โ† All ISACA Flashcard Decks

Protection of Information Assets Flashcards

7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Protection of Information Assets flashcards as text
  1. Which of the following BEST describes the concept of defense-in-depth?

    Answer: Applying multiple overlapping security controls so that the failure of one does not expose the system

    Defense-in-depth uses multiple layers of security controls so that if one layer fails, others still provide protection.

  2. An organization implements multifactor authentication (MFA). Which combination represents true multifactor authentication?

    Answer: A PIN and a smart card

    A PIN (something you know) combined with a smart card (something you have) satisfies two distinct authentication factors.

  3. Which of the following BEST describes the role of a Certificate Revocation List (CRL)?

    Answer: A list of digital certificates that have been invalidated before their expiration date

    A CRL is published by a CA to list certificates that have been revoked and should no longer be trusted.

  4. Data loss prevention (DLP) tools are PRIMARILY designed to:

    Answer: Detect and prevent unauthorized transmission of sensitive data

    DLP tools inspect data in motion, at rest, and in use to prevent sensitive information from leaving the organization without authorization.

  5. Which type of malware disguises itself as legitimate software to trick users into installing it?

    Answer: Trojan horse

    A Trojan horse masquerades as benign or useful software while carrying a malicious payload, tricking users into executing it.

  6. When assessing third-party vendor security, which document MOST comprehensively defines required security obligations?

    Answer: Data Processing Agreement (DPA) with security annexes

    A Data Processing Agreement with security annexes specifies technical and organizational security requirements for vendors handling personal or sensitive data.

  7. Which of the following BEST describes the purpose of security awareness training?

    Answer: To reduce human error and improve recognition of social engineering attacks

    Security awareness training aims to reduce risk by educating users to recognize threats like phishing and practice safe security behaviors.