Home > Consumer Behavior 101 > Quizzes > CISA Domain 5: Protection of Information Asset
CISA Domain 5: Protection of Information Asset
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 28% Most missed: “An organization suspects one of its employees of a security violation regarding …”
CISA Domain 5: Protection of Information Asset
Time left 00:00
25 Questions

1. Why would a hypervisor conceal its existence from a guest OS?
2. In an environment where users are not local administrators of their workstations, which of the following methods ensures that end users are not able to use their mobile devices as mobile Wi-Fi hotspots for circumventing network security controls such as web content filters and IPS?
3. An organization is seeking to establish a protocol standard for federated authentication. Which of the following protocols is least likely to be selected?
4. What is the purpose of the Firesheep tool?
5. The “right to be forgotten” was first implemented by:
6. An attack technique in which an attacker attempts to place arbitrary code into the instruction space of a running process is known as:
7. An employee notes that a company document is marked “Confidential.” Is it acceptable for the employee to e-mail the document to a party outside the company?
8. The primary purpose of a mantrap is:
9. An organization is implementing a new SIEM. How must engineers get log data from systems and devices to the SIEM?
10. Chain of custody is employed in which business process?
11. What feature permits enterprise users of Microsoft Outlook to digitally sign e-mail messages?
12. An organization has updated its identity and access management infrastructure so that users use their AD credentials to log in to the network as well as internal business applications. What has the organization implemented?
13. While useful for detecting fires, what is one known problem associated with the use of smoke detectors under a raised computer room floor?
14. Which of the following is the best policy for a security awareness training course?
15. A security analyst who is troubleshooting a security issue has asked another engineer to obtain a PCAP file associated with a given user’s workstation. What is the security analyst asking for?
16. All of the following are appropriate uses of digital signatures except:
17. For what reason would an engineer choose to use a hosted hypervisor versus a bare-metal hypervisor?
18. Guessing that an intended victim has a particular online banking session open, an attacker attempts to trick the victim into clicking on a link that will attempt to execute a transaction on the online banking site. This type of an attack is known as:
19. Which of the following correctly describes the correct sequence for computer security incident response?
20. An organization is investigating the use of an automated DLP solution that controls whether data files can be sent via e-mail or stored on USB drives based on their tags. What is the advantage of the use of tags for such a solution?
21. Which of the following statements is true regarding the Payment Card Industry Data Security Standard (PCI-DSS)?
22. A security analyst spends most of her time on a system that collects log data and correlates events from various systems to deduce potential attacks in progress. What kind of a system is the security analyst using?
23. An auditor has completed an audit of an organization’s use of a tool that generates SSL certificates for its external web sites. The auditor has determined that key management procedures are insufficient and that split custody of the key generation procedure is required. How might this be implemented?
24. What method is used by a transparent proxy filter to prevent a user from visiting a site that has been blacklisted?
25. A CIO is investigating the prospect of a hosting center for its IT infrastructure. A specific hosting center claims to have “N+1 HVAC Systems.” What is meant by this term?