Study sets
English

Certified Information Systems Auditor (CISA) | Domain 5 Information Security and Access Protection 01

1 / 130.0s

Problem 1 ・ Question 1 / 13

Which best shows that an information security policy is effective?

View explanation

A policy must set a direction grounded in the business and its risks and be taken down into standards, procedures and controls.

Problem 1 ・ Question 2 / 13

Who should be responsible for classifying information?

View explanation

The information owner understands the value, the sensitivity and the legal requirements and decides the classification and protection requirements.

Problem 1 ・ Question 3 / 13

What is the most important basis for deciding a data retention period?

View explanation

Keep data only as long as needed and dispose of it securely once legal holds and business purposes are satisfied.

Problem 1 ・ Question 4 / 13

Which mechanism most effectively removes a leaver's access promptly?

View explanation

Disabling access immediately, triggered by HR information, prevents unauthorised access after departure.

Problem 1 ・ Question 5 / 13

What characterises RBAC?

View explanation

RBAC manages permissions through job roles, which standardises granting and review.

Problem 1 ・ Question 6 / 13

Which control matters most in privileged access management?

View explanation

Limit privileged use to when it is needed and secure approval and traceability.

Problem 1 ・ Question 7 / 13

Which is an example of multi-factor authentication?

View explanation

It combines different kinds of factor, such as something you know and something you have.

Problem 1 ・ Question 8 / 13

Which risk deserves particular attention when introducing single sign-on?

View explanation

The authentication platform becomes a single critical point, so strong authentication, availability and monitoring are needed.

Problem 1 ・ Question 9 / 13

Which mechanism grants access using the authentication result of an external identity provider?

View explanation

Federation links identity information across different domains on the basis of a trust relationship.

Problem 1 ・ Question 10 / 13

Which physical control most directly prevents tailgating into a data centre?

View explanation

A mantrap does not open the next door until the previous one has closed and authentication has succeeded, which deters tailgating.

Problem 1 ・ Question 11 / 13

Which key management control matters most when encrypting data at rest?

View explanation

The security of encryption depends on the generation, storage, distribution, renewal, revocation and recovery of the keys.

Problem 1 ・ Question 12 / 13

What is the main purpose of DLP?

View explanation

DLP controls the leakage of confidential information on the basis of content, classification, channel and so on.

Problem 1 ・ Question 13 / 13

Which is correct about pseudonymised personal data?

View explanation

Pseudonymisation lowers the risk, but the possibility of re-identification remains, so appropriate protection is still needed.