Protection of Information Assets
Drill 20 practice questions focused entirely on Protection of Information Assets for the ISACA CISA exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
During a review of a perimeter firewall, an IS auditor finds that the rule base ends with an explicit 'permit any any' statement placed after several specific deny rules. Which of the following is the auditor's GREATEST concern?
A financial analyst needs to send a confidential report to an external business partner and wants to ensure that only that partner can read the message. Both parties have valid PKI certificates. Which key should the analyst use to encrypt the report so that confidentiality is preserved?
During an audit of a data center's biometric access control system, the IS auditor notes that the system administrator recently lowered the sensitivity threshold to reduce the number of complaints from employees who were repeatedly denied entry. Which risk is MOST directly increased by this change?
An IS auditor is reviewing a bring-your-own-device (BYOD) program in which employees access corporate email and documents from personal smartphones. Management's primary concern is protecting confidential corporate data if a device is lost or the employee leaves the company, without infringing on personal data such as family photos. Which control BEST addresses this concern?
During a physical walkthrough of an open-plan office, an IS auditor observes several workstations left unlocked and unattended, with printed customer records visible on desks and sticky notes containing passwords attached to monitors. Which control would BEST address the root cause of these observations?
During a review of a financial application, an IS auditor finds that the database is encrypted at rest using AES-256, but the encryption keys are stored in a plaintext configuration file on the same database server. Which of the following represents the GREATEST concern with this arrangement?
An IS auditor is reviewing controls at a company that recently deployed a data loss prevention (DLP) solution to prevent leakage of customer personally identifiable information (PII). During testing, the auditor discovers that a large volume of PII is being emailed externally without being blocked, even though rules exist to detect PII patterns. Investigation reveals the outbound email is encrypted by the users before sending. Which of the following is the MOST significant limitation the auditor should report?
During an audit of a company's public-facing e-commerce site, an IS auditor notes that customers' browsers display a security warning when connecting via HTTPS. Investigation shows the web server presents a certificate that was issued and signed by the company's own internal certificate authority rather than a publicly recognized CA. Which of the following BEST explains why the browser warning appears?
A financial institution sends high-value payment instructions to a correspondent bank electronically. Management wants assurance that a sender cannot later deny having authorized a transaction and that the instruction was not altered in transit. Which control BEST meets both requirements?
An organization wants to protect the confidentiality of sensitive emails sent to external business partners. IT proposes encrypting all outbound messages using the sender's own private key so recipients can verify the origin. As the IS auditor, what is your PRIMARY concern with this proposed approach?
During a data center review, an IS auditor finds that the room temperature is well controlled but that the relative humidity frequently drops below the recommended range and no humidity control is in place. Which risk should the auditor be MOST concerned about?
An IS auditor is observing the incident response team's handling of a compromised server that is still powered on and connected to the network. The team wants to preserve evidence for a potential legal case. Which action should be performed FIRST to maximize the evidentiary value of the collected data?
During a security review, an IS auditor notes that the organization has deployed an isolated system that mimics production servers but contains only fabricated data and is closely monitored. No legitimate business process uses this system. What is the PRIMARY purpose of this control?
A mobile banking application communicates with backend APIs over HTTPS. During a security review, an IS auditor discovers that the app accepts any certificate signed by a trusted root CA rather than validating a specific expected certificate. Which risk is MOST directly increased by this design?
During a review of an organization's identity and access management process, an IS auditor observes that system administrators create new user accounts and assign application entitlements immediately upon receiving an email request from any department manager. The requests are later reviewed in a monthly access report. Which of the following is the auditor's GREATEST concern?
During an audit of a financial application, the IS auditor notes that all users successfully log in using unique credentials and multifactor authentication. However, several junior clerks are able to approve wire transfers exceeding their assigned transaction limits. Which control weakness does this finding MOST directly indicate?
During a review of identity and access management, an IS auditor discovers that several active user accounts belong to employees who left the organization more than six months ago. HR performs timely terminations in its own system, but these accounts still have access to a critical financial application. Which control weakness is MOST likely the root cause?
An IS auditor reviewing an organization's identity and access management program finds that access is granted individually to each user based on the specific request submitted by their manager. As the workforce has grown, the auditor observes that many users with the same job function have inconsistent access rights, and access reviews take excessive time. Which control approach should the auditor recommend to BEST address this situation?
An IS auditor is reviewing an organization's network intrusion detection system (IDS). Management is concerned that a recent breach exploited a previously unknown vulnerability that the IDS failed to flag. The IDS currently operates using only a database of known attack patterns. Which of the following recommendations would BEST address management's concern about detecting future novel attacks?
An IS auditor is reviewing an organization's implementation of ISO/IEC 27001. The security manager states that certain Annex A controls were excluded because they were not relevant to the business. Which document should the auditor examine FIRST to determine whether these exclusions are justified and properly authorized?
More CISA practice
Keep going with the other ISACA CISA — Certified Information Systems Auditor domains, or take a full timed mock exam.
← Back to CISA overview