
Cybersecurity-Audit-Certificate PDF Dumps Nov 13, 2023 Exam Questions – Valid Cybersecurity-Audit-Certificate Dumps
Ultimate Cybersecurity-Audit-Certificate Guide to Prepare Free Latest ISACA Practice Tests Dumps
NEW QUESTION # 16
What would be an IS auditor's BEST response to an IT managers statement that the risk associated with the use of mobile devices in an organizational setting is the same as for any other device?
- A. The ability to wipe mobile devices and disable connectivity adequately mitigates additional
- B. The risk associated with mobile devices cannot be mitigated with similar controls for workstations.
- C. The risk associated with mobile devices is less than that of other devices and systems.
- D. Replication of privileged access and the greater likelihood of physical loss increases risk levels.
Answer: D
Explanation:
Explanation
The BEST response to an IT manager's statement that the risk associated with the use of mobile devices in an organizational setting is the same as for any other device is that replication of privileged access and the greater likelihood of physical loss increases risk levels. Mobile devices pose unique risks to an organization due to their portability, connectivity, and functionality. Mobile devices may store or access sensitive data or systems that require privileged access, which can be compromised if the device is lost, stolen, or hacked. Mobile devices also have a higher chance of being misplaced or taken by unauthorized parties than other devices.
NEW QUESTION # 17
he MOST significant limitation of vulnerability scanning is the fact that modern scanners only detect:
- A. unknown vulnerabilities.
- B. zero-day vulnerabilities.
- C. common vulnerabilities.
- D. known vulnerabilities.
Answer: D
Explanation:
Explanation
The MOST significant limitation of vulnerability scanning is the fact that modern scanners only detect known vulnerabilities. This is because vulnerability scanners rely on databases or repositories of known vulnerabilities, such as CVE (Common Vulnerabilities and Exposures), to compare and identify the weaknesses or flaws in systems or applications. Vulnerability scanners cannot detect unknown vulnerabilities, such as zero-day vulnerabilities, that have not been reported or disclosed yet, and may be exploited by attackers before they are patched or fixed. The other options are not the most significant limitation of vulnerability scanning, because they either involve detecting common (A), unknown (B), or zero-day (D) vulnerabilities, which are not the capabilities or limitations of modern scanners.
NEW QUESTION # 18
Which of the following is a computer-software vulnerability that is unknown to those who would be interested in mitigating the vulnerability?
- A. SQL injection vulnerability
- B. Zero-day vulnerability
- C. Memory leakage vulnerability
- D. Cross-site scripting vulnerability
Answer: B
Explanation:
Explanation
A computer-software vulnerability that is unknown to those who would be interested in mitigating the vulnerability is a zero-day vulnerability. This is because a zero-day vulnerability is a type of vulnerability that has not been reported or disclosed to the public or to the software vendor yet, and may be exploited by attackers before it is patched or fixed. A zero-day vulnerability poses a high risk to systems and applications that are affected by it, as there may be no known defense or solution against it. The other options are not computer-software vulnerabilities that are unknown to those who would be interested in mitigating the vulnerability, but rather types of vulnerabilities that are known and reported to the public or to the software vendor, such as cross-site scripting vulnerability (A), SQL injection vulnerability (B), or memory leakage vulnerability C.
NEW QUESTION # 19
Using a data loss prevention (DLP) solution to monitor data saved to a USB memory device is an example of managing:
- A. data redundancy.
- B. data availability.
- C. data at rest.
- D. data in use.
Answer: C
Explanation:
Explanation
Using a data loss prevention (DLP) solution to monitor data saved to a USB memory device is an example of managing data at rest. Data at rest is data that is stored on a device or media, such as hard disks, flash drives, tapes, or CDs. Data at rest can be exposed to unauthorized access, theft, or loss if not properly protected. A DLP solution is a tool that monitors and controls the movement and usage of data across an organization's network or endpoints. A DLP solution can prevent users from saving sensitive data to removable devices or alert on any violations of data policies.
NEW QUESTION # 20
In public key cryptography, digital signatures are primarily used to;
- A. prove sender authenticity.
- B. maintain confidentiality.
- C. ensure message accuracy.
- D. ensure message integrity.
Answer: A
Explanation:
Explanation
In public key cryptography, digital signatures are primarily used to prove sender authenticity. A digital signature is a cryptographic technique that allows the sender of a message to sign it with their private key, which can only be decrypted by their public key. The recipient can verify that the message was sent by the sender and not tampered with by using the sender's public key.
NEW QUESTION # 21
Which of the following is a feature of a stateful inspection firewall?
- A. It tracks the destination IP address of each packet that leaves the organization's internal network.
- B. It is capable of detecting and blocking sophisticated attacks
- C. It prevents any attack initiated and originated by an insider.
- D. It translates the MAC address to the destination IP address of each packet that enters the organization's internal network.
Answer: B
Explanation:
Explanation
A feature of a stateful inspection firewall is that it is capable of detecting and blocking sophisticated attacks. A stateful inspection firewall is a type of firewall that monitors and analyzes the state and context of network traffic. It keeps track of the source, destination, protocol, port, and session information of each packet and compares it with a set of predefined rules. A stateful inspection firewall can detect and block attacks that exploit the logic or behavior of network protocols or applications, such as fragmentation attacks, session hijacking, or application-layer attacks.
NEW QUESTION # 22
Which of the following describes specific, mandatory controls or rules to support and comply with a policy?
- A. Standards
- B. Guidelines
- C. Basedine
- D. Frameworks
Answer: A
Explanation:
Explanation
Specific, mandatory controls or rules to support and comply with a policy are known as standards. This is because standards define the minimum level of performance or behavior that is expected from an organization or its employees in order to achieve a policy objective or requirement. Standards also provide clear and measurable criteria for auditing and monitoring compliance with policies. The other options are not specific, mandatory controls or rules to support and comply with a policy, but rather different types of documents or tools that provide guidance or recommendations for implementing policies or controls, such as frameworks (A), guidelines (B), or baselines C.
NEW QUESTION # 23
Which of the following would provide the BEST basis for allocating proportional protection activities when comprehensive classification is not feasible?
- A. Business dependency assessment
- B. Comprehensive cyber insurance procurement
- C. Single classification level allocation
- D. Business process re-engineering
Answer: A
Explanation:
Explanation
The BEST basis for allocating proportional protection activities when comprehensive classification is not feasible is a business dependency assessment. This is because a business dependency assessment helps to identify the criticality and sensitivity of business processes and their supporting assets, based on their contribution to the organization's objectives and value proposition. This allows for prioritizing protection activities according to the level of risk and impact. The other options are not as effective as a business dependency assessment, because they either use a single classification level allocation (A), which does not account for different levels of risk and impact; require a significant amount of time and resources to perform a business process re-engineering (B); or rely on external parties to cover potential losses without reducing the likelihood or impact of incidents (D).
NEW QUESTION # 24
One way to control the integrity of digital assets is through the use of:
- A. hashing.
- B. caching
- C. policies.
- D. frameworks.
Answer: A
Explanation:
Explanation
One way to control the integrity of digital assets is through the use of hashing. This is because hashing is a technique that applies a mathematical function to a digital asset, such as a file or a message, and produces a unique and fixed-length value, known as a hash or a digest. Hashing helps to verify the integrity of digital assets, by comparing the hash values before and after transmission or storage, and detecting any changes or modifications to the original asset. The other options are not ways to control the integrity of digital assets, but rather different concepts or techniques that are related to information security, such as policies (A), frameworks (B), or caching C.
NEW QUESTION # 25
Which of the following is a feature of an intrusion detection system (IDS)?
- A. Intrusion prevention
- B. Back doors into applications
- C. Automated response
- D. Interface with firewalls
Answer: C
Explanation:
Explanation
A feature of an intrusion detection system (IDS) is automated response. This is because an IDS is a system that monitors network or system activities for malicious or anomalous behavior, and alerts or reports on any detected incidents. An IDS can also perform automated response actions, such as blocking traffic, terminating sessions, or sending notifications, to contain or mitigate the incidents. The other options are not features of an IDS, but rather different concepts or techniques that are related to intrusion detection or prevention, such as intrusion prevention (A), interface with firewalls C, or back doors into applications (D).
NEW QUESTION # 26
Which of the following is a feature of an intrusion detection system (IDS)?
- A. Intrusion prevention
- B. Back doors into applications
- C. Automated response
- D. Interface with firewalls
Answer: C
Explanation:
Explanation
A feature of an intrusion detection system (IDS) is automated response. This is because an IDS is a system that monitors network or system activities for malicious or anomalous behavior, and alerts or reports on any detected incidents. An IDS can also perform automated response actions, such as blocking traffic, terminating sessions, or sending notifications, to contain or mitigate the incidents. The other options are not features of an IDS, but rather different concepts or techniques that are related to intrusion detection or prevention, such as intrusion prevention (A), interface with firewalls C, or back doors into applications (D).
NEW QUESTION # 27
Which of the following backup procedure would only copy files that have changed since the last backup was made?
- A. Incremental backup
- B. Daily backup
- C. Differential backup
- D. Full backup
Answer: A
Explanation:
Explanation
The backup procedure that would only copy files that have changed since the last backup was made is an incremental backup. This is because an incremental backup is a type of backup that only copies the files that have been created or modified since the previous backup, whether it was a full or an incremental backup. An incremental backup helps to reduce the backup time and storage space, as well as the recovery time, as only the changed files need to be restored. The other options are not backup procedures that would only copy files that have changed since the last backup was made, but rather different types of backup procedures that copy files based on different criteria, such as daily backup (B), differential backup C, or full backup (D).
NEW QUESTION # 28
Which of the following presents the GREATEST challenge to information risk management when outsourcing IT function to a third party?
- A. It is difficult to determine vendor financial viability to assess their potential inability to meet contract requirements.
- B. It is difficult to know the applicable regulatory requirements when data is located on another country.
- C. Providers may be restricted from providing detailed ^formation on their employees.
- D. Providers may be reluctant to share technical delays on the extent of their information protection mechanisms.
Answer: D
Explanation:
Explanation
The GREATEST challenge to information risk management when outsourcing IT function to a third party is that providers may be reluctant to share technical details on the extent of their information protection mechanisms. This is because providers may consider their information protection mechanisms as proprietary or confidential, or may not want to reveal their weaknesses or vulnerabilities. This makes it difficult for the outsourcing organization to assess the level of security and compliance of the provider, and to monitor and audit their performance. The other options are not as challenging as providers being reluctant to share technical details, because they either involve legal or contractual aspects that can be clarified or negotiated before outsourcing (A, D), or human resource aspects that can be verified or validated by the provider C.
NEW QUESTION # 29
While risk is measured by potential activity, which of the following describes the actual occurrence of a threat?
- A. Attack
- B. Target
- C. Vulnerability
- D. Payload
Answer: A
Explanation:
Explanation
An attack is the actual occurrence of a threat, which is a potential activity that could harm an asset. An attack is the result of a threat actor exploiting a vulnerability in a system or network to achieve a malicious objective.
For example, a denial-of-service attack is the occurrence of a threat that aims to disrupt the availability of a service.
NEW QUESTION # 30
Which of the following is MOST important to ensure the successful implementation of continuous auditing?
- A. Budget for additional technical resources
- B. Top management support
- C. Budget for additional storage hardware
- D. Surplus processing capacity
Answer: B
Explanation:
Explanation
The MOST important factor to ensure the successful implementation of continuous auditing is top management support. This is because top management support helps to provide the vision, direction, and resources for implementing continuous auditing within the organization. Top management support also helps to overcome any resistance or challenges that may arise from implementing continuous auditing, such as cultural change, stakeholder buy-in, process reengineering, etc. Top management support also helps to ensure that the results and findings of continuous auditing are communicated and acted upon by the relevant decision-makers and stakeholders. The other options are not factors that are more important than top management support for ensuring the successful implementation of continuous auditing, but rather different aspects or benefits of continuous auditing, such as storage hardware (A), technical resources (B), or processing capacity (D).
NEW QUESTION # 31
Which of the following is the BEST method of maintaining the confidentiality of digital information?
- A. Use of access controls, file permissions, and encryption
- B. Use of the awareness tracing programs and related end-user testing
- C. Use of backups and business continuity planning
- D. Use of logging digital signatures, and write protection
Answer: A
Explanation:
Explanation
The BEST method of maintaining the confidentiality of digital information is using access controls, file permissions, and encryption. This is because these techniques help to prevent unauthorized access, disclosure, or modification of digital information, by restricting who can access the information, what they can do with it, and how they can access it. The other options are not as effective as using access controls, file permissions, and encryption, because they either relate to protecting availability (B), integrity C, or awareness (D).
NEW QUESTION # 32
What is the PRIMARY purpose of creating a security architecture?
- A. To visually show gaps in information security controls
- B. To provide senior management a measure of information security maturity
- C. To map out how security controls interact with an organization's systems
- D. To create a long-term information security strategy
Answer: D
Explanation:
Explanation
The PRIMARY purpose of creating a security architecture is to create a long-term information security strategy that aligns with the organization's business goals and objectives. A security architecture defines the vision, principles, standards, policies, and guidelines for how security will be implemented and managed across the organization's systems, networks, and data.
NEW QUESTION # 33
Which of the following BEST facilitates the development of metrics for repotting to senior management on vulnerability management efforts?
- A. Tracking vulnerabilities and the remediation efforts to mitigate them
- B. Regularly benchmarking the number of new vulnerabilities identified with industry peers
- C. Reviewing business impact analysis (BIA) results
- D. Monitoring the frequency of vulnerability assessments using automated scans
Answer: A
Explanation:
Explanation
The BEST feature that facilitates the development of metrics for reporting to senior management on vulnerability management efforts is tracking vulnerabilities and the remediation efforts to mitigate them. This is because tracking vulnerabilities and remediation efforts helps to measure and monitor the performance and effectiveness of vulnerability management efforts, by providing quantifiable and objective data on the number, severity, impact, status, and resolution time of vulnerabilities. Tracking vulnerabilities and remediation efforts also helps to identify and communicate any gaps or issues in vulnerability management efforts to senior management and other stakeholders. The other options are not features that facilitate the development of metrics for reporting to senior management on vulnerability management efforts, but rather different aspects or factors that affect vulnerability management efforts, such as reviewing business impact analysis (BIA) results (A), benchmarking with industry peers (B), or monitoring the frequency of vulnerability assessments (D).
NEW QUESTION # 34
Using digital evidence to provide validation that an attack has actually occurred is an example of;
- A. identification.
- B. data acquisition.
- C. extraction.
- D. computer forensic
Answer: D
Explanation:
Explanation
Using digital evidence to provide validation that an attack has actually occurred is an example of computer forensics. This is because computer forensics is a discipline that involves the identification, preservation, analysis, and presentation of digital evidence from various sources, such as computers, networks, mobile devices, etc., to support investigations of cyber incidents or crimes. Computer forensics helps to provide validation that an attack has actually occurred, by examining the digital traces or artifacts left by the attackers on the compromised systems or devices, and by reconstructing the sequence and timeline of events that led to the attack. The other options are not examples of using digital evidence to provide validation that an attack has actually occurred, but rather different techniques or processes that are related to computer forensics, such as extraction (B), identification C, or data acquisition (D).
NEW QUESTION # 35
Which of the following is a more efficient form of public key cryptography as it demands less computational power and offers more security per bit?
- A. Secret Key Cryptography
- B. Digital Signature Standard
- C. Diffie-Hellman Key Agreement
- D. Elliptic Curve Cryptography
Answer: D
Explanation:
Explanation
Elliptic curve cryptography (ECC) is a more efficient form of public key cryptography as it demands less computational power and offers more security per bit. ECC is based on the mathematical properties of elliptic curves, which are curves that have a special shape that makes them suitable for cryptography. ECC can achieve the same level of security as other public key algorithms with much smaller key sizes, which reduces storage and bandwidth requirements.
NEW QUESTION # 36
......
Passing Key To Getting Cybersecurity-Audit-Certificate Certified Exam Engine PDF: https://www.testvalid.com/Cybersecurity-Audit-Certificate-exam-collection.html
Get Top-Rated ISACA Cybersecurity-Audit-Certificate Exam Dumps Now: https://drive.google.com/open?id=197y356SPPRwQS3zzS4lGI4mENQuj1Ptl