โ† All CISA Flashcard Decks

Protection of Information Assets Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Protection of Information Assets flashcards as text
  1. An IS auditor reviewing a company's encryption practices finds that sensitive data at rest is encrypted using a symmetric key stored in the same database as the data. What is the PRIMARY concern?

    Answer: The encryption key and ciphertext are co-located, negating protection

    Storing the encryption key alongside the encrypted data defeats the purpose of encryption, since an attacker who gains access to the database obtains both.

  2. Which of the following BEST describes the purpose of a data loss prevention (DLP) solution?

    Answer: Detecting and blocking unauthorized transmission of sensitive data

    DLP solutions detect, monitor, and block the unauthorized exfiltration or transmission of sensitive data across endpoints, networks, and cloud services.

  3. During a network security audit, an IS auditor observes that the organization uses a screened subnet (DMZ) architecture. What is the PRIMARY security benefit of this design?

    Answer: It isolates publicly accessible services from the internal network

    A DMZ places publicly accessible servers in an isolated zone, preventing direct access from the internet to the internal network if a DMZ host is compromised.

  4. An organization allows employees to use personal mobile devices for work (BYOD). Which control is MOST important for protecting corporate data on these devices?

    Answer: Implementing mobile device management (MDM) with remote wipe capability

    MDM with remote wipe capability ensures that corporate data can be erased from personal devices if they are lost, stolen, or the employee leaves the organization.

  5. An IS auditor is evaluating a company's key management practices. Which of the following represents the GREATEST risk to a public key infrastructure (PKI)?

    Answer: Failure to maintain a current certificate revocation list (CRL)

    An outdated CRL means that compromised or revoked certificates may still be trusted, allowing attackers to impersonate legitimate entities.

  6. Which security concept is BEST demonstrated when a financial system requires both a manager and an accountant to approve wire transfers above a threshold?

    Answer: Separation of duties

    Requiring two individuals from different roles to authorize a transaction enforces separation of duties, preventing any single person from completing a sensitive transaction alone.

  7. An IS auditor reviews logs and finds that a privileged administrator account was used to access financial records outside of business hours with no change ticket. What should the auditor do FIRST?

    Answer: Determine whether the access was authorized and investigate the business justification

    The auditor should first gather facts by determining whether the after-hours access was authorized before drawing conclusions or escalating the finding.