Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

CISA Domain 5: Information Asset Protection | 340 questions and answers supported by logic

Beoordeling
-
Verkocht
-
Pagina's
193
Cijfer
A+
Geüpload op
06-09-2024
Geschreven in
2024/2025

CISA Domain 5: Information Asset Protection | 340 questions and answers supported by logic

Instelling
CISA Domain 5: Protection Of Information Assets
Vak
CISA Domain 5: Protection of Information Assets

Voorbeeld van de inhoud

Match term to definition
1-340 of 340

Select a definition to match it with its term




Which of the following choices BEST helps information owners to properly classify data?


a. Understanding of technical controls that protect data


b. Training on organizational policies and standards


c. Use of an automated data leak prevention tool


d. Understanding which people need to access the data

,Give this one a go later!


b. Training on organizational policies and standards


While implementing data classification, it is most essential that organizational
policies and standards, including the data classification schema, are understood
by the owner or custodian of the data so they can be properly classified.




During a review of intrusion detection logs, an IS auditor notices traffic coming from the
Internet, which appears to originate from the internal IP address of the company payroll
server. Which of the following malicious activities would MOST likely cause this type of
result?


a. A denial-of-service attack
b. Spoofing
c. Port scanning
d. A man-in-the-middle attack


Give this one a go later!


b. Spoofing


This is a form of impersonation where one computer tries to take on the identity of
another computer. When an attack originates from the external network but uses
an internal network address, the attacker is most likely trying to bypass firewalls
and other network security controls by impersonating (or spoofing) the payroll
server's internal network address. By impersonating the payroll server, the attacker
may be able to access sensitive internal resources.




An organization is planning to deploy an outsourced cloud-based application that is used to
track job applicant data for the human resources department. Which of the following should

,be the GREATEST concern to an IS auditor?


a. The service level agreement (SLA) ensures strict limits for uptime and performance.


b. The cloud provider will not agree to an unlimited right-to-audit as part of the SLA.


c. The SLA is not explicit regarding the disaster recovery plan capabilities of the cloud
provider.


d. The cloud provider's data centers are in multiple cities and countries.


Give this one a go later!


d. The cloud provider's data centers are in multiple cities and countries.


Having data in multiple countries is the greatest concern because human
resources (HR) applicant data could contain personally identifiable information.
There may be legal compliance issues if these data are stored in a country with
different laws regarding data privacy. While the organization would be bound by
the privacy laws where it is based, it may not have legal recourse if a data breach
happens in a jurisdiction where the same laws do not apply.




Which of the following types of firewalls provide the GREATEST degree and granularity of
control?


a. Screening router
b. Packet filter
c. Application gateway
d. Circuit gateway


Give this one a go later!

, c. application gateway

This is similar to a circuit gateway, but it has specific proxies for each service. To
handle web services, it has a Hypertext Transmission Protocol (HTTP) proxy that
acts as an intermediary between externals and internals but is specifically for
HTTP. This means that it not only checks the packet Internet Protocol (IP)
addresses (Open Systems Interconnection [OSI] Layer 3) and the ports it is
directed to (in this case port 80, or layer 4), it also checks every HTTP command
(OSI Layers 5 and 7). Therefore, it works in a more detailed (granularity) way than
the other choices.




IS management recently replaced its existing wired local area network with a wireless
infrastructure to accommodate the increased use of mobile devices within the organization.
This will increase the risk of which of the following attacks?


a. Port scanning


b. Back door


c. Man-in-the-middle


d. War driving


Give this one a go later!


d. war driving


wifi think war driving

This attack uses a wireless Ethernet card, set in promiscuous mode, and a powerful
antenna to penetrate wireless systems from outside.

Geschreven voor

Instelling
CISA Domain 5: Protection of Information Assets
Vak
CISA Domain 5: Protection of Information Assets

Documentinformatie

Geüpload op
6 september 2024
Aantal pagina's
193
Geschreven in
2024/2025
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$18.50
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF


Ook beschikbaar in voordeelbundel

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
codersimon West Virgina University
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
791
Lid sinds
3 jaar
Aantal volgers
478
Documenten
6336
Laatst verkocht
1 week geleden
**SOUNDEST LEANING MATERIALS FROM CODERSIMON **

Learning is not attained by chance; it must be sought for with ardor and diligence On this page, you find exams,tests,summaries, notes ,documents, package deals, and flashcards offered by codersimon

3.8

85 beoordelingen

5
42
4
11
3
16
2
4
1
12

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen