{"id":13835,"date":"2026-09-16T11:21:05","date_gmt":"2026-09-16T11:21:05","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=13835"},"modified":"2026-09-16T11:21:05","modified_gmt":"2026-09-16T11:21:05","slug":"isaca-cisa-practice-test-questions-and-exam-dumps-part-6-q101-q120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cisa-practice-test-questions-and-exam-dumps-part-6-q101-q120\/","title":{"rendered":"Isaca CISA Practice Test Questions and Exam Dumps Part 6 Q101-Q120"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cisa-exam-dumps\"><b>Isaca CISA Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 101. What is the primary purpose of regularly testing data backups?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To reduce the amount of data stored<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To verify that data can be successfully restored when needed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for recovery procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent all hardware failures<\/span><\/p>\n<p><b>Answer: 2) To verify that data can be successfully restored when needed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Backup procedures are only effective if the organization can recover usable data when required. Regular restoration testing verifies that backup files are complete, accessible, and capable of supporting recovery objectives. It can also identify problems such as corrupted backup media, incorrect configurations, missing files, or inadequate recovery procedures. An IS auditor should determine whether backup testing is performed according to organizational requirements and whether test results are documented and reviewed. Simply confirming that backups were created does not prove that they can be restored successfully. Restoration testing therefore provides assurance that the organization has a practical capability to recover critical information after a disruption or data-loss event.<\/span><\/p>\n<h3><b>Question 102. Which activity provides the strongest evidence that a backup recovery procedure is effective?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Reviewing the backup schedule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Checking that backup jobs show successful status messages<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Confirming that backup storage has sufficient capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Performing a documented restoration test using selected backup data<\/span><\/p>\n<p><b>Answer: 4) Performing a documented restoration test using selected backup data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A documented restoration test provides direct evidence that backup data can actually be recovered and used. Successful backup job messages only indicate that the backup process completed according to the system, but they do not necessarily prove that the resulting data is complete or restorable. A restoration test allows the organization to identify corrupted files, incomplete backups, configuration problems, or procedural weaknesses before a real recovery is required. The IS auditor should review test scope, results, exceptions, and management follow-up. Testing should cover appropriate systems and data based on business criticality and recovery requirements. This provides stronger assurance than simply reviewing backup logs or schedules.<\/span><\/p>\n<h3><b>Question 103. Which backup control is specifically designed to reduce the risk of ransomware encrypting available backup copies?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Maintaining immutable or offline backup copies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Increasing the frequency of user password changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Disabling system monitoring during backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Storing all backups on the same production network<\/span><\/p>\n<p><b>Answer: 1) Maintaining immutable or offline backup copies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable or offline backups provide additional protection because attackers cannot easily modify or encrypt them through compromised production systems. Immutable storage prevents changes or deletion for a defined retention period, while offline backups are isolated from normal network access. These approaches can support recovery when production data and connected backup repositories have been compromised. An IS auditor should evaluate whether backup protections are aligned with the organization\u2019s recovery requirements and threat environment. The auditor should also verify that protected copies are tested periodically. Maintaining multiple protected recovery copies can improve resilience, but organizations should still confirm that the backup data is usable through appropriate restoration testing.<\/span><\/p>\n<h3><b>Question 104. Which control is most important for ensuring that database transactions are processed completely and accurately?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Increasing database storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Allowing all users direct database access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Using input, processing, and output controls with appropriate transaction validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Removing database audit records after processing<\/span><\/p>\n<p><b>Answer: 3) Using input, processing, and output controls with appropriate transaction validation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Database transaction integrity depends on controls throughout the processing cycle. Input controls help ensure that only valid and authorized data enters the system. Processing controls help verify that calculations and transactions are performed completely and accurately, while output controls help ensure that generated information is accurate and distributed appropriately. Depending on the system, additional controls may include transaction sequencing, completeness checks, validation rules, error handling, and reconciliation. An IS auditor should evaluate whether these controls are appropriately designed and operating effectively. Increasing storage capacity does not directly ensure transaction integrity, and unrestricted access or deletion of audit records can introduce significant control weaknesses.<\/span><\/p>\n<h3><b>Question 105. Which database control helps ensure that a record cannot reference a nonexistent related record?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Referential integrity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Data compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Load balancing<\/span><\/p>\n<p><b>Answer: 2) Referential integrity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Referential integrity is a database control that helps maintain valid relationships between related tables. It ensures that a foreign key value corresponds to an appropriate primary key or otherwise permitted relationship in the referenced table. For example, an order should not reference a customer record that does not exist. Maintaining referential integrity reduces inconsistent, orphaned, or invalid relationships within databases. An IS auditor reviewing database controls should consider whether integrity constraints are appropriately designed and enforced. Encryption protects confidentiality, compression reduces storage requirements, and load balancing distributes processing workloads. None of these controls directly addresses the validity of relationships between related database records.<\/span><\/p>\n<h3><b>Question 106. What is the primary purpose of data masking when sensitive information is used in a nonproduction environment?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To permanently delete the original production data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase database processing speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To remove the need for access controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To obscure sensitive values while retaining usable data characteristics**<\/span><\/p>\n<p><b>Answer: 4) To obscure sensitive values while retaining usable data characteristics<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data masking protects sensitive information by replacing or obscuring actual values while preserving enough structure or characteristics for authorized testing or development activities. For example, a test environment may require realistic customer records but should not expose actual personal or financial information unnecessarily. Masking can reduce the risk of sensitive data exposure when production information is copied outside controlled production environments. An IS auditor should evaluate whether masking rules adequately protect sensitive fields and whether masked datasets remain suitable for their intended purpose. Data masking does not eliminate the need for access controls, encryption, or other security measures. It is one layer within a broader data protection strategy.<\/span><\/p>\n<h3><b>Question 107. Which control should be based primarily on an organization&#8217;s information classification scheme?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Handling and protection requirements for different types of information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The physical location of every employee<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The number of software developers assigned to a project<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The color used in application interfaces<\/span><\/p>\n<p><b>Answer: 1) Handling and protection requirements for different types of information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information classification identifies the sensitivity and importance of information and provides a basis for determining appropriate handling requirements. Highly sensitive information may require stronger access restrictions, encryption, retention controls, secure transmission, and specialized disposal procedures than publicly available information. An IS auditor should assess whether classification categories are clearly defined, consistently applied, and supported by appropriate handling procedures. Classification should also be understood by employees and other authorized users who handle organizational information. The purpose is to align protection measures with information sensitivity and business requirements. Classification should not be based on irrelevant factors such as interface design, employee location, or development team size.<\/span><\/p>\n<h3><b>Question 108. What is the primary purpose of a privacy impact assessment (PIA)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To determine the financial value of a database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To measure application processing speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To identify and evaluate privacy risks associated with processing personal information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace all information security assessments<\/span><\/p>\n<p><b>Answer: 3) To identify and evaluate privacy risks associated with processing personal information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A privacy impact assessment helps an organization identify and evaluate potential privacy risks associated with collecting, using, storing, sharing, or otherwise processing personal information. It can be performed during planning or before significant changes to systems and processes so that privacy considerations can be addressed early. An effective PIA may examine the types of personal information involved, purposes of processing, access, retention, disclosure, and applicable obligations. An IS auditor may review whether PIAs are required by organizational policy or applicable regulations and whether identified risks receive appropriate treatment. A PIA complements security assessments rather than replacing broader security or risk-management activities.<\/span><\/p>\n<h3><b>Question 109. Which principle recommends collecting only the personal information necessary for a specified business purpose?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Data replication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Data aggregation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Data redundancy<\/span><\/p>\n<p><b>Answer: 2) Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means limiting the collection and processing of personal information to what is necessary for a defined and legitimate purpose. Collecting unnecessary information can increase privacy exposure, storage requirements, access-control requirements, and the potential impact of a security incident. An IS auditor should assess whether business processes define the information they genuinely require and whether unnecessary fields are avoided. Data minimization can also support retention management by reducing the amount of information that must be maintained. It does not mean that organizations should eliminate information needed for legitimate business operations. Instead, it encourages purposeful collection and processing consistent with documented requirements and applicable obligations.<\/span><\/p>\n<h3><b>Question 110. What is the primary objective of third-party risk management?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To transfer all organizational risks to vendors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for internal controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To ensure vendors use identical technology to the organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To identify, assess, and manage risks arising from third-party relationships**<\/span><\/p>\n<p><b>Answer: 4) To identify, assess, and manage risks arising from third-party relationships<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party risk management helps an organization understand and control risks associated with vendors, suppliers, contractors, and other external service providers. These risks may involve information security, privacy, availability, compliance, business continuity, and operational dependencies. Effective management typically includes due diligence before engagement, contractual requirements, ongoing monitoring, performance reviews, and appropriate exit arrangements. An IS auditor should assess whether third-party risks are identified according to business importance and whether controls are proportionate to the services and information involved. Outsourcing a function does not automatically transfer accountability for managing associated risks. The organization should maintain appropriate oversight of critical external relationships throughout their lifecycle.<\/span><\/p>\n<h3><b>Question 111. Which activity should normally occur before an organization enters into a contract with a critical service provider?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Performing appropriate vendor due diligence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Removing all contractual security requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Granting unrestricted system access immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Waiting until the contract expires to assess risk<\/span><\/p>\n<p><b>Answer: 1) Performing appropriate vendor due diligence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vendor due diligence helps an organization evaluate whether a prospective service provider has the capabilities, controls, financial stability, security practices, and operational arrangements necessary to support the relationship. For critical providers, due diligence may include reviewing independent assurance reports, security documentation, business continuity capabilities, relevant certifications, control assessments, and references. The depth of assessment should be proportionate to the services provided and associated risks. An IS auditor should verify that due diligence occurs before material commitments are made and that significant findings are addressed. Contractual requirements should then reflect the identified risks and the organization&#8217;s expectations for security, performance, compliance, and continuity.<\/span><\/p>\n<h3><b>Question 112. Which item should be included in an SLA when information security is a significant concern?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Employee vacation schedules<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Office decoration standards<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Clearly defined security responsibilities and measurable security requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Personal preferences of individual administrators<\/span><\/p>\n<p><b>Answer: 3) Clearly defined security responsibilities and measurable security requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service-level agreement should establish clear and measurable expectations when security is an important aspect of an outsourced service. Relevant requirements may address access management, incident notification, availability, vulnerability management, data protection, logging, compliance, and response times. Clearly assigned responsibilities help prevent gaps between the organization and the service provider. Measurable requirements also allow performance to be monitored and exceptions to be identified. An IS auditor should determine whether security obligations are documented, understood, and monitored throughout the contract period. Generic statements that a provider will maintain security may not provide sufficient assurance because they may lack measurable requirements, responsibilities, or consequences for noncompliance.<\/span><\/p>\n<h3><b>Question 113. What is the primary purpose of a right-to-audit clause in a third-party contract?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To allow the vendor to change organizational policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To provide the organization with defined rights to assess the provider&#8217;s relevant controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for service-level agreements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To guarantee that no audit findings will occur<\/span><\/p>\n<p><b>Answer: 2) To provide the organization with defined rights to assess the provider&#8217;s relevant controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A right-to-audit clause establishes contractual authority for an organization to obtain information or perform assessments concerning a service provider&#8217;s relevant controls. Depending on the agreement, this may involve reviewing independent assurance reports, conducting assessments, requesting evidence, or performing other agreed procedures. Such provisions are particularly important when a provider handles sensitive information or supports critical business processes. An IS auditor should determine whether contractual audit rights are practical, clearly defined, and consistent with the organization&#8217;s risk requirements. The clause does not guarantee that controls are effective; rather, it provides a mechanism through which the organization can obtain assurance and investigate significant concerns.<\/span><\/p>\n<h3><b>Question 114. What is a key benefit of reviewing an independent SOC report for a critical service provider?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It guarantees that the provider has no security weaknesses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It replaces every internal audit procedure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It eliminates the need for contractual requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It provides independent information about specified controls and their operation**<\/span><\/p>\n<p><b>Answer: 4) It provides independent information about specified controls and their operation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A SOC report can provide useful independent assurance information about controls operated by a service organization. Depending on the report type and scope, it may describe relevant controls and provide information about whether those controls were suitably designed and, in applicable reports, operated effectively over a defined period. An IS auditor should review the report&#8217;s scope, period, service commitments, control objectives, exceptions, and the relevance of the covered services to the organization. A SOC report does not automatically guarantee that every risk is addressed because its scope is limited. Organizations should therefore determine whether additional procedures or evidence are necessary based on their own risk assessment.<\/span><\/p>\n<h3><b>Question 115. Under the cloud shared responsibility model, which statement is generally correct?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Security responsibilities are divided between the cloud provider and the customer according to the services used<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The cloud provider is always responsible for every customer configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The customer has no responsibility for access management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The customer is always responsible for physical data-center security<\/span><\/p>\n<p><b>Answer: 1) Security responsibilities are divided between the cloud provider and the customer according to the services used<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The shared responsibility model recognizes that cloud security responsibilities are distributed between the provider and customer, although the exact division depends on the cloud service model and provider arrangement. Providers generally manage certain underlying infrastructure responsibilities, while customers may remain responsible for areas such as identities, data, configurations, applications, or operating systems depending on the service. An IS auditor should understand the specific responsibilities documented in the cloud agreement and service model rather than assuming that the provider handles all security activities. Effective auditing therefore requires reviewing contractual responsibilities, configurations, monitoring arrangements, and evidence that both parties are performing their assigned controls.<\/span><\/p>\n<h3><b>Question 116. When auditing a cloud environment, what should the auditor first establish regarding security configuration responsibilities?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> That all cloud configurations are controlled exclusively by the provider<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> That configuration management is unnecessary in cloud services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Which security configuration responsibilities belong to the customer and which belong to the provider<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> That customers should avoid documenting cloud configurations<\/span><\/p>\n<p><b>Answer: 3) Which security configuration responsibilities belong to the customer and which belong to the provider<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud environments can involve different security responsibilities depending on the service model and contractual arrangement. Before evaluating configuration controls, an auditor should establish which party is responsible for specific settings and activities. Customer responsibilities may include identity permissions, network settings, application configurations, encryption options, or other controls depending on the service. Provider responsibilities may involve underlying infrastructure and platform components. Clearly understanding this division prevents an auditor from assigning responsibility to the wrong party. The auditor should then evaluate whether each party performs its assigned activities and whether evidence exists to demonstrate effective configuration management, monitoring, and review.<\/span><\/p>\n<h3><b>Question 117. Which control is most important for protecting an API from unauthorized requests?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Increasing screen resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Strong authentication and authorization controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Disabling all application logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Increasing database storage capacity<\/span><\/p>\n<p><b>Answer: 2) Strong authentication and authorization controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">APIs expose application functionality and data through programmatic interfaces, making authentication and authorization important security controls. Authentication helps establish the identity of the requester, while authorization determines which resources or operations that requester is permitted to access. Additional API controls can include rate limiting, input validation, secure transport, logging, monitoring, and protection against common application attacks. An IS auditor should evaluate whether API access is appropriately restricted and whether permissions follow business requirements and least-privilege principles. Strong controls should also account for service-to-service communication and credential management where applicable. Merely increasing storage capacity or disabling logging does not protect an API from unauthorized requests.<\/span><\/p>\n<h3><b>Question 118. What is a primary objective of secure code review?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To increase the number of application features<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate all testing requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To reduce software documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To identify security weaknesses in source code before deployment**<\/span><\/p>\n<p><b>Answer: 4) To identify security weaknesses in source code before deployment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure code review examines source code to identify weaknesses that could lead to vulnerabilities, such as improper input handling, insecure authentication logic, authorization errors, hard-coded secrets, or unsafe use of functions. Finding weaknesses during development can allow remediation before software is deployed into production, potentially reducing the cost and impact of security defects. Reviews may be performed manually, through automated static analysis, or through a combination of methods. An IS auditor should determine whether secure development practices include appropriate code review activities and whether identified defects are tracked through resolution. Code review complements other security testing methods rather than replacing functional testing or vulnerability assessments.<\/span><\/p>\n<h3><b>Question 119. What is the main purpose of a responsible vulnerability disclosure process?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To provide a controlled method for reporting and addressing security vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To prevent security researchers from reporting vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To publish every vulnerability immediately without assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for vulnerability remediation<\/span><\/p>\n<p><b>Answer: 1) To provide a controlled method for reporting and addressing security vulnerabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A responsible vulnerability disclosure process establishes a defined way for researchers, customers, employees, or other parties to report security weaknesses to an organization. It can specify reporting channels, information requirements, communication procedures, investigation responsibilities, remediation processes, and disclosure expectations. Such a process can help organizations receive vulnerability information in a structured manner and coordinate appropriate responses. An IS auditor may evaluate whether the process is documented, accessible to relevant parties, and connected to the organization&#8217;s vulnerability management activities. The goal is not to prevent reporting or automatically publish vulnerabilities, but to create a controlled approach that supports investigation, remediation, and appropriate communication.<\/span><\/p>\n<h3><b>Question 120. What distinguishes a key risk indicator (KRI) from a key performance indicator (KPI)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> A KRI measures only financial performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> A KPI is always related to cybersecurity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> A KRI provides an indication of changing risk exposure, while a KPI measures performance against objectives<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> There is no meaningful distinction between KRIs and KPIs<\/span><\/p>\n<p><b>Answer: 3) A KRI provides an indication of changing risk exposure, while a KPI measures performance against objectives<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Key risk indicators and key performance indicators support different management objectives. A KRI provides information about conditions that may indicate increasing or changing exposure to a particular risk. A KPI measures performance against defined objectives, targets, or expected outcomes. For example, the number of overdue critical vulnerabilities could serve as a risk-related measure, while the percentage of security reviews completed on schedule could be a performance measure. An IS auditor should evaluate whether metrics are relevant, measurable, timely, and aligned with organizational objectives. Effective metrics should provide useful information for management decisions rather than simply producing large quantities of data without meaningful interpretation.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISA Exam Dumps and Practice Test Dumps &nbsp; Question 101. What is the primary purpose of regularly testing data backups? 1) To reduce the amount of data stored 2) To verify that data can be successfully restored when needed 3) To eliminate the need for recovery procedures 4) To prevent all hardware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13835"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=13835"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13835\/revisions"}],"predecessor-version":[{"id":13864,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13835\/revisions\/13864"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=13835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=13835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=13835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}