Study sets
English

Certified Information Systems Auditor (CISA) | Domain 5 Cybersecurity and Response 02

1 / 130.0s

Problem 1 ・ Question 1 / 13

What is the main security benefit of segmenting a network?

View explanation

Separating by trust level or business function and controlling traffic at the boundaries limits how far a compromise spreads.

Problem 1 ・ Question 2 / 13

What is the most important purpose of reviewing firewall rules regularly?

View explanation

Revisit permissions left over after business changes and keep traffic to the minimum.

Problem 1 ・ Question 3 / 13

What is the main difference between an IDS and an IPS?

View explanation

An IDS mainly detects and alerts, while an in-line IPS can also take defensive action.

Problem 1 ・ Question 4 / 13

Which configuration best strengthens enterprise authentication on a wireless LAN?

View explanation

Enterprise authentication provides individual credentials and strong encryption, and improves traceability.

Problem 1 ・ Question 5 / 13

Which setting should most commonly be audited over leaks from cloud storage?

View explanation

Mistaken public settings and excessive permissions are a leading cause of cloud data leaks.

Problem 1 ・ Question 6 / 13

Which combination of controls best protects an API?

View explanation

Combining identity, input handling, abuse prevention and monitoring reduces API risk.

Problem 1 ・ Question 7 / 13

Which best describes the difference between vulnerability scanning and penetration testing?

View explanation

Scanning mainly identifies candidates, while penetration testing evaluates the real impact under controlled conditions.

Problem 1 ・ Question 8 / 13

What should be given the highest priority in risk-based vulnerability remediation?

View explanation

Prioritise on asset value, exposure, exploitation activity and compensating controls, not on severity alone.

Problem 1 ・ Question 9 / 13

What is the first technical response to a device suspected of malware infection?

View explanation

Isolation limits spread and outbound traffic while evidence is preserved and analysis proceeds.

Problem 1 ・ Question 10 / 13

Which measure best shows the effectiveness of simulated targeted-mail training?

View explanation

Measure continuously the increase in the desired reporting behaviour and the decrease in risky behaviour.

Problem 1 ・ Question 11 / 13

What is the purpose of maintaining the chain of custody for evidence in digital forensics?

View explanation

Recording how the evidence was handled supports its integrity and its credibility for legal and investigative purposes.

Problem 1 ・ Question 12 / 13

What is the main role of a SIEM?

View explanation

A SIEM normalises and correlates a wide range of logs and supports visibility of and response to suspicious activity.

Problem 1 ・ Question 13 / 13

What is the most important outcome of the review after responding to a security incident?

View explanation

Turning the lessons of the post-incident review into improvements reduces the recurrence and the impact of similar incidents.