โ† All ISACA Flashcard Decks

Protection of Information Assets Flashcards

7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Protection of Information Assets flashcards as text
  1. Which of the following BEST describes the purpose of a digital certificate?

    Answer: Binding a public key to an authenticated identity

    A digital certificate binds a public key to a verified identity, enabling trust in public key infrastructure (PKI).

  2. An IS auditor discovers that developers have direct access to the production environment. What is the PRIMARY risk?

    Answer: Unauthorized or untested changes may be introduced into production

    Developer access to production violates segregation of duties and could allow unauthorized, untested changes that impact integrity and availability.

  3. What is the PRIMARY purpose of a honeypot in an information security architecture?

    Answer: Detecting and studying attacker techniques by luring them to a decoy system

    A honeypot is a decoy system designed to attract and observe attackers, providing intelligence on their techniques and intent.

  4. During a penetration test, the tester has full knowledge of the system architecture and source code. This approach is called:

    Answer: White-box testing

    White-box (or crystal-box) testing gives the tester complete knowledge of the internal system, enabling thorough coverage of the codebase.

  5. Which of the following network segmentation techniques BEST isolates a web-facing server from internal corporate resources?

    Answer: Placing the server in a DMZ (demilitarized zone)

    A DMZ isolates public-facing servers from internal networks using firewalls, limiting the blast radius of a compromise.

  6. Which of the following is an example of a compensating control when segregation of duties cannot be fully implemented?

    Answer: Implementing enhanced logging and supervisory review of transactions

    Enhanced logging and supervisory review acts as a compensating control by increasing the likelihood that unauthorized activity will be detected.

  7. A vulnerability assessment differs from a penetration test in that a vulnerability assessment:

    Answer: Identifies and reports weaknesses without actively exploiting them

    A vulnerability assessment identifies and classifies security weaknesses, while a penetration test actively exploits them to demonstrate real-world impact.