2024年最新の有効なCISAリアル試験問題(更新された)100%問題集と練習試験合格させます [Q209-Q229]

Share

2024年最新の有効なCISAリアル試験問題(更新された)100%問題集と練習試験合格させます

[更新されたのは2024年]ISACA CISA問題準備には無料サンプルのPDF


ISACA CISA(Certified Information Systems Auditor)試験は、情報システムの監査、管理、セキュリティを専門としたいIT専門家向けに設計された国際的に認められた認定です。この認定は、ITガバナンス、セキュリティ、および監査のために世界的に認められた専門家協会である情報システム監査および制御協会(ISACA)によって授与されます。


ISACA CISA(Certified Information Systems Auditor)試験は、情報システムの監査、管理、セキュリティの分野における専門家の知識と専門知識を評価するグローバルに認められた認定試験です。 CISA認定は、雇用市場で競争力を提供し、情報システム監査の分野で高いレベルの専門知識を実証しています。

 

質問 # 209
Labeling information according to its security classification:

  • A. reduces the number and type of countermeasures required.
  • B. enhances the likelihood of people handling information securely.
  • C. affects the consequences if information is handled insecurely.
  • D. reduces the need to identify baseline controls for each classification.

正解:C

解説:
Section: Information System Operations, Maintenance and Support


質問 # 210
The use of residual biometric information to gain unauthorized access is an example of which of the following attacks?

  • A. Replay
  • B. Cryptographic
  • C. Brute force
  • D. Mimic

正解:A

解説:
Explanation/Reference:
Explanation:
Residual biometric characteristics, such as fingerprints left on a biometric capture device, may be reused by an attacker to gain unauthorized access. A brute force attack involves feeding the biometric capture device numerous different biometric samples. A cryptographic attack targets the algorithm or the encrypted data, in a mimic attack, the attacker reproduces characteristics similar to those of the enrolled user, such as forging a signature or imitating a voice.


質問 # 211
An organization is concerned with meeting new regulations for protecting data confidentiality and asks an IS auditor to evaluate their procedures for transporting data. Which of the following would BEST support the organization's objectives?

  • A. Dedicated lines
  • B. Virtual local area network (VLAN)
  • C. Cryptographic hashes
  • D. Encryption

正解:D

解説:
Explanation
The best option to support the organization's objectives of protecting data confidentiality while transporting data is encryption. Encryption is a process of transforming data into an unreadable form using a secret key or algorithm, so that only authorized parties can access the original data. Encryption protects the confidentiality of data in transit by preventing unauthorized interception, modification, or disclosure of the data. Encryption can also help comply with data privacy and security regulations, such as the GDPR and HIPAA.
The other options are not as effective as encryption in protecting data confidentiality while transporting data.
Cryptographic hashes are mathematical functions that generate a fixed-length output from an input, but they do not encrypt the data. Hashes are used to verify the integrity and authenticity of data, but they do not prevent unauthorized access to the data. Virtual local area network (VLAN) is a logical grouping of network devices that share the same broadcast domain, but they do not encrypt the data. VLANs can improve network performance and security by isolating traffic, but they do not protect the data from being intercepted or modified by external attackers. Dedicated lines are physical connections that provide exclusive access to a network or service, but they do not encrypt the data. Dedicated lines can offer higher bandwidth and reliability, but they do not guarantee the confidentiality of the data from being compromised by physical tampering or eavesdropping.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription2 Data Security and Confidentiality Guidelines - Centers for Disease Control and Prevention3 Information Security | Confidentiality - GeeksforGeeks4


質問 # 212
Which of the following is MOST important for an organization to complete when planning a new marketing
platform that targets advertising based on customer behavior?

  • A. Security vulnerability assessment
  • B. Cross-border data transfer assessment
  • C. Data privacy impact assessment
  • D. Data quality assessment

正解:C

解説:
Section: Information System Acquisition, Development and Implementation


質問 # 213
What can be implemented to provide the highest level of protection from external attack?

  • A. Configuring two load-sharing firewalls facilitating VPN access from external hosts to internal hosts
  • B. Configuring the firewall as the protecting bastion host
  • C. Layering perimeter network protection by configuring the firewall as a screened host in a screened subnet behind the bastion host
  • D. Configuring the firewall as a screened host behind a router

正解:C

解説:
Explanation/Reference:
Layering perimeter network protection by configuring the firewall as a screened host in a screened subnet behind the bastion host provides a higher level of protection from external attack than all other answers.


質問 # 214
A CIO has asked an IS to implement several security controls for an organization's IT process and system. The auditor should:

  • A. Communicate the conflict of interest to audit management.
  • B. Obtain approval from execute management for the implementation.
  • C. Perform the assignment and future audits with the due professional care.
  • D. Refuse due to independence issue

正解:A


質問 # 215
The MOST effective control for addressing the risk of piggybacking is:

  • A. a single entry point with a receptionist.
  • B. a biometric door lock.
  • C. a deadman door.
  • D. the use of smart cards.

正解:C

解説:
Section: Protection of Information Assets
Explanation:
Deadman doors are a system of using a pair of (two) doors. For the second door to operate, the first entry
door must close and lock with only one person permitted in the holding areA. This reduces the risk of an
unauthorized person following an authorized person through a secured entry (piggybacking). The other
choices are all physical controls over entry to a secure area but do not specifically address the risk of
piggybacking.


質問 # 216
Why is the WAP gateway a component warranting critical concern and review for the IS auditor when auditing and testing controls enforcing message confidentiality?

  • A. WAP is often configured by default settings and is thus insecure.
  • B. WAP often interfaces critical IT systems.
  • C. WAP provides weak encryption for wireless traffic.
  • D. WAP functions as a protocol-conversion gateway for wireless TLS to Internet SSL.

正解:D

解説:
Section: Protection of Information Assets
Explanation:
Functioning as a protocol-conversion gateway for wireless TLS to Internet SSL, the WAP gateway is a component warranting critical concern and review for the IS auditor when auditing and testing controls that enforce message confidentiality


質問 # 217
Which of the following scenarios would enable a forensic investigation?

  • A. Incident response team members extracted the logs showing the suspicious activity and added their notes before submitting for investigation.
  • B. The media in question was preserved using imaging, and chain of custody was documented according to the organization's incident response plan.
  • C. The suspected computer was rebooted, and the evidence log file was converted to a readable format for further analysis.
  • D. The incident response team prepared a final report for the forensic investigator and deleted the original file securely to avoid further damage.

正解:B


質問 # 218
Disaster recovery planning for network connectivity to a hot site over a public-switched network would be
MOST likely to include:

  • A. reciprocal agreements with customers of that network
  • B. minimizing the number of points of presence
  • C. redirecting private virtual circuits
  • D. contracts for acquiring new leased lines

正解:C

解説:
Section: Protection of Information Assets


質問 # 219
An IS auditor is assessing the results of an organization's post-implementation review of a newly developed
information system. Which of the following should be the auditor's MAIN focus?

  • A. The disaster recovery plan has been updated.
  • B. Benefits realization analysis has been completed.
  • C. Lessons learned have been identified.
  • D. The procurement contract has been closed.

正解:A

解説:
Section: Protection of Information Assets


質問 # 220
Which of the following is an example of the defense in-depth security principle?

  • A. Having no physical signs on the outside of a computer center building
  • B. Using two firewalls in parallel to check different types of incoming traffic
  • C. Using a firewall as well as logical access controls on the hosts to control incoming network traffic
  • D. Using two firewalls of different vendors to consecutively check the incoming network traffic

正解:C

解説:
Section: Protection of Information Assets
Explanation
Explanation:
Defense in-depth means using different security mechanisms that back each other up. When network
traffic passes the firewall unintentionally, the logical access controls form a second line of defense. Using
two firewalls of different vendors to consecutively check the incoming network traffic is an example of
diversity in defense. The firewalls are the same security mechanisms. By using two different products the
probability of both products having the same vulnerabilities is diminished. Having no physical signs on the
outside of a computer center building is a single security measure. Using two firewalls in parallel to check
different types of incoming traffic is a single security mechanism and therefore no different than having a
single firewall checking all traffic.


質問 # 221
During an application audit, an IS auditor finds several problems related to corrupted data in the database. Which of the following is a corrective control that the IS auditor should recommend?

  • A. Establish controls to handle concurrent access problems.
  • B. implement data backup and recovery procedures.
  • C. Ensure that only authorized personnel can update the database.
  • D. Define standards and closely monitor for compliance.

正解:B

解説:
Implementing data backup and recovery procedure is a corrective control, because backup and recovery procedures can be used to roll back database errors. Defining or establishing standards is a preventive control, while monitoring for compliance is adetective control. Ensuring that only authorized personnel can update the database is a preventive control. Establishing controls to handle concurrent access problems is also a preventive control.


質問 # 222
Which of the following is the MAIN purpose of an information security management system?

  • A. To enhance the impact of reports used to monitor information security incidents
  • B. To reduce the frequency and impact of information security incidents
  • C. To identify and eliminate the root causes of information security incidents
  • D. To keep information security policies and procedures up-to-date

正解:B


質問 # 223
Normally, it would be essential to involve which of the following stakeholders in the initiation stage of a project?

  • A. System users
  • B. System designers
  • C. System owners
  • D. System builders

正解:C

解説:
System owners are the information systems (project) sponsors or chief advocates. They normally are responsible for initiating and funding projects to develop, operate and maintain information systems. System users are the individuals who use or are affected by the information system. Their requirements are crucial in the testing stage of a project. System designers translate business requirements and constraints into technical solutions. System builders construct the system based on the specifications from the systems designers. In most cases, the designers and builders are one and the same.


質問 # 224
To support an organization's goals, an IS department should have:

  • A. long- and short-range plans.
  • B. plans to acquire new hardware and software.
  • C. a low-cost philosophy.
  • D. leading-edge technology.

正解:A

解説:
Section: Protection of Information Assets
Explanation:
To ensure its contribution to the realization of an organization's overall goals, the IS department should
have long- and short-range plans that are consistent with the organization's broader plans for attaining its
goals. Choices A and C are objectives, and plans would be needed to delineate how each of the objectives
would be achieved. Choice D could be a part of the overall plan but would be required only if hardware or
software is needed to achieve the organizational goals.


質問 # 225
When reviewing system parameters, an IS auditor's PRIMARY concern should be that:

  • A. changes are recorded in an audit trail and periodically reviewed.
  • B. they are set to meet security and performance requirements.
  • C. changes are authorized and supported by appropriate documents.
  • D. access to parameters in the system is restricted.

正解:B

解説:
The primary concern is to find the balance between security and performance. Recording changes in an audit trail and periodically reviewing them is a detective control; however, if parameters are not set according to business rules, monitoring of changes may not be an effective control. Reviewing changes to ensure they are supported by appropriate documents is also a detective control, if parameters are set incorrectly, the related documentation and the fact that these are authorized does not reduce the impact. Restriction of access to parameters ensures that only authorized staff can access the parameters; however, if the parameters are set incorrectly, restricting access will still have an adverse impact.


質問 # 226
Which of the following would BEST facilitate the detection of internal fraud perpetrated by an individual?

  • A. Segregation of duties
  • B. Flexible time
  • C. Corporate fraud hotline
  • D. Mandatory leave

正解:D


質問 # 227
Which of the following is MOST important to verify when implementing an organization's information security program?

  • A. The security program has been benchmarked to industry standards.
  • B. The IT department has developed and implemented training programs.
  • C. The security program is adequately funded in the budget.
  • D. The organization's security strategy is documented and approved.

正解:D


質問 # 228
An external security audit risk has reported multiple instances of control noncompliance. Which of the following would be MOST important for the information security manager to communicate to senior management?

  • A. A plan for mitigating the risk due to noncompliance
  • B. An accountability report to initiate remediation activities
  • C. Control owner responses based on a root cause analysis
  • D. The impact of noncompliance on the organization's risk profile

正解:D

解説:
Section: Information System Operations, Maintenance and Support


質問 # 229
......

CISA豪華セット学習ガイドにはオンライン試験エンジン:https://www.goshiken.com/ISACA/CISA-mondaishu.html

2024年最新の認定サンプル問題CISA問題集と練習試験:https://drive.google.com/open?id=1N_uEn1CNpDOYDRvA2jI2G6Z6NhanSE9j