
2022年最新のCISA試験解答最新版GoShiken CISAのPDF問題集をダウンロードせよ(440問題と解答)
無料2022年最新のIsaca Certification CISA問題集を提供しております!GoShiken
質問 73
Which of the following is an object-oriented technology characteristic that permits an enhanced degree of security over data?
- A. Encapsulation
- B. Polymorphism
- C. inheritance
- D. Dynamic warehousing
正解: A
解説:
Encapsulation is a property of objects, and it prevents accessing either properties or methods that have not been previously defined as public. This means that any implementation of the behavior of an object is not accessible. An object defines a communication interface with the exterior and only that which belongs to that interface can be accessed.
質問 74
.What are used as a countermeasure for potential database corruption when two processes attempt to simultaneously edit or update the same information? Choose the BEST answer.
- A. Concurrency controls
- B. Run-to-run totals
- C. Normalization controls
- D. Referential integrity controls
正解: D
解説:
Concurrency controls are used as a countermeasure for potential database corruption when two processes attempt to simultaneously edit or update the same information.
質問 75
As a driver of IT governance, transparency of IT's cost, value and risks is primarily achieved through:
- A. strategic alignment.
- B. performance measurement.
- C. resource management.
- D. value delivery.
正解: B
解説:
Explanation/Reference:
Explanation:
Performance measurement includes setting and monitoring measurable objectives of what the IT processes need to deliver {process outcome) and how they deliver it (process capability and performance).
Strategic alignment primarily focuses on ensuring linkage of business and IT plans. Value delivery is about executing the value proposition throughout the delivery cycle. Resource management is about the optimal investment in and proper management of critical IT resources. Transparency is primarily achieved through performance measurement as it provides information to the stakeholders on how well the enterprise is performing when compared to objectives.
質問 76
Which of the following is the MOST efficient solution for a multi-location healthcare organization that wants to be able to access patient data wherever patients present themselves for care?
- A. Software as a Service (SaaS) provider
- B. Network segmentation
- C. Dynamic localization
- D. Infrastructure as a Service (laaSJ provider
正解: C
質問 77
Which of the following biometrics methods provides the HIGHEST accuracy and is LEAST accepted by users?
- A. Palm Scan
- B. Retina scan
- C. Hand Geometry
- D. Fingerprint
正解: B
解説:
Explanation/Reference:
Retina based biometric involves analyzing the layer of blood vessels situated at the back of the eye.
An established technology, this technique involves using a low-intensity light source through an optical coupler to scan the unique patterns of the retina. Retinal scanning can be quite accurate but does require the user to look into a receptacle and focus on a given point. This is not particularly convenient if you wear glasses or are concerned about having close contact with the reading device. For these reasons, retinal scanning is not warmly accepted by all users, even though the technology itself can work well.
For your exam you should know the information below:
Biometrics
Biometrics verifies an individual's identity by analyzing a unique personal attribute or behavior, which is one of the most effective and accurate methods of verifying identification and not well received by society.
Biometrics is a very sophisticated technology; thus, it is much more expensive and complex than the other types of identity verification processes. A biometric system can make authentication decisions based on an individual's behavior, as in signature dynamics, but these can change over time and possibly be forged.
Biometric systems that base authentication decisions on physical attributes (such as iris, retina, or fingerprint) provide more accuracy because physical attributes typically don't change, absent some disfiguring injury, and are harder to impersonate
Biometrics is typically broken up into two different categories. The first is the physiological. These are traits that are physical attributes unique to a specific individual. Fingerprints are a common example of a physiological trait used in biometric systems. The second category of biometrics is known as behavioral.
The behavioral authentication is also known as continuous authentication. The behavioral/continuous authentication prevents session hijacking attack. This is based on a characteristic of an individual to confirm his identity. An example is signature Dynamics. Physiological is "what you are" and behavioral is
"what you do."
When a biometric system rejects an authorized individual, it is called a Type I error (false rejection rate).
When the system accepts impostors who should be rejected, it is called a Type II error (false acceptance rate). The goal is to obtain low numbers for each type of error, but Type II errors are the most dangerous and thus the most important to avoid.
When comparing different biometric systems, many different variables are used, but one of the most important metrics is the crossover error rate (CER). This rating is stated as a percentage and represents the point at which the false rejection rate equals the false acceptance rate. This rating is the most important measurement when determining the system's accuracy. A biometric system that delivers a CER of 3 will be more accurate than a system that delivers a CER of 4. Crossover error rate (CER) is also called equal error rate (EER).
Throughput describes the process of authenticating to a biometric system. This is also referred to as the biometric system response time. The primary consideration that should be put into the purchasing and implementation of biometric access control are user acceptance, accuracy and processing speed.
Biometric Considerations
In addition to the access control elements of a biometric system, there are several other considerations that are important to the integrity of the control environment. These are:
Resistance to counterfeiting
Data storage requirements
User acceptance
Reliability and
Target User and approach
Fingerprint
Fingerprints are made up of ridge endings and bifurcations exhibited by friction ridges and other detailed characteristics called minutiae. It is the distinctiveness of these minutiae that gives each individual a unique fingerprint. An individual places his finger on a device that reads the details of the fingerprint and compares this to a reference file. If the two match, the individual's identity has been verified.
Palm Scan
The palm holds a wealth of information and has many aspects that are used to identify an individual. The palm has creases, ridges, and grooves throughout that are unique to a specific person. The palm scan also includes the fingerprints of each finger. An individual places his hand on the biometric device, which scans and captures this information. This information is compared to a reference file, and the identity is either verified or rejected.
Hand Geometry
The shape of a person's hand (the shape, length, and width of the hand and fingers) defines hand geometry. This trait differs significantly between people and is used in some biometric systems to verify identity. A person places her hand on a device that has grooves for each finger. The system compares the geometry of each finger, and the hand as a whole, to the information in a reference file to verify that person's identity.
Retina Scan
A system that reads a person's retina scans the blood-vessel pattern of the retina on the backside of the eyeball. This pattern has shown to be extremely unique between different people. A camera is used to project a beam inside the eye and capture the pattern and compare it to a reference file recorded previously.
Iris Scan
An iris scan is a passive biometric control
The iris is the colored portion of the eye that surrounds the pupil. The iris has unique patterns, rifts, colors, rings, coronas, and furrows. The uniqueness of each of these characteristics within the iris is captured by a camera and compared with the information gathered during the enrollment phase.
When using an iris pattern biometric system, the optical unit must be positioned so the sun does not shine into the aperture; thus, when implemented, it must have proper placement within the facility.
Signature Dynamics
When a person signs a signature, usually they do so in the same manner and speed each time. Signing a signature produces electrical signals that can be captured by a biometric system. The physical motions performed when someone is signing a document create these electrical signals. The signals provide unique characteristics that can be used to distinguish one individual from another. Signature dynamics provides more information than a static signature, so there are more variables to verify when confirming an individual's identity and more assurance that this person is who he claims to be.
Keystroke Dynamics
Whereas signature dynamics is a method that captures the electrical signals when a person signs a name, keystroke dynamics captures electrical signals when a person types a certain phrase. As a person types a specified phrase, the biometric system captures the speed and motions of this action. Each individual has a certain style and speed, which translate into unique signals. This type of authentication is more effective than typing in a password, because a password is easily obtainable. It is much harder to repeat a person's typing style than it is to acquire a password.
Voice Print
People's speech sounds and patterns have many subtle distinguishing differences. A biometric system that is programmed to capture a voice print and compare it to the information held in a reference file can differentiate one individual from another. During the enrollment process, an individual is asked to say several different words.
Facial Scan
A system that scans a person's face takes many attributes and characteristics into account. People have different bone structures, nose ridges, eye widths, forehead sizes, and chin shapes. These are all captured during a facial scan and compared to an earlier captured scan held within a reference record. If the information is a match, the person is positively identified.
Hand Topography
Whereas hand geometry looks at the size and width of an individual's hand and fingers, hand topology looks at the different peaks and valleys of the hand, along with its overall shape and curvature. When an individual wants to be authenticated, she places her hand on the system. Off to one side of the system, a camera snaps a side-view picture of the hand from a different view and angle than that of systems that target hand geometry, and thus captures different data. This attribute is not unique enough to authenticate individuals by itself and is commonly used in conjunction with hand geometry.
Vascular Scan
Vascular Scan uses the blood vessel under the first layer of skin.
The following answers are incorrect:
Fingerprint - Fingerprints are made up of ridge endings and bifurcations exhibited by friction ridges and other detailed characteristics called minutiae. It is the distinctiveness of these minutiae that gives each individual a unique fingerprint. An individual places his finger on a device that reads the details of the fingerprint and compares this to a reference file. If the two match, the individual's identity has been verified.
Hand Geometry - The shape of a person's hand (the shape, length, and width of the hand and fingers) defines hand geometry. This trait differs significantly between people and is used in some biometric systems to verify identity. A person places her hand on a device that has grooves for each finger. The system compares the geometry of each finger, and the hand as a whole, to the information in a reference file to verify that person's identity.
Palm Scan - The palm holds a wealth of information and has many aspects that are used to identify an individual. The palm has creases, ridges, and grooves throughout that are unique to a specific person. The palm scan also includes the fingerprints of each finger. An individual places his hand on the biometric device, which scans and captures this information. This information is compared to a reference file, and the identity is either verified or rejected.
Following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 330 and 331
Official ISC2 guide to CISSP CBK 3rd Edition Page number 924
質問 78
An organization has implemented an automated match between purchase orders, goods receipts, and invoices.
Which of the following risks will this control BEST mitigate?
- A. A legitimate transaction being paid multiple times
- B. Invalid payments being processed by the system
- C. Delay of purchase orders
- D. Customer discounts not being applied
正解: C
質問 79
In order to coordinate the activity of many infected computers, attackers have used coordinating systems known as:
- A. backdoor
- B. rootnets
- C. botnets
- D. wormnets
- E. trojannets
- F. spynets
正解: C
解説:
Section: Protection of Information Assets
Explanation:
In order to coordinate the activity of many infected computers, attackers are used coordinating systems known as botnets. In a botnet, the malware or mailbot logs in to an Internet Relay Chat channel or other chat system. The attacker can then give instructions to all the infected systems simultaneously.
質問 80
Cisco IOS based routers perform basic traffic filtering via which of the following mechanisms?
- A. state checking
- B. datagram scanning
- C. link progressing
- D. access lists
- E. None of the choices.
- F. stateful inspection
正解: D
解説:
Explanation/Reference:
Explanation:
In addition to deploying stateful firewall, you may setup basic traffic filtering on a more sophisticated router.
As an example, on a Cisco IOS based router you may use ip access lists (ACL) to perform basic filtering on the network edge. Note that if they have denied too much traffic, something is obviously being too restrictive and you may want to reconfigure them.
質問 81
Attribute sampling is BEST suited to estimate:
- A. whether a recorded balance is within limits of materiality,
- B. the total error amount in the population
- C. the true monetary value of a population
- D. compliance with approved procedures
正解: A
質問 82
The MOST likely explanation for a successful social engineering attack is:
- A. the computer knowledge of the attackers.
- B. that computers make logic errors.
- C. the technological sophistication of the attack method.
- D. that people make judgment errors.
正解: D
解説:
Explanation/Reference:
Explanation:
Humans make errors in judging others; they may trust someone when, in fact, the person is untrustworthy.
Driven by logic, computers make the same error every time they execute the erroneous logic; however, this is not the basic argument in designing a social engineering attack. Generally, social engineering attacks do not require technological expertise; often, the attacker is not proficient in information technology or systems. Social engineering attacks are human-based and generally do not involve complicated technology.
質問 83
Back Orifice is an example of:
- A. a virus.
- B. a backdoor that takes the form of an installed program.
- C. an eavedropper.
- D. a legitimate remote control software.
- E. None of the choices.
正解: B
解説:
"A backdoor may take the form of an installed program (e.g., Back Orifice) or could be in the form of an existing ""legitimate"" program, or executable file. A specific form of backdoors are rootkits , which replaces system binaries and/or hooks into the function calls of the operating system to hide the presence of other programs, users, services and open ports."
質問 84
When evaluating database management practices, which of the following controls would MOST effectively support data integrity?
- A. User access controls
- B. System processing output balanced to control totals
- C. System edit checks
- D. System-generated duplicate transaction reports
正解: C
質問 85
.What is often assured through table link verification and reference checks?
- A. Database normalcy
- B. Database accuracy
- C. Database integrity
- D. Database synchronization
正解: C
解説:
Database integrity is most often ensured through table link verification and reference checks.
質問 86
Which of the following is an IS auditor s GREATEST concern when an organization does not regularly update software on individual workstations in the internal environment?
- A. System functionality may not meet business requirements.
- B. The system may have version control issues.
- C. The organization may not be in compliance with licensing agreement.
- D. The organization may be more susceptible to cyber-attacks.
正解: D
質問 87
While planning a security audit, an IS auditor is made aware of a security review carried out by external consultants. It is MOST implement for the auditor to:
- A. Re-perform the security review
- B. Asses the objectively and competence of the consultant
- C. Review similar reports issued by the consultants.
- D. Accept the finding and conclusion of the consultants
正解: C
質問 88
Which of the following would be MOST important for an IS auditor to review during an audit of an automated continuous monitoring process being used by the finance department.
- A. Resiliency of the monitoring service
- B. Management sign-off of test documentation
- C. Dual control and approvals embedded in processes
- D. Configuration of the monitoring tool
正解: A
質問 89
An IS auditor finds that conference rooms have active network ports. Which of the following is MOST important to ensure?
- A. The corporate network is using an intrusion prevention system (IPS)
- B. This part of the network is isolated from the corporate network
- C. A single sign-on has been implemented in the corporate network
- D. Antivirus software is in place to protect the corporate network
正解: B
解説:
Explanation/Reference:
Explanation:
If the conference rooms have access to the corporate network, unauthorized users may be able to connect to the corporate network; therefore, both networks should be isolated either via a firewall or being physically separated. An I PS would detect possible attacks, but only after they have occurred. A single sign-on would ease authentication management. Antivirus software would reduce the impact of possible viruses; however, unauthorized users would still be able to access the corporate network, which is the biggest risk.
質問 90
Which of the following findings should an IS auditor be MOST concerned about when performing an audit of backup and recovery and the offsite storage vault?
- A. Paper documents are also stored in the offsite vault.
- B. The offsite vault is located in a separate facility.
- C. Data files that are stored in the vault are synchronized.
- D. There are three individuals with a key to enter the area.
正解: C
解説:
Choice A is incorrect because more than one person would typically need to have a key to the vault to ensure that individuals responsible for the offsite vault can take vacations and rotate duties. Choice B is not correct because an IS auditor would not be concerned with whether paper documents are stored in the offsite vault. In fact, paper documents, such as procedural documents and a copy of the contingency plan, would most likely be stored in the offsite vault, and the location of the vault is important, but not as important as the files being synchronized.
質問 91
A security review reveals an organization b struggling with a large number of findings from vulnerability scans. What should the IS auditor recommend be done FIRST.
- A. Remediate vulnerabilities for the most critical systems
- B. Conduct penetration tests to confirm critical findings.
- C. Address gaps for all internally developed applications
- D. Remediate issues that are rated as most critical
正解: D
質問 92
What type of risk is associated with authorized program exits (trap doors)? Choose the BEST answer.
- A. Business risk
- B. Audit risk
- C. Detective risk
- D. Inherent risk
正解: D
解説:
Explanation/Reference:
Inherent risk is associated with authorized program exits (trap doors).
質問 93
An organization globally distributes a free phone application that includes a module to gather and report user information. The application includes a privacy notice alerting users to the data gathering. Which of the following presents the GREATEST risk?
- A. There is no framework to delete personal data.
- B. The data is not properly encrypted on the application server.
- C. There may be a backlash among users when the data gathering is revealed.
- D. The data gathering notice is available in only one language.
正解: B
解説:
Section: Protection of Information Assets
質問 94
What is used to provide authentication of the website and can also be used to successfully authenticate
keys used for data encryption?
- A. Authenticode
- B. A user certificate
- C. A website certificate
- D. An organizational certificate
正解: C
解説:
Section: Protection of Information Assets
Explanation:
A website certificate is used to provide authentication of the website and can also be used to successfully
authenticate keys used for data encryption.
質問 95
A small organization is experiencing rapid growth and plans to create a new information security policy.
Which of the following is MOST relevant to creating the policy?
- A. Industry standards
- B. The business objectives
- C. Previous audit recommendations
- D. The business impact analysis (BIA)
正解: B
質問 96
In an audit of an inventory application, which approach would provide the BEST evidence that purchase
orders are valid?
- A. Testing whether inappropriate personnel can change application parameters
- B. Tracing purchase orders to a computer listing
- C. Reviewing the application documentation
- D. Comparing receiving reports to purchase order details
正解: A
解説:
Section: Protection of Information Assets
Explanation:
To determine purchase order validity, testing access controls will provide the best evidence. Choices B and
C are based on after-the-fact approaches, while choice D does not serve the purpose because what is in
the system documentation may not be the same as what is happening.
質問 97
Following a security breach, an IS auditor finds an organization's transport layer security (TLS) certificate is compromised. Which of the following would be the auditor's BEST recommendation to the system administrator?
- A. Revoke and regenerate TLS certificates
- B. Re-issue TLS certificates with a new effective date
- C. Repurchase the key from the certification authority (CA)
- D. Disable and retrieve the key from escrow
正解: A
質問 98
......
CISA試験解答問題集:https://www.goshiken.com/ISACA/CISA-mondaishu.html(440問題と解答)
無料2022年最新のIsaca Certification CISA問題集を提供しております!GoShiken:https://drive.google.com/open?id=1r5jv4SGtGzbdUXJQEeMVlK_PYyF7cI4h