CISA EXAM SCRIPT FULL QUESTIONS AND
CORRECT ANSWERS REVIEW
●● Reverse proxy server
Answer: secure remote connection; type of proxy server that retrieves
resources on behalf of a client from one or more servers. These
resources are then returned to the client as though they originated from
the proxy server itself.
●● Sensitive emails
Answer: should be auto encrypted
●● Data Custodians
Answer: implement app info security& access rules based on Data
Owner
●● Info Asset Owner
Answer: define criticality and sensitivity of info
●● Data Owner
Answer: 1. RESONSIBLE for defining Access Rule. 2.
ACCOUNTABILITY for maintenance of proper security controls over
IS assets. Responsible for access provisioning (with help of SECOFR)
,●● Best way to exploit data/ determine a company's info is secure
Answer: Social Engineering
●● Naming conventions for system resources make for
Answer: efficient administration of access controls
●● It's OK for data owners to change Access Controls to
Answer: low risk applications (DAC)
●● TEMPEST
Answer: looks at electromagnetic emissions for any sensitive data it
might reveal
●● Data Classification
Answer: First establish ownership. Then define access rules based on
need to do/know
●● Defense in depth
Answer: means using two different security mechanisms to back each
other up
●● Hashing
,Answer: creates a message hash or digest, ensures integrity, part of
cryptography. (Irreversible)
●● Steganography
Answer: technique for concealing info, egg watermarking
●● Black box pen testing
Answer: no prior knowledge of infra. Important to legally agree. AKA
BLIND TESTING, ORG IS AWARE ITS HAPPENING
●● External USB Risk -
Answer: Theft or Loss. (Good companies scan for malware already)
●● Certificate Authority (CA)
Answer: delegates link of requesting entity with public key. CA must
perform certificate life cycle mgmt. (revoking/suspending people, issue
and distribute certificates)
●● Registration Authority
Answer: links requesting entity with public key; responsible for
verifying the subject requesting a certificate, verifies the requestors right
to a certificate
●● Ping of death
, Answer: packet >65KB, results in DOS
●● Leapfrog attack
Answer: uses stolen credentials to telnet through 1+ hosts w/o trace
●● Elliptic Curve Encryption
Answer: (faster, smaller keys than RSA encryption)
BETTER THAN AES ON MOBILE DEVICES
●● Both ECC and RSA
Answer: support digital signatures, are used for public key encryption, &
offer message entity controls)
●● Secure Socket Layer (SSL)
Answer: best control for Internet confidentiality, reliability, and data
integrity. Sets up a secure channel for communication through public &
symmetric key encryption through Hash Messaging Authentication Code
(HMAC)
●● Symmetric key
Answer: - good, fast, algorithms for cryptography that use the same
cryptographic keys for both encryption of plaintext and decryption of
ciphertext
CORRECT ANSWERS REVIEW
●● Reverse proxy server
Answer: secure remote connection; type of proxy server that retrieves
resources on behalf of a client from one or more servers. These
resources are then returned to the client as though they originated from
the proxy server itself.
●● Sensitive emails
Answer: should be auto encrypted
●● Data Custodians
Answer: implement app info security& access rules based on Data
Owner
●● Info Asset Owner
Answer: define criticality and sensitivity of info
●● Data Owner
Answer: 1. RESONSIBLE for defining Access Rule. 2.
ACCOUNTABILITY for maintenance of proper security controls over
IS assets. Responsible for access provisioning (with help of SECOFR)
,●● Best way to exploit data/ determine a company's info is secure
Answer: Social Engineering
●● Naming conventions for system resources make for
Answer: efficient administration of access controls
●● It's OK for data owners to change Access Controls to
Answer: low risk applications (DAC)
●● TEMPEST
Answer: looks at electromagnetic emissions for any sensitive data it
might reveal
●● Data Classification
Answer: First establish ownership. Then define access rules based on
need to do/know
●● Defense in depth
Answer: means using two different security mechanisms to back each
other up
●● Hashing
,Answer: creates a message hash or digest, ensures integrity, part of
cryptography. (Irreversible)
●● Steganography
Answer: technique for concealing info, egg watermarking
●● Black box pen testing
Answer: no prior knowledge of infra. Important to legally agree. AKA
BLIND TESTING, ORG IS AWARE ITS HAPPENING
●● External USB Risk -
Answer: Theft or Loss. (Good companies scan for malware already)
●● Certificate Authority (CA)
Answer: delegates link of requesting entity with public key. CA must
perform certificate life cycle mgmt. (revoking/suspending people, issue
and distribute certificates)
●● Registration Authority
Answer: links requesting entity with public key; responsible for
verifying the subject requesting a certificate, verifies the requestors right
to a certificate
●● Ping of death
, Answer: packet >65KB, results in DOS
●● Leapfrog attack
Answer: uses stolen credentials to telnet through 1+ hosts w/o trace
●● Elliptic Curve Encryption
Answer: (faster, smaller keys than RSA encryption)
BETTER THAN AES ON MOBILE DEVICES
●● Both ECC and RSA
Answer: support digital signatures, are used for public key encryption, &
offer message entity controls)
●● Secure Socket Layer (SSL)
Answer: best control for Internet confidentiality, reliability, and data
integrity. Sets up a secure channel for communication through public &
symmetric key encryption through Hash Messaging Authentication Code
(HMAC)
●● Symmetric key
Answer: - good, fast, algorithms for cryptography that use the same
cryptographic keys for both encryption of plaintext and decryption of
ciphertext