Protection of Information Assets Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Protection of Information Assets flashcards as text
An IS auditor reviews an organization's patch management policy and finds that critical security patches are applied within 72 hours on internet-facing servers but within 30 days on internal servers. What is the AUDITOR'S BEST assessment?
Answer: The 30-day window for internal servers may be excessive and should be risk-assessed
A blanket 30-day patch cycle for internal servers may be too long, especially for critical vulnerabilities, and the risk should be evaluated against the organization's threat profile.
Which of the following BEST describes the concept of 'defense in depth' as applied to information security?
Answer: Applying multiple overlapping security controls so that failure of one does not compromise the system
Defense in depth layers multiple security controls so that if one control fails or is bypassed, additional controls still protect the asset.
An organization is implementing a new cloud storage solution for sensitive data. Which of the following should the IS auditor verify FIRST?
Answer: Whether the organization retains control of encryption keys used to protect the data
Retaining control of encryption keys ensures that the organization can protect its data even if the cloud provider is compromised, subpoenaed, or goes out of business.
An IS auditor evaluates an organization's identity governance program and finds that user access reviews are performed annually. What is the PRIMARY weakness of this approach?
Answer: Excessive or unauthorized access can persist for up to 12 months before detection
Annual access reviews allow inappropriate access to go undetected for up to a year, significantly increasing the risk window for insider threats and privilege abuse.
Which of the following is the MOST effective control to prevent SQL injection attacks against a web application?
Answer: Using parameterized queries and prepared statements in application code
Parameterized queries separate SQL code from user-supplied input at the code level, eliminating the root cause of SQL injection vulnerabilities.
During a security audit, an IS auditor finds that developers have direct write access to the production database. What is the PRIMARY concern?
Answer: Direct production access bypasses change management controls and increases insider threat risk
Direct developer access to production bypasses change management and audit trails, enabling unauthorized data modification and violating separation of duties.
A company implements a data classification policy with four levels: Public, Internal, Confidential, and Restricted. Which control is MOST critical for Restricted data?
Answer: Restricting access on a need-to-know basis with strong authentication and audit logging
Need-to-know access combined with strong authentication and full audit logging provides the most comprehensive protection for the highest-sensitivity data classification.