CERTIFIED INFORMATION SYSTEMS AUDITOR (CISA) EXAM |
NEWEST 2026/2027 ACTUAL EXAM | COMPLETE QUESTIONS AND
CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY
GRADED A+||BRAND NEW VERSION!!
Which of the following would be the BEST overall control for an Internet business looking for
confidentiality, reliability and integrity of data?
A.Transport Layer Security (TLS)
B.Intrusion detection system (IDS)
C.Public key infrastructure
D.Virtual private network (VPN) -
CORRECT|ANSWER
A. Transport Layer Security (TLS) is used for many ecommerce applications to set up a secure
channel for communications that provides confidentiality through a combination of public and
symmetric key encryption and integrity through hash message authentication code.
What is the MOST prevalent security risk when an organization implements remote virtual private
network (VPN) access to its network?
A.Malicious code can be spread across the network.
B.The VPN logon can be spoofed.
C.Traffic can be sniffed and decrypted.
D.The VPN gateway can be compromised. -
CORRECT|ANSWER
A. Virtual private network (VPN) is a mature technology; VPN devices are hard to break. However,
when remote access is enabled, malicious code in a remote client can spread to the enterprise's
network. One problem is when the VPN terminates inside the network and the encrypted VPN traffic
goes through the firewall. This means that the firewall cannot adequately examine the traffic.
An IT auditor completed the fieldwork phase of a network security review and is preparing the initial
draft of the audit report. Which of the following findings would be the BIGGEST risk to the
enterprise?
A.Network penetration tests are performed by an internal team.
B.Network firewall rules are not approved by the chief information security officer (CISO) before
implementation.
C.Network penetration tests are not performed.
,D.The inventory of network devices was last updated two years ago. -
CORRECT|ANSWER
D. Keeping an up-to-date asset inventory is the most important requirement to keep an enterprise's
information assets secure. Without a complete inventory list and asset criticality determination, the
risk assessment cannot be completed and controls will be inadequate.
The reason a certification and accreditation process is performed on critical systems is to ensure that:
A.security compliance has been technically evaluated.
B.data have been encrypted and are ready to be stored.
C.the systems have been tested to run on different platforms.
D.the systems have followed the phases of a waterfall model. -
CORRECT|ANSWER
A. Certified and accredited systems are systems that have had their security compliance technically
evaluated for running in a specific environment and configuration.
An information systems (IS) auditor is reviewing a manufacturing enterprise and finds that
mainframe users at a remote site connect to the mainframe at headquarters over the Internet via
Telnet. Which of the following offers the STRONGEST security?
A.Use of a point-to-point leased line
B.Use of a firewall rule to allow only the internet protocol (IP) address of the remote site
C.Use of two-factor authentication
D.Use of a nonstandard port for Telnet -
CORRECT|ANSWER
A. A leased line effectively extends the local area network of the headquarters to the remote site,
and the mainframe Telnet connection travels over the private line, which is less of a security risk
when using an insecure protocol such as Telnet.
The BEST filter rule for protecting a network from being used as an amplifier in a denial-of-service
attack is to deny all:
A.outgoing traffic with source addresses external to the network.
B.incoming traffic with discernible spoofed internet protocol (IP) source addresses.
C.incoming traffic that includes options set in the Internet Protocol.
D.incoming traffic whose destination address belongs to critical hosts. -
CORRECT|ANSWER
, A. Outgoing traffic with an internet protocol (IP) source address different than the internal IP range
in the network is invalid. In most cases, it signals a denial-of-service attack originated by an internal
user or by a previously compromised internal machine; in both cases, applying this filter will stop the
infected machine from participating in the attack.
Validated digital signatures in an email software application will:
A.help detect unauthorized email.
B.provide confidentiality.
C.add to the workload of gateway servers.
D.significantly reduce available bandwidth. -
CORRECT|ANSWER
A. Validated electronic signatures are based on qualified certificates that are created by a certificate
authority, with the technical standards required to ensure the key can neither be forced nor
reproduced in a reasonable time. Such certificates are only delivered through a registration authority
after proof of identity has been passed. Using strong signatures in email traffic, nonrepudiation can
be assured, and a sender can be tracked. The recipient can configure his/her email server or client to
automatically delete emails from specific senders.
Which of the following functions is performed by a virtual private network (VPN)?
A.Hiding information from sniffers on the net
B.Enforcing security policies
C.Detecting misuse or mistakes
D.Regulating access -
CORRECT|ANSWER
A. A virtual private network (VPN) hides information from sniffers on the Internet using tunneling. It
works based on encapsulation and encryption of sensitive traffic.
Which of the following will BEST maintain the integrity of a firewall log?
A.Granting access to log information only to administrators
B.Capturing log events in the operating system (OS) layer
C.Writing dual logs onto separate storage media
D.Sending log information to a dedicated third-party log server -
CORRECT|ANSWER
D. Establishing a dedicated third-party log server and logging events in it is the best procedure for
maintaining the integrity of a firewall log. When access control to the log server is adequately
NEWEST 2026/2027 ACTUAL EXAM | COMPLETE QUESTIONS AND
CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY
GRADED A+||BRAND NEW VERSION!!
Which of the following would be the BEST overall control for an Internet business looking for
confidentiality, reliability and integrity of data?
A.Transport Layer Security (TLS)
B.Intrusion detection system (IDS)
C.Public key infrastructure
D.Virtual private network (VPN) -
CORRECT|ANSWER
A. Transport Layer Security (TLS) is used for many ecommerce applications to set up a secure
channel for communications that provides confidentiality through a combination of public and
symmetric key encryption and integrity through hash message authentication code.
What is the MOST prevalent security risk when an organization implements remote virtual private
network (VPN) access to its network?
A.Malicious code can be spread across the network.
B.The VPN logon can be spoofed.
C.Traffic can be sniffed and decrypted.
D.The VPN gateway can be compromised. -
CORRECT|ANSWER
A. Virtual private network (VPN) is a mature technology; VPN devices are hard to break. However,
when remote access is enabled, malicious code in a remote client can spread to the enterprise's
network. One problem is when the VPN terminates inside the network and the encrypted VPN traffic
goes through the firewall. This means that the firewall cannot adequately examine the traffic.
An IT auditor completed the fieldwork phase of a network security review and is preparing the initial
draft of the audit report. Which of the following findings would be the BIGGEST risk to the
enterprise?
A.Network penetration tests are performed by an internal team.
B.Network firewall rules are not approved by the chief information security officer (CISO) before
implementation.
C.Network penetration tests are not performed.
,D.The inventory of network devices was last updated two years ago. -
CORRECT|ANSWER
D. Keeping an up-to-date asset inventory is the most important requirement to keep an enterprise's
information assets secure. Without a complete inventory list and asset criticality determination, the
risk assessment cannot be completed and controls will be inadequate.
The reason a certification and accreditation process is performed on critical systems is to ensure that:
A.security compliance has been technically evaluated.
B.data have been encrypted and are ready to be stored.
C.the systems have been tested to run on different platforms.
D.the systems have followed the phases of a waterfall model. -
CORRECT|ANSWER
A. Certified and accredited systems are systems that have had their security compliance technically
evaluated for running in a specific environment and configuration.
An information systems (IS) auditor is reviewing a manufacturing enterprise and finds that
mainframe users at a remote site connect to the mainframe at headquarters over the Internet via
Telnet. Which of the following offers the STRONGEST security?
A.Use of a point-to-point leased line
B.Use of a firewall rule to allow only the internet protocol (IP) address of the remote site
C.Use of two-factor authentication
D.Use of a nonstandard port for Telnet -
CORRECT|ANSWER
A. A leased line effectively extends the local area network of the headquarters to the remote site,
and the mainframe Telnet connection travels over the private line, which is less of a security risk
when using an insecure protocol such as Telnet.
The BEST filter rule for protecting a network from being used as an amplifier in a denial-of-service
attack is to deny all:
A.outgoing traffic with source addresses external to the network.
B.incoming traffic with discernible spoofed internet protocol (IP) source addresses.
C.incoming traffic that includes options set in the Internet Protocol.
D.incoming traffic whose destination address belongs to critical hosts. -
CORRECT|ANSWER
, A. Outgoing traffic with an internet protocol (IP) source address different than the internal IP range
in the network is invalid. In most cases, it signals a denial-of-service attack originated by an internal
user or by a previously compromised internal machine; in both cases, applying this filter will stop the
infected machine from participating in the attack.
Validated digital signatures in an email software application will:
A.help detect unauthorized email.
B.provide confidentiality.
C.add to the workload of gateway servers.
D.significantly reduce available bandwidth. -
CORRECT|ANSWER
A. Validated electronic signatures are based on qualified certificates that are created by a certificate
authority, with the technical standards required to ensure the key can neither be forced nor
reproduced in a reasonable time. Such certificates are only delivered through a registration authority
after proof of identity has been passed. Using strong signatures in email traffic, nonrepudiation can
be assured, and a sender can be tracked. The recipient can configure his/her email server or client to
automatically delete emails from specific senders.
Which of the following functions is performed by a virtual private network (VPN)?
A.Hiding information from sniffers on the net
B.Enforcing security policies
C.Detecting misuse or mistakes
D.Regulating access -
CORRECT|ANSWER
A. A virtual private network (VPN) hides information from sniffers on the Internet using tunneling. It
works based on encapsulation and encryption of sensitive traffic.
Which of the following will BEST maintain the integrity of a firewall log?
A.Granting access to log information only to administrators
B.Capturing log events in the operating system (OS) layer
C.Writing dual logs onto separate storage media
D.Sending log information to a dedicated third-party log server -
CORRECT|ANSWER
D. Establishing a dedicated third-party log server and logging events in it is the best procedure for
maintaining the integrity of a firewall log. When access control to the log server is adequately