CISA Protection of Information Assets 5 — Questions and Answers
Question 1: An IS auditor is reviewing controls over a company's security awareness training program. Which finding would be of GREATEST concern?
- Training is delivered via an online learning management system
- Only 60% of employees completed the annual security awareness training
- Training content has not been updated to reflect new phishing techniques in the past 18 months (Correct answer)
- Training completion is tracked but not linked to HR performance reviews
Correct answer: Training content has not been updated to reflect new phishing techniques in the past 18 months
Outdated training that does not address current attack methods fails to prepare employees for actual threats, undermining the program's effectiveness regardless of completion rates.
Question 2: When reviewing an organization's incident response plan, an IS auditor should verify that the plan includes which of the following as a CRITICAL element?
- A list of all potential threats ranked by likelihood
- Defined roles, responsibilities, and escalation procedures (Correct answer)
- A requirement to report all incidents to law enforcement
- Technical specifications for all security tools used in response
Correct answer: Defined roles, responsibilities, and escalation procedures
Clearly defined roles, responsibilities, and escalation procedures ensure coordinated and timely response when an incident occurs, which is the most critical operational element.
Question 3: An organization uses tokenization to protect customer payment data. What is the PRIMARY advantage of tokenization over encryption for this use case?
- Tokenized data can be decrypted faster than encrypted data
- Tokens are meaningless outside the tokenization system, reducing the value of a data breach (Correct answer)
- Tokenization does not require any key management
- Tokenization is mandated by PCI DSS for all payment data
Correct answer: Tokens are meaningless outside the tokenization system, reducing the value of a data breach
Tokens are random substitutes with no mathematical relationship to the original data, so stolen tokens have no value to an attacker without access to the token vault.
Question 4: Which of the following activities BEST demonstrates that an organization's security controls are operating effectively, rather than merely existing?
- Maintaining a current inventory of all security policies and procedures
- Conducting regular control testing and reviewing exception reports (Correct answer)
- Having all security policies approved by senior management
- Documenting all security controls in the risk register
Correct answer: Conducting regular control testing and reviewing exception reports
Regular testing validates that controls function as intended in practice, while exception reports reveal gaps between expected and actual control performance.
Question 5: An IS auditor discovers that an organization has not implemented log monitoring for its cloud infrastructure because management believes the cloud provider handles security. What risk does this represent?
- The organization may violate the cloud provider's terms of service
- The organization loses visibility into security events within its own cloud environment (Correct answer)
- Cloud providers are legally responsible for all security incidents
- The cloud provider may charge extra for security monitoring services
Correct answer: The organization loses visibility into security events within its own cloud environment
Under the shared responsibility model, organizations are responsible for monitoring activity within their cloud environments even if the cloud provider secures the underlying infrastructure.
Question 6: During a review of an organization's network security, an IS auditor finds that firewall rules have not been reviewed for three years and contain numerous rules allowing 'any' traffic. What is the PRIMARY risk?
- Firewall performance may degrade due to excessive rule sets
- Overly permissive rules may allow unauthorized traffic that should be blocked (Correct answer)
- The firewall vendor may not support firmware updates for older rule configurations
- Network administrators may have difficulty managing a large rule set
Correct answer: Overly permissive rules may allow unauthorized traffic that should be blocked
Overly permissive firewall rules—especially those allowing 'any' traffic—undermine network segmentation and may permit attackers or malware to move freely across the network.
Question 7: An IS auditor is assessing controls over privileged access management (PAM). Which of the following represents the BEST practice for managing privileged accounts?
- Assigning privileged accounts to senior IT staff permanently to ensure availability
- Using shared privileged accounts so multiple administrators can respond during incidents
- Issuing just-in-time privileged access that is time-limited and fully logged (Correct answer)
- Requiring privileged users to use the same credentials for both regular and admin tasks
Correct answer: Issuing just-in-time privileged access that is time-limited and fully logged
Just-in-time (JIT) privileged access minimizes the attack surface by granting elevated rights only when needed and for a limited time, with full audit logging.
An IS auditor is reviewing controls over a company's security awareness training program.
Which finding would be of GREATEST concern?