Protection of Information Assets Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Protection of Information Assets flashcards as text
An IS auditor is reviewing controls over a company's security awareness training program. Which finding would be of GREATEST concern?
Answer: Training content has not been updated to reflect new phishing techniques in the past 18 months
Outdated training that does not address current attack methods fails to prepare employees for actual threats, undermining the program's effectiveness regardless of completion rates.
When reviewing an organization's incident response plan, an IS auditor should verify that the plan includes which of the following as a CRITICAL element?
Answer: Defined roles, responsibilities, and escalation procedures
Clearly defined roles, responsibilities, and escalation procedures ensure coordinated and timely response when an incident occurs, which is the most critical operational element.
An organization uses tokenization to protect customer payment data. What is the PRIMARY advantage of tokenization over encryption for this use case?
Answer: Tokens are meaningless outside the tokenization system, reducing the value of a data breach
Tokens are random substitutes with no mathematical relationship to the original data, so stolen tokens have no value to an attacker without access to the token vault.
Which of the following activities BEST demonstrates that an organization's security controls are operating effectively, rather than merely existing?
Answer: Conducting regular control testing and reviewing exception reports
Regular testing validates that controls function as intended in practice, while exception reports reveal gaps between expected and actual control performance.
An IS auditor discovers that an organization has not implemented log monitoring for its cloud infrastructure because management believes the cloud provider handles security. What risk does this represent?
Answer: The organization loses visibility into security events within its own cloud environment
Under the shared responsibility model, organizations are responsible for monitoring activity within their cloud environments even if the cloud provider secures the underlying infrastructure.
During a review of an organization's network security, an IS auditor finds that firewall rules have not been reviewed for three years and contain numerous rules allowing 'any' traffic. What is the PRIMARY risk?
Answer: Overly permissive rules may allow unauthorized traffic that should be blocked
Overly permissive firewall rules—especially those allowing 'any' traffic—undermine network segmentation and may permit attackers or malware to move freely across the network.
An IS auditor is assessing controls over privileged access management (PAM). Which of the following represents the BEST practice for managing privileged accounts?
Answer: Issuing just-in-time privileged access that is time-limited and fully logged
Just-in-time (JIT) privileged access minimizes the attack surface by granting elevated rights only when needed and for a limited time, with full audit logging.