Home > Class 11 Business Studies > Quizzes > CISA Domain 5: Protection of Information Asset
CISA Domain 5: Protection of Information Asset
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 28% Most missed: “An organization suspects one of its employees of a security violation regarding …”
CISA Domain 5: Protection of Information Asset
Time left 00:00
25 Questions

1. What is the purpose of recordkeeping in a security awareness training program?
2. What is the Unix command to dynamically view the end of a text logfile?
3. A security leader needs to develop a data classification program. After developing the data classification and handling policy, what is the best next step to perform?
4. Blockchain is best described as:
5. An auditor has completed an audit of an organization’s use of a tool that generates SSL certificates for its external web sites. The auditor has determined that key management procedures are insufficient and that split custody of the key generation procedure is required. How might this be implemented?
6. Which of the following techniques most accurately describes a penetration test?
7. An attacker who is attempting to infiltrate an organization has decided to employ a DNS poison cache attack. What method will the attacker use to attempt this attack?
8. An organization is implementing a new SIEM. How must engineers get log data from systems and devices to the SIEM?
9. What is the best approach for implementing a new blocking rule in an IPS?
10. A CIO is investigating the prospect of a hosting center for its IT infrastructure. A specific hosting center claims to have “N+1 HVAC Systems.” What is meant by this term?
11. What is the biggest risk associated with access badges that show the name of the organization?
12. The “right to be forgotten” was first implemented by:
13. What is the purpose of locking a user account that has not been used for long periods of time?
14. A URL starting with shttp:// signifies what technology?
15. Chain of custody is employed in which business process?
16. Which of the following is the best policy for a security awareness training course?
17. In a virtualized environment, which method is the fastest way to ensure rapid recovery of servers at an alternative processing center?
18. The term “virtual memory” refers to what mechanism?
19. A security analyst has determined that some of the OS configuration file alterations have taken place without proper authorization. Which tool did the security analyst use to determine this?
20. The process of ensuring proper protection and use of PII is known as:
21. An organization suspects one of its employees of a security violation regarding the use of their workstation. The workstation, a laptop computer that is powered down, has been delivered to a forensic expert. What is the first thing the expert should do?
22. Which of the following statements is true regarding the Payment Card Industry Data Security Standard (PCI-DSS)?
23. The best time to assign roles and responsibilities for computer security incident response is:
24. What feature permits enterprise users of Microsoft Outlook to digitally sign e-mail messages?
25. A development lab employs a syslog server for security and troubleshooting issues. The information security office has recently implemented a SIEM and has directed that all log data be sent to the SIEM. How can the development lab continue to employ its local syslog server while complying with this request?