CISA Domain 2: Governance & Management of IT
Exam Comprehensive Questions And Answers
Complete!
Save
Terms in this set (85)
The duration a function C
can continue to operate
without a given resource is
the
a. mean time between
failures
b. minimum acceptable
down time
c. maximum tolerable
downtime
d. annual loss expectancy
,An organization a. a firewall is risk mitigation
determines that they are
running a vulnerable web
server. Instead of patching
the server they decide to
put the service behind an
application firewall.
a. risk mitigation
b. risk acceptance
c. risk transference
d. risk avoidance
Why is it a good idea to B. the BCP should be sanitized so that no other
sanitize a BCP before hackers can use it
release it to an external
entity?
a. because the BCP may
not be accurate
b. because it contains
information about
vulnerabilities that could
be used by another
attacker
c. because the BCP is
usually too large to be
exported easily
d. because the BCP
cannot be used unless it is
accompanied by the
disaster recovery plan
,A service level agreement d. a SLA defines the relationship between the
defines the relationship organization and vendor
between what two parties
a. consultant and vendor
b. employee and
consultant
c. employer and
employee
d. organization and
vendor
Who has the final approval d. management has the final approval of the plans
of the disaster recovery
and business continuity
plan?
a. each representative of
each department
b. external authority
c. the planning committe
d. management
What is not a reason for a. speed of operation
segregation of duties
(SoD)
a. speed of operation
b. improves error
detection
c. assisting in avoiding
single points of failure
d. reduces fraud
, a systems administrator a. cold site
suggests to their manager
that they use a
subscription hot site in
case of a disaster. Their
manager informed them
that they cannot afford the
expense of a subscription
hot site. what should they
choose?
a. cold site
b. boiling site
c. off site
d. backup site
you audit an organization a. SOD
and discover that errors
are not being detected
before it's too late. How
can you improve the
situation
a. SOD
b. Risk avoidance
c. auditors reporting
directly to management
d. security team reporting
directly to management
Exam Comprehensive Questions And Answers
Complete!
Save
Terms in this set (85)
The duration a function C
can continue to operate
without a given resource is
the
a. mean time between
failures
b. minimum acceptable
down time
c. maximum tolerable
downtime
d. annual loss expectancy
,An organization a. a firewall is risk mitigation
determines that they are
running a vulnerable web
server. Instead of patching
the server they decide to
put the service behind an
application firewall.
a. risk mitigation
b. risk acceptance
c. risk transference
d. risk avoidance
Why is it a good idea to B. the BCP should be sanitized so that no other
sanitize a BCP before hackers can use it
release it to an external
entity?
a. because the BCP may
not be accurate
b. because it contains
information about
vulnerabilities that could
be used by another
attacker
c. because the BCP is
usually too large to be
exported easily
d. because the BCP
cannot be used unless it is
accompanied by the
disaster recovery plan
,A service level agreement d. a SLA defines the relationship between the
defines the relationship organization and vendor
between what two parties
a. consultant and vendor
b. employee and
consultant
c. employer and
employee
d. organization and
vendor
Who has the final approval d. management has the final approval of the plans
of the disaster recovery
and business continuity
plan?
a. each representative of
each department
b. external authority
c. the planning committe
d. management
What is not a reason for a. speed of operation
segregation of duties
(SoD)
a. speed of operation
b. improves error
detection
c. assisting in avoiding
single points of failure
d. reduces fraud
, a systems administrator a. cold site
suggests to their manager
that they use a
subscription hot site in
case of a disaster. Their
manager informed them
that they cannot afford the
expense of a subscription
hot site. what should they
choose?
a. cold site
b. boiling site
c. off site
d. backup site
you audit an organization a. SOD
and discover that errors
are not being detected
before it's too late. How
can you improve the
situation
a. SOD
b. Risk avoidance
c. auditors reporting
directly to management
d. security team reporting
directly to management