Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Legit CISA Exam Download

Page: 31 / 106
Total 1407 questions

Certified Information Systems Auditor Questions and Answers

Question 121

Which of the following should be done FIRST when creating a data protection program?

Options:

A.

Implement data loss prevention (DLP) controls.

B.

Perform classification based on standards.

C.

Deploy intrusion detection systems (IDS).

D.

Test logical access controls for effectiveness.

Question 122

A security review focused on data loss prevention (DLP) revealed the organization has no visibility to data stored in the cloud. What is the IS auditor's BEST recommendation to address this

issue?

Options:

A.

Enhance the firewall at the network perimeter.

B.

Implement a file system scanner to discover data stored in the cloud.

C.

Employ a cloud access security broker (CASB).

D.

Utilize a DLP tool on desktops to monitor user activities.

Question 123

Which of the following is the BEST indication that an information security awareness program is effective?

Options:

A.

A reduction in the number of reported information security incidents

B.

A reduction in the success rate of social engineering attacks

C.

A reduction in the cost of maintaining the information security program

D.

A reduction in the number of information security attacks

Question 124

Which of the following is the MOST likely root cause of shadow IT in an organization?

Options:

A.

Lengthy approval for technology investment

B.

The opportunity to reduce software license fees

C.

Ease of use for cloud-based applications and services

D.

Approved software not meeting user requirements

Page: 31 / 106
Total 1407 questions