Protection of Information Assets Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Protection of Information Assets flashcards as text
An IS auditor is assessing an organization's vulnerability management program. Which metric is MOST useful for evaluating the program's effectiveness?
Answer: Mean time to remediate critical vulnerabilities
Mean time to remediate critical vulnerabilities measures how quickly the organization closes its highest-risk exposures, reflecting the program's actual risk-reduction effectiveness.
Which type of access control model assigns permissions based on an individual's job function and restricts access to only what is needed to perform that role?
Answer: Role-based access control (RBAC)
RBAC groups users into roles based on job function and assigns permissions to roles, ensuring users can only access resources required for their position.
A company stores customer credit card data. According to the Payment Card Industry Data Security Standard (PCI DSS), what is the MINIMUM requirement for protecting stored cardholder data?
Answer: Primary account numbers (PAN) must be rendered unreadable wherever stored
PCI DSS requires that PANs be rendered unreadable in storage through methods such as truncation, hashing, tokenization, or strong cryptography.
An IS auditor discovers that a third-party vendor with access to the organization's network has not implemented multi-factor authentication (MFA). What is the GREATEST risk this presents?
Answer: Compromised vendor credentials could provide an attacker with network access
Without MFA, a single compromised vendor credential can grant attackers full network access, as was demonstrated in high-profile supply chain breaches.
Which security testing technique involves simulating an attacker's behavior to identify exploitable vulnerabilities in a live system?
Answer: Penetration testing
Penetration testing actively exploits vulnerabilities in a controlled manner to determine what an attacker could actually achieve, going beyond automated scanning.
An organization implements a security information and event management (SIEM) system. What is the PRIMARY purpose of this control?
Answer: Correlating security events from multiple sources to detect threats
A SIEM aggregates and correlates log data from across the environment to identify security incidents that may not be visible from any single source.
When auditing physical security controls for a data center, which finding would represent the HIGHEST risk?
Answer: Terminated employees' access badges are deactivated within 24 hours
Retaining departed employees' access for any period after termination allows them to potentially access physical areas, representing an immediate and significant risk.