Isaca CISA Practice Test Questions and Exam Dumps Part 4 Q61-80

View Full Isaca CISA Exam Dumps and Practice Test Dumps

 

Question 61. What is the PRIMARY responsibility of an incident response coordinator?

1) Approve all employee salaries
2) Coordinate response activities, communications, and escalation
3) Replace the organization’s security policy
4) Perform every technical investigation personally

Answer: 2) Coordinate response activities, communications, and escalation

Explanation:

The incident response coordinator helps organize the overall response when a security incident occurs. This role typically coordinates technical teams, business representatives, management, legal personnel, and other stakeholders as required. The coordinator helps ensure that responsibilities are clearly assigned, communications follow established procedures, and significant events are escalated appropriately. The coordinator does not necessarily perform every technical investigation or replace management’s responsibilities. An IS auditor should evaluate whether incident response roles are clearly defined and whether escalation procedures identify who must be notified based on incident severity. Clear coordination can reduce confusion and help the organization respond consistently during security events.

Question 62. Which factor should MOST influence the severity classification of a security incident?

1) The number of security tools installed
2) The age of the affected workstation
3) The department that reported the incident
4) The potential business impact, scope, and criticality of affected resources

Answer: 4) The potential business impact, scope, and criticality of affected resources

Explanation:

Incident severity should be determined using objective criteria that reflect the potential consequences to the organization. Important considerations can include business impact, affected systems, number of users, sensitivity of information, operational disruption, legal obligations, and the criticality of the affected service. The department reporting an incident or the age of a device should not independently determine severity. Clearly defined classification criteria help ensure incidents receive an appropriate response and escalation level. An IS auditor should verify that the organization has documented severity categories and that personnel consistently apply them. Consistent classification supports timely prioritization and management reporting.

Question 63. What is the PRIMARY purpose of maintaining a chain of custody for digital evidence?

1) To document how evidence was collected, handled, transferred, and stored
2) To increase the amount of evidence collected
3) To permanently encrypt every system involved
4) To allow investigators to modify evidence during analysis

Answer: 1) To document how evidence was collected, handled, transferred, and stored

Explanation:

A chain of custody provides a documented history of evidence from the time it is collected through storage, transfer, examination, and eventual disposition. This documentation helps demonstrate that evidence was handled in a controlled manner and that its integrity was protected. Records may identify who collected the evidence, when it was collected, where it was stored, and who accessed or transferred it. Investigators should avoid altering original evidence unnecessarily. An IS auditor reviewing forensic processes should determine whether evidence handling procedures are documented, consistently followed, and supported by appropriate access controls and records.

Question 64. What is the PRIMARY objective of digital forensics during an investigation?

1) To immediately delete compromised files
2) To restore every affected system before investigation
3) To identify, preserve, and analyze digital evidence
4) To replace the organization’s incident response plan

Answer: 3) To identify, preserve, and analyze digital evidence

Explanation:

Digital forensics involves the systematic identification, collection, preservation, examination, and analysis of digital evidence. The objective is to obtain reliable information that can help determine what happened, how an incident occurred, what systems or data were affected, and potentially how the activity was performed. Investigators must use controlled procedures to minimize changes to evidence. Simply deleting suspicious files or immediately rebuilding systems may destroy information needed for investigation. An IS auditor should assess whether forensic procedures define responsibilities, evidence handling requirements, documentation standards, and appropriate safeguards for maintaining evidence integrity throughout the investigation process.

Question 65. Why is a cryptographic hash commonly calculated for a forensic image?

1) To make the forensic image smaller
2) To verify that the image has not been altered
3) To automatically remove malware
4) To identify the owner of the computer

Answer: 2) To verify that the image has not been altered

Explanation:

A cryptographic hash produces a value based on the contents of a file or forensic image. Investigators can calculate the hash when evidence is acquired and later recalculate it to determine whether the contents have changed. If the values match, this provides evidence that the image remained consistent between the relevant checks. Hashing does not remove malware, identify ownership, or reduce the size of an image. An IS auditor reviewing forensic controls should determine whether evidence integrity mechanisms are consistently applied and whether hash values are securely documented. Maintaining evidence integrity is essential when digital evidence may be reviewed during formal investigations.

Question 66. What is the PRIMARY purpose of root cause analysis following a security incident?

1) To determine which employee should receive disciplinary action
2) To close the incident ticket immediately
3) To increase the number of security alerts
4) To identify the underlying cause so similar incidents can be prevented**

Answer: 4) To identify the underlying cause so similar incidents can be prevented

Explanation:

Root cause analysis focuses on determining why an incident occurred rather than simply identifying its immediate symptoms. The analysis may examine weaknesses in processes, technology, configurations, access controls, procedures, or human activities. Understanding the underlying cause enables management to implement corrective actions that reduce the possibility of recurrence. Assigning blame to an individual is not the primary objective. An IS auditor should evaluate whether significant incidents undergo appropriate analysis and whether identified corrective actions are assigned to responsible parties and tracked to completion. Effective root cause analysis can provide valuable information for improving preventive and detective controls.

Question 67. What is the PRIMARY purpose of a post-incident lessons-learned review?

1) To identify improvements to security controls and incident response processes
2) To eliminate incident documentation
3) To prevent management from reviewing incidents
4) To automatically close all unresolved vulnerabilities

Answer: 1) To identify improvements to security controls and incident response processes

Explanation:

A lessons-learned review examines the organization’s response after an incident and identifies opportunities for improvement. The review may consider detection effectiveness, communication, escalation, response procedures, technical controls, staffing, documentation, and recovery activities. Findings should lead to practical corrective actions where appropriate. The purpose is not simply to close the incident record or assign blame. An IS auditor should verify that significant incidents are reviewed, lessons are documented, and improvement actions have responsible owners and target dates. Reviewing incidents systematically helps organizations strengthen their response capability and address control weaknesses revealed by real-world events.

Question 68. Which sequence BEST represents the vulnerability management lifecycle?

1) Remediate, ignore, identify, report
2) Report, purchase, delete, recover
3) Identify, assess, prioritize, remediate, and verify
4) Encrypt, archive, disconnect, replace

Answer: 3) Identify, assess, prioritize, remediate, and verify

Explanation:

Vulnerability management is an ongoing process rather than a single scanning activity. Organizations first identify vulnerabilities through appropriate assessment methods. They then evaluate severity, exploitability, affected assets, business criticality, and other relevant factors to prioritize remediation. Remediation may involve patching, configuration changes, compensating controls, or other treatments. Verification confirms whether the vulnerability was successfully addressed. An IS auditor should assess whether the process is formally defined, risk-based, and supported by appropriate records. Effective vulnerability management also requires periodic reassessment because new vulnerabilities can emerge and previously addressed weaknesses can return through configuration or software changes.

Question 69. What is a key difference between a vulnerability scan and a penetration test?

1) A vulnerability scan always requires physical access
2) A penetration test actively attempts to exploit identified weaknesses within an authorized scope
3) A penetration test does not require authorization
4) A vulnerability scan replaces all security testing

Answer: 2) A penetration test actively attempts to exploit identified weaknesses within an authorized scope

Explanation:

Vulnerability scanning generally uses automated or semi-automated techniques to identify potential weaknesses in systems, applications, configurations, or devices. Penetration testing goes further by attempting to exploit selected weaknesses under an approved scope and rules of engagement. The objective is to determine whether vulnerabilities can realistically be exploited and what impact could result. Both activities have different purposes and should be managed appropriately. An IS auditor should verify that scanning and penetration testing are conducted according to organizational requirements, that results are documented, and that identified weaknesses are appropriately prioritized and addressed.

Question 70. What should be obtained BEFORE conducting an authorized penetration test?

1) A new production server
2) A complete replacement of the firewall
3) Approval from every system user
4) Written authorization, defined scope, and rules of engagement

Answer: 4) Written authorization, defined scope, and rules of engagement

Explanation:

Penetration testing can intentionally generate activity that resembles an actual attack. Therefore, written authorization is essential before testing begins. The authorization should establish the approved scope, systems or applications included, testing windows, permitted techniques, communication procedures, and rules of engagement. Clearly defining these elements reduces the possibility of unintended disruption or testing of systems that were not approved. An IS auditor should verify that penetration tests are formally authorized and appropriately controlled. Test results should also be documented and communicated to responsible management. Unauthorized testing can create operational, legal, and security risks even when the tester’s intentions are legitimate.

Question 71. Which factor should MOST influence the priority of a security patch?

1) Vulnerability severity, exploitability, and criticality of the affected asset
2) The age of the patching server
3) The number of employees in the IT department
4) The software vendor’s marketing budget

Answer: 1) Vulnerability severity, exploitability, and criticality of the affected asset

Explanation:

Patch prioritization should be risk-based. A vulnerability affecting a critical internet-facing system and actively exploited in the environment may require much faster attention than a lower-risk weakness on an isolated noncritical system. Relevant factors can include vulnerability severity, exploit availability, active exploitation, asset criticality, exposure, regulatory requirements, and available compensating controls. Simply patching systems in the order requests are received may not address the greatest risks first. An IS auditor should evaluate whether the organization has documented patching priorities and service-level expectations and whether exceptions are formally approved, monitored, and periodically reviewed.

Question 72. Which statement BEST describes a zero-day vulnerability?

1) A vulnerability that has already been completely remediated
2) A vulnerability that exists only on obsolete hardware
3) A newly discovered vulnerability for which an effective vendor patch may not yet be available
4) A vulnerability that can never be exploited

Answer: 3) A newly discovered vulnerability for which an effective vendor patch may not yet be available

Explanation:

A zero-day vulnerability generally refers to a previously unknown or newly disclosed security weakness for which defenders may not yet have a vendor-provided fix or sufficient time to deploy one. When such a vulnerability is actively exploited, organizations may face elevated exposure. Security teams may need to use compensating measures such as restricting access, disabling vulnerable functionality, increasing monitoring, applying vendor-recommended mitigations, or isolating affected systems. An IS auditor should evaluate whether the organization has procedures for handling emerging vulnerabilities and whether management can rapidly implement temporary controls while awaiting a permanent remediation.

Question 73. What is the PRIMARY purpose of threat intelligence?

1) To replace all security controls
2) To provide relevant information about threats that supports security decisions
3) To guarantee that attacks will never occur
4) To eliminate the need for incident response

Answer: 2) To provide relevant information about threats that supports security decisions

Explanation:

Threat intelligence provides analyzed information about threats, threat actors, attack techniques, indicators, vulnerabilities, and other relevant security developments. Its value comes from helping organizations make better-informed decisions about monitoring, detection, prevention, vulnerability management, and incident response. Threat intelligence does not guarantee that attacks will be prevented and does not eliminate the need for other security controls. An IS auditor should determine whether intelligence sources are relevant to the organization’s environment, whether information is appropriately validated and analyzed, and whether actionable intelligence is communicated to personnel responsible for managing security risks.

Question 74. Which of the following is an example of an Indicator of Compromise (IoC)?

1) An approved employee vacation request
2) A scheduled system backup
3) A documented security policy
4) A suspicious file hash or unusual network connection associated with malicious activity

Answer: 4) A suspicious file hash or unusual network connection associated with malicious activity

Explanation:

An Indicator of Compromise is observable evidence that may suggest a system or environment has been compromised. Examples can include known malicious file hashes, suspicious domains, unusual network connections, unexpected processes, unauthorized account activity, or other technical artifacts associated with malicious behavior. IoCs are useful for detection and investigation because security teams can search systems and logs for matching indicators. An IoC by itself may not prove that an incident occurred, so analysts should consider context and additional evidence. An IS auditor should evaluate whether relevant indicators are incorporated into monitoring and incident detection processes where appropriate.

Question 75. What is the PRIMARY purpose of Data Loss Prevention (DLP) controls?

1) To prevent unauthorized disclosure or exfiltration of sensitive information
2) To increase storage capacity
3) To replace database backups
4) To improve processor performance

Answer: 1) To prevent unauthorized disclosure or exfiltration of sensitive information

Explanation:

Data Loss Prevention controls are designed to identify and help prevent inappropriate movement, disclosure, or exfiltration of sensitive information. Depending on the implementation, DLP can monitor data in use, in motion, or at rest and apply policies based on information type, destination, user, or activity. Examples include blocking unauthorized transmission of sensitive documents or generating alerts when protected information is copied to an unapproved location. DLP does not replace backups or directly improve system performance. An IS auditor should assess whether DLP policies are aligned with data classification requirements and whether alerts, exceptions, and policy violations are appropriately monitored.

Question 76. What is the PRIMARY function of Endpoint Detection and Response (EDR)?

1) To provide office furniture inventory
2) To replace network architecture
3) To monitor endpoint activity and detect and respond to suspicious behavior
4) To eliminate the need for authentication

Answer: 3) To monitor endpoint activity and detect and respond to suspicious behavior

Explanation:

Endpoint Detection and Response solutions monitor activity on endpoints such as computers and servers to identify suspicious behavior and support investigation and response. EDR may collect process activity, network connections, file events, and other telemetry that can help security teams detect threats. Depending on its capabilities, an EDR platform may also support containment or other response actions. It does not eliminate the need for authentication or replace broader security architecture. An IS auditor should evaluate whether endpoint monitoring covers critical assets, whether alerts are reviewed appropriately, and whether response procedures are integrated with the organization’s broader incident management processes.

Question 77. What is the PRIMARY security benefit of network segmentation?

1) It guarantees that no attack can enter the network
2) It limits unauthorized lateral movement between network areas
3) It eliminates the need for firewalls
4) It removes all network monitoring requirements

Answer: 2) It limits unauthorized lateral movement between network areas

Explanation:

Network segmentation divides an environment into separate logical or physical security zones. Properly designed segmentation can limit an attacker’s ability to move laterally from one compromised system to other systems, particularly critical servers or sensitive environments. Segmentation can also support different security policies for different network zones. It does not guarantee that attacks cannot enter a network and does not eliminate the need for firewalls, monitoring, authentication, or other controls. An IS auditor should assess whether segmentation reflects business and security requirements, whether traffic between segments is appropriately controlled, and whether critical environments have stronger protections.

Question 78. What should an IS auditor focus on when reviewing firewall rules?

1) The physical color of firewall equipment
2) The number of cables connected to the firewall
3) The age of the firewall’s documentation alone
4) Whether rules are authorized, necessary, current, and appropriately restrictive

Answer: 4) Whether rules are authorized, necessary, current, and appropriately restrictive

Explanation:

Firewall rule reviews should determine whether configured rules continue to support legitimate business and security requirements. Auditors should look for obsolete, duplicate, overly broad, unauthorized, or unnecessary rules that could increase exposure. Rules should have appropriate ownership and justification, and changes should be controlled. Broad permissions may create unnecessary attack paths, while poorly maintained rules can make security administration difficult. An IS auditor should examine whether periodic reviews are performed, whether unused rules are removed or disabled, and whether rule changes are authorized and documented. Effective review helps maintain a controlled boundary between network environments.

Question 79. What is the PRIMARY difference between an IDS and an IPS?

1) An IPS can actively block or prevent detected malicious traffic, while an IDS primarily detects and alerts
2) An IDS always encrypts network traffic
3) An IPS is used only for physical security
4) An IDS cannot monitor network activity

Answer: 1) An IPS can actively block or prevent detected malicious traffic, while an IDS primarily detects and alerts

Explanation:

An Intrusion Detection System primarily monitors activity and generates alerts when potentially malicious or suspicious behavior is identified. An Intrusion Prevention System can perform detection and may also take automated actions, such as blocking or dropping traffic according to configured policies. Both technologies require appropriate configuration, monitoring, and maintenance because excessive false positives or poorly designed prevention rules can affect legitimate activity. An IS auditor should evaluate whether detection and prevention controls are appropriately configured, monitored, and periodically reviewed. The organization should also have procedures for responding to alerts and investigating significant events.

Question 80. What is the PRIMARY purpose of establishing a security configuration baseline?

1) To allow every system administrator to use different configurations
2) To eliminate all system updates
3) To define an approved secure configuration that reduces unnecessary attack exposure
4) To remove the need for vulnerability management

Answer: 3) To define an approved secure configuration that reduces unnecessary attack exposure

Explanation:

A security configuration baseline establishes an approved standard for configuring systems securely. It may specify required settings, disabled services, authentication requirements, logging, network configurations, software versions, and other security controls. The baseline provides a reference against which systems can be assessed for unauthorized or insecure deviations. It does not prevent legitimate updates or eliminate the need for vulnerability management. An IS auditor should verify that baselines are documented, approved, maintained, and periodically reviewed. Automated configuration monitoring can help identify deviations and support timely corrective action, particularly across large or frequently changing technology environments.