{"id":13833,"date":"2026-09-16T11:21:33","date_gmt":"2026-09-16T11:21:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=13833"},"modified":"2026-09-16T11:21:33","modified_gmt":"2026-09-16T11:21:33","slug":"isaca-cisa-practice-test-questions-and-exam-dumps-part-4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cisa-practice-test-questions-and-exam-dumps-part-4-q61-80\/","title":{"rendered":"Isaca CISA Practice Test Questions and Exam Dumps Part 4 Q61-80"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cisa-exam-dumps\"><b>Isaca CISA Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 61. What is the PRIMARY responsibility of an incident response coordinator?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Approve all employee salaries<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Coordinate response activities, communications, and escalation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Replace the organization&#8217;s security policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Perform every technical investigation personally<\/span><\/p>\n<p><b>Answer: 2) Coordinate response activities, communications, and escalation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The incident response coordinator helps organize the overall response when a security incident occurs. This role typically coordinates technical teams, business representatives, management, legal personnel, and other stakeholders as required. The coordinator helps ensure that responsibilities are clearly assigned, communications follow established procedures, and significant events are escalated appropriately. The coordinator does not necessarily perform every technical investigation or replace management&#8217;s responsibilities. An IS auditor should evaluate whether incident response roles are clearly defined and whether escalation procedures identify who must be notified based on incident severity. Clear coordination can reduce confusion and help the organization respond consistently during security events.<\/span><\/p>\n<h3><b>Question 62. Which factor should MOST influence the severity classification of a security incident?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The number of security tools installed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The age of the affected workstation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The department that reported the incident<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The potential business impact, scope, and criticality of affected resources<\/span><\/p>\n<p><b>Answer: 4) The potential business impact, scope, and criticality of affected resources<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident severity should be determined using objective criteria that reflect the potential consequences to the organization. Important considerations can include business impact, affected systems, number of users, sensitivity of information, operational disruption, legal obligations, and the criticality of the affected service. The department reporting an incident or the age of a device should not independently determine severity. Clearly defined classification criteria help ensure incidents receive an appropriate response and escalation level. An IS auditor should verify that the organization has documented severity categories and that personnel consistently apply them. Consistent classification supports timely prioritization and management reporting.<\/span><\/p>\n<h3><b>Question 63. What is the PRIMARY purpose of maintaining a chain of custody for digital evidence?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To document how evidence was collected, handled, transferred, and stored<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase the amount of evidence collected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To permanently encrypt every system involved<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To allow investigators to modify evidence during analysis<\/span><\/p>\n<p><b>Answer: 1) To document how evidence was collected, handled, transferred, and stored<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A chain of custody provides a documented history of evidence from the time it is collected through storage, transfer, examination, and eventual disposition. This documentation helps demonstrate that evidence was handled in a controlled manner and that its integrity was protected. Records may identify who collected the evidence, when it was collected, where it was stored, and who accessed or transferred it. Investigators should avoid altering original evidence unnecessarily. An IS auditor reviewing forensic processes should determine whether evidence handling procedures are documented, consistently followed, and supported by appropriate access controls and records.<\/span><\/p>\n<h3><b>Question 64. What is the PRIMARY objective of digital forensics during an investigation?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To immediately delete compromised files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To restore every affected system before investigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To identify, preserve, and analyze digital evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace the organization&#8217;s incident response plan<\/span><\/p>\n<p><b>Answer: 3) To identify, preserve, and analyze digital evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Digital forensics involves the systematic identification, collection, preservation, examination, and analysis of digital evidence. The objective is to obtain reliable information that can help determine what happened, how an incident occurred, what systems or data were affected, and potentially how the activity was performed. Investigators must use controlled procedures to minimize changes to evidence. Simply deleting suspicious files or immediately rebuilding systems may destroy information needed for investigation. An IS auditor should assess whether forensic procedures define responsibilities, evidence handling requirements, documentation standards, and appropriate safeguards for maintaining evidence integrity throughout the investigation process.<\/span><\/p>\n<h3><b>Question 65. Why is a cryptographic hash commonly calculated for a forensic image?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To make the forensic image smaller<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To verify that the image has not been altered<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To automatically remove malware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To identify the owner of the computer<\/span><\/p>\n<p><b>Answer: 2) To verify that the image has not been altered<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash produces a value based on the contents of a file or forensic image. Investigators can calculate the hash when evidence is acquired and later recalculate it to determine whether the contents have changed. If the values match, this provides evidence that the image remained consistent between the relevant checks. Hashing does not remove malware, identify ownership, or reduce the size of an image. An IS auditor reviewing forensic controls should determine whether evidence integrity mechanisms are consistently applied and whether hash values are securely documented. Maintaining evidence integrity is essential when digital evidence may be reviewed during formal investigations.<\/span><\/p>\n<h3><b>Question 66. What is the PRIMARY purpose of root cause analysis following a security incident?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To determine which employee should receive disciplinary action<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To close the incident ticket immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To increase the number of security alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To identify the underlying cause so similar incidents can be prevented**<\/span><\/p>\n<p><b>Answer: 4) To identify the underlying cause so similar incidents can be prevented<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root cause analysis focuses on determining why an incident occurred rather than simply identifying its immediate symptoms. The analysis may examine weaknesses in processes, technology, configurations, access controls, procedures, or human activities. Understanding the underlying cause enables management to implement corrective actions that reduce the possibility of recurrence. Assigning blame to an individual is not the primary objective. An IS auditor should evaluate whether significant incidents undergo appropriate analysis and whether identified corrective actions are assigned to responsible parties and tracked to completion. Effective root cause analysis can provide valuable information for improving preventive and detective controls.<\/span><\/p>\n<h3><b>Question 67. What is the PRIMARY purpose of a post-incident lessons-learned review?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To identify improvements to security controls and incident response processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate incident documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To prevent management from reviewing incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To automatically close all unresolved vulnerabilities<\/span><\/p>\n<p><b>Answer: 1) To identify improvements to security controls and incident response processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A lessons-learned review examines the organization&#8217;s response after an incident and identifies opportunities for improvement. The review may consider detection effectiveness, communication, escalation, response procedures, technical controls, staffing, documentation, and recovery activities. Findings should lead to practical corrective actions where appropriate. The purpose is not simply to close the incident record or assign blame. An IS auditor should verify that significant incidents are reviewed, lessons are documented, and improvement actions have responsible owners and target dates. Reviewing incidents systematically helps organizations strengthen their response capability and address control weaknesses revealed by real-world events.<\/span><\/p>\n<h3><b>Question 68. Which sequence BEST represents the vulnerability management lifecycle?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Remediate, ignore, identify, report<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Report, purchase, delete, recover<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Identify, assess, prioritize, remediate, and verify<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Encrypt, archive, disconnect, replace<\/span><\/p>\n<p><b>Answer: 3) Identify, assess, prioritize, remediate, and verify<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability management is an ongoing process rather than a single scanning activity. Organizations first identify vulnerabilities through appropriate assessment methods. They then evaluate severity, exploitability, affected assets, business criticality, and other relevant factors to prioritize remediation. Remediation may involve patching, configuration changes, compensating controls, or other treatments. Verification confirms whether the vulnerability was successfully addressed. An IS auditor should assess whether the process is formally defined, risk-based, and supported by appropriate records. Effective vulnerability management also requires periodic reassessment because new vulnerabilities can emerge and previously addressed weaknesses can return through configuration or software changes.<\/span><\/p>\n<h3><b>Question 69. What is a key difference between a vulnerability scan and a penetration test?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> A vulnerability scan always requires physical access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> A penetration test actively attempts to exploit identified weaknesses within an authorized scope<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> A penetration test does not require authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> A vulnerability scan replaces all security testing<\/span><\/p>\n<p><b>Answer: 2) A penetration test actively attempts to exploit identified weaknesses within an authorized scope<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning generally uses automated or semi-automated techniques to identify potential weaknesses in systems, applications, configurations, or devices. Penetration testing goes further by attempting to exploit selected weaknesses under an approved scope and rules of engagement. The objective is to determine whether vulnerabilities can realistically be exploited and what impact could result. Both activities have different purposes and should be managed appropriately. An IS auditor should verify that scanning and penetration testing are conducted according to organizational requirements, that results are documented, and that identified weaknesses are appropriately prioritized and addressed.<\/span><\/p>\n<h3><b>Question 70. What should be obtained BEFORE conducting an authorized penetration test?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> A new production server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> A complete replacement of the firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Approval from every system user<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Written authorization, defined scope, and rules of engagement<\/span><\/p>\n<p><b>Answer: 4) Written authorization, defined scope, and rules of engagement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Penetration testing can intentionally generate activity that resembles an actual attack. Therefore, written authorization is essential before testing begins. The authorization should establish the approved scope, systems or applications included, testing windows, permitted techniques, communication procedures, and rules of engagement. Clearly defining these elements reduces the possibility of unintended disruption or testing of systems that were not approved. An IS auditor should verify that penetration tests are formally authorized and appropriately controlled. Test results should also be documented and communicated to responsible management. Unauthorized testing can create operational, legal, and security risks even when the tester&#8217;s intentions are legitimate.<\/span><\/p>\n<h3><b>Question 71. Which factor should MOST influence the priority of a security patch?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Vulnerability severity, exploitability, and criticality of the affected asset<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The age of the patching server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The number of employees in the IT department<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The software vendor&#8217;s marketing budget<\/span><\/p>\n<p><b>Answer: 1) Vulnerability severity, exploitability, and criticality of the affected asset<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Patch prioritization should be risk-based. A vulnerability affecting a critical internet-facing system and actively exploited in the environment may require much faster attention than a lower-risk weakness on an isolated noncritical system. Relevant factors can include vulnerability severity, exploit availability, active exploitation, asset criticality, exposure, regulatory requirements, and available compensating controls. Simply patching systems in the order requests are received may not address the greatest risks first. An IS auditor should evaluate whether the organization has documented patching priorities and service-level expectations and whether exceptions are formally approved, monitored, and periodically reviewed.<\/span><\/p>\n<h3><b>Question 72. Which statement BEST describes a zero-day vulnerability?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> A vulnerability that has already been completely remediated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> A vulnerability that exists only on obsolete hardware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> A newly discovered vulnerability for which an effective vendor patch may not yet be available<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> A vulnerability that can never be exploited<\/span><\/p>\n<p><b>Answer: 3) A newly discovered vulnerability for which an effective vendor patch may not yet be available<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zero-day vulnerability generally refers to a previously unknown or newly disclosed security weakness for which defenders may not yet have a vendor-provided fix or sufficient time to deploy one. When such a vulnerability is actively exploited, organizations may face elevated exposure. Security teams may need to use compensating measures such as restricting access, disabling vulnerable functionality, increasing monitoring, applying vendor-recommended mitigations, or isolating affected systems. An IS auditor should evaluate whether the organization has procedures for handling emerging vulnerabilities and whether management can rapidly implement temporary controls while awaiting a permanent remediation.<\/span><\/p>\n<h3><b>Question 73. What is the PRIMARY purpose of threat intelligence?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To replace all security controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To provide relevant information about threats that supports security decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To guarantee that attacks will never occur<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for incident response<\/span><\/p>\n<p><b>Answer: 2) To provide relevant information about threats that supports security decisions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat intelligence provides analyzed information about threats, threat actors, attack techniques, indicators, vulnerabilities, and other relevant security developments. Its value comes from helping organizations make better-informed decisions about monitoring, detection, prevention, vulnerability management, and incident response. Threat intelligence does not guarantee that attacks will be prevented and does not eliminate the need for other security controls. An IS auditor should determine whether intelligence sources are relevant to the organization&#8217;s environment, whether information is appropriately validated and analyzed, and whether actionable intelligence is communicated to personnel responsible for managing security risks.<\/span><\/p>\n<h3><b>Question 74. Which of the following is an example of an Indicator of Compromise (IoC)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> An approved employee vacation request<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> A scheduled system backup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> A documented security policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> A suspicious file hash or unusual network connection associated with malicious activity<\/span><\/p>\n<p><b>Answer: 4) A suspicious file hash or unusual network connection associated with malicious activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Indicator of Compromise is observable evidence that may suggest a system or environment has been compromised. Examples can include known malicious file hashes, suspicious domains, unusual network connections, unexpected processes, unauthorized account activity, or other technical artifacts associated with malicious behavior. IoCs are useful for detection and investigation because security teams can search systems and logs for matching indicators. An IoC by itself may not prove that an incident occurred, so analysts should consider context and additional evidence. An IS auditor should evaluate whether relevant indicators are incorporated into monitoring and incident detection processes where appropriate.<\/span><\/p>\n<h3><b>Question 75. What is the PRIMARY purpose of Data Loss Prevention (DLP) controls?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To prevent unauthorized disclosure or exfiltration of sensitive information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To replace database backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To improve processor performance<\/span><\/p>\n<p><b>Answer: 1) To prevent unauthorized disclosure or exfiltration of sensitive information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention controls are designed to identify and help prevent inappropriate movement, disclosure, or exfiltration of sensitive information. Depending on the implementation, DLP can monitor data in use, in motion, or at rest and apply policies based on information type, destination, user, or activity. Examples include blocking unauthorized transmission of sensitive documents or generating alerts when protected information is copied to an unapproved location. DLP does not replace backups or directly improve system performance. An IS auditor should assess whether DLP policies are aligned with data classification requirements and whether alerts, exceptions, and policy violations are appropriately monitored.<\/span><\/p>\n<h3><b>Question 76. What is the PRIMARY function of Endpoint Detection and Response (EDR)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To provide office furniture inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To replace network architecture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To monitor endpoint activity and detect and respond to suspicious behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for authentication<\/span><\/p>\n<p><b>Answer: 3) To monitor endpoint activity and detect and respond to suspicious behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response solutions monitor activity on endpoints such as computers and servers to identify suspicious behavior and support investigation and response. EDR may collect process activity, network connections, file events, and other telemetry that can help security teams detect threats. Depending on its capabilities, an EDR platform may also support containment or other response actions. It does not eliminate the need for authentication or replace broader security architecture. An IS auditor should evaluate whether endpoint monitoring covers critical assets, whether alerts are reviewed appropriately, and whether response procedures are integrated with the organization&#8217;s broader incident management processes.<\/span><\/p>\n<h3><b>Question 77. What is the PRIMARY security benefit of network segmentation?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It guarantees that no attack can enter the network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It limits unauthorized lateral movement between network areas<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It eliminates the need for firewalls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It removes all network monitoring requirements<\/span><\/p>\n<p><b>Answer: 2) It limits unauthorized lateral movement between network areas<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides an environment into separate logical or physical security zones. Properly designed segmentation can limit an attacker&#8217;s ability to move laterally from one compromised system to other systems, particularly critical servers or sensitive environments. Segmentation can also support different security policies for different network zones. It does not guarantee that attacks cannot enter a network and does not eliminate the need for firewalls, monitoring, authentication, or other controls. An IS auditor should assess whether segmentation reflects business and security requirements, whether traffic between segments is appropriately controlled, and whether critical environments have stronger protections.<\/span><\/p>\n<h3><b>Question 78. What should an IS auditor focus on when reviewing firewall rules?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The physical color of firewall equipment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The number of cables connected to the firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The age of the firewall&#8217;s documentation alone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Whether rules are authorized, necessary, current, and appropriately restrictive<\/span><\/p>\n<p><b>Answer: 4) Whether rules are authorized, necessary, current, and appropriately restrictive<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall rule reviews should determine whether configured rules continue to support legitimate business and security requirements. Auditors should look for obsolete, duplicate, overly broad, unauthorized, or unnecessary rules that could increase exposure. Rules should have appropriate ownership and justification, and changes should be controlled. Broad permissions may create unnecessary attack paths, while poorly maintained rules can make security administration difficult. An IS auditor should examine whether periodic reviews are performed, whether unused rules are removed or disabled, and whether rule changes are authorized and documented. Effective review helps maintain a controlled boundary between network environments.<\/span><\/p>\n<h3><b>Question 79. What is the PRIMARY difference between an IDS and an IPS?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> An IPS can actively block or prevent detected malicious traffic, while an IDS primarily detects and alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> An IDS always encrypts network traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> An IPS is used only for physical security<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> An IDS cannot monitor network activity<\/span><\/p>\n<p><b>Answer: 1) An IPS can actively block or prevent detected malicious traffic, while an IDS primarily detects and alerts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Detection System primarily monitors activity and generates alerts when potentially malicious or suspicious behavior is identified. An Intrusion Prevention System can perform detection and may also take automated actions, such as blocking or dropping traffic according to configured policies. Both technologies require appropriate configuration, monitoring, and maintenance because excessive false positives or poorly designed prevention rules can affect legitimate activity. An IS auditor should evaluate whether detection and prevention controls are appropriately configured, monitored, and periodically reviewed. The organization should also have procedures for responding to alerts and investigating significant events.<\/span><\/p>\n<h3><b>Question 80. What is the PRIMARY purpose of establishing a security configuration baseline?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To allow every system administrator to use different configurations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate all system updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To define an approved secure configuration that reduces unnecessary attack exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To remove the need for vulnerability management<\/span><\/p>\n<p><b>Answer: 3) To define an approved secure configuration that reduces unnecessary attack exposure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security configuration baseline establishes an approved standard for configuring systems securely. It may specify required settings, disabled services, authentication requirements, logging, network configurations, software versions, and other security controls. The baseline provides a reference against which systems can be assessed for unauthorized or insecure deviations. It does not prevent legitimate updates or eliminate the need for vulnerability management. An IS auditor should verify that baselines are documented, approved, maintained, and periodically reviewed. Automated configuration monitoring can help identify deviations and support timely corrective action, particularly across large or frequently changing technology environments.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISA Exam Dumps and Practice Test Dumps &nbsp; Question 61. What is the PRIMARY responsibility of an incident response coordinator? 1) Approve all employee salaries 2) Coordinate response activities, communications, and escalation 3) Replace the organization&#8217;s security policy 4) Perform every technical investigation personally Answer: 2) Coordinate response activities, communications, and escalation [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13833"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=13833"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13833\/revisions"}],"predecessor-version":[{"id":13866,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13833\/revisions\/13866"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=13833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=13833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=13833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}