โ† All CISA Flashcard Decks

Logical Access Controls Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Logical Access Controls flashcards as text
  1. An organization is implementing Zero Trust Architecture. Which core principle does this model rely on for logical access controls?

    Answer: Verify every access request regardless of network location

    Zero Trust operates on 'never trust, always verify,' requiring authentication and authorization for every access attempt regardless of source.

  2. Which type of access control list (ACL) entry represents the GREATEST security risk in a network environment?

    Answer: Permit any source to any destination on all ports

    An 'any-to-any on all ports' rule effectively removes network access controls, exposing all systems to unrestricted traffic.

  3. During an audit, an IS auditor finds that privileged accounts are used for routine daily tasks by IT staff. What is the PRIMARY recommendation?

    Answer: Implement separate standard accounts for routine tasks

    Privileged accounts should be used only when elevated rights are needed; daily tasks should use standard accounts to reduce exposure risk.

  4. What does 'access recertification' mean in the context of logical access control governance?

    Answer: Periodic formal review and reaffirmation of user access rights by managers

    Access recertification is a formal process where managers periodically confirm that their direct reports' access rights remain appropriate.

  5. An IS auditor is evaluating a cloud application where multiple clients share the same infrastructure. Which logical access control is MOST critical in this environment?

    Answer: Tenant isolation to prevent cross-client data access

    In multi-tenant environments, robust logical isolation ensures one tenant cannot access another tenant's data, even when sharing infrastructure.

  6. Which of the following represents a compensating control when segregation of duties cannot be fully implemented due to staffing constraints?

    Answer: Enhanced monitoring and supervisory review of all transactions

    When full segregation of duties is infeasible, enhanced monitoring and supervisory review provides detective controls to identify misuse.

  7. A CISA exam question asks about the difference between identification and authentication. Which statement BEST describes authentication?

    Answer: The process of verifying that a claimed identity is genuine

    Authentication verifies the legitimacy of an identity claim through credentials such as passwords, tokens, or biometrics.