!!!|A+ GRADED|EXAM READY|95% SUCCESS
Q3) During the review of an in-house developed application, the GREATEST concern to an IS
auditor is if a:
A) manager approves a change request and then reviews it in production.
B) programmer codes a change in the development environment and tests it in the test
environment.
C) manager initiates a change request and subsequently approves it.
D) user raises a change request and tests it in the test environment. - ANSWER C)
Manager initiates a change request and subsequently approves it is correct. Initiating and
subsequently approving a change request violates the principle of segregation of duties.
D) A person should not be able to approve their own requests. User raises a change request
and tests it in the test environment is incorrect. Having a user involved in testing changes is
common practice.
B) Programmer codes a change in the development environment and tests it in the test
environment is incorrect. Having a programmer code a change in development and then
separately test the change in a test environment is a good practice and preferable over
testing in production.
A) Manager approves a change request and then reviews it in production is incorrect.
C) Having a manager review a change to make sure it was done correctly is an acceptable
practice.
1
,Q1) When installing an intrusion detection system, which of the following is MOST
important?
A) Identifying messages that need to be quarantined
B) Properly locating it in the network architecture
C) Preventing denial-of-service attacks
D) Minimizing the rejection errors - ANSWER B) Properly locating it in the network
architecture is correct. Proper location of an intrusion detection system (IDS) in the network
is the most important decision during installation. A poorly located IDS could leave key areas
of the network unprotected.
C) Preventing denial-of-service attacks is incorrect. A network IDS will monitor network
traffic and a host-based IDS will monitor activity on the host, but it has no capability of
preventing a denial-of-service (DoS) attack.
A) Identifying messages that need to be quarantined is incorrect. Configuring an IDS can be a
challenge because it may require the IDS to "learn" what normal activity is, but the most
important part of the installation is to install it in the right places.
D) Minimizing the rejection errors is incorrect. An IDS is only a monitoring device and does
not reject traffic. Rejection errors would apply to a biometric device.
Q2) An organization is proposing to establish a wireless local area network (WLAN).
Management asks the IS auditor to recommend security controls for the WLAN. Which of
the following would be the MOST appropriate recommendation?
A) Implement the Simple Network Management Protocol to allow active monitoring.
2
,B) Use service set identifiers that clearly identify the organization.
C) Encrypt traffic using the Wired Equivalent Privacy mechanism.
D) Physically secure wireless access points to prevent tampering. - ANSWER D)
Physically secure wireless access points to prevent tampering is correct. Physically securing
access points such as wireless routers, as well as preventing theft, addresses the risk of
malicious parties tampering with device settings. If access points can be physically reached,
it is often a simple matter to restore weak default passwords and encryption keys, or to
totally remove authentication and encryption from the network.
B) Use service set identifiers that clearly identify the organization is incorrect. Service set
identifiers should not be used to identify the organization because hackers can associate the
wireless local area network with a known organization, and this increases both their
motivation to attack and, potentially, the information available to do so.
C) Encrypt traffic using the Wired Equivalent Privacy mechanism is incorrect. The original
Wired Equivalent Privacy security mechanism has been demonstrated to have a number of
exploitable weaknesses. The more recently developed Wi-Fi Protected Access and Wi-Fi
Protected Access 2 standards represent considerably more secure means of authentication
and encryption.
A) Implement the Simple Network Management Protocol to allow active monitoring is
incorrect. Installing Simple Network Management Protocol on wireless access points can
actually open up security vulnerabilities. If SNMP is required at all, then SNMP v3, which has
stronger authentication mechanisms than earlier versions, should be deployed.
Q4) To protect a Voice-over Internet Protocol infrastructure against a denial-of-service
attack, it is MOST important to secure the:
A) intrusion detection system.
3
, B) session border controllers.
C) backbone gateways.
D) access control servers - ANSWER B) Session border controllers is correct. These
enhance the security in the access network and in the core. In the access network, they hide
a user's real address and provide a managed public address. This public address can be
monitored, minimizing the opportunities for scanning and denial-of-service (DoS) attacks.
Session border controllers permit access to clients behind firewalls while maintaining the
firewall's effectiveness. In the core, session border controllers protect the users and the
network. They hide network topology and users' real addresses. They can also monitor
bandwidth and quality of service.
D) Access control servers is incorrect. Securing the access control server may prevent
account alteration or lockout but is not the primary protection against DoS attacks.
C) Backbone gateways is incorrect. These are isolated and not readily accessible to hackers,
so this is not a location of DoS attacks.
A) Intrusion detection system is incorrect. This monitors traffic, but does not protect against
DoS attacks.
Q5) An IS auditor is reviewing the change management process for an enterprise resource
planning application. Which of the following is the BEST method for testing program
changes?
A) Select a sample of change tickets and review them for authorization.
B) Use query software to analyze all change tickets for missing fields.
C) Trace a sample of modified programs to supporting change tickets.
4