Certified Information Systems Auditor (CISA) | Domain 5 Information Security and Access Protection 01
Problem 1 ・ Question 1 / 13
Which best shows that an information security policy is effective?
View explanation
A policy must set a direction grounded in the business and its risks and be taken down into standards, procedures and controls.
Problem 1 ・ Question 2 / 13
Who should be responsible for classifying information?
View explanation
The information owner understands the value, the sensitivity and the legal requirements and decides the classification and protection requirements.
Problem 1 ・ Question 3 / 13
What is the most important basis for deciding a data retention period?
View explanation
Keep data only as long as needed and dispose of it securely once legal holds and business purposes are satisfied.
Problem 1 ・ Question 4 / 13
Which mechanism most effectively removes a leaver's access promptly?
View explanation
Disabling access immediately, triggered by HR information, prevents unauthorised access after departure.
Problem 1 ・ Question 5 / 13
What characterises RBAC?
View explanation
RBAC manages permissions through job roles, which standardises granting and review.
Problem 1 ・ Question 6 / 13
Which control matters most in privileged access management?
View explanation
Limit privileged use to when it is needed and secure approval and traceability.
Problem 1 ・ Question 7 / 13
Which is an example of multi-factor authentication?
View explanation
It combines different kinds of factor, such as something you know and something you have.
Problem 1 ・ Question 8 / 13
Which risk deserves particular attention when introducing single sign-on?
View explanation
The authentication platform becomes a single critical point, so strong authentication, availability and monitoring are needed.
Problem 1 ・ Question 9 / 13
Which mechanism grants access using the authentication result of an external identity provider?
View explanation
Federation links identity information across different domains on the basis of a trust relationship.
Problem 1 ・ Question 10 / 13
Which physical control most directly prevents tailgating into a data centre?
View explanation
A mantrap does not open the next door until the previous one has closed and authentication has succeeded, which deters tailgating.
Problem 1 ・ Question 11 / 13
Which key management control matters most when encrypting data at rest?
View explanation
The security of encryption depends on the generation, storage, distribution, renewal, revocation and recovery of the keys.
Problem 1 ・ Question 12 / 13
What is the main purpose of DLP?
View explanation
DLP controls the leakage of confidential information on the basis of content, classification, channel and so on.
Problem 1 ・ Question 13 / 13
Which is correct about pseudonymised personal data?
View explanation
Pseudonymisation lowers the risk, but the possibility of re-identification remains, so appropriate protection is still needed.
Result
More sets in this exam
- Certified Information Systems Auditor (CISA) | IS Audit Fundamentals
- Certified Information Systems Auditor (CISA) | Domain 1 Audit Planning and Risk Assessment 01
- Certified Information Systems Auditor (CISA) | Domain 1 Audit Execution and Reporting 02
- Certified Information Systems Auditor (CISA) | Domain 2 IT Governance and Strategy 01
- Certified Information Systems Auditor (CISA) | Domain 2 Resources, Data and Third Parties 02
- Certified Information Systems Auditor (CISA) | Domain 3 Acquisition and Development Governance 01