CISA DOMAIN 5 PRACTICE
39 QUESTIONS
Question 1: An IS auditor is reviewing an organization's information security
program. Which evidence provides the BEST assurance that security requirements are aligned with business needs?
Choices:
1) A list of security products currently deployed 2) A risk assessment linked to business processes and information assets 3) A penetration test performed by an external consultant 4) A monthly report of blocked rewall connections Correct Answer: A risk assessment linked to business processes and information assets Explanation: A risk assessment tied to business processes and information assets demonstrates that security requirements are driven by business risk. Product inventories, penetration tests, and rewall reports may support security operations, but they do not by themselves establish alignment with business needs.Page 1
Question 2: Management has approved an information security policy. Which action should occur NEXT to make the policy operational?
Choices:
1) Dene supporting standards and procedures 2) Purchase additional security monitoring tools 3) Perform a forensic readiness assessment 4) Outsource the internal audit function
Correct Answer: Dene supporting standards and procedures
Explanation: High-level policy statements must be translated into enforceable standards and repeatable procedures. Tools and specialized assessments may follow, but standards and procedures are needed rst to implement the approved policy consistently.Question 3: An IS auditor nds that a security standard is stricter than the organization's approved security policy. What is the auditor's PRIMARY concern?
Choices:
1) The standard may be too expensive to implement 2) The standard may not be traceable to approved management direction 3) The policy should contain detailed conguration settings 4) The standard should be replaced by vendor recommendations Correct Answer: The standard may not be traceable to approved management direction Explanation: Standards should derive from and support approved policy. A standard that cannot be traced to management-approved direction may impose requirements without proper authority or risk justication. Policies normally remain high level rather than containing detailed technical settings.Page 2
Question 4: A data center is located in an area with a signicant ood risk. Which control would provide the BEST protection for critical computing equipment?
Choices:
1) Installing equipment on raised ooring above the expected ood level 2) Requiring two-factor authentication for administrators 3) Encrypting all backup media 4) Implementing a web application rewall Correct Answer: Installing equipment on raised ooring above the expected ood level Explanation: Raising critical equipment above the expected ood level directly reduces exposure to the identied physical hazard. The other controls address logical access, backup condentiality, or application attacks rather than ood damage.Question 5: During a physical security audit, the auditor observes that employees frequently allow unknown persons to follow them through badge-controlled doors.Which control would BEST address this weakness?
Choices:
1) Increase password complexity requirements 2) Implement anti-tailgating controls and reinforce access awareness 3) Encrypt visitor badge records 4) Disable wireless access in the lobby Correct Answer: Implement anti-tailgating controls and reinforce access awareness Explanation: The weakness is tailgating, so the most direct response is to use anti-tailgating mechanisms such as mantraps or turnstiles and reinforce employee awareness. Password, encryption, and wireless controls do not prevent unauthorized physical entry.Page 3