ISACA CISA — Certified Information Systems Auditor · Domain 5 · 26% of exam

Protection of Information Assets

Drill 20 practice questions focused entirely on Protection of Information Assets for the ISACA CISA exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

During a review of a perimeter firewall, an IS auditor finds that the rule base ends with an explicit 'permit any any' statement placed after several specific deny rules. Which of the following is the auditor's GREATEST concern?

Reviewed for accuracy · Report an issue
Question 2 of 20

A financial analyst needs to send a confidential report to an external business partner and wants to ensure that only that partner can read the message. Both parties have valid PKI certificates. Which key should the analyst use to encrypt the report so that confidentiality is preserved?

Reviewed for accuracy · Report an issue
Question 3 of 20

During an audit of a data center's biometric access control system, the IS auditor notes that the system administrator recently lowered the sensitivity threshold to reduce the number of complaints from employees who were repeatedly denied entry. Which risk is MOST directly increased by this change?

Reviewed for accuracy · Report an issue
Question 4 of 20

An IS auditor is reviewing a bring-your-own-device (BYOD) program in which employees access corporate email and documents from personal smartphones. Management's primary concern is protecting confidential corporate data if a device is lost or the employee leaves the company, without infringing on personal data such as family photos. Which control BEST addresses this concern?

Reviewed for accuracy · Report an issue
Question 5 of 20

During a physical walkthrough of an open-plan office, an IS auditor observes several workstations left unlocked and unattended, with printed customer records visible on desks and sticky notes containing passwords attached to monitors. Which control would BEST address the root cause of these observations?

Reviewed for accuracy · Report an issue
Question 6 of 20

During a review of a financial application, an IS auditor finds that the database is encrypted at rest using AES-256, but the encryption keys are stored in a plaintext configuration file on the same database server. Which of the following represents the GREATEST concern with this arrangement?

Reviewed for accuracy · Report an issue
Question 7 of 20

An IS auditor is reviewing controls at a company that recently deployed a data loss prevention (DLP) solution to prevent leakage of customer personally identifiable information (PII). During testing, the auditor discovers that a large volume of PII is being emailed externally without being blocked, even though rules exist to detect PII patterns. Investigation reveals the outbound email is encrypted by the users before sending. Which of the following is the MOST significant limitation the auditor should report?

Reviewed for accuracy · Report an issue
Question 8 of 20

During an audit of a company's public-facing e-commerce site, an IS auditor notes that customers' browsers display a security warning when connecting via HTTPS. Investigation shows the web server presents a certificate that was issued and signed by the company's own internal certificate authority rather than a publicly recognized CA. Which of the following BEST explains why the browser warning appears?

Reviewed for accuracy · Report an issue
Question 9 of 20

A financial institution sends high-value payment instructions to a correspondent bank electronically. Management wants assurance that a sender cannot later deny having authorized a transaction and that the instruction was not altered in transit. Which control BEST meets both requirements?

Reviewed for accuracy · Report an issue
Question 10 of 20

An organization wants to protect the confidentiality of sensitive emails sent to external business partners. IT proposes encrypting all outbound messages using the sender's own private key so recipients can verify the origin. As the IS auditor, what is your PRIMARY concern with this proposed approach?

Reviewed for accuracy · Report an issue
Question 11 of 20

During a data center review, an IS auditor finds that the room temperature is well controlled but that the relative humidity frequently drops below the recommended range and no humidity control is in place. Which risk should the auditor be MOST concerned about?

Reviewed for accuracy · Report an issue
Question 12 of 20

An IS auditor is observing the incident response team's handling of a compromised server that is still powered on and connected to the network. The team wants to preserve evidence for a potential legal case. Which action should be performed FIRST to maximize the evidentiary value of the collected data?

Reviewed for accuracy · Report an issue
Question 13 of 20

During a security review, an IS auditor notes that the organization has deployed an isolated system that mimics production servers but contains only fabricated data and is closely monitored. No legitimate business process uses this system. What is the PRIMARY purpose of this control?

Reviewed for accuracy · Report an issue
Question 14 of 20

A mobile banking application communicates with backend APIs over HTTPS. During a security review, an IS auditor discovers that the app accepts any certificate signed by a trusted root CA rather than validating a specific expected certificate. Which risk is MOST directly increased by this design?

Reviewed for accuracy · Report an issue
Question 15 of 20

During a review of an organization's identity and access management process, an IS auditor observes that system administrators create new user accounts and assign application entitlements immediately upon receiving an email request from any department manager. The requests are later reviewed in a monthly access report. Which of the following is the auditor's GREATEST concern?

Reviewed for accuracy · Report an issue
Question 16 of 20

During an audit of a financial application, the IS auditor notes that all users successfully log in using unique credentials and multifactor authentication. However, several junior clerks are able to approve wire transfers exceeding their assigned transaction limits. Which control weakness does this finding MOST directly indicate?

Reviewed for accuracy · Report an issue
Question 17 of 20

During a review of identity and access management, an IS auditor discovers that several active user accounts belong to employees who left the organization more than six months ago. HR performs timely terminations in its own system, but these accounts still have access to a critical financial application. Which control weakness is MOST likely the root cause?

Reviewed for accuracy · Report an issue
Question 18 of 20

An IS auditor reviewing an organization's identity and access management program finds that access is granted individually to each user based on the specific request submitted by their manager. As the workforce has grown, the auditor observes that many users with the same job function have inconsistent access rights, and access reviews take excessive time. Which control approach should the auditor recommend to BEST address this situation?

Reviewed for accuracy · Report an issue
Question 19 of 20

An IS auditor is reviewing an organization's network intrusion detection system (IDS). Management is concerned that a recent breach exploited a previously unknown vulnerability that the IDS failed to flag. The IDS currently operates using only a database of known attack patterns. Which of the following recommendations would BEST address management's concern about detecting future novel attacks?

Reviewed for accuracy · Report an issue
Question 20 of 20

An IS auditor is reviewing an organization's implementation of ISO/IEC 27001. The security manager states that certain Annex A controls were excluded because they were not relevant to the business. Which document should the auditor examine FIRST to determine whether these exclusions are justified and properly authorized?

Reviewed for accuracy · Report an issue

More CISA practice

Keep going with the other ISACA CISA — Certified Information Systems Auditor domains, or take a full timed mock exam.

← Back to CISA overview