Home > General Studies (Hindi) > Quizzes > CISA Domain 5: Protection of Information Asset
CISA Domain 5: Protection of Information Asset
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 28% Most missed: “An organization suspects one of its employees of a security violation regarding …”
CISA Domain 5: Protection of Information Asset
Time left 00:00
25 Questions

1. An auditor has completed an audit of an organization’s use of a tool that generates SSL certificates for its external web sites. The auditor has determined that key management procedures are insufficient and that split custody of the key generation procedure is required. How might this be implemented?
2. All of the following tools are used to detect changes in static files except:
3. A forensic investigator is seen to be creating a detailed record of artifacts that are collected, analyzed, controlled, transferred to others, and stored for safekeeping. What kind of a written record is this?
4. A security manager in a large organization has found that the IT department has no central management of privileged user accounts. What kind of a tool should the security manager introduce to remedy this practice?
5. In a virtualized environment, which method is the fastest way to ensure rapid recovery of servers at an alternative processing center?
6. An organization wants to implement an IPS that utilizes SSL inspection. What must first be implemented so that the IPS will function?
7. Which U.S. government agency enforces retail organizations’ information privacy policy?
8. What is the purpose of recordkeeping in a security awareness training program?
9. The general counsel is becoming annoyed with notifications of minor security events occurring in the organization. This is most likely due to:
10. What is the most effective method for training users to more accurately detect and delete phishing messages?
11. The term “virtual memory” refers to what mechanism?
12. An attack technique in which an attacker attempts to place arbitrary code into the instruction space of a running process is known as:
13. What is the biggest risk associated with access badges that show the name of the organization?
14. In the United States, what are organizations required to do when discovering child pornography on a user’s workstation?
15. A browser contacts a web server and requests a web page. The web server responds with a status code 200. What is the meaning of this status code?
16. A security analyst has determined that some of the OS configuration file alterations have taken place without proper authorization. Which tool did the security analyst use to determine this?
17. The default principle in the European General Data Protection Regulation for marketing communications from organizations to citizens is:
18. An organization suspects one of its employees of a security violation regarding the use of their workstation. The workstation, a laptop computer that is powered down, has been delivered to a forensic expert. What is the first thing the expert should do?
19. In the context of information technology and information security, what is the purpose of fuzzing?
20. The best time to assign roles and responsibilities for computer security incident response is:
21. The primary purpose of a mantrap is:
22. How can an organization prevent employees from connecting to the corporate Exchange e-mail environment with personally owned mobile devices?
23. What is one distinct disadvantage of the use of on-premises web content filtering?
24. According to the European General Data Protection Regulation (GDPR), what is the requirement for organizations’ use of a Data Protection Officer (DPO)?
25. What is the effect of suppressing the broadcast of SSID?