.

Why this answer

Managers approving all access requests without verifying job requirements is the most concerning finding because it defeats the purpose of recertification: access is rubber-stamped rather than validated against least privilege. This creates a systemic risk of privilege creep and unauthorized access that no amount of process formality can offset. The other findings are either positive or minor operational issues.

Exam trap

CISA often tests the difference between a control's existence and its effectiveness; candidates pick operational issues (missed deadlines) over the substantive failure (blind approval) because the former sounds more concrete.

How to eliminate wrong answers

Option A is wrong because including all active users in the report is a completeness control, not a deficiency. Option B is wrong because quarterly reviews are more frequent (and thus stronger) than annual reviews. Option C is wrong because non-response within a deadline is an operational lapse that can be remediated, not a fundamental control failure.

53
Multi-Selecteasy

An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?

Select 3 answers
A.There is no audit trail of who granted access and why
B.Segregation of duties between HR and IT is not maintained
C.Password policies may not be enforced
D.Users may be granted excessive privileges beyond their job requirements
E.User accounts may not be locked after multiple failed login attempts
AnswersA, B, D

Absent formal requests or approvals, no record exists linking an account to an authoriser or business justification. This defeats accountability and non-repudiation, leaving the auditor unable to reconstruct who granted access, when, or why — undermining investigation, disciplinary action and regulatory evidence.

Why this answer

Option A is correct because provisioning without a formal access request or approval process means there is no documented record of who authorized or granted each user's access, eliminating the audit trail needed to trace accountability for access decisions. Option B is correct because HR performing user provisioning without IT involvement removes the segregation of duties between the department that owns the employee data and the function that administers system access, allowing a single group to both request and grant privileges. Option D is correct because without a formal request and approval workflow, there is no validation against job roles, so users can be provisioned with rights exceeding their job requirements (excessive privileges).

Options C and E are not among the most significant risks here because password policy enforcement and account lockout after failed logins are authentication controls configured within the system itself, and nothing in the scenario indicates these controls are absent or affected by the HR provisioning process.

Exam trap

CISA often tests whether candidates can distinguish risks directly caused by the described control gap (no approval, no SoD) from generic security risks (password policy, lockout) that are not implicated by the scenario.

54
MCQeasy

An IS auditor is reviewing the access control list (ACL) on a router that connects the corporate network to the internet. The auditor notices that the ACL permits inbound traffic on port 3389 (RDP) from any source IP address to a specific internal server. Which of the following is the MOST appropriate recommendation?

A.Implement account lockout policies to prevent brute-force attacks.
B.Change the default RDP port to a non-standard port to obscure the service.
C.Enable Network Level Authentication (NLA) on the RDP server.
D.Restrict inbound RDP access to specific trusted IP addresses or require VPN access.
AnswerD

Allowing RDP from any source IP exposes the server to brute-force attacks, credential stuffing, and exploitation of RDP vulnerabilities. The most appropriate recommendation is to restrict access to known trusted IPs or require users to connect via VPN, which adds an authentication layer. This reduces the attack surface and aligns with the principle of least privilege. It directly addresses the risk of unauthorized access.

Why this answer

The most appropriate recommendation is to restrict inbound RDP access to specific trusted IP addresses or require VPN access. This directly reduces the exposure of the RDP service to potential attackers. While other measures like NLA or account lockout can add defense in depth, they do not address the fundamental issue of allowing RDP from any source.

Restricting access is a preventive control that aligns with least privilege and reduces the attack surface.

Exam trap

The trap here is choosing a hardening measure like changing the port or enabling NLA, which does not address the core problem of unrestricted inbound access.

55
MCQmedium

An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?

A.Access rights are recertified annually instead of quarterly.
B.There is no process to act on access changes identified during recertification.
C.Recertification forms are completed by users themselves rather than managers.
D.Recertification results are not documented or retained.
AnswerB

Recertification only reduces excessive access if identified changes are actually revoked or modified. Without an execution process, managers' quarterly confirmations produce no remediation, leaving inappropriate rights intact indefinitely — defeating the control's purpose and exposing the financial application to unauthorised transactions.

Why this answer

The most concerning finding is that there is no process to act on access changes identified during recertification. Even if recertification is performed, without follow-up to revoke or modify access, the process is ineffective and leaves inappropriate access in place, increasing the risk of unauthorized access. This directly undermines the control's purpose.

Exam trap

CISA often tests the difference between a control activity and its effectiveness; candidates may focus on the frequency or who performs recertification, but the lack of follow-up is the critical failure.

How to eliminate wrong answers

Option A is wrong because while quarterly recertification is required, annual recertification still provides some level of review; the lack of action on findings is a more severe control failure. Option C is wrong because although recertification by users themselves is a segregation of duties issue, it is less severe than having no remediation process; user self-certification can still be reviewed by managers. Option D is wrong because lack of documentation is a compliance and audit trail issue, but the absence of action on identified changes means the control does not mitigate risk at all.

56
Multi-Selectmedium

During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?

Select 2 answers
A.Increased complexity in password management
B.Lack of individual accountability for actions performed
C.Increased overhead for account provisioning
D.Audit trails may not be reliable for forensic investigations
E.Higher likelihood of password sharing outside the authorized group
AnswersB, D

Shared credentials remove the unique user identifier that links an action to a person, so no one can be held answerable for privileged changes. This directly undermines the accountability principle the audit is testing, since attribution becomes impossible when several administrators use one login.

Why this answer

Option B is correct because shared accounts eliminate the one-to-one mapping between a user identity and an account, so when multiple administrators use the same credentials there is no way to attribute a specific action to a specific individual, destroying individual accountability. Option D is correct because the audit logs generated under a shared account record only the account name, not the actual person, so the resulting audit trail cannot reliably support forensic investigations or non-repudiation. Options A and C are operational inconveniences rather than the most significant risks, and option E describes a possible consequence of poor password hygiene rather than the core accountability and forensic integrity risks that an IS auditor would emphasize.

Exam trap

CISA often tests the distinction between operational inconveniences (password complexity, provisioning overhead) and fundamental control failures (lack of accountability, unreliable audit trails); candidates may pick the more visible but less severe operational risks.

57
MCQmedium

An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?

A.Unmanaged devices may retain unencrypted copies of protected health information after a clinician leaves the organization.
B.Personal devices may introduce malware that spreads to the EHR application servers.
C.Clinicians may install unauthorized software that consumes excessive bandwidth on the hospital network.
D.The acceptable-use agreement may be unenforceable because it was not signed by a witness.
AnswerA

Without enrollment or inspection, the hospital cannot enforce encryption, remote wipe, or data-retention controls on personally owned devices. Clinical data cached locally on an unmanaged laptop or tablet survives the end of employment, and the organization has no technical means to erase it. This loss of control over protected health information is the most significant exposure because it creates both regulatory breach liability and direct patient-privacy harm.

Why this answer

The defining weakness is that personally owned devices are used for clinical work without enrollment, inspection, or technical controls. That means the organization cannot enforce encryption, remote wipe, or retention limits, so protected health information can persist on hardware it does not own or manage. Data remanence on unmanaged endpoints is the most consequential risk because it directly threatens confidentiality and creates reportable breach exposure.

Exam trap

The trap here is focusing on malware or network performance, which are secondary operational concerns, instead of the organization's inability to control or erase sensitive data on devices it does not manage.

58
MCQhard

An IS auditor is evaluating how an organization disposes of decommissioned hard drives that previously stored customer financial records. Management states that drives are physically destroyed by a third-party vendor, but no certificates of destruction are retained and the vendor's personnel perform the destruction at the organization's loading dock without supervision. Which of the following is the MOST important control weakness?

A.Physical destruction is less secure than software-based overwriting of the drives.
B.The third-party vendor has not been assessed for financial stability.
C.Destruction is performed without supervision and no certificates of destruction are retained to evidence the disposal.
D.Drives should be degaussed before being released to the vendor.
AnswerC

Without supervision, drives could be diverted, swapped, or only partially destroyed, and without certificates there is no evidence that destruction occurred. This combination eliminates accountability and leaves the organization unable to demonstrate compliance with data disposal requirements. For media containing customer financial records, the auditor should report the lack of oversight and documentation as the most important weakness because it directly threatens data confidentiality.

Why this answer

When a third party destroys media containing customer financial records, the organization remains accountable for the confidentiality of that data. Unsupervised destruction at the loading dock allows drives to be diverted or inadequately destroyed, and the absence of certificates means the organization cannot prove disposal occurred. The auditor should report the lack of supervision and destruction evidence as the most important weakness because it removes both physical control and auditability.

Exam trap

The trap here is treating physical destruction as inherently sufficient and overlooking that without supervision and certificates the organization cannot prove the drives were actually destroyed.

59
MCQmedium

An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?

A.The plan is approved by senior management
B.The plan is updated annually
C.Lessons learned from tabletop exercises are incorporated into the plan
D.The plan includes contact information for key stakeholders
AnswerC

Incorporating lessons learned from tabletop exercises demonstrates a functioning feedback loop: identified gaps are remediated and the plan evolves. This evidences continuous improvement and validates that the IR plan adapts to discovered weaknesses, the strongest indicator of effectiveness.

Why this answer

The best indicator of an IR plan's effectiveness is that lessons learned from tabletop exercises are incorporated into the plan. Tabletop exercises simulate real-world incidents, revealing gaps in procedures, communication, and decision-making. When findings from these exercises are fed back into the plan, it demonstrates a continuous improvement cycle—meaning the plan is not just a static document but a living, tested capability.

This directly evidences that the plan works in practice and evolves to address weaknesses, which is the essence of effectiveness.

Exam trap

CISA often tests the difference between compliance-oriented attributes (approval, annual review, contact lists) and effectiveness-oriented evidence (testing and continuous improvement), tempting candidates to choose the most formal or frequently updated option rather than the one that proves the plan works in practice.

How to eliminate wrong answers

Option A is wrong because senior management approval indicates governance and support, but not operational effectiveness—a plan can be approved yet untested and flawed. Option B is wrong because annual updates may be a compliance requirement, but updating without testing does not guarantee the plan addresses real incident scenarios or that changes are based on actual performance. Option D is wrong because including contact information is a basic completeness check, not an indicator of effectiveness; contacts may be outdated or the plan may still fail during an incident.

60
Multi-Selectmedium

An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?

Select 2 answers
A.Session recording and monitoring of privileged activities
B.Implementation of just-in-time (JIT) privileged access
C.Quarterly review of privileged account access
D.Assignment of generic administrative accounts to multiple users
E.Use of shared passwords for emergency access
AnswersA, B

Session recording and monitoring create attributable, tamper-evident evidence of every privileged action, deterring misuse and enabling detection after the fact. This satisfies the stem's prevention-of-misuse constraint by removing the anonymity that privileged accounts otherwise grant, since administrators know their sessions are captured and reviewed.

Why this answer

Option A is correct because session recording and monitoring of privileged activities creates a tamper-evident audit trail and real-time oversight, which deters misuse and enables detection and accountability for every privileged action. Option B is correct because just-in-time (JIT) privileged access grants elevated rights only for a limited, approved window and revokes them automatically, drastically shrinking the standing attack surface and the opportunity for misuse. Option C is not the most effective preventive control because a quarterly review is a detective, after-the-fact activity that can leave misuse undetected for up to three months.

Option D is wrong because generic administrative accounts shared by multiple users destroy individual accountability and make attribution of actions impossible. Option E is wrong because shared passwords for emergency access eliminate non-repudiation and cannot be traced to a specific individual, increasing the risk of undetected misuse.

Exam trap

CISA often tests the difference between preventive and detective controls, and candidates may select periodic reviews or shared accounts as effective controls when they actually weaken accountability and do not prevent real-time misuse.

61
MCQmedium

During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?

A.Escalate to senior management immediately
B.Update the policy to allow 30 days for critical patches
C.Require risk acceptance documentation for each patch that misses the SLA
D.Accept the delay as necessary for stability
AnswerC

Where testing causes patches to breach the seven-day SLA, documented risk acceptance transfers accountability to business owners for the residual exposure during the delay. This satisfies the stem's compliance gap by ensuring deviations are formally acknowledged rather than silently tolerated, without abandoning the testing control.

Why this answer

The policy requires 7-day patching but actual practice is 30 days, creating a documented control gap. Rather than silently accepting the deviation or weakening the standard, the auditor should recommend that each missed SLA be formally documented as a risk acceptance so management owns the residual risk. This preserves the control baseline while providing an auditable trail of conscious risk decisions.

Exam trap

CISA often tests the distinction between the auditor's role and management's role, so the trap is choosing escalation or policy relaxation when the correct answer is to require formal risk acceptance by the business owner, preserving auditor independence and the control baseline.

How to eliminate wrong answers

Option A is wrong because immediate escalation to senior management is premature; the auditor's first duty is to recommend a governance-based remedy (documented risk acceptance) before escalating, and escalation without a documented risk decision skips the proper remediation path. Option B is wrong because changing the policy to match the deficient practice lowers the security baseline to fit the weakness rather than fixing the process, which violates the principle that policy should drive practice, not the reverse. Option D is wrong because simply accepting the delay as necessary for stability provides no formal accountability, no documented risk decision, and no audit trail, which is exactly what an IS auditor must not endorse.

62
MCQhard

An IS auditor is examining how an organization classifies and handles its data. The auditor finds that the data classification policy defines four tiers but does not specify retention periods, handling procedures, or labeling requirements for each tier. Management states that employees use their judgment when handling sensitive information. Which of the following is the MOST appropriate recommendation?

A.Implement automated data loss prevention (DLP) tools to enforce handling rules across all endpoints.
B.Reduce the number of classification tiers to two to simplify employee decision-making.
C.Require management to define retention periods, handling procedures, and labeling requirements for each classification tier.
D.Conduct mandatory security awareness training so employees can better judge how to handle sensitive data.
AnswerC

The policy establishes tiers but omits the operational requirements that make classification meaningful. Without defined retention, handling, and labeling rules, employees cannot apply consistent protection, and reliance on individual judgment creates unacceptable variability. The auditor should recommend that management complete the policy by specifying these requirements for each tier, which provides a basis for later technical enforcement and monitoring.

Why this answer

A data classification policy is only effective when each tier carries explicit retention, handling, and labeling requirements. The organization's policy defines tiers but leaves their treatment to employee judgment, which produces inconsistent protection and no auditable standard. The auditor should recommend that management complete the policy by specifying these requirements per tier, creating the foundation for consistent handling and subsequent enforcement through technical controls.

Exam trap

The trap here is recommending a technical enforcement tool such as DLP before the underlying policy defines what must be enforced.

63
MCQhard

An IS auditor is examining how a financial services firm enforces data loss prevention (DLP) for outbound email. The firm uses a network DLP appliance that inspects SMTP traffic and blocks messages containing unencrypted account numbers. The auditor discovers that employees can bypass the appliance by using a personal webmail account over HTTPS. Which of the following should the auditor recommend FIRST?

A.Require employees to sign an acceptable use policy acknowledging that personal webmail use is prohibited.
B.Increase the sensitivity of the DLP appliance's pattern matching so it detects account numbers in more formats.
C.Block access to personal webmail and other unauthorized exfiltration channels at the web gateway, then extend DLP coverage to those channels.
D.Deploy TLS inspection at the perimeter so the DLP appliance can examine HTTPS sessions to webmail providers.
AnswerC

The first step is to close the channel that bypasses the existing control. If personal webmail is blocked at the web gateway and DLP coverage is extended to web and other egress paths, employees can no longer trivially circumvent the appliance. This addresses the root cause by eliminating the unmonitored path, after which additional inspection technologies can be layered in as needed. It also aligns with a defense-in-depth approach that does not rely on a single inspection point.

Why this answer

The DLP appliance only inspects SMTP, so employees who use personal webmail over HTTPS bypass it entirely. The most effective first step is to block unauthorized exfiltration channels at the web gateway and extend DLP coverage so the control cannot be trivially circumvented. Closing the unmonitored path addresses the root cause, whereas tuning detection patterns or relying on policy alone leaves the bypass intact.

Exam trap

The trap here is focusing on improving detection accuracy inside a channel that is already monitored instead of closing the unmonitored channel that defeats the control.

64
MCQmedium

An IS auditor is evaluating how an organization detects unauthorized changes to the configuration of its internet-facing web servers. The organization runs a file integrity monitoring tool that hashes critical configuration files hourly and alerts on any hash mismatch. Which of the following is the MOST important factor in determining whether this control provides effective detection?

A.The tool uses a well-known cryptographic hash algorithm such as SHA-256.
B.The baseline of approved file hashes is stored on the same server being monitored.
C.The tool hashes files every hour rather than in real time.
D.Alerts generated by the tool are routed to a monitored queue that is reviewed and acted upon.
AnswerD

A detection control is only effective if its output leads to timely investigation and response. Routing alerts to a queue that is actively monitored and acted upon closes the loop between detection and response, ensuring that a hash mismatch actually triggers investigation. Without this, even a technically perfect integrity check produces no security value because no one responds.

Why this answer

Detection controls create value only when their alerts are reviewed and acted upon. A file integrity monitoring tool can hash files perfectly and still provide no protection if mismatches are logged to an unmonitored queue. Routing alerts to a staffed queue with defined response procedures connects detection to action, making it the most important factor.

Algorithm strength, polling frequency, and baseline placement matter, but each is secondary to whether someone responds to the alert.

Exam trap

The trap here is focusing on the technical strength of the hashing implementation when the decisive factor is whether anyone reviews and acts on the alerts it produces.

65
MCQmedium

An IS auditor is examining how a data center protects its backup tapes while they are transported to an offsite vault. Management states that tapes are encrypted at rest using AES-256. Which of the following is the MOST important control the auditor should verify to protect the tapes during transit?

A.The offsite vault maintains a temperature and humidity-controlled environment.
B.The encryption keys are stored in a hardware security module (HSM) at the primary data center.
C.Backup jobs are scheduled outside business hours to reduce contention with production systems.
D.A chain-of-custody log with tamper-evident seals and dual custody is maintained for each shipment.
AnswerD

During transit, tapes are outside the physically protected data center, so the primary risk is loss, theft, or substitution. A chain-of-custody log with tamper-evident seals and dual custody provides detective and preventive assurance that media were not accessed or swapped. This directly addresses the in-transit exposure and complements encryption by ensuring the physical media remain accounted for.

Why this answer

Because transport places media outside the controlled data center, the auditor should focus on physical custody controls. A documented chain of custody with tamper-evident seals and dual custody provides accountability and detects unauthorized access or substitution. Encryption protects confidentiality of data on the tape, but it does not prevent loss of the media or a denial of recovery capability, so custody controls are the most important complement.

Exam trap

The trap here is assuming encryption at rest fully protects backup tapes, when physical custody and tamper evidence are the controls that address the in-transit risk window.

66
Multi-Selecthard

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

Select 3 answers
A.Obtain business justification for each any-to-any rule
B.Replace any-to-any rules with specific source/destination rules
C.Immediately delete all any-to-any rules without review
D.Increase logging for any-to-any rules to detect misuse
E.Remove any-to-any rules that lack business justification
AnswersA, B, E

Any-to-any rules bypass least privilege, so the auditor must first establish why each exists. Obtaining business justification determines whether the rule is genuinely required, enabling informed decisions to tighten, replace or remove it rather than blindly deleting needed connectivity.

Why this answer

Option A is correct because an IS auditor must first obtain business justification for each any-to-any rule, since a rule may be required for a legitimate business or technical purpose and cannot be judged in isolation. Option B is correct because the fundamental remediation for overly permissive rules is to replace any-to-any rules with specific source, destination, port, and protocol rules that enforce least privilege and reduce the attack surface. Option E is correct because any any-to-any rule that lacks a valid business justification should be removed, as it represents unnecessary exposure with no documented need.

Option C is not appropriate because immediately deleting all any-to-any rules without review could disrupt legitimate business traffic and cause outages, violating change management and availability requirements. Option D is not the most appropriate action because increasing logging only detects misuse after the fact; it does not remediate the excessive permissiveness that the auditor should recommend eliminating.

Exam trap

CISA often tests the temptation to recommend immediate deletion of risky rules, when the correct audit approach is justification, replacement, and controlled removal.

67
MCQmedium

An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?

A.Interview employees about their understanding of the policy.
B.Review security awareness training records.
C.Review incident reports related to lost documents.
D.Conduct unannounced walkthroughs of work areas.
AnswerD

Unannounced walkthroughs provide direct, contemporaneous evidence of actual workspace conditions, since staff cannot tidy desks in advance. This tests real compliance with the clean desk policy, unlike interviews or policy reviews that only confirm awareness or documentation.

Why this answer

Direct observation provides the most reliable evidence of compliance.

68
MCQmedium

An IS auditor is reviewing how an organization manages its backup media. The auditor learns that full backups are written to tape each night, the tapes are stored in a cabinet in the data center, and the same cabinet is used to store cleaning supplies and spare hardware. Which of the following is the MOST significant risk the auditor should highlight?

A.Backup media are stored without environmental protection and alongside materials that could damage or contaminate the tapes.
B.Nightly full backups consume excessive storage capacity and should be replaced with incremental backups.
C.The backup process may not be documented, creating a risk of inconsistent restores.
D.Backup tapes stored on-site cannot be used to restore data after a disaster that destroys the data center.
AnswerA

Cleaning supplies and spare hardware in the same cabinet introduce chemical vapors, dust, physical impact, and possible liquid spills that can corrupt magnetic tape media. This is a direct threat to the recoverability of the organization's backup data. The auditor should report that media lack proper environmental controls and are exposed to contaminants and physical hazards, which jeopardizes restoration when it is needed most.

Why this answer

Backup tapes stored in a cabinet shared with cleaning supplies and spare hardware are exposed to chemical vapors, dust, impact, and spills that can render the media unreadable. Because these tapes are the organization's recovery capability, their physical protection is critical. The auditor should report the lack of environmental controls and the co-location with potentially damaging materials as the most significant risk in this finding.

Exam trap

The trap here is jumping to the on-site storage issue while overlooking that the media are physically exposed to contaminants in the same cabinet.

69
MCQmedium

An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?

A.Strong password policy
B.Audit logging of access attempts
C.Monthly access recertification
D.Role-based access control (RBAC)
AnswerB

Audit logging records every authentication and authorisation event, including failed attempts, giving the auditor an independent trail to detect unauthorised access after the fact. This directly satisfies the stem's requirement for a detective control, unlike preventive measures such as passwords or Microsoft Entra ID conditional access, which block access but cannot reveal that an intrusion occurred.

Why this answer

Audit logging of access attempts is the most important control to detect unauthorized access because it creates a chronological record of who attempted to access what, when, and whether the attempt succeeded or failed. Detection requires evidence of events, and only logging provides that evidence after the fact. Strong passwords, recertification, and RBAC are preventive or administrative controls that reduce the likelihood of unauthorized access but do not detect it when it occurs.

Exam trap

CISA often tests the distinction between preventive, detective, and corrective controls; candidates frequently choose a strong preventive control like RBAC or password policy when the question specifically asks for detection of unauthorized access.

How to eliminate wrong answers

Option A is wrong because a strong password policy is a preventive control that makes credential guessing harder, but it does not record or alert on unauthorized access attempts. Option C is wrong because monthly access recertification is a detective control for excessive or inappropriate entitlements, not for actual unauthorized access events; it reviews who should have access, not who actually accessed. Option D is wrong because RBAC is a preventive access control model that limits permissions based on roles, but it does not detect when someone bypasses or abuses those permissions.

70
MCQmedium

An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?

A.Scores on post-training quizzes
B.Reduction in the number of successful phishing attacks
C.Percentage of employees who completed the annual training
D.Number of security incidents reported by employees
AnswerB

Awareness programmes aim to change behaviour, so fewer successful phishing attacks demonstrates that staff actually recognise and resist real threats. This outcome metric reflects genuine risk reduction, unlike completion rates or quiz scores, which measure attendance rather than effectiveness.

Why this answer

The primary objective of a security awareness program is to change employee behavior to reduce security risks. A reduction in successful phishing attacks directly measures whether employees are applying what they learned to avoid real-world threats, making it the best outcome-based metric. Post-training quiz scores, completion rates, and incident reporting numbers are activity or output metrics that do not necessarily reflect actual behavioral change or risk reduction.

Exam trap

CISA often tests the difference between output metrics (e.g., completion rates, quiz scores) and outcome metrics (e.g., reduction in successful attacks). Candidates may mistakenly select completion rates or quiz scores as they are easy to measure, but the exam expects the metric that best indicates achievement of objectives, which is behavioral change.

How to eliminate wrong answers

Option A is wrong because quiz scores measure knowledge retention in a test environment, not actual behavior or application in real scenarios. Option C is wrong because completion rates only show participation, not whether the training was effective in changing behavior. Option D is wrong because the number of reported incidents can be influenced by many factors (e.g., reporting culture, actual incident increase) and does not directly measure the program's effectiveness in preventing successful attacks.

71
Multi-Selecthard

An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)

Select 2 answers
A.Verify that the ERP system's database backups complete successfully each night.
B.Confirm that the ERP system's password policy enforces complexity and expiration requirements.
C.Examine a sample of users provisioned in the last quarter to confirm that conflicting access was not granted.
D.Interview the ERP administrator to confirm that SoD conflicts are taken seriously.
E.Review the ruleset used by the access management tool to identify conflicting role combinations.
AnswersC, E

Provisioning-time detection can fail if the tool is bypassed, if roles change later, or if emergency access is granted outside the workflow. Testing a sample of recently provisioned users verifies whether the control actually prevented conflicting combinations in practice. This substantive test provides evidence that the designed control operated on real transactions, complementing a review of the ruleset and revealing gaps between policy and execution.

Why this answer

Effective SoD assurance requires both design and operating evidence. Reviewing the conflict ruleset confirms that the detection logic covers the right combinations of duties, while testing recently provisioned users confirms the control actually prevented conflicts in practice. Together they address whether the control is correctly defined and whether it operates as intended.

Password policy, backups, and interviews do not provide direct evidence about conflicting access assignments in the ERP system.

Exam trap

The trap here is accepting management's statement that conflicts are caught at provisioning, when the auditor must test both the ruleset that defines conflicts and the actual users provisioned under it.

72
MCQeasy

An IS auditor is reviewing the antivirus and endpoint protection deployment across a hospital's clinical workstations. The auditor finds that signature updates are delivered daily, real-time scanning is enabled on all workstations, but the endpoint protection console shows that 40 of 600 workstations have not checked in for more than 30 days. Which of the following should the auditor do FIRST?

A.Report a critical finding that 40 workstations are unprotected and could spread malware throughout the hospital network.
B.Recommend that the organization purchase additional endpoint protection licenses to cover the 40 unmanaged devices.
C.Verify that the antivirus signature update frequency meets the organization's policy of daily updates.
D.Determine whether the 40 unmanaged workstations are still in service and whether they have compensating controls.
AnswerD

Before concluding that a control failure exists, the auditor must establish whether those endpoints are still active and what protection they actually have. The 40 devices may be decommissioned, in storage, or covered by an alternate solution, in which case the finding changes significantly. Confirming asset status and compensating controls is the appropriate first step to validate the observation and avoid reporting an inaccurate finding.

Why this answer

The missing check-ins could indicate unprotected endpoints, but they could equally reflect decommissioned hardware or devices covered by other controls. An auditor must validate the condition before reporting it, since the characterization of risk depends entirely on whether those 40 workstations are active and what protection they have. Confirming asset status and compensating controls is the logical first step.

Exam trap

The trap here is treating a management console gap as conclusive proof that endpoints are unprotected without first validating whether the devices are still in service.

73
MCQeasy

An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?

A.Reduced scope of the PCI DSS assessment
B.Improved network performance
C.Elimination of the need for firewalls
D.Simplified patch management
AnswerA

Segmenting the cardholder data environment from corporate systems isolates it behind controlled conduits, so only that zone falls within PCI DSS assessment boundaries. This directly satisfies the stem's requirement by shrinking the systems, networks and business processes requiring validation, lowering audit effort and residual risk exposure.

Why this answer

Network segmentation reduces the scope of the PCI DSS assessment by isolating the cardholder data environment from other networks, so only systems that handle card data need to comply with PCI DSS.

74
MCQmedium

An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?

A.The technical details of the vulnerability
B.The patch deployment schedule for the next quarter
C.Whether a formal risk acceptance and compensating controls are in place
D.The vendor's patch release notes
AnswerC

Unpatched critical vulnerabilities accepted for six months require documented risk acceptance and compensating controls. Examining these satisfies the stem's constraint by verifying that the business impact assessment was formally approved and that residual risk is mitigated, rather than merely deferred.

Why this answer

When a critical vulnerability remains unpatched due to a business impact assessment, the auditor's next step is to verify whether a formal risk acceptance and compensating controls are in place, because unpatched critical vulnerabilities require documented management approval and mitigating measures. This ensures the organization has consciously accepted the risk with proper governance rather than leaving it unaddressed. The auditor must confirm that the decision was authorized, documented, and supported by controls that reduce the residual risk to an acceptable level.

Exam trap

CISA often tests the principle that unpatched vulnerabilities are acceptable only with formal risk acceptance and compensating controls, so the trap is focusing on technical remediation or patch scheduling instead of verifying governance documentation.

How to eliminate wrong answers

Option A is wrong because the technical details of the vulnerability are already known and are not the auditor's focus; the issue is governance and risk treatment, not technical characterization. Option B is wrong because reviewing the next quarter's patch schedule does not address the six-month delay or the absence of risk acceptance — it only looks forward without resolving the current governance gap. Option D is wrong because vendor patch release notes provide technical information about the patch, not evidence of the organization's risk management decision or compensating controls.

75
MCQhard

An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?

A.Report the issue to senior management as a critical finding
B.Recommend immediate removal of the rule
C.Accept the risk as a compensating control
D.Determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs
AnswerD

The rule permits unrestricted access to Microsoft SQL on TCP port 1433, a severe exposure. Validating business justification before recommending removal or IP restriction is proportionate: the auditor confirms whether the documented temporary need still exists, then addresses the actual risk rather than assuming misuse.

Why this answer

The auditor's best course of action is to determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs, because audit findings must be based on evidence and business context rather than assumptions. A rule permitting any source IP to access TCP port 1433 is a significant security risk, but the auditor must first understand why it exists before recommending action. This approach ensures the recommendation is appropriate, justified, and aligned with business needs.

Exam trap

CISA often tests the auditor's role as an independent assessor who gathers evidence before recommending action, so the trap is selecting immediate escalation or removal instead of first determining business justification.

How to eliminate wrong answers

Option A is wrong because reporting to senior management as a critical finding before investigating the business justification skips the evidence-gathering step and may result in an inaccurate or premature escalation. Option B is wrong because recommending immediate removal without understanding the business need could disrupt legitimate operations and is not the auditor's role — auditors recommend, they do not implement. Option C is wrong because accepting the risk as a compensating control is not the auditor's decision; risk acceptance is a management prerogative, and the auditor should not assume the rule is a valid compensating control without evidence.

Page 1 of 2 · 114 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Protection of Information Assets questions.