🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor72 / 148
Question 72 of 148
A mobile banking application communicates with backend APIs over HTTPS. During a security review, an IS auditor discovers that the app accepts any certificate signed by a trusted root CA rather than validating a specific expected certificate. Which risk is MOST directly increased by this design?
Reviewed for accuracy · Report an issueNext question