🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor72 / 148
Question 72 of 148

A mobile banking application communicates with backend APIs over HTTPS. During a security review, an IS auditor discovers that the app accepts any certificate signed by a trusted root CA rather than validating a specific expected certificate. Which risk is MOST directly increased by this design?

Reviewed for accuracy · Report an issueNext question