Courseiva

CCNA Protection of Information Assets Questions

39 of 114 questions · Page 2/2 · Protection of Information Assets · Answers revealed

76
MCQhard

An IS auditor is reviewing how a retail company protects stored payment card data. The company states it encrypts card numbers using AES-256, but the auditor finds that the database encryption keys are stored in a plaintext configuration file on the same application server as the encrypted data. Which of the following is the auditor's PRIMARY concern?

A.Cardholder data should be tokenized instead of encrypted.
B.AES-256 is insufficient for protecting cardholder data at rest.
C.Storing the key with the encrypted data on the same server defeats the protection the encryption is meant to provide.
D.The encryption keys are not rotated frequently enough.
AnswerC

When the decryption key sits in plaintext on the same host as the ciphertext, a single server compromise yields both, so encryption provides little protection against that threat. The control objective for stored card data is to keep keys separate from data and from the application, typically in a key management system or hardware security module (HSM), which this configuration fails to do.

Why this answer

Encryption only reduces risk if the key is protected independently of the ciphertext and the host that processes it. A plaintext key file on the same application server means a single compromise exposes both data and key, nullifying the protection. Proper key management places keys in a dedicated key management system or hardware security module with strict access controls, separation from data, and documented lifecycle procedures.

Exam trap

The trap here is focusing on the strength of the encryption algorithm or on rotation schedules while overlooking that the key is stored in cleartext beside the data, which collapses the entire control.

77
MCQhard

An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?

A.Report the finding as a non-compliance with the patch management policy
B.Discuss with management the absence of a risk acceptance
C.Escalate the issue to senior management immediately
D.Determine if compensating controls exist to mitigate the vulnerability
AnswerD

Before escalating or reporting, the auditor must establish whether existing compensating controls already reduce the vulnerability's exploitability, since unpatched systems are often mitigated by segmentation, virtual patching or monitoring, which determines the actual residual risk.

Why this answer

The auditor should first determine if compensating controls exist to mitigate the vulnerability, because the presence of effective compensating controls may reduce the residual risk to an acceptable level even without patching. This step gathers evidence before concluding on the adequacy of risk treatment. Only after understanding the control environment can the auditor assess whether the lack of patching and risk acceptance constitutes a significant finding.

Exam trap

CISA often tests the auditor's sequence of evidence gathering before drawing conclusions, so the trap is jumping to reporting or escalation without first assessing whether compensating controls mitigate the risk.

How to eliminate wrong answers

Option A is wrong because reporting non-compliance with the patch management policy before assessing compensating controls may be premature — the policy may allow exceptions with compensating controls. Option B is wrong because discussing the absence of risk acceptance with management is a valid step but should come after determining whether compensating controls exist, as that information shapes the conversation. Option C is wrong because escalating to senior management immediately skips the investigative steps and may be disproportionate if compensating controls effectively mitigate the risk.

78
MCQhard

During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?

A.PCI DSS
B.SOX
C.HIPAA
D.GDPR
AnswerD

GDPR mandates a DPO for public authorities and for processing requiring large-scale, regular and systematic monitoring or special-category data. Processing EU residents' personal data without an appointed DPO breaches that obligation, whereas other privacy regulations impose no equivalent universal DPO requirement.

Why this answer

The GDPR (EU Regulation 2016/679) governs the processing of personal data of EU residents and mandates the appointment of a Data Protection Officer (DPO) in specific circumstances—such as large-scale systematic monitoring or large-scale processing of special categories of data by public authorities or core-activity organizations. Processing EU residents' personal data without a required DPO is a direct GDPR Article 37 violation. The other regulations listed address payment card data, financial reporting integrity, and US healthcare information, none of which impose a DPO requirement for EU personal data.

Exam trap

CISA often tests regulation-to-requirement mapping, and the trap is confusing HIPAA's 'Privacy Officer' or PCI DSS's security controls with GDPR's specific DPO mandate—candidates who see 'privacy' and jump to HIPAA or PCI DSS miss the EU-resident trigger.

How to eliminate wrong answers

Option A is wrong because PCI DSS is a payment card industry standard governing cardholder data (PAN, CVV, etc.) and has no DPO appointment requirement—it focuses on protecting card data through controls like encryption and access management. Option B is wrong because SOX (Sarbanes-Oxley) governs financial reporting controls and corporate governance for publicly traded US companies; it does not address personal data privacy or DPOs. Option C is wrong because HIPAA governs protected health information (PHI) in the US healthcare context and requires a Privacy Officer, not a GDPR-style DPO, and does not apply to general EU resident data processing.

79
MCQmedium

An IS auditor is reviewing a data center's environmental controls and observes that the fire suppression system uses water sprinklers in the main server room. The auditor learns that the sprinkler system was installed when the facility was a general office space. Management states that the sprinklers have never activated. Which of the following should the IS auditor recommend as the MOST appropriate control improvement?

A.Document a formal exception accepting the water sprinkler system based on its clean activation history.
B.Replace the water sprinkler system with a clean agent or pre-action suppression system appropriate for IT equipment.
C.Increase the frequency of sprinkler head inspections to ensure they remain operational.
D.Install additional smoke detectors to provide earlier warning of a fire event.
AnswerB

Water-based sprinklers can cause catastrophic damage to energized IT equipment, and the historical absence of activation does not reduce that risk. A clean agent or pre-action system suppresses fire while limiting collateral damage to servers and storage. Recommending replacement addresses the actual environmental risk identified during the review and aligns with accepted data center protection practices.

Why this answer

Water sprinklers are inappropriate for rooms housing energized IT equipment because discharge can destroy hardware and interrupt operations far beyond the fire itself. A clean agent or pre-action system provides suppression while minimizing collateral damage. Because management's justification rests only on the absence of prior activations, the auditor should recommend replacing the suppression method rather than merely inspecting or accepting it.

Exam trap

The trap here is treating a long incident-free history as evidence that the water sprinkler system is an acceptable control, when the risk is the damage it would cause upon activation.

80
MCQhard

An IS auditor is reviewing the backup strategy for a transactional database that processes customer orders. The database is backed up nightly with full backups, and transaction log backups occur every 15 minutes. The recovery point objective (RPO) for the system is 5 minutes. Which of the following is the MOST significant finding the auditor should report?

A.The backup schedule cannot meet the stated recovery point objective.
B.Nightly full backups consume excessive storage capacity.
C.Transaction log backups are not encrypted at rest.
D.Full backups should be performed weekly instead of nightly.
AnswerA

The transaction log backups run every 15 minutes, but the RPO requires no more than 5 minutes of data loss. In a failure between log backups, up to 15 minutes of committed transactions could be lost, exceeding the objective. This is a direct mismatch between the configured backup frequency and the business requirement, making it the most significant finding.

Why this answer

The RPO defines the maximum tolerable data loss, and the transaction log interval determines how much committed data could be lost in a failure. With log backups every 15 minutes, the system can lose up to 15 minutes of transactions, which exceeds the 5-minute objective. The auditor should report this mismatch between configured backup frequency and the stated business requirement.

Exam trap

The trap here is comparing the nightly full backup to the RPO and overlooking that the transaction log interval, not the full backup frequency, governs how much data can be lost.

81
MCQmedium

An IS auditor is examining how a hospital enforces least privilege for its electronic health record (EHR) system. During walkthroughs, the auditor observes that nurses can access the billing module and that no formal process exists to request, approve, or periodically recertify role assignments. Which of the following is the MOST appropriate recommendation?

A.Implement role-based access control (RBAC) with documented request, approval, and periodic recertification of role assignments.
B.Enable database activity monitoring (DAM) to alert on any nurse queries against billing tables.
C.Deploy multifactor authentication (MFA) for all EHR logins by clinical staff.
D.Require nurses to sign an acceptable use policy (AUP) acknowledging that billing data is confidential.
AnswerA

RBAC ties entitlements to defined job functions, and pairing it with documented request, approval, and recertification removes the observed gap of informal role assignments. Because the nurses' billing access is unnecessary for their clinical duties, RBAC with recertification corrects the least-privilege failure while providing audit evidence that assignments are authorized and reviewed.

Why this answer

The observation describes excessive entitlements combined with no formal role lifecycle, which is a least-privilege and access governance failure. Role-based access control aligns permissions to job duties, and documented request, approval, and periodic recertification provide the accountability and review evidence the auditor expects. Detective monitoring, user acknowledgments, and stronger authentication do not correct or govern the underlying entitlements.

Exam trap

The trap here is treating a detective or administrative control, such as monitoring or an acceptable use acknowledgment, as a substitute for actually removing excessive entitlements through role design and recertification.

82
Multi-Selectmedium

An IS auditor is reviewing an organization's data loss prevention (DLP) strategy. The organization has implemented a network DLP solution but has not yet deployed endpoint DLP. Which TWO of the following are the MOST significant risks of relying solely on network DLP? (Choose two.)

Select 2 answers
A.Network DLP does not provide visibility into data stored on file servers.
B.Data copied to removable media such as USB drives may not be detected.
C.Network DLP cannot prevent data leakage via email attachments.
D.Encrypted data traversing the network may not be inspected by network DLP.
E.Network DLP cannot monitor traffic between internal network segments.
AnswersB, D

Network DLP monitors data in transit across the network perimeter. It does not monitor data at rest or data being copied to removable media on an endpoint. If an employee copies sensitive data to a USB drive, the network DLP will not see this action because it does not traverse the network. Endpoint DLP is required to control and monitor such activities. This is a significant gap that can lead to data exfiltration.

Why this answer

The two most significant risks of relying solely on network DLP are that data copied to removable media may not be detected and that encrypted data traversing the network may not be inspected. Network DLP monitors data in motion across network boundaries but lacks visibility into endpoint actions like USB copying and often cannot decrypt traffic without interception. Endpoint DLP complements network DLP by monitoring data at the endpoint, closing these gaps.

Exam trap

The trap here is assuming network DLP covers all data movement, when in fact it has blind spots at the endpoint and with encrypted traffic.

83
MCQmedium

An IS auditor is reviewing the access recertification process for a financial institution. The process requires users and their managers to confirm access rights quarterly. During the review, the auditor finds that recertifications are consistently completed late, with an average delay of 45 days. Additionally, terminated employees' access is not always removed promptly, and there are no compensating controls. Which of the following is the MOST significant risk arising from these findings?

A.Increased likelihood of audit findings for non-compliance with internal policies
B.Difficulty in tracking user access history
C.Higher probability of unauthorized access to sensitive information
D.Potential loss of audit trails for access changes
AnswerC

Late recertification leaves stale entitlements in place for weeks, and terminated users retaining access creates a direct path to sensitive financial data. Combined with no compensating controls, this materially raises the likelihood of unauthorised access, which is the most significant risk.

Why this answer

The most significant risk is unauthorized access to sensitive information because late recertifications and failure to promptly remove terminated employees' access increase the window for misuse. Without compensating controls, this directly threatens data confidentiality. Thus, C is correct.

Exam trap

CISA often tests the difference between a risk and its symptoms; candidates may pick audit findings or tracking issues, but the core risk is unauthorized access.

How to eliminate wrong answers

Option A is wrong because audit findings for non-compliance are a consequence but not the most significant risk; the actual risk is unauthorized access. Option B is wrong because difficulty in tracking user access history is an operational issue, not a direct risk of unauthorized access. Option D is wrong because loss of audit trails is a concern but less critical than the potential for unauthorized access to sensitive data.

84
Multi-Selectmedium

An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?

Select 2 answers
A.Data elements or fields containing personal data
B.Data classification labels
C.Location of personal data storage and processing
D.Data retention periods
E.Data subject consent status
AnswersA, C

Recording individual data elements or fields containing personal data lets the inventory map each processing activity to specific personal data categories, satisfying the privacy requirement to know what personal data exists and where. Without field-level granularity, retention limits, consent scope and subject access requests cannot be scoped or evidenced accurately.

Why this answer

Option A is correct because a data inventory must identify the specific data elements or fields that contain personal data, since this is the foundational step for determining what privacy obligations (e.g., GDPR, CCPA) apply and where protection controls are needed. Option C is correct because knowing the location of personal data storage and processing—whether on-premises, in the cloud, or across jurisdictions—is essential for assessing cross-border transfer restrictions, access controls, and regulatory applicability. Options B, D, and E, while useful attributes that may be recorded in a mature inventory, are not the most important core elements; classification labels, retention periods, and consent status are downstream details that depend on first knowing what personal data exists and where it resides.

Exam trap

CISA often tests the distinction between foundational inventory elements and downstream controls; the trap is selecting classification, retention, or consent fields that are important but depend on the inventory rather than constituting it.

85
MCQeasy

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA) before implementing a new system that processes personal data?

A.To document data flows for audit purposes.
B.To identify and mitigate privacy risks.
C.To obtain consent from data subjects.
D.To ensure compliance with data protection regulations.
AnswerB

A PIA systematically identifies privacy risks and evaluates mitigation before personal data processing begins, satisfying the stem's pre-implementation constraint. It examines data flows, legal bases and controls, enabling the organisation to reduce identified risks early rather than after deployment, when remediation is costlier and exposure already exists.

Why this answer

PIA aims to identify and mitigate privacy risks early in the project lifecycle.

86
Multi-Selecthard

An IS auditor is assessing the physical and environmental controls of a primary data center located in a region subject to seasonal flooding. Management has installed a raised floor, a water detection system, and a pre-action fire suppression system. Which TWO of the following findings would the auditor consider MOST significant? (Choose two.)

Select 2 answers
A.The generator and fuel storage are located in the basement level of the building.
B.The water detection sensors are installed only under the raised floor and not in the ceiling plenum above the equipment.
C.The raised floor tiles are rated for a uniform load capacity that exceeds the weight of the installed racks.
D.Access to the computer room is controlled by a badge reader with a documented visitor escort procedure.
E.The fire suppression system discharges a gaseous agent rather than water when activated.
AnswersA, B

Placing standby power and fuel below grade in a region with seasonal flooding risks losing both the utility feed and the backup supply in the same event, defeating the purpose of redundancy. Floodwater can also make fuel unusable and delay refueling. This is a significant siting weakness that undermines the facility's ability to ride through an extended outage during the flood season.

Why this answer

In a flood-prone region, the dominant threats are water ingress and loss of standby power during the same event. Detection limited to the subfloor leaves overhead leaks unseen, and below-grade generators and fuel can be inundated precisely when they are needed. Both findings undermine continuity for the facility as a whole, whereas the suppression agent, floor rating, and badge access described are appropriate controls.

Exam trap

The trap here is treating any deviation from a generic checklist as a finding, when the scenario's flood exposure makes water detection coverage and standby power siting the findings that actually matter.

87
Multi-Selectmedium

An IS auditor is assessing how an organization classifies and handles its information assets. The auditor finds that a data classification policy exists but is inconsistently applied across business units. Which TWO of the following are the MOST important elements the auditor should verify are present to support effective data classification? (Choose two.)

Select 2 answers
A.A documented mapping of classification levels to specific handling and protection requirements.
B.Use of a commercial data loss prevention tool to enforce labels.
C.Annual penetration testing of systems that store classified data.
D.Defined ownership and accountability for each information asset.
E.A requirement that all data be stored in a single centralized repository.
AnswersA, D

A classification scheme must translate labels into concrete handling rules such as encryption, retention, and access restrictions. Without that mapping, users cannot know what a given label requires, producing the inconsistent application the auditor found. Mapping levels to controls is the mechanism that converts a classification decision into measurable, auditable protection.

Why this answer

Effective classification depends on two foundational elements: an accountable owner for each information asset and a documented mapping from classification levels to specific handling requirements. Ownership drives consistent labeling and review, while the mapping translates labels into enforceable controls. Absent either element, business units interpret classification differently, which explains the inconsistency the auditor observed.

Exam trap

The trap here is selecting a technology such as a DLP tool or an unrelated assurance activity instead of the governance elements that make classification consistent.

88
MCQmedium

An IS auditor is reviewing an organization's backup and recovery procedures for a critical database. The backup policy states that full backups are performed weekly and transaction log backups every 15 minutes. The recovery point objective (RPO) for the database is 5 minutes. Which of the following is the MOST appropriate recommendation?

A.Implement database mirroring to provide a real-time copy and eliminate the need for transaction log backups.
B.Document the current backup schedule as an accepted risk because the RPO is only a guideline.
C.Increase the frequency of transaction log backups to meet the 5-minute RPO.
D.Perform full backups more frequently, such as daily, to reduce the potential data loss.
AnswerC

The RPO defines the maximum acceptable data loss, measured in time. With transaction log backups every 15 minutes, up to 15 minutes of transactions could be lost, exceeding the 5-minute RPO. Reducing the interval to 5 minutes or less aligns the backup frequency with the RPO. This is the most direct and appropriate recommendation to close the gap between policy and requirement.

Why this answer

The RPO of 5 minutes means the organization can tolerate losing at most 5 minutes of data. Transaction log backups every 15 minutes create a potential 15-minute data loss window, exceeding the RPO. The auditor should recommend increasing the frequency of transaction log backups to 5 minutes or less to meet the stated recovery objective.

Exam trap

The trap here is confusing RPO with recovery time objective (RTO) and recommending faster restoration rather than more frequent data capture.

89
MCQhard

During a review of a data center, an IS auditor observes that backup tapes containing customer records are transported nightly by a courier to an offsite vault. The tapes are placed in sealed containers, but the auditor learns that the courier contract does not require background checks for drivers and that no encryption is applied to the tape contents. Which of the following should the auditor recommend as the MOST effective compensating control?

A.Require two-person integrity for the nightly tape handover at the loading dock.
B.Implement encryption of the backup data before it is written to tape.
C.Increase the frequency of tape inventory counts at both the data center and the offsite vault.
D.Require the courier to provide a certificate of insurance covering the value of the tapes in transit.
AnswerB

Encrypting backup data at the source renders the tapes unreadable if they are lost, stolen, or accessed in transit, directly mitigating the confidentiality risk that the missing courier vetting creates. This is the most effective compensating control because it protects the data itself rather than relying on physical custody. Key management must be handled separately, but the control addresses the exposure at its root.

Why this answer

The exposure is that unencrypted media leaves the controlled environment in the hands of personnel who have not been screened. Because the confidentiality risk travels with the data, the durable fix is to make the data unreadable to anyone who gains possession of the tape. Encryption at the source neutralizes the threat regardless of courier behavior, while insurance, counting, and dual custody only address custody or recovery.

Exam trap

The trap here is choosing a physical or contractual control such as insurance or dual custody, which manages custody, instead of a control that protects the data itself.

90
MCQeasy

Which of the following is the PRIMARY objective of a penetration test?

A.To test the incident response capability
B.To validate the effectiveness of security controls
C.To ensure compliance with security standards
D.To identify vulnerabilities that could be exploited by an attacker
AnswerD

A penetration test simulates real attacker techniques to identify vulnerabilities that could actually be exploited, then validates whether existing controls withstand them. This exploitation-focused identification of genuine weaknesses, rather than theoretical findings, is its primary objective.

Why this answer

The primary objective of a penetration test is to identify vulnerabilities that could be exploited by an attacker, simulating real-world attack techniques to uncover weaknesses before malicious actors do. While penetration tests can inform control validation and compliance, their core purpose is offensive discovery of exploitable weaknesses, which then feeds remediation and risk management. This distinguishes them from vulnerability scans, which are automated and broader but less deep.

Exam trap

CISA often tests the distinction between penetration testing and other assurance activities; the trap is selecting control validation or compliance as the primary objective when the defining purpose is identifying exploitable vulnerabilities.

How to eliminate wrong answers

Option A is wrong because testing incident response capability is the objective of a red team exercise or incident response simulation, not a penetration test, although a pen test may trigger IR if the organization chooses to test detection. Option B is wrong because validating the effectiveness of security controls is a broader assurance objective that can be achieved through audits, control testing, and red teaming; it is a byproduct of pen testing, not its primary objective. Option C is wrong because ensuring compliance with security standards is a compliance objective, and while pen tests are required by standards like PCI DSS, the test itself is not performed primarily to check a box.

91
MCQmedium

An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?

A.Unauthorized access to sensitive data due to excessive privileges
B.Increased likelihood of successful social engineering attacks
C.Non-compliance with regulatory requirements for access controls
D.Inability to detect insider threats in a timely manner
AnswerA

Annual owner reviews without manager confirmation mean access is never validated against current job need, so transferred or terminated staff retain entitlements. Accumulated excessive privileges let users reach sensitive financial data beyond their remit, the specific risk the undocumented confirmation step leaves unmitigated.

Why this answer

The most significant risk is unauthorized access to sensitive data due to excessive privileges, because the absence of manager confirmation means access rights may persist after role changes or terminations, accumulating unnecessary entitlements. Annual reviews by the application owner alone, without manager validation, fail to verify that each user still requires access for their current duties. This directly enables the accumulation of excessive privileges, which is the primary threat to data confidentiality in a financial application.

Exam trap

CISA often tests whether candidates can distinguish the direct technical risk (excessive privileges leading to unauthorized access) from secondary or related risks (compliance, detection, social engineering) when asked for the MOST significant risk.

How to eliminate wrong answers

Option B is wrong because social engineering attacks exploit human manipulation rather than excessive access rights, and the finding does not address phishing or pretexting controls. Option C is wrong because while regulatory non-compliance is a concern, it is a secondary consequence rather than the most significant operational risk; the question asks for the MOST significant risk, and unauthorized access is the direct technical impact. Option D is wrong because inability to detect insider threats relates to monitoring and logging controls, not to the access review documentation gap described; the finding is about access recertification, not detection capability.

92
MCQmedium

An IS auditor is reviewing an organization's data loss prevention (DLP) deployment. The auditor finds that the DLP solution is configured to monitor outbound email traffic at the network gateway, but endpoint agents are not installed on any workstations. Management states that this configuration is sufficient because all sensitive data leaves through email. Which of the following is the MOST significant risk arising from this configuration?

A.Email encryption will prevent the DLP solution from identifying sensitive content in outbound messages.
B.The DLP solution will generate an excessive number of false positives because it cannot correlate with endpoint activity.
C.Sensitive data could be copied to removable media or transmitted through unmonitored channels that never traverse the email gateway.
D.Sensitive data could be exfiltrated through encrypted webmail sessions that the network gateway cannot inspect.
AnswerC

Network-gateway-only DLP inspects traffic crossing that gateway, so copying files to USB drives, printing, or using unauthorized cloud sync clients on the endpoint never passes through the inspection point. Without endpoint agents, these channels are completely unmonitored, making this the most significant gap in the stated control objective of preventing sensitive data loss.

Why this answer

A DLP solution that only monitors the email gateway has a fundamental coverage gap: any data leaving through endpoints—USB drives, printing, cloud sync, or non-email network protocols—is invisible. Management's assumption that all sensitive data leaves via email is unverified and likely incorrect, so the auditor should flag the absence of endpoint agents as the most significant risk to the control objective.

Exam trap

The trap here is assuming that because email is the most common exfiltration vector, gateway-only monitoring is adequate, when in fact DLP requires coverage of all egress channels to be effective.

93
MCQeasy

An IS auditor is reviewing the physical security of a data center. The auditor observes that the main entrance uses a proximity card reader, but the door to the server cage area is propped open with a box because the badge reader is malfunctioning. Staff state that the reader has been broken for two weeks and that a work order has been submitted. Which of the following should the IS auditor recommend FIRST?

A.Recommend disciplinary action against the staff who propped the door open.
B.Immediately secure the door and implement interim monitoring until the reader is repaired.
C.Escalate the outstanding work order to expedite the badge reader repair.
D.Document the finding in the audit report and await management's remediation plan.
AnswerB

A propped-open door defeats the access control protecting the server cage, allowing unescorted entry to critical assets. The immediate priority is to close the exposure through interim measures such as a guard, logging, or a temporary lock, while the repair proceeds. Addressing the vulnerability first aligns with the auditor's duty to escalate significant control failures promptly.

Why this answer

The propped door is an active physical access control failure exposing the server cage to unauthorized entry. The auditor should first ensure the exposure is contained through immediate securing of the door and interim compensating measures such as monitoring, then pursue repair and accountability. Reporting alone or focusing on discipline or repair scheduling does not protect the assets during the outage.

Exam trap

The trap here is choosing the administrative or disciplinary follow-up, such as expediting the repair or punishing staff, instead of first containing the live physical access exposure.

94
MCQhard

An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication. The auditor discovers that the RADIUS server is configured to accept EAP-TLS certificates but does not validate the certificate revocation status. Which of the following is the MOST likely consequence of this configuration?

A.An attacker with a revoked certificate could still authenticate to the wireless network.
B.Wireless traffic could be decrypted by an attacker because the session key is not properly generated.
C.Clients would be unable to connect because the server would reject all certificates without revocation information.
D.The RADIUS server could be susceptible to a denial-of-service attack due to certificate validation overhead.
AnswerA

If the RADIUS server does not check certificate revocation status, a client certificate that has been revoked (e.g., because the device was lost or the employee left) will still be accepted during the EAP-TLS handshake. This allows an unauthorized device or user to gain network access, undermining the purpose of certificate-based authentication. The revocation check is critical to ensure that only currently valid certificates are trusted.

Why this answer

The lack of certificate revocation validation means the RADIUS server will accept revoked certificates, allowing devices or users whose certificates have been revoked to authenticate. This defeats a key control of PKI-based authentication, as revocation is how compromised or expired credentials are invalidated. The most likely consequence is unauthorized network access by a revoked certificate holder.

Exam trap

The trap here is assuming that EAP-TLS encryption is weakened without revocation checks, when actually the failure is in authentication, not encryption.

95
MCQhard

An IS auditor is reviewing a software-as-a-service (SaaS) provider that hosts a company's customer relationship management (CRM) data. The contract states the provider will maintain a SOC 2 Type II report, but the most recent report covers a period ending 14 months ago, and the provider has not responded to requests for a bridge letter. Which of the following should the auditor conclude?

A.The provider is noncompliant with the contract and should be replaced immediately.
B.Assurance over the provider's controls for the current period is inadequate and requires further action.
C.The company should perform a penetration test of the SaaS provider's environment to close the gap.
D.The provider's controls are effective because a SOC 2 Type II report was previously issued.
AnswerB

The report is stale and no bridge letter covers the gap, so the auditor cannot rely on it to conclude controls are effective today. Third-party assurance must align with the period under review. The appropriate conclusion is that assurance is insufficient, prompting follow-up such as requesting a current report, obtaining a bridge letter, or applying additional procedures and considering the risk in the audit report.

Why this answer

Third-party assurance is only valid for the period it covers. A SOC 2 Type II report ending 14 months ago, with no bridge letter explaining the intervening period, leaves the auditor without evidence that controls operated effectively during the current period. The correct conclusion is that assurance is inadequate, and the auditor should pursue a current report, a bridge letter, or alternative procedures before relying on the provider.

Exam trap

The trap here is treating a previously issued SOC 2 Type II report as ongoing assurance, when its coverage is limited to the stated period and a bridge letter is needed to address the gap.

96
MCQhard

An IS auditor is examining how a retail bank protects stored cardholder data. The bank encrypts the primary account number in its customer database using AES-256, but the auditor learns that the encryption keys are stored in a configuration file on the same database server, readable by the database administrator account. Which of the following is the MOST appropriate conclusion?

A.The finding is acceptable provided the database administrator's activity is logged and reviewed monthly.
B.The encryption is ineffective for protecting confidentiality because the key is exposed wherever the data is exposed.
C.The bank should migrate the keys to a hardware security module but may continue storing them with the database until the migration completes.
D.The encryption remains effective because AES-256 is computationally infeasible to break by brute force.
AnswerB

Encryption only protects data when the key is held separately from the ciphertext. Storing the key in a file readable by the same administrator who can already query the database removes the separation, so anyone who compromises that account obtains both the data and the means to decrypt it. The control provides no meaningful additional confidentiality against that threat, which is the auditor's central concern.

Why this answer

Strong encryption depends on keeping the key outside the reach of anyone who can access the ciphertext. When the key file sits on the database server and is readable by the database administrator, the separation of duties that gives encryption its value disappears, and a single compromised account yields both data and key. The auditor should conclude that confidentiality protection is defeated and recommend a dedicated key-management capability such as a hardware security module.

Exam trap

The trap here is treating a long AES key length as proof of protection, when the real failure is that the key is stored with the data it is meant to protect.

97
MCQmedium

During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?

A.The organization may fail to detect an incident in a timely manner
B.The organization may not comply with regulatory reporting requirements
C.The incident response plan may be outdated
D.Employees may not know their roles during an incident
AnswerD

Without tabletop exercises, staff never rehearse incident roles, so during a real event they may duplicate effort, miss escalation steps or fail to contain the breach promptly. This directly addresses the stem's two-year gap in exercising, leaving role familiarity untested.

Why this answer

Tabletop exercises are primarily designed to validate and practice the incident response plan by walking participants through simulated scenarios, which reveals whether employees understand their roles, responsibilities, and decision-making authority during an incident. Without them, the most significant risk is that staff will be unprepared and confused when a real incident occurs, leading to delayed or ineffective response.

Exam trap

CISA often tests the distinction between detection capabilities and response readiness — candidates may incorrectly attribute detection failures to a lack of exercises when exercises actually test response roles and plan effectiveness.

How to eliminate wrong answers

Option A is wrong because incident detection depends on monitoring tools, SIEM, and alerting processes, not on tabletop exercises; exercises test response, not detection capability. Option B is wrong because regulatory reporting compliance is a documentation and process requirement that can be met without tabletop exercises; while exercises may help, the absence of exercises does not directly cause non-compliance. Option C is wrong because the plan becoming outdated is a documentation maintenance issue; tabletop exercises test the plan's effectiveness and staff readiness, but an outdated plan is a different risk than untested staff roles.

98
MCQhard

An IS auditor is reviewing a biometric access control system used to protect a data center. The system uses fingerprint recognition and is configured so that any single enrolled user who fails three consecutive attempts is locked out and must be re-enrolled by security staff. Which of the following is the MOST significant security concern with this configuration?

A.The system does not combine biometrics with a second authentication factor.
B.The lockout and re-enrollment process creates a denial-of-service and administrative burden risk.
C.The false acceptance rate may be too high for a high-security environment.
D.Fingerprint biometrics can be affected by changes in the user's skin condition.
AnswerB

Locking out any user after three failed attempts and requiring security staff to re-enroll means an attacker or a clumsy user can repeatedly trigger lockouts, denying access to legitimate staff and consuming administrative effort. The re-enrollment requirement also depends on staff availability, so the process itself becomes an availability and operational risk that outweighs the tuning concerns in this scenario.

Why this answer

The configuration described makes repeated lockouts easy to trigger and requires security staff to re-enroll affected users, which can deny access to legitimate personnel and create an administrative bottleneck. That operational and availability exposure is more significant than general biometric tuning questions such as false acceptance rate, skin variability, or the absence of a second factor, none of which are uniquely highlighted by the configuration as described.

Exam trap

The trap here is focusing on biometric accuracy metrics like false acceptance rate when the described lockout and manual re-enrollment process is the concrete availability and administration weakness.

99
MCQhard

During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?

A.The IR team may not have adequate forensic capabilities
B.The exercises are not conducted quarterly
C.The IR team is not following the defined procedures
D.The IR plan may not address all relevant incident types
AnswerD

Restricting tabletop scenarios to malware outbreaks leaves the IR plan untested against other plausible incidents, such as insider misuse, denial of service or data breach. The plan's coverage of relevant incident types therefore remains unverified.

Why this answer

If tabletop exercises only cover malware outbreaks, the incident response plan may not be validated against other relevant incident types such as ransomware, insider threats, DDoS, or data breaches. The greatest concern is that the IR plan has untested gaps for scenarios the organization is likely to face. This is a coverage and validation issue, not a frequency or capability issue.

Exam trap

CISA often tests the difference between frequency and coverage — candidates pick 'not quarterly' because it sounds like a control gap, but the real issue is that limited scenario coverage leaves the IR plan unvalidated for other incident types.

How to eliminate wrong answers

Option A is wrong because forensic capability is a specific technical skill set, and the scenario does not provide evidence that forensics are inadequate; the concern is scenario coverage, not forensic proficiency. Option B is wrong because quarterly exercises are a frequency preference, not a control requirement; annual exercises can be adequate if scenarios are comprehensive, so frequency alone is not the greatest concern. Option C is wrong because the scenario states the team conducts exercises, which implies they are following the exercise process; there is no evidence they are deviating from defined procedures.

100
Multi-Selecthard

An IS auditor is evaluating a cloud service provider's (CSP) security posture before the organization migrates a customer-facing application to the provider's infrastructure as a service (IaaS) environment. The auditor is reviewing the shared responsibility model and the provider's assurance documentation. Which TWO of the following are the auditor's MOST important considerations? (Choose two.)

Select 2 answers
A.Confirming which security controls remain the organization's responsibility under the shared responsibility model.
B.Confirming that the provider offers the lowest price among competing CSPs for equivalent compute capacity.
C.Reviewing the provider's marketing materials describing its security certifications and awards.
D.Verifying that the provider's data center is located in a country with lower operating costs.
E.Obtaining and evaluating an independent assurance report such as SOC 2 Type II covering the provider's control environment.
AnswersA, E

In an IaaS engagement the provider secures the physical facilities, hosts, and hypervisor, while the customer remains responsible for guest operating systems, applications, data, and identity management. If the auditor does not clearly establish the boundary, controls may fall into a gap where each party assumes the other is responsible. Mapping responsibilities explicitly is therefore essential before relying on the provider's certifications or contractual commitments.

Why this answer

Under the IaaS shared responsibility model, the provider secures the underlying infrastructure while the customer remains accountable for the guest operating system, applications, data, and identities. The auditor must therefore establish exactly where the responsibility boundary lies and obtain independent assurance, such as a SOC 2 Type II report, that the provider's controls operated effectively over time. Together these give the organization a reliable basis for relying on the provider.

Exam trap

The trap here is treating a provider's marketing claims or certifications at face value without confirming the scope and the split of responsibilities under the shared responsibility model.

101
MCQmedium

During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?

A.Performance degradation due to key reuse
B.Inability to revoke access to specific data
C.Non-compliance with GDPR pseudonymization requirements
D.Increased risk of data exposure if the key is compromised
AnswerD

A single shared key means one compromise decrypts every customer's data at rest, eliminating any blast-radius containment. Per-customer or per-tenant keys would limit exposure to one dataset; key reuse converts an isolated incident into organisation-wide data exposure.

Why this answer

Using the same encryption key for all customer data at rest creates a single point of failure: if that key is compromised, all encrypted data becomes exposed. This is the primary concern because it violates the principle of key separation and significantly amplifies the impact of a key breach. While other issues like performance or compliance may exist, the immediate and severe risk is the potential for mass data exposure.

Exam trap

CISA often tests the principle of least privilege in key management, and candidates may focus on secondary concerns like performance or compliance, missing the primary risk of a single key compromise leading to widespread data exposure.

How to eliminate wrong answers

Option A is wrong because performance degradation due to key reuse is not a primary concern; encryption performance is generally not significantly affected by using the same key, and modern systems can handle high throughput regardless. Option B is wrong because inability to revoke access to specific data is a concern, but it is secondary to the risk of a single key compromise exposing all data; revocation can be managed through other means like access controls. Option C is wrong because non-compliance with GDPR pseudonymization requirements is not directly caused by using the same key; pseudonymization requires that data cannot be attributed to a specific individual without additional information, which is about the encryption process, not key uniqueness.

Moreover, GDPR does not mandate unique keys per data subject.

102
MCQmedium

During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?

A.Increase the frequency of phishing simulations to quarterly
B.Disciplinary action for employees who fail phishing tests
C.Mandate that all employees repeat the training annually
D.Revise the security awareness program content to focus on practical phishing recognition
AnswerD

The 30% phishing failure rate exposes a gap between theoretical completion and practical detection, so revising content toward realistic phishing recognition directly targets that behavioural deficiency. Generic awareness material satisfies compliance metrics but not applied judgement; scenario-based recognition training addresses the actual control weakness the simulation revealed.

Why this answer

The high training completion rate (95%) but high phishing failure rate (30%) indicates that the current training is not effectively translating into practical skills. Therefore, the most appropriate recommendation is to revise the content to focus on practical phishing recognition, making it more hands-on and relevant. This addresses the root cause: the training may be too theoretical or not engaging enough to change behavior.

Exam trap

CISA often tests the difference between training completion and training effectiveness, and candidates may choose to increase frequency or add disciplinary measures instead of addressing the content quality, which is the root cause.

How to eliminate wrong answers

Option A is wrong because increasing the frequency of phishing simulations alone does not address the underlying issue of poor training effectiveness; it may help but is not the most direct solution. Option B is wrong because disciplinary action is punitive and may create a culture of fear rather than improving security awareness; it does not address the skills gap. Option C is wrong because mandating annual repeat training is already likely happening (since completion rate is high) and does not change the content or approach, so it would not improve phishing recognition.

103
MCQmedium

An IS auditor is reviewing the backup strategy for a critical database server. The database administrator states that a full backup is performed every Sunday, and transaction log backups are performed every hour. The auditor finds that the transaction log backups are stored on the same volume as the database data files. Which of the following is the MOST significant risk associated with this configuration?

A.The backups are not stored offsite, so they would be unavailable in the event of a site-wide disaster.
B.The recovery time objective (RTO) may be exceeded because restoring from transaction log backups is slower than restoring from a full backup.
C.A failure of the volume containing the database and its transaction log backups could result in the loss of both the data and the backups, preventing recovery.
D.The recovery point objective (RPO) may not be met because transaction log backups are only taken hourly.
AnswerC

Storing transaction log backups on the same volume as the database data files creates a single point of failure. If that volume fails, both the live database and the backups are lost, making it impossible to recover the database to a recent point in time. This is the most significant risk because it directly threatens the ability to restore operations, regardless of RPO or RTO.

Why this answer

The most significant risk is that a single volume failure could destroy both the database and its transaction log backups, eliminating any possibility of recovery. While RPO and RTO are important, the fundamental flaw is the lack of separation between production data and backups, which violates the principle of not storing backups on the same media as the data they protect. This configuration exposes the organization to catastrophic data loss.

Exam trap

The trap here is focusing on RPO or RTO metrics without recognizing that the physical co-location of backups and data creates an immediate, unrecoverable failure scenario.

104
Multi-Selecteasy

An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?

Select 2 answers
A.Conducting security awareness training on tailgating risks
B.Requiring longer and more complex PINs
C.Installing additional access points
D.Increasing the number of CCTV cameras
E.Implementing a mantrap with biometric authentication
AnswersA, E

Training addresses the human behaviour the auditor observed: staff deliberately holding doors for unbadged individuals. It reinforces badge discipline and challenges social-engineering pretexts, directly reducing tailgating attempts. It complements, rather than replaces, the physical mantrap control.

Why this answer

Option A is correct because security awareness training directly targets the human behavior observed—employees deliberately holding the door for unbadged individuals—by educating staff on tailgating risks and reinforcing the policy that every person must badge individually, which is the root cause of the failure. Option E is correct because upgrading the existing mantrap to biometric authentication enforces one-person-at-a-time entry tied to an immutable physical characteristic, making it technically infeasible to piggyback through on another person's credentials and providing a preventive rather than detective control. Option B does not belong because longer or more complex PINs only strengthen the credential itself and do nothing to stop an unauthorized person from walking through a door held open by an authenticated employee.

Option C does not belong because adding access points increases the number of entry portals and thus potentially widens the attack surface rather than preventing piggybacking. Option D does not belong because additional CCTV cameras are a detective control that only records the tailgating after the fact and does not prevent unauthorized entry.

Exam trap

CISA often tests the difference between preventive and detective controls, and candidates may choose CCTV or PIN complexity as solutions, overlooking that tailgating is best mitigated by physical barriers and employee awareness.

105
Multi-Selectmedium

An IS auditor is evaluating a data loss prevention (DLP) deployment intended to stop sensitive customer records from leaving a bank's network. Management wants assurance that the solution is operating effectively. Which TWO of the following are the MOST important factors for the auditor to assess? (Choose two.)

Select 2 answers
A.Whether alerts generated by the DLP solution are investigated and resolved through a defined incident process.
B.Whether the DLP solution supports encryption of data at rest on endpoint devices.
C.Whether the DLP vendor is certified to an internationally recognized quality management standard.
D.Whether the DLP rules are tuned to the bank's actual data classifications and business workflows.
E.Whether the DLP server's operating system has the latest vendor-recommended patch level.
AnswersA, D

A DLP tool only reduces risk if alerts lead to investigation and action. Without a defined process that assigns, tracks, and closes alerts, the solution is purely decorative and violations go unaddressed. Assessing the handling process verifies the detective control is actually operational, which is essential before the auditor can conclude the deployment prevents sensitive records from leaving.

Why this answer

To judge whether DLP stops sensitive records from leaving, the auditor must confirm the rules reflect the bank's data classifications and workflows, and that generated alerts are investigated and resolved through a defined incident process. These two factors together establish that the control both detects the right events and triggers action. Platform patching, endpoint encryption, and vendor certifications address adjacent concerns but not the operational effectiveness of the DLP control itself.

Exam trap

The trap here is selecting infrastructure or vendor assurance items, such as patching or certifications, that feel like controls but do not demonstrate that the DLP rules detect the right data or that alerts are actually acted upon.

106
MCQeasy

An IS auditor is examining how an organization classifies and handles its information assets. The auditor finds that the data classification policy defines four sensitivity levels and corresponding handling rules, but the asset inventory does not record a classification for most systems. Which of the following is the MOST likely consequence of this gap?

A.The organization will be unable to calculate the depreciated book value of its IT assets.
B.Software license compliance reports will be incomplete because unclassified systems are excluded.
C.Network bandwidth planning will be inaccurate because traffic volumes per system are unknown.
D.Handling rules cannot be consistently applied because protection requirements are not tied to specific assets.
AnswerD

Classification is the mechanism that maps an asset to its required safeguards. If the inventory does not carry a classification label, owners and administrators have no authoritative basis for deciding encryption, access, retention, or disposal requirements, and controls become ad hoc. The policy exists but is inoperable at the asset level, which is the direct and most significant consequence of the missing data.

Why this answer

A classification scheme only produces security value when each asset is labeled and the label drives the handling rules. Without classification recorded in the inventory, owners cannot determine which baseline applies, so encryption, access restrictions, and disposal methods are chosen inconsistently. The policy becomes documentation rather than an operating control, and the auditor cannot trace requirements to implementation.

Exam trap

The trap here is accepting the existence of a well-written classification policy as evidence of effective classification, when the inventory shows the labels were never actually assigned.

107
MCQhard

An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?

A.Implement a password vault with automatic checkout and check-in
B.Increase the frequency of password changes to monthly
C.Implement individual accounts with privilege escalation for administrative tasks
D.Require two-factor authentication for shared account usage
AnswerC

Individual accounts with privilege escalation tie each administrative action to a named user, so logs attribute activity to a person rather than an anonymous shared login. This preserves accountability and satisfies the audit trail requirement that shared credentials destroy.

Why this answer

Individual accounts with privilege escalation ensure that every administrative action is tied to a unique user identity, which is the only way to preserve a reliable, attributable audit trail. Shared accounts inherently destroy accountability because the log records the account, not the person. Privilege escalation (e.g., sudo, just-in-time elevation) grants elevated rights only when needed, so the audit trail captures who performed each privileged action.

Exam trap

CISA often tests the distinction between authentication strength and accountability—candidates mistakenly pick password vaults or MFA because they sound like strong controls, but the question specifically asks about audit trail loss, which only individual accounts with privilege escalation can fully address.

How to eliminate wrong answers

Option A is wrong because a password vault with checkout/check-in still relies on a shared credential; while it improves accountability by recording who checked out the password, the audit trail on the target system still shows only the shared account, so actions cannot be definitively attributed to an individual. Option B is wrong because increasing password change frequency from quarterly to monthly does nothing to improve audit trail attribution—it only slightly reduces the window of credential misuse and may even encourage poor password practices. Option D is wrong because two-factor authentication strengthens authentication for the shared account but does not solve the fundamental problem that multiple people use the same identity, so the audit trail remains non-attributable.

108
MCQhard

An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication against a RADIUS server. The auditor discovers that the RADIUS server is configured to accept EAP-MD5 as an authentication method for legacy devices. Which of the following is the MOST significant security concern with this configuration?

A.EAP-MD5 requires the use of a public key infrastructure (PKI) that the organization may not have deployed.
B.EAP-MD5 does not support mutual authentication, allowing a rogue access point to capture user credentials.
C.EAP-MD5 is incompatible with WPA3-Enterprise and will cause the wireless network to fall back to WPA2.
D.EAP-MD5 transmits credentials in cleartext, exposing them to eavesdropping on the wireless medium.
AnswerB

EAP-MD5 provides only one-way authentication of the client to the server and does not support mutual authentication. An attacker can set up a rogue access point that impersonates the legitimate network, prompting the client to send its MD5-hashed credentials, which can then be captured and cracked offline. This makes it the most significant concern because it directly enables credential theft and network compromise.

Why this answer

EAP-MD5 is a legacy EAP method that authenticates only the client to the server, not the server to the client. Without mutual authentication, an attacker can deploy a rogue access point to impersonate the legitimate network, capture the client's MD5-hashed credentials, and crack them offline. Enabling EAP-MD5 on a RADIUS server for WPA3-Enterprise therefore introduces a serious credential theft vector.

Exam trap

The trap here is focusing on the cryptographic weakness of MD5 hashing while overlooking that the absence of mutual authentication is what enables the rogue access point attack.

109
MCQmedium

An IS auditor is reviewing the data backup strategy for a hospital's electronic health record (EHR) system. The auditor finds that full backups are performed weekly, with daily incremental backups, but the backup tapes are stored in the same server room as the production system. Which of the following is the MOST significant finding?

A.The backup tapes are stored in the same location as the production system, creating a single point of failure.
B.The backup process lacks a documented restoration testing procedure.
C.The backup schedule does not meet the recovery point objective (RPO) for the EHR system.
D.The backup tapes are not encrypted, exposing sensitive patient data.
AnswerA

Storing backups in the same room as the production system means that a fire, flood, or other physical disaster could destroy both the original data and its backups, making recovery impossible. This is a critical control weakness because it defeats the purpose of backups. Offsite storage is a fundamental requirement for disaster recovery, especially for critical systems like an EHR.

Why this answer

Storing backup media in the same physical location as the production system creates a single point of failure. A disaster such as a fire or flood could destroy both the original data and the backups, rendering recovery impossible. Best practice requires that backups be stored offsite or in a geographically separate location to ensure availability and support disaster recovery objectives.

Exam trap

The trap here is focusing on backup frequency or encryption while overlooking the fundamental physical security principle that backups must be stored separately from the source data.

110
MCQeasy

An IS auditor is reviewing the physical security of a data center that houses production servers. During a walkthrough, the auditor observes that the main entrance uses a badge reader, but the door to the network operations center (NOC) is propped open with a chair. Which of the following is the MOST appropriate action for the auditor to take?

A.Ignore the observation because the main entrance badge reader still controls access to the building.
B.Document the observation as a finding because propping the door defeats the access control protecting the NOC.
C.Close the door personally and take no further action.
D.Recommend replacing the badge reader with a biometric scanner at the main entrance.
AnswerB

A propped door bypasses the badge-controlled access point and allows anyone passing by to enter the NOC without authentication. This is a clear control failure that exposes critical infrastructure to unauthorized physical access. The auditor should record it as a finding with the observed condition, the risk, and a recommendation such as door alarms or automatic closers, so management can remediate the weakness.

Why this answer

The propped NOC door bypasses the badge-controlled entry and permits unauthenticated physical access to critical systems. The auditor's role is to document the condition, articulate the risk, and recommend remediation rather than to fix it personally or ignore it. Proposing an unrelated upgrade at the main entrance would not address the observed weakness, so reporting the finding with a targeted recommendation is the appropriate response.

Exam trap

The trap here is believing that perimeter badge access compensates for an open interior door, when physical access control must be enforced at each layer protecting critical areas.

111
MCQeasy

During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?

A.To provide detailed step-by-step instructions for implementing security controls
B.To specify the technical configurations for security devices
C.To define the roles and responsibilities for information security
D.To communicate management's commitment and direction for information security
AnswerD

The policy exists to articulate management's commitment and strategic direction for information security, authorising the programme and setting expectations. This satisfies the stem's constraint by establishing the mandate from which standards, procedures and controls derive their authority.

Why this answer

The primary purpose of an information security policy is to communicate management's commitment, intent, and direction for information security across the organization. It is a high-level governance document that establishes the mandate from which standards, procedures, and guidelines flow. It is not intended to be technically prescriptive or operational.

Exam trap

CISA often tests the policy vs. procedure vs. standard distinction; candidates pick 'define roles and responsibilities' because it sounds governance-oriented, but that is a supporting artifact, not the policy's primary purpose.

How to eliminate wrong answers

Option A is wrong because step-by-step implementation instructions belong in procedures, not the policy, which is deliberately high-level. Option B is wrong because technical configurations for security devices belong in standards, baselines, or hardening guides (e.g., CIS Benchmarks), not the policy. Option C is wrong because while roles and responsibilities may be referenced in a policy, defining them in detail is typically the role of supporting documents; the policy's primary purpose is to express management's direction and commitment, not to be an RACI chart.

112
MCQeasy

An IS auditor is assessing physical security at a data center that houses the organization's core transaction processing systems. The auditor observes that the main entrance uses a badge reader, but the door to the server hall is propped open with a box while staff move equipment. Which of the following is the auditor's GREATEST concern?

A.The data center lacks a mantrap or interlocking double-door entry at the main entrance.
B.The server hall door being propped open allows unauthorized physical access to critical systems.
C.Equipment is being moved without a documented change management ticket.
D.The badge reader at the main entrance does not record access attempts for later review.
AnswerB

A propped door defeats the entire physical access control for the server hall, letting anyone in the vicinity reach the core transaction systems. Physical access often leads to direct compromise, theft, or destruction that logical controls cannot stop. This is the greatest concern because the exposure is immediate, affects the most critical assets, and nullifies the badge-based control design.

Why this answer

Physical access to core transaction systems is a foundational control, and a door propped open removes that barrier entirely, allowing anyone nearby to reach the servers. Because physical proximity enables direct compromise, theft, or sabotage that logical controls cannot prevent, this observation carries the greatest risk. Missing logs, undocumented moves, and the absence of a mantrap are lesser issues by comparison.

Exam trap

The trap here is ranking a missing enhancement or a logging gap above an active control failure, when the propped door represents an immediate, realized exposure of the most critical assets.

113
Multi-Selectmedium

An IS auditor is evaluating the network segmentation of a manufacturing company that separates its corporate network from the industrial control system (ICS) environment. The auditor finds that a firewall exists between the zones, but engineering workstations on the corporate network can reach programmable logic controllers directly over several open ports. Which TWO of the following findings should the auditor report as the MOST significant weaknesses? (Choose two.)

Select 2 answers
A.Multiple ports are open through the firewall between the corporate and ICS zones, expanding the attack surface.
B.Engineering workstations are not running the same endpoint protection version as corporate desktops.
C.The firewall between the corporate and ICS zones does not perform deep packet inspection of industrial protocols.
D.The ICS network uses the same directory services as the corporate network for authentication.
E.Direct connectivity from corporate workstations to programmable logic controllers bypasses the intended zone separation.
AnswersA, E

Each permitted port represents an allowed path into the control environment, and unnecessary open ports give an attacker additional footholds and lateral-movement options. A firewall that passes many services to programmable logic controllers is effectively a porous boundary rather than a controlled one. The auditor should report the excessive rule set and recommend restricting traffic to only the specific protocols and hosts genuinely required for operations.

Why this answer

Effective segmentation depends on preventing corporate systems from initiating sessions with control devices and on keeping the boundary rule set as narrow as operations allow. Direct reachability from engineering workstations to programmable logic controllers defeats the zone design, and a broad set of open ports gives attackers multiple paths into the ICS environment. Together these findings show that the firewall exists in name only and does not enforce the intended separation.

Exam trap

The trap here is chasing secondary hardening items such as protocol inspection or antivirus versions while missing that the boundary itself is functionally bypassed by direct connectivity and permissive rules.

114
MCQhard

An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?

A.Implement a risk-based patching process that allows faster deployment for critical patches
B.Require automated patching without testing
C.Accept the current practice as a compensating control
D.Modify the policy to align with the actual patching timeline
AnswerA

A risk-based process lets critical patches be deployed faster than the current 30-day cycle while retaining testing for lower-risk updates, closing the gap against the 7-day policy requirement. It directly resolves the conflict between the IT manager's testing constraint and the mandated remediation timeline.

Why this answer

A risk-based patching process prioritizes critical patches for immediate deployment while allowing less critical patches to undergo standard testing. This balances security needs with operational stability, addressing the policy violation without sacrificing testing entirely. The auditor should recommend this approach because it aligns with industry best practices (e.g., NIST, ISO 27001) and enables faster remediation of high-risk vulnerabilities.

Exam trap

CISA often tests the confusion between policy compliance and risk management; candidates may choose to modify the policy or accept the delay, but the correct answer is to recommend a risk-based approach that satisfies both security and operational needs.

How to eliminate wrong answers

Option B is wrong because automated patching without testing can introduce instability and outages, especially in complex environments. Option C is wrong because accepting the current practice as a compensating control does not address the policy violation; a compensating control must provide equivalent risk mitigation, which a 30-day delay does not. Option D is wrong because modifying the policy to match the actual timeline weakens security governance and does not address the root cause of the delay.

← PreviousPage 2 of 2 · 114 questions total

Ready to test yourself?

Try a timed practice session using only Protection of Information Assets questions.