CISA Practice Questions and
Answers Updated 2026
InBaBpublicBkeyBinfrastructureB(PKI),BwhichBofBtheBfollowingBmayBbeBreliedBuponBtoBproveBth
atBanBonlineBtransactionBwasBauthorizedBbyBaBspecificBcustomer?
CorrectBA.BNonrepudiation
B
BB.BEncryption
B
BC.BAuthentication
B
BD.BIntegrity
B
.B-BAnswerYouBareBcorrect,BtheBanswerBisBA.B
A.BNonrepudiation,BachievedBthroughBtheBuseBofBdigitalBsignatures,BpreventsBtheBsendersBfro
mBlaterBdenyingBthatBtheyBgeneratedBandBsentBtheBmessage.
B.BEncryptionBmayBprotectBtheBdataBtransmittedBoverBtheBInternet,BbutBmayBnotBproveBthat
BtheBtransactionsBwereBmade.
C.BAuthenticationBisBnecessaryBtoBestablishBtheBidentificationBofBallBpartiesBtoBaBcommunicati
on.
D.BIntegrityBensuresBthatBtransactionsBareBaccurateBbutBdoesBnotBprovideBtheBidentificationBo
fBtheBcustomer
WhichBofBtheBfollowingBBESTBensuresBtheBintegrityBofBaBserver'sBoperatingBsystemB(OS)?
BA.BProtectingBtheBserverBinBaBsecureBlocation
B
,BB.BSettingBaBbootBpassword
B
CorrectBC.BHardeningBtheBserverBconfiguration
B
BD.BImplementingBactivityBloggingB-BAnswerYouBareBcorrect,BtheBanswerBisBC.B
A.BProtectingBtheBserverBinBaBsecureBlocationBisBaBgoodBpractice,BbutBdoesBnotBensureBthat
BaBuserBwillBnotBtryBtoBexploitBlogicalBvulnerabilitiesBandBcompromiseBtheBoperatingBsystemB
(OS).
B.BSettingBaBbootBpasswordBisBaBgoodBpractice,BbutBdoesBnotBensureBthatBaBuserBwillBnotBt
ryBtoBexploitBlogicalBvulnerabilitiesBandBcompromiseBtheBOS.
C.BHardeningBaBsystemBmeansBtoBconfigureBitBinBtheBmostBsecureBmannerB(installBlatestBsec
urityBpatches,BproperlyBdefineBaccessBauthorizationBforBusersBandBadministrators,BdisableBinse
cureBoptionsBandBuninstallBunusedBservices)BtoBpreventBnonprivilegedBusersBfromBgainingBthe
BrightBtoBexecuteBprivilegedBinstructionsBand,Bthus,BtakeBcontrolBofBtheBentireBmachine,Bjeop
ardizingBtheBintegrityBofBtheBOS.
D.BActivityBloggingBhasBtwoBweaknessesBinBthisBscenario—
itBisBaBdetectiveBcontrolB(notBaBpreventiveBone),BandBtheBattackerBwhoBalreadyBgainedBprivil
egedBaccessBcanBmodifyBlogsBorBdisableBthem.
TheBISBauditorBisBreviewingBanBorganization'sBhumanBresourcesB(HR)BdatabaseBimplementatio
n.BTheBISBauditorBdiscoversBthatBtheBdatabaseBserversBareBclusteredBforBhighBavailability,BallB
defaultBdatabaseBaccountsBhaveBbeenBremovedBandBdatabaseBauditBlogsBareBkeptBandBrevie
wedBonBaBweeklyBbasis.BWhatBotherBareaBshouldBtheBISBauditorBcheckBtoBensureBthatBtheB
databasesBareBappropriatelyBsecured?
BA.BDatabaseBdigitalBsignatures
B
IncorrectBB.BDatabaseBencryptionBnoncesBandBotherBvariables
B
BC.BDatabaseBmediaBaccessBcontrolB(MAC)BaddressBauthentication
B
,BD.BDatabaseBinitializationBparametersB-BAnswerYouBansweredBB.BTheBcorrectBanswerBisBD.B
A.BDigitalBsignaturesBareBusedBforBauthenticationBandBnonrepudiation,BandBareBnotBcommonly
BusedBinBdatabases.BAsBaBresult,BthisBisBnotBanBareaBinBwhichBtheBISBauditorBshouldBinvesti
gate.
B.BABnonceBisBdefinedBasBaB"parameterBthatBchangesBoverBtime"BandBisBsimilarBtoBaBnumbe
rBgeneratedBtoBauthenticateBoneBspecificBuserBsession.BNoncesBareBnotBrelatedBtoBdatabaseB
securityB(theyBareBcommonlyBusedBinBencryptionBschemes).
C.BABmediaBaccessBcontrolB(MAC)BaddressBisBtheBhardwareBaddressBofBaBnetworkBinterface.B
MACBaddressBauthenticationBisBsometimesBusedBwithBwirelessBlocalBareaBnetworkB(WLAN)Bte
chnology,BbutBisBnotBrelatedBtoBdatabaseBsecurity.
D.BWhenBaBdatabaseBisBopened,BmanyBofBitsBconfigurationBoptionsBareBgovernedBbyBinitializa
tionBparameters.BTheseBparametersBareBusuallyBgovernedBbyBaBfileB("init.ora"BinBtheBcaseBof
BOracleBDBMS),BwhichBcontainsBmanyBsettings.BTheBsystemBinitializationBparametersBaddressB
manyB"global"BdatabaseBsettings,BincludingBauthentication,BremoteBaccessBandBotherBcriticalBs
ecurityBareas.BToBeffectivelyBauditBaBdatabaseBimplementation,BtheBISBauditorBmustBexamineB
theBdatabaseBinitializationBparameters.
WhichBofBtheBfollowingBprocessesBwillBbeBMOSTBeffectiveBinBreducingBtheBriskBthatBunauthor
izedBsoftwareBonBaBbackupBserverBisBdistributedBtoBtheBproductionBserver?
BA.BManuallyBcopyBfilesBtoBaccomplishBreplication.
B
BB.BReviewBchangesBinBtheBsoftwareBversionBcontrolBsystem.
B
IncorrectBC.BEnsureBthatBdevelopersBdoBnotBhaveBaccessBtoBtheBbackupBserver.
B
BD.BReviewBtheBaccessBcontrolBlogBofBtheBbackupBserver.B-
BAnswerYouBansweredBC.BTheBcorrectBanswerBisBB.B
, A.BEvenBifBreplicationBisBbeBconductedBmanuallyBwithBdueBcare,BthereBstillBremainsBaBriskBto
BcopyingBunauthorizedBsoftwareBfromBoneBserverBtoBanother.
B.BItBisBcommonBpracticeBforBsoftwareBchangesBtoBbeBtrackedBandBcontrolledBusingBversionBc
ontrolBsoftware.BAnBISBauditorBshouldBreviewBreportsBorBlogsBfromBthisBsystemBtoBidentifyBt
heBsoftwareBthatBisBpromotedBtoBproduction.BOnlyBmovingBtheBversionsBonBtheBversionBcont
rolBsystemB(VCS)BprogramBwillBpreventBtheBtransferBofBdevelopmentBorBearlierBversions.
C.BIfBunauthorizedBcodeBwasBintroducedBontoBtheBbackupBserverBbyBdevelopers,BcontrolsBon
BtheBproductionBserverBandBtheBsoftwareBversionBcontrolBsystemBshouldBmitigateBthisBrisk.
D.BReviewBofBtheBaccessBlogBwillBidentifyBstaffBaccessBorBtheBoperationsBperformed;Bhowever
,BitBmayBnotBprovideBenoughBinformationBtoBdetectBtheBreleaseBofBunauthorizedBsoftware.
ABconsultingBfirmBhasBcreatedBaBFileBTransferBProtocolB(FTP)BsiteBforBtheBpurposeBofBreceivin
gBfinancialBdataBandBhasBcommunicatedBtheBsite'sBaddress,BuserBIDBandBpasswordBtoBtheBfin
ancialBservicesBcompanyBinBseparateBemailBmessages.BTheBcompanyBisBtoBtransmitBitsBdataBt
oBtheBFTPBsiteBafterBmanuallyBencryptingBtheBdata.BTheBISBauditor'sBGREATESTBconcernBwith
BthisBprocessBisBthat:
CorrectBA.BtheBusersBmayBnotBrememberBtoBmanuallyBencryptBtheBdataBbeforeBtransmission.
B
BB.BtheBsiteBcredentialsBwereBsentBtoBtheBfinancialBservicesBcompanyBviaBemail.
B
BC.BpersonnelBatBtheBconsultingBfirmBmayBobtainBaccessBtoBsensitiveBdata.
B
BD.BtheBuseBofBaBsharedBuserBIDBtoBtheBFTPBsiteBdoesBnotBallowBforBuserBaccountability.B-
BAnswerYouBareBcorrect,BtheBanswerBisBA.B
A.BIfBtheBdataBisBnotBencrypted,BanBunauthorizedBexternalBpartyBmayBdownloadBsensitiveBco
mpanyBdata.
B.BEvenBthoughBtheBpossibilityBexistsBthatBtheBlogonBinformationBwasBcapturedBfromBtheBem
ails,BdataBshouldBbeBencrypted,BsoBtheBtheftBofBtheBdataBwouldBnotBallowBtheBattackerBtoBr
eadBit.
Answers Updated 2026
InBaBpublicBkeyBinfrastructureB(PKI),BwhichBofBtheBfollowingBmayBbeBreliedBuponBtoBproveBth
atBanBonlineBtransactionBwasBauthorizedBbyBaBspecificBcustomer?
CorrectBA.BNonrepudiation
B
BB.BEncryption
B
BC.BAuthentication
B
BD.BIntegrity
B
.B-BAnswerYouBareBcorrect,BtheBanswerBisBA.B
A.BNonrepudiation,BachievedBthroughBtheBuseBofBdigitalBsignatures,BpreventsBtheBsendersBfro
mBlaterBdenyingBthatBtheyBgeneratedBandBsentBtheBmessage.
B.BEncryptionBmayBprotectBtheBdataBtransmittedBoverBtheBInternet,BbutBmayBnotBproveBthat
BtheBtransactionsBwereBmade.
C.BAuthenticationBisBnecessaryBtoBestablishBtheBidentificationBofBallBpartiesBtoBaBcommunicati
on.
D.BIntegrityBensuresBthatBtransactionsBareBaccurateBbutBdoesBnotBprovideBtheBidentificationBo
fBtheBcustomer
WhichBofBtheBfollowingBBESTBensuresBtheBintegrityBofBaBserver'sBoperatingBsystemB(OS)?
BA.BProtectingBtheBserverBinBaBsecureBlocation
B
,BB.BSettingBaBbootBpassword
B
CorrectBC.BHardeningBtheBserverBconfiguration
B
BD.BImplementingBactivityBloggingB-BAnswerYouBareBcorrect,BtheBanswerBisBC.B
A.BProtectingBtheBserverBinBaBsecureBlocationBisBaBgoodBpractice,BbutBdoesBnotBensureBthat
BaBuserBwillBnotBtryBtoBexploitBlogicalBvulnerabilitiesBandBcompromiseBtheBoperatingBsystemB
(OS).
B.BSettingBaBbootBpasswordBisBaBgoodBpractice,BbutBdoesBnotBensureBthatBaBuserBwillBnotBt
ryBtoBexploitBlogicalBvulnerabilitiesBandBcompromiseBtheBOS.
C.BHardeningBaBsystemBmeansBtoBconfigureBitBinBtheBmostBsecureBmannerB(installBlatestBsec
urityBpatches,BproperlyBdefineBaccessBauthorizationBforBusersBandBadministrators,BdisableBinse
cureBoptionsBandBuninstallBunusedBservices)BtoBpreventBnonprivilegedBusersBfromBgainingBthe
BrightBtoBexecuteBprivilegedBinstructionsBand,Bthus,BtakeBcontrolBofBtheBentireBmachine,Bjeop
ardizingBtheBintegrityBofBtheBOS.
D.BActivityBloggingBhasBtwoBweaknessesBinBthisBscenario—
itBisBaBdetectiveBcontrolB(notBaBpreventiveBone),BandBtheBattackerBwhoBalreadyBgainedBprivil
egedBaccessBcanBmodifyBlogsBorBdisableBthem.
TheBISBauditorBisBreviewingBanBorganization'sBhumanBresourcesB(HR)BdatabaseBimplementatio
n.BTheBISBauditorBdiscoversBthatBtheBdatabaseBserversBareBclusteredBforBhighBavailability,BallB
defaultBdatabaseBaccountsBhaveBbeenBremovedBandBdatabaseBauditBlogsBareBkeptBandBrevie
wedBonBaBweeklyBbasis.BWhatBotherBareaBshouldBtheBISBauditorBcheckBtoBensureBthatBtheB
databasesBareBappropriatelyBsecured?
BA.BDatabaseBdigitalBsignatures
B
IncorrectBB.BDatabaseBencryptionBnoncesBandBotherBvariables
B
BC.BDatabaseBmediaBaccessBcontrolB(MAC)BaddressBauthentication
B
,BD.BDatabaseBinitializationBparametersB-BAnswerYouBansweredBB.BTheBcorrectBanswerBisBD.B
A.BDigitalBsignaturesBareBusedBforBauthenticationBandBnonrepudiation,BandBareBnotBcommonly
BusedBinBdatabases.BAsBaBresult,BthisBisBnotBanBareaBinBwhichBtheBISBauditorBshouldBinvesti
gate.
B.BABnonceBisBdefinedBasBaB"parameterBthatBchangesBoverBtime"BandBisBsimilarBtoBaBnumbe
rBgeneratedBtoBauthenticateBoneBspecificBuserBsession.BNoncesBareBnotBrelatedBtoBdatabaseB
securityB(theyBareBcommonlyBusedBinBencryptionBschemes).
C.BABmediaBaccessBcontrolB(MAC)BaddressBisBtheBhardwareBaddressBofBaBnetworkBinterface.B
MACBaddressBauthenticationBisBsometimesBusedBwithBwirelessBlocalBareaBnetworkB(WLAN)Bte
chnology,BbutBisBnotBrelatedBtoBdatabaseBsecurity.
D.BWhenBaBdatabaseBisBopened,BmanyBofBitsBconfigurationBoptionsBareBgovernedBbyBinitializa
tionBparameters.BTheseBparametersBareBusuallyBgovernedBbyBaBfileB("init.ora"BinBtheBcaseBof
BOracleBDBMS),BwhichBcontainsBmanyBsettings.BTheBsystemBinitializationBparametersBaddressB
manyB"global"BdatabaseBsettings,BincludingBauthentication,BremoteBaccessBandBotherBcriticalBs
ecurityBareas.BToBeffectivelyBauditBaBdatabaseBimplementation,BtheBISBauditorBmustBexamineB
theBdatabaseBinitializationBparameters.
WhichBofBtheBfollowingBprocessesBwillBbeBMOSTBeffectiveBinBreducingBtheBriskBthatBunauthor
izedBsoftwareBonBaBbackupBserverBisBdistributedBtoBtheBproductionBserver?
BA.BManuallyBcopyBfilesBtoBaccomplishBreplication.
B
BB.BReviewBchangesBinBtheBsoftwareBversionBcontrolBsystem.
B
IncorrectBC.BEnsureBthatBdevelopersBdoBnotBhaveBaccessBtoBtheBbackupBserver.
B
BD.BReviewBtheBaccessBcontrolBlogBofBtheBbackupBserver.B-
BAnswerYouBansweredBC.BTheBcorrectBanswerBisBB.B
, A.BEvenBifBreplicationBisBbeBconductedBmanuallyBwithBdueBcare,BthereBstillBremainsBaBriskBto
BcopyingBunauthorizedBsoftwareBfromBoneBserverBtoBanother.
B.BItBisBcommonBpracticeBforBsoftwareBchangesBtoBbeBtrackedBandBcontrolledBusingBversionBc
ontrolBsoftware.BAnBISBauditorBshouldBreviewBreportsBorBlogsBfromBthisBsystemBtoBidentifyBt
heBsoftwareBthatBisBpromotedBtoBproduction.BOnlyBmovingBtheBversionsBonBtheBversionBcont
rolBsystemB(VCS)BprogramBwillBpreventBtheBtransferBofBdevelopmentBorBearlierBversions.
C.BIfBunauthorizedBcodeBwasBintroducedBontoBtheBbackupBserverBbyBdevelopers,BcontrolsBon
BtheBproductionBserverBandBtheBsoftwareBversionBcontrolBsystemBshouldBmitigateBthisBrisk.
D.BReviewBofBtheBaccessBlogBwillBidentifyBstaffBaccessBorBtheBoperationsBperformed;Bhowever
,BitBmayBnotBprovideBenoughBinformationBtoBdetectBtheBreleaseBofBunauthorizedBsoftware.
ABconsultingBfirmBhasBcreatedBaBFileBTransferBProtocolB(FTP)BsiteBforBtheBpurposeBofBreceivin
gBfinancialBdataBandBhasBcommunicatedBtheBsite'sBaddress,BuserBIDBandBpasswordBtoBtheBfin
ancialBservicesBcompanyBinBseparateBemailBmessages.BTheBcompanyBisBtoBtransmitBitsBdataBt
oBtheBFTPBsiteBafterBmanuallyBencryptingBtheBdata.BTheBISBauditor'sBGREATESTBconcernBwith
BthisBprocessBisBthat:
CorrectBA.BtheBusersBmayBnotBrememberBtoBmanuallyBencryptBtheBdataBbeforeBtransmission.
B
BB.BtheBsiteBcredentialsBwereBsentBtoBtheBfinancialBservicesBcompanyBviaBemail.
B
BC.BpersonnelBatBtheBconsultingBfirmBmayBobtainBaccessBtoBsensitiveBdata.
B
BD.BtheBuseBofBaBsharedBuserBIDBtoBtheBFTPBsiteBdoesBnotBallowBforBuserBaccountability.B-
BAnswerYouBareBcorrect,BtheBanswerBisBA.B
A.BIfBtheBdataBisBnotBencrypted,BanBunauthorizedBexternalBpartyBmayBdownloadBsensitiveBco
mpanyBdata.
B.BEvenBthoughBtheBpossibilityBexistsBthatBtheBlogonBinformationBwasBcapturedBfromBtheBem
ails,BdataBshouldBbeBencrypted,BsoBtheBtheftBofBtheBdataBwouldBnotBallowBtheBattackerBtoBr
eadBit.