CISA DOMAIN 5 PRACTICE
EXAM GUIDE 39
QUESTIONS
Question 1: An IS auditor is reviewing an organization's information security control baseline. What should the auditor determine FIRST?
Choices:
1) Whether the baseline contains the newest commercially available tools 2) Whether the baseline is sucient to address identied risks and security requirements 3) Whether every business unit uses identical technical settings 4) Whether the baseline eliminates the need for risk assessments Correct Answer: Whether the baseline is sucient to address identied risks and security requirements Explanation: A control baseline should rst be evaluated for suciency against the organization's risks and security requirements. New tools or uniform settings do not by themselves show that the baseline provides appropriate protection.Page 1
Question 2: Which approach BEST supports selecting security controls for
information assets?
Choices:
1) Apply the strongest available controls to every asset 2) Base controls on asset classication and risk exposure 3) Let system administrators choose controls independently 4) Use only controls required by the operating system vendor Correct Answer: Base controls on asset classication and risk exposure Explanation: Security controls should be proportionate to the sensitivity, criticality, and risk exposure of the asset. Classication and risk assessment provide the basis for selecting appropriate safeguards.Question 3: During a data center physical security review, which nding should receive the HIGHEST priority?
Choices:
1) A visitor log is retained for only 60 days 2) A camera does not cover one equipment aisle 3) An emergency exit is blocked by stored equipment 4) A badge reader does not display the employee's photograph
Correct Answer: An emergency exit is blocked by stored equipment
Explanation: Life safety takes priority over asset protection. A blocked emergency exit can endanger personnel during a re or other emergency and therefore requires immediate remediation.Page 2
Question 4: Which control is MOST important when a clean-agent re suppression system can discharge into an occupied computer room?
Choices:
1) A pre-discharge alarm and evacuation procedure 2) A higher air-conditioning set point 3) A visitor escort log 4) A raised-oor grounding grid
Correct Answer: A pre-discharge alarm and evacuation procedure
Explanation: Personnel must have warning and a safe evacuation process before re- suppression discharge. Protecting human life is the primary concern even when the agent is designed for electronic equipment areas.
Question 5: An employee is terminated without notice. Which action should occur
FIRST from an identity and access management perspective?
Choices:
1) Delete all audit logs associated with the employee 2) Disable the employee's logical access immediately 3) Transfer the employee's les to removable media 4) Wait for the next scheduled access recertication
Correct Answer: Disable the employee's logical access immediately
Explanation: Access should be disabled immediately when employment ends to prevent unauthorized use of active credentials. Records and business data can then be preserved and transferred through controlled procedures.Page 3