{"id":13834,"date":"2026-09-16T11:21:18","date_gmt":"2026-09-16T11:21:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=13834"},"modified":"2026-09-16T11:21:18","modified_gmt":"2026-09-16T11:21:18","slug":"isaca-cisa-practice-test-questions-and-exam-dumps-part-5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cisa-practice-test-questions-and-exam-dumps-part-5-q81-100\/","title":{"rendered":"Isaca CISA Practice Test Questions and Exam Dumps Part 5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cisa-exam-dumps\"><b>Isaca CISA Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 81. Which control is MOST effective for detecting unauthorized changes to critical system files?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> File integrity monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Employee satisfaction surveys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Capacity planning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Software licensing reviews<\/span><\/p>\n<p><b>Answer: 1) File integrity monitoring<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring detects changes to files, configurations, and other protected system objects by comparing current states with known approved baselines or expected values. It can alert security personnel when unauthorized modifications occur. This is particularly useful for critical operating system files, application files, and configuration settings. Other activities, such as capacity planning or licensing reviews, address different management concerns and do not directly identify unauthorized file changes. An IS auditor should determine whether critical files are appropriately identified, monitoring rules are configured correctly, alerts are reviewed, and exceptions are investigated. Effective monitoring can provide early evidence of unauthorized activity.<\/span><\/p>\n<h3><b>Question 82. What is the PRIMARY purpose of security logging?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To increase system storage indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To provide records that support monitoring, investigation, and accountability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for access controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent every security incident automatically<\/span><\/p>\n<p><b>Answer: 2) To provide records that support monitoring, investigation, and accountability<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security logs provide records of system and user activity that can support monitoring, incident investigation, troubleshooting, and accountability. Depending on the system, logs may capture authentication attempts, administrative actions, configuration changes, security events, and other relevant activities. Logging alone does not prevent every incident, but it provides important evidence for detecting and investigating suspicious behavior. An IS auditor should assess whether logging requirements are defined according to risk, whether important events are captured, and whether logs are protected against unauthorized modification or deletion. Retention periods should also reflect business, legal, regulatory, and investigative requirements.<\/span><\/p>\n<h3><b>Question 83. Which characteristic is MOST important for audit logs used as evidence?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> They should be stored only on user workstations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> They should contain as many unrelated events as possible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> They should be protected from unauthorized modification and deletion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> They should be accessible to every employee<\/span><\/p>\n<p><b>Answer: 3) They should be protected from unauthorized modification and deletion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit logs are valuable evidence only when their reliability and integrity can be reasonably trusted. If users or administrators can freely modify or delete logs, important evidence may be lost or manipulated. Therefore, organizations should implement appropriate access controls, centralized collection, retention mechanisms, and monitoring to protect important logs. Depending on the environment, time synchronization and secure transmission may also be necessary to support accurate event reconstruction. An IS auditor should evaluate whether logging systems restrict unauthorized access and whether log integrity is appropriately protected. Evidence should also be retained according to defined organizational and regulatory requirements.<\/span><\/p>\n<h3><b>Question 84. Why is time synchronization important across systems used for security monitoring?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It increases processor speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It reduces software licensing costs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It automatically removes malicious files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It helps establish an accurate chronological sequence of events<\/span><\/p>\n<p><b>Answer: 4) It helps establish an accurate chronological sequence of events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Consistent time settings across systems are important because security investigations often depend on reconstructing events in chronological order. If different systems use significantly different timestamps, analysts may have difficulty determining which event occurred first or correlating activity across multiple sources. Network Time Protocol and other controlled time-synchronization mechanisms can help maintain consistent system clocks. An IS auditor should evaluate whether critical systems synchronize time with approved sources and whether deviations are monitored. Accurate timestamps support security monitoring, incident investigation, audit trails, and forensic analysis. Time synchronization should be protected because manipulation of system time can interfere with investigations.<\/span><\/p>\n<h3><b>Question 85. What is the PRIMARY purpose of a Security Information and Event Management (SIEM) system?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To replace all endpoint security controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To collect, correlate, and analyze security-related events<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To physically secure data centers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To manage employee payroll<\/span><\/p>\n<p><b>Answer: 2) To collect, correlate, and analyze security-related events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A SIEM platform collects security-related events from multiple sources and can correlate information to identify patterns that may indicate suspicious or malicious activity. It may receive data from servers, applications, network devices, authentication systems, and security tools. Centralized analysis can help security teams investigate events more efficiently and identify relationships that may not be obvious when reviewing individual logs. A SIEM does not replace every security control. An IS auditor should assess whether important event sources are integrated, alerts are appropriately configured, monitoring responsibilities are assigned, and significant events are investigated within defined procedures.<\/span><\/p>\n<h3><b>Question 86. Which factor is MOST important when determining log retention requirements?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The amount of free disk space<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The preference of individual system administrators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Business, legal, regulatory, and investigative requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The age of the logging software<\/span><\/p>\n<p><b>Answer: 3) Business, legal, regulatory, and investigative requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Log retention should be based on the organization&#8217;s requirements rather than simply the amount of available storage. Certain records may need to be retained for specific periods because of regulatory obligations, legal requirements, contractual commitments, business needs, or the possibility of delayed security investigations. Retaining everything indefinitely may also introduce unnecessary cost and privacy concerns. An IS auditor should evaluate whether retention periods are formally defined, approved, and consistently applied. The auditor should also consider whether logs are protected throughout their retention period and whether secure disposal occurs when the approved retention period expires.<\/span><\/p>\n<h3><b>Question 87. What is the PRIMARY purpose of security event correlation?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To combine related events to identify potentially significant patterns<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To delete duplicate users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To increase network bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace vulnerability management<\/span><\/p>\n<p><b>Answer: 1) To combine related events to identify potentially significant patterns<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security event correlation analyzes events from different sources and identifies relationships that may indicate a security incident or suspicious activity. For example, multiple failed authentication attempts followed by a successful login and unusual data access may be more significant when considered together than when reviewed individually. Correlation can improve detection and reduce the time required to identify complex activity. An IS auditor should evaluate whether correlation rules reflect relevant risks and whether alerts are reviewed by qualified personnel. Poorly configured rules may generate excessive false positives or fail to detect meaningful patterns, so periodic tuning is important.<\/span><\/p>\n<h3><b>Question 88. What is the PRIMARY objective of vulnerability remediation verification?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To confirm that the vulnerability has actually been addressed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To identify the original software developer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To increase the number of reported vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To remove vulnerability documentation<\/span><\/p>\n<p><b>Answer: 1) To confirm that the vulnerability has actually been addressed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remediation verification determines whether a previously identified vulnerability has been successfully resolved. A patch may have been reported as installed, but verification provides evidence that the weakness is no longer present or that the approved compensating control is functioning. Depending on the vulnerability, verification may involve rescanning, configuration review, testing, or other appropriate procedures. An IS auditor should evaluate whether remediation records are supported by evidence rather than relying solely on management assertions. Exceptions should be documented and monitored. Verification is an important final stage of vulnerability management because unresolved weaknesses can remain hidden when closure is based only on administrative updates.<\/span><\/p>\n<h3><b>Question 89. Which control BEST helps prevent unauthorized software from being installed on corporate endpoints?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Annual financial reporting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Application allowlisting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Business continuity testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Physical inventory counting only<\/span><\/p>\n<p><b>Answer: 2) Application allowlisting<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting restricts software execution to programs that have been explicitly approved or meet defined trust criteria. This can help prevent unauthorized or potentially malicious applications from running on corporate endpoints. The control should be appropriately managed so that legitimate software updates and business requirements can be accommodated without creating unnecessary exceptions. An IS auditor should evaluate whether approved applications are formally managed, exceptions are authorized, and allowlisting rules are periodically reviewed. Other controls, such as endpoint monitoring and user awareness, can complement application allowlisting. However, simply maintaining a physical inventory does not directly prevent unauthorized software execution.<\/span><\/p>\n<h3><b>Question 90. Which practice MOST reduces the risk associated with unsupported software?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Ignoring vendor notifications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Disabling all system monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Maintaining an inventory and replacing or upgrading unsupported software<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Allowing unsupported systems to remain permanently<\/span><\/p>\n<p><b>Answer: 3) Maintaining an inventory and replacing or upgrading unsupported software<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unsupported software may no longer receive security patches, vendor fixes, or technical assistance, increasing exposure to known and newly discovered vulnerabilities. Organizations should maintain an accurate inventory of software and identify products approaching or exceeding their supported lifecycle. Management can then plan upgrades, replacements, isolation, or other compensating controls based on risk. An IS auditor should determine whether unsupported software is identified and whether exceptions are formally documented and monitored. Simply ignoring vendor notifications or disabling monitoring does not reduce the underlying risk. Lifecycle management is particularly important for systems that process sensitive information or support critical business operations.<\/span><\/p>\n<h3><b>Question 91. What is the PRIMARY purpose of application input validation?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To increase database storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To ensure input conforms to expected formats and rules before processing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To improve employee attendance<\/span><\/p>\n<p><b>Answer: 2) To ensure input conforms to expected formats and rules before processing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Input validation checks whether data submitted to an application meets defined expectations before the application processes it. Validation may examine data type, length, range, format, allowed characters, and other business or security rules. Proper validation can reduce the risk of malformed or malicious input being processed in unintended ways. It is an important application control but does not replace authentication, authorization, or other security measures. An IS auditor should evaluate whether input validation is applied consistently at appropriate trust boundaries and whether testing demonstrates that invalid and unexpected inputs are handled safely.<\/span><\/p>\n<h3><b>Question 92. Which control is MOST relevant to preventing SQL injection attacks?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Parameterized queries or prepared statements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Increasing monitor resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Extending backup retention only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Installing additional office printers<\/span><\/p>\n<p><b>Answer: 1) Parameterized queries or prepared statements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Parameterized queries separate SQL instructions from user-supplied data, reducing the opportunity for malicious input to alter the intended structure of a database query. This is a widely used application security control against SQL injection. Input validation and appropriate database permissions can provide additional protection, but applications should not rely solely on filtering because attackers may find ways around poorly designed validation. An IS auditor reviewing application security should evaluate whether secure coding practices are consistently followed and whether applications undergo appropriate security testing. Database accounts should also follow least-privilege principles to limit potential impact if an application is compromised.<\/span><\/p>\n<h3><b>Question 93. What is the PRIMARY security benefit of using encryption for sensitive data at rest?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It prevents all malware infections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It increases application processing speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It helps protect data if storage media is accessed without authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It eliminates the need for access controls<\/span><\/p>\n<p><b>Answer: 3) It helps protect data if storage media is accessed without authorization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption at rest transforms sensitive information into an encoded form that requires an appropriate cryptographic key for access. It can reduce the risk of unauthorized disclosure if storage devices, databases, backups, or other media are accessed improperly. Encryption does not prevent malware, eliminate the need for access controls, or guarantee complete protection. Key management is particularly important because poorly protected encryption keys can undermine the effectiveness of encryption. An IS auditor should assess whether sensitive data is identified, appropriate encryption requirements are defined, and cryptographic keys are securely generated, stored, rotated, and revoked according to organizational standards.<\/span><\/p>\n<h3><b>Question 94. Which factor is MOST important when evaluating encryption key management?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The color of the encryption software interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The number of employees using the application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The size of the database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Protection, access control, lifecycle management, and recovery of cryptographic keys<\/span><\/p>\n<p><b>Answer: 4) Protection, access control, lifecycle management, and recovery of cryptographic keys<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption is only as effective as the protection of the keys used to encrypt and decrypt information. Key management should address secure generation, storage, access, distribution, rotation, backup, recovery, revocation, and destruction. Access to keys should be restricted to authorized users and systems based on defined requirements. If keys are exposed, lost, or poorly managed, encrypted information may become vulnerable or inaccessible. An IS auditor should evaluate whether key-management responsibilities are clearly assigned and whether controls protect keys throughout their lifecycle. Separation of duties and appropriate logging can further reduce the risk of unauthorized key use.<\/span><\/p>\n<h3><b>Question 95. What is the PRIMARY purpose of tokenization for sensitive information?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To replace sensitive data with non-sensitive tokens while preserving required functionality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To permanently delete all sensitive information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To increase network speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To disable database auditing<\/span><\/p>\n<p><b>Answer: 1) To replace sensitive data with non-sensitive tokens while preserving required functionality<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive data with a token that does not directly reveal the original value. The token can often be used by applications for necessary processing while the actual sensitive information is stored separately in a protected environment. Tokenization can reduce exposure of sensitive values across systems that do not require direct access to the original information. It does not mean the original data is necessarily destroyed. An IS auditor should evaluate how tokens are generated, how the mapping to original values is protected, and which systems can access the underlying information. Proper access controls remain important around the tokenization environment.<\/span><\/p>\n<h3><b>Question 96. Which control is MOST effective for detecting anomalous user behavior?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Periodic office furniture inspections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> User and Entity Behavior Analytics (UEBA)<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Annual inventory counting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Manual password printing<\/span><\/p>\n<p><b>Answer: 2) User and Entity Behavior Analytics (UEBA)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics analyzes activity patterns associated with users and systems to identify behavior that deviates from established norms. For example, unusual login locations, abnormal data access, unexpected administrative activity, or large data transfers may generate alerts for investigation. UEBA can complement traditional security controls by identifying activity that may not match predefined attack signatures. An IS auditor should assess whether behavioral monitoring is appropriately configured, whether privacy and access requirements are addressed, and whether alerts are investigated consistently. Behavioral analytics should support\u2014not replace\u2014other preventive, detective, and response controls.<\/span><\/p>\n<h3><b>Question 97. What is the PRIMARY purpose of privileged account monitoring?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To reduce the need for system administrators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate all administrative accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To detect and investigate potentially inappropriate use of powerful accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To allow unrestricted administrator activity<\/span><\/p>\n<p><b>Answer: 3) To detect and investigate potentially inappropriate use of powerful accounts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged accounts have elevated capabilities that can affect systems, configurations, data, and security controls. Monitoring their use provides visibility into administrative actions and can help identify inappropriate or suspicious activity. Organizations should generally limit privileged access to authorized personnel and use controls such as privileged access management, strong authentication, logging, session monitoring, and periodic reviews. An IS auditor should evaluate whether privileged activities are adequately recorded and whether significant events are reviewed. Monitoring does not mean that every administrative action is automatically malicious; alerts and unusual activities should be evaluated according to defined procedures and relevant context.<\/span><\/p>\n<h3><b>Question 98. Which control BEST supports accountability for administrative actions?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Shared administrator accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Individual privileged accounts with appropriate logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Anonymous system access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Unrestricted use of generic credentials<\/span><\/p>\n<p><b>Answer: 2) Individual privileged accounts with appropriate logging<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Individual privileged accounts allow administrative actions to be associated with specific users. When combined with appropriate logging, authentication, and access controls, this improves accountability and supports investigation of administrative activity. Shared or generic administrator accounts make it difficult to determine which person performed a particular action and therefore weaken accountability. An IS auditor should evaluate whether privileged users have uniquely assigned accounts, whether shared accounts are prohibited or tightly controlled, and whether administrative activities are logged and reviewed. Strong accountability controls help organizations investigate unauthorized changes and demonstrate that privileged access is being used appropriately.<\/span><\/p>\n<h3><b>Question 99. What is the PRIMARY purpose of security control self-assessments?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To replace all independent audits<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To identify control weaknesses through management or process-owner evaluation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate management responsibility<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To guarantee that no control failures exist<\/span><\/p>\n<p><b>Answer: 2) To identify control weaknesses through management or process-owner evaluation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security control self-assessment allows control owners or responsible personnel to evaluate whether controls are appropriately designed and operating as expected. It can help organizations identify weaknesses, document exceptions, and initiate corrective actions before problems become more significant. Self-assessments do not replace independent assurance because participants may have limited objectivity or may overlook issues. An IS auditor should understand how self-assessments are performed and consider the results as part of the broader control evaluation process. The reliability of self-assessment results depends on clear criteria, appropriate evidence, qualified participants, and management follow-up.<\/span><\/p>\n<h3><b>Question 100. What is the PRIMARY purpose of a security control exception process?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To allow permanent bypassing of security controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate security policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To document, assess, approve, and monitor justified deviations from established controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent management from knowing about control weaknesses<\/span><\/p>\n<p><b>Answer: 3) To document, assess, approve, and monitor justified deviations from established controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security control exception process provides a formal method for handling situations where an approved security requirement cannot temporarily or permanently be met. Exceptions should include a documented business justification, risk assessment, appropriate approval, defined duration where applicable, and compensating controls when necessary. This prevents informal or undocumented bypasses from becoming permanent weaknesses. An IS auditor should review whether exceptions are authorized by appropriate management, periodically reassessed, and tracked until they expire or are resolved. A well-managed exception process provides transparency while allowing legitimate business needs to be addressed without abandoning security governance.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISA Exam Dumps and Practice Test Dumps &nbsp; Question 81. Which control is MOST effective for detecting unauthorized changes to critical system files? 1) File integrity monitoring 2) Employee satisfaction surveys 3) Capacity planning 4) Software licensing reviews Answer: 1) File integrity monitoring Explanation: File integrity monitoring detects changes to files, configurations, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13834"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=13834"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13834\/revisions"}],"predecessor-version":[{"id":13865,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13834\/revisions\/13865"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=13834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=13834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=13834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}