CISA Practice Exam 559 Questions with Verified Answers,100% CORRECT
CISA Practice Exam 559 Questions with Verified Answers It is important to understand the organization and its environment in order to effectively pinpoint the organization's key risk. One specific factor is an understanding of: - CORRECT ANSWER The organization's selection and application of policies and procedures Of the following, which is not a way to treat a risk? - CORRECT ANSWER Ignore it The three focus areas that management must address in order to govern IT include all of the following except: - CORRECT ANSWER Control optimization The first step in establishing a risk management program is: - CORRECT ANSWER To decide what the purpose of the program is An incident is any unexpected occurrence. The severity of an incident is generally: - CORRECT ANSWER Directly proportional to the time elapsed from the incident to the resolution of the incident One of the issues in managing a project is managing scope changes. Which of the following should be included in management of scope changes? - CORRECT ANSWER The work structure should be documented in a component management database Personal area networks (PANs) are used for: - CORRECT ANSWER Communications among computer devices, which include telephones, PDAs, cameras, etc. The IS Auditor is preparing the external network security assessment. Of the following, which step should the IS Auditor start with? - CORRECT ANSWER Reconnaissance. The IS Auditor should perform reconnaissance, or "footprinting" of the enterprise to appropriate gauge several details such as the scope (what elements to include in the test), what protocols and technology are involved, whether there is any sensitive information readily available to the public, or "leaked" Fire suppression systems can be divided into total flooding and local application fire extinguishing systems. The difference between the two is that: - CORRECT ANSWER Local application design lacks physical barriers enclosing the fire space Computer crime can be performed __________________ without anything being physically taken or stolen. - CORRECT ANSWER Remotely All of these are COBIT principles: - CORRECT ANSWER Apply a single integrated framework; separate governance from management; enable a holistic approach Continuous auditing: - CORRECT ANSWER involves a minimal time lapse between the collection of evidence and the audit reporting What fundamental change in the information systems (IS) role has taken place? - CORRECT ANSWER IS is now an integral part of every department of an organization What does the term SCADA stand for? - CORRECT ANSWER Supervisory Control and Data Acquisition Computer-aided software engineering (CASE) tools are divided into the categories upper CASE, middle CASE, and lower CASE. Middle CASE is: - CORRECT ANSWER The products for detailed design and development 4GLs include all of the following classifications: - CORRECT ANSWER Relational database 4GLs; Embedded database 4GLs; Quary and report generators After the successful adoption of the capability maturity model (CMM), the CMMI was developed. The CMMI: - CORRECT ANSWER Includes models for disciplines such as systems engineering and integrated product development What are the 5 volumes of the IT infrastructure library (ITIL)? - CORRECT ANSWER 1. Service Strategy 2. Service Design 3. Service Transition 4. Service Operations 5. Continual Service Which of the following best describes "Frame Relay"? - CORRECT ANSWER A data link layer protocol for switch devices that uses a standard encapsulation technique to handle multiple virtual circuits between connected devices Which of the following is an attack in which the attacker collects small amounts of money from computerized transactions or accounts? - CORRECT ANSWER Salami In handling computer evidence, it's important for a forensic auditor to: - CORRECT ANSWER Make a bitstream image of the hard drive, taking care not to alter date stamps or other identifying information The IS auditor is currently evaluating the new application implementation and would like to review the operations of their computer systems. Which of the following would be the most appropriate method? - CORRECT ANSWER Compare the service delivery report to the service level agreement There are four primary cloud architectures or deployment models: private, public, hybrid, and community. Which cloud deployment model potentially has the least scalability and agility? - CORRECT ANSWER Private cloud When a new system is ready to go, there are several different ways of actually switching the old system to the new system. The following are all changeover techniques: - CORRECT ANSWER -Phased changeover -Abrupt changeover -Parallel changeover Hardware needs careful monitoring. Part of that monitoring is effective reporting. All of the following are commonly used hardware monitoring reports: - CORRECT ANSWER -Availability reports -Asset management reports -Hardware error report A virtual circuit is: - CORRECT ANSWER A logical circuit between two network points that supplies reliable data communication between the two An SLA is an agreement between the IT organization and the: - CORRECT ANSWER Customer When dealing with auditing environment controls, what fire resistance rating should fireproof walls, ceilings, and floors have around the information processing facility? - CORRECT ANSWER 2 hour The common link between all forms of social media is ________________________. - CORRECT ANSWER Content is supplied and managed by individual users Information Security Control is extremely important and enacted controls should be tested against industry benchmarks. What is the benchmark for security across the payment card industry? - CORRECT ANSWER PCI DSS There are a number of governmental and external requirements related to computer system practices and controls and the way data is stored and used. These controls include Sarbanes-Oxley and HIPAA. The CISA candidate is expected to know: - CORRECT ANSWER How one would audit for compliance with laws and regulations What is non-statistical sampling? - CORRECT ANSWER Its based on the auditor's judgement as to what kind of samples to evaluate, the sample size, and the sampling method Continuous auditing is superior to periodic auditing insofar as it: - CORRECT ANSWER Captures control problems as they occur, helping to prevent negative consequences The Framework for Enterprise Architecture (EA) is otherwise known as _____________________. - CORRECT ANSWER The Zachman Framework SteelWorks Manufacturing utilizes a system where its production line is controlled by remote terminal units (RTUs) and programmable logic controllers (PLCs). These automated system components comprise an overall system capable of measuring and collating the data, compiling it, and then providing it to the control room. From this human machine interface (HMI) network, operators can make supervisory decisions to maximize production. What is this system an example of? - CORRECT ANSWER Supervisory Control and Data Acquisition (SCADA) In the software design process, the auditor is concerned with all of the following: - CORRECT ANSWER -Whether adequate controls are built into the system specifications -Whether online auditing functions are built into the system -Whether the design process is effective in establishing a formal software change process The difference between a virus and a worm is that a worm: - CORRECT ANSWER Doesn't attach itself physically to another program What are the phases of penetration testing? - CORRECT ANSWER Planning, Reconnaissance/Discovery, Attacks, Reporting Of the following, which controls can be enacted for Instant Messaging (IM) that could be applied to risks of malware, eavesdropping, and excessive use of IM? - CORRECT ANSWER Develop and conduct awareness training The CISO has concerns with the proximity cards and would like to implement a biometric scanning alongside the card scanner to enhance security. Which of the following risks is the CISO most likely concerned with? - CORRECT ANSWER Access card sharing ISACA IS Audit and Assurance Standards contain how many categories? - CORRECT ANSWER 3. General, Performance, and Reporting Effective security management is facilitated by all of the following: - CORRECT ANSWER -Performance Measurement -Resource Management -Process Integration Performance optimization tools types include all of the following: - CORRECT ANSWER -Continuous improvement methodologies -Frameworks -Comprehensive best practices Which of the following are project organizational forms? - CORRECT ANSWER -Influence project organization -Pure project organization -Matrix project organization When acquiring hardware, all of the following should be considered: - CORRECT ANSWER -Utilization -Turnaround time -Throughput Virtualization software that runs as an application within operating systems such as Windows, Linux, or MacOS is an example of what type of virtualization architecture? - CORRECT ANSWER Hosted virtualization Which of the following has evolved over the years to become a widely use multi-point technique used for estimating large business application development complexity? - CORRECT ANSWER Function Point Analysis (FPA) Which IT Service Management framework utilizes five volumes with titles such as Service Strategy and Service Operations? - CORRECT ANSWER ITIL - 5 volumes 1. Service strategy 2. Service design 3. Service transition 4. Service operations 5. Continual service improvement An IS auditor is working with an organization to assist in planning for disaster recovery. The executives explain to the auditor that their primary systems cannot support a downtime of over an hour and can support a data loss of about four hours of data. From these recovery objectives, which of the following would be an appropriate recovery option? - CORRECT ANSWER Active-active clustering with disk-based backups To monitor data in motion, data leak prevention systems use what technology? - CORRECT ANSWER Deep packet inspection (DPI) The role of an internal audit function is established by: - CORRECT ANSWER An audit charter that's been approved by senior management Laws and regulations control audit plans in what way? - CORRECT ANSWER The audit plan must adhere to and test for all regulations to ensure a company is compliant Of the following, which falls under the General category in the ISACA IS Assurance Guidelines? - CORRECT ANSWER Audit Charter An IS auditor is reviewing the specific standards and compliance requirements that need to be achieved from the systems that they will be auditing. The auditor has discovered that the ISACA IS Audit and Assurance Standards are not as stringent as the local regulatory authority. What should the auditor do in this case? - CORRECT ANSWER Abide by the more stringent regulations and incorporate them into the audit Risks are measured using various kinda of analysis: quantitative, qualitative, or semi qualitative. Semi qualitative analysis is: - CORRECT ANSWER Defining risk using a numeric scale One of the popular cloud computing models is a platform-as-a-service can be very attractive, but there are some things to consider. All of the following need to be taken to into account before making a decision to use platform-as-a-service: - CORRECT ANSWER -Data ownership -Confidentiality -E-discovery concerns Acme Inc. has contracted with CoverAll Insurance agency in order to be compensated for their critical asset risks in case of catastrophic failure. In return, Acme Inc pays Coverall Insurance a premium and when the covered risks occur, CoverAll pays out what the company would stand to lose in that event. What kind of risk management strategy is this? - CORRECT ANSWER Share/Transfer An invitation to respond to an RFP is likely to result in more than one qualified finalist vendor. To resolve the situation, the shortlisted vendors should be asked to: - CORRECT ANSWER Prepare an agenda-based presentation Data leak prevention technologies typically have technologies that facilitate 3 key objectives: - CORRECT ANSWER -Monitor and control the movement of sensitive information on end-user systems -Monitor and control the movement of sensitive information across enterprise networks -Locate and catalog sensitive information stored throughout the enterprise An IS Auditor is reviewing information classifications at an organization to determine appropriateness. They are currently looking at internal policies, procedures, and several pieces of information controlled by legislation. This information should be classified under which of the following? - CORRECT ANSWER Private information Abend - CORRECT ANSWER Abnormal end to a computer job; termination of a task prior to its completion because of an error condition that cannot be resolved by recovery facilities while the task is executing Acceptable use policy - CORRECT ANSWER Establishes an agreement between users and enterprise and defines for all parties' the ranges of use that are approved before gaining access to network or internet Access control - CORRECT ANSWER The processes, rules and deployment mechanisms that control access to information systems, resources and physical access to premises Acess control list (ACL) - CORRECT ANSWER Internal computerized table of access rules regarding the levels of computer access permitted to logon IDs and computer terminals (aka access control tables) Access control table - CORRECT ANSWER internal computerized table of access rules regarding levels of computer access permitted to logon IDs and computer terminals Access Method - CORRECT ANSWER The technique used for selecting records in a file, one at a time, for processing, retrieval or storage. The access method is related to, but distinct from, the file organization, which determines how the records are stored. Access path - CORRECT ANSWER The logical route that an end user takes to access computerized information. Typically includes a route through the operating system, telecommunications software, selected application software and the access control system Access rights - CORRECT ANSWER The permission or privileges granted to users, programs or workstations to create, change, delete or view data and files within a system, as defined by rules established by data owners and the information security policy Access servers - CORRECT ANSWER Provides centralized access control for managing remote access dial-up services Address - CORRECT ANSWER Within computer storage, the code used to designate the location of a specific piece of data Address space - CORRECT ANSWER The number of distinct locations that may be referred to with the machine address. For most binary machines, it is equal to 2n, where n is the number of bits in the machine address. Addressing - CORRECT ANSWER The method used to identify the location of a participant in a network. Ideally, addressing specifies where the participant is located rather than who they are (name) or how to get there (routing). Administrative Controls - CORRECT ANSWER The rules, procedures and practices dealing with operational effectiveness, efficiency and adherence to regulations and management policies Adware - CORRECT ANSWER A software package that automatically plays, displays, or downloads advertising material to a computer after the software is installed on it or while the application is being used. In most cases, this is done without any notification to the user or without the user's consent. The term adware may also refer to software that displays advertisements. Alpha - CORRECT ANSWER The use of alphabetic characters or an alphabetic character string Alternative routing - CORRECT ANSWER A service that allows the option of having an alternate route to complete a call when the marked destination is not available. In signaling, alternate routing is the process of allocating substitute routes for a given signaling traffic stream in case of failure(s) affecting the normal signaling links or routes of that traffic stream. Anonymous File Transfer Protocol (FTP) - CORRECT ANSWER A method for downloading public files using the File Transfer Protocol (FTP). Anonymous FTP is called anonymous because users do not need to identify themselves before accessing files from a particular server. In general; users enter the word anonymous when the host prompts for a username; anything can be entered for the password; such as the user's e-mail address or simply the word guest. In many cases; an anonymous FTP site will not even prompt users for a name and password. Antivirus Software - CORRECT ANSWER An application software deployed at multiple points in an IT architecture. It is designed to detect and potentially eliminate virus code before damage is done and repair or quarantine files that have already been infected. Applet - CORRECT ANSWER A program written in a portable; platform independent computer language; such as Java. It is usually embedded in an HTML page and then executed by a browser. Applets can only perform a restricted set of operations; thus preventing; or at least minimizing; the possible security compromise of the host computers. Applets expose the user's machine to risk if not properly controlled by the browser, which should not allow an applet to access a machine's information without prior authorization of the user Application - CORRECT ANSWER a computer program or set of programs that perform the processing of records for a specific function. Contrasts with systems programs, which as an OS or network control program, and with utility programs, such as a copy and sort Application Controls - CORRECT ANSWER The policies, procedures and activities designed to provide reasonable assurance that objectives relevant to a given automated solution (application) are achieved Application Layer - CORRECT ANSWER In the Open Systems Interconnection (OSI) communications model, the application layer provides services for an application program to ensure that effective communication with another application program in a network is possible. The application layer is not the application that is doing the communication; a service layer that provides these services. Application Program - CORRECT ANSWER A program that processes business data through activities such as data entry, update or query. Contrasts with systems programs, such as an operating system or network control program, and with utility programs such as copy or sort. Application Programming - CORRECT ANSWER The act or function of developing and maintaining applications programs in production Application Programming Interface (API) - CORRECT ANSWER a set of routines, protocols, and tools referred to as building blocks used in business application software development. A good API makes it easier to develop a program by providing all the building blocks related to functional characteristics of an OS that applications need to specify (for ex when interfacing with the OS provided by Microsoft Windows. A programmer uses these APIs in developing applications that can operate effectively and efficiently on the platform chosen Application software tracing and mapping - CORRECT ANSWER Specialized tools that can be used to analyze the flow of data through the processing logic of the application software and document the logic, paths, control conditions and processing sequences. Both the command language or job control statements and programming language can be analyzed. This technique includes program/system: mapping, tracing, snapshots, parallel simulations and code comparisons. Arithmetic Logic Unit (ALU) - CORRECT ANSWER The area of the central processing unit that performs mathematical and analytical operations Artificial Intelligence - CORRECT ANSWER Advanced computer systems that can simulate human capabilities, such as analysis, based on a predetermined set of rules ASCII - CORRECT ANSWER American Standard Code for Information Interchange; represents 128 characters, normally uses 7 bits Assembler - CORRECT ANSWER A program that takes as input a program written in assembly language and translates it into machine code or machine language Asymmetric Key (Public Key) - CORRECT ANSWER A cipher technique in which different cryptographic keys are used to encrypt and decrypt a message. See public key encryption. Asynchronous Transfer Mode (ATM) - CORRECT ANSWER A high-bandwidth, low-delay, connection-oriented, switching, and multiplexing technique that allows the seamless end-to-end transmission of voice, data, and video traffic. Data link layer protocol which is protocol-independent transport mechanism. Allows high-speed data transfer Asynchronous Transmission - CORRECT ANSWER Character-at-a-time transmission Attribute Sampling - CORRECT ANSWER An audit technique used to select items from a population for audit testing purposes based on selecting all those items that have certain attributes or characteristics (such as all items over a certain size) Audit Evidence - CORRECT ANSWER The information used to support the audit opinion Audit Objective - CORRECT ANSWER The specific goal(s) of an audit. These often center on substantiating the existence of internal controls to minimize business risk. Audit Plan - CORRECT ANSWER 1. A plan containing the nature, timing and extent of audit procedures to be performed by engagement team members in order to obtain sufficient appropriate audit evidence to form an opinion appropriate opinion. Includes areas to be audited, type of work planned, high-level objectives and scope of the work -- budget, resource allocation, shcedule, intended audience & other general aspects 2. A high-level description of the audit work to be performed in a certain period of time Audit Program - CORRECT ANSWER A step-by-step set of audit procedures and instructions that should be performed to complete an audit Audit Risk - CORRECT ANSWER the probability that information or financial reports may contain material errors and that the auditor may not detect an error that has occurred Audit Trail - CORRECT ANSWER A visible trail of evidence enabling one to trace information contained in statements or reports back to the original input source Authentication - CORRECT ANSWER The act of verifying the identity of a user and the user's eligibility to access computerized information. Authentication is designed to prevent against fraudulent logon activity; also can refer to verification of the correctness of a piece of data Backbone - CORRECT ANSWER The main communications channel of a digital network. The part of the network that handles the major traffic. Employs the highest-speed transmission paths in the network and may also run the longest distances. Smaller networks are attached to the backbone, and networks that connect directly to the end user or customer are called access networks. A backbone can span a geographic area of any size, from a single building to an office complex, to an entire country. Or, it can be as small as a backplane in a single cabinet. Backup - CORRECT ANSWER Files, equipment, data and procedures available for use in the event of a failure or loss, if the originals are destroyed or out of service Badge - CORRECT ANSWER A card or other device that is presented or displayed to obtain access to an otherwise restricted facility, as a symbol of authority (e.g. police) or as a simple means of identification. Also used in advertising and publicity. Balanced Scorecard (BSC) - CORRECT ANSWER Developed by Robert S. Kaplan and David P. Norton as a coherent set of performance measures organized into four categories that includes traditional financial measures, but adds customer, internal business process, and learning and growth perspectives Bandwidth - CORRECT ANSWER The range between the highest and lowest transmittable frequencies. It equates to the transmission capacity of an electronic line and is expressed in bytes per second or Hertz (cycles per second) Bar Code - CORRECT ANSWER A printed machine-readable code that consists of parallel bars of varied width and spacing Base Case - CORRECT ANSWER A standardized body of data created for testing purposes. Users normally establish the data. Base cases validate production application systems and test the ongoing accurate operation of the system. Baseband - CORRECT ANSWER A form of modulation in which data signals are pulsed directly on the transmission medium without frequency division and usually utilize a transceiver. The entire bandwidth of the transmission medium (e.g., coaxial cable) is utilized for a single channel. Batch Control - CORRECT ANSWER Correctness checks built into data processing systems and applied to batches of input data, particularly in the data preparation stage. There are two main forms of batch controls: sequence control, which involves consecutively numbering the records in a batch so that the presence of each record can be confirmed, and control total, which is a total of the values in selected fields within the transactions. Batch Processing - CORRECT ANSWER The processing of a group of transactions at the same time. Transactions are collected and processed against the master files at a specified time. Baud Rate - CORRECT ANSWER The rate of transmission for telecommunications data, expressed in bits per second (bps) Bayesian Filter - CORRECT ANSWER A method often employed by antispam software to filter spam based on probabilities. The message header and every word or number are each considered a token and given a probability score. Then the entire message is given a spam probability score. A message with a high score will be flagged as spam and discarded, returned to its sender or put in a spam directory for further review by the intended recipient. Benchmarking - CORRECT ANSWER a systematic approach to comparing organization performance against peers and competitors in an effort to learn the best ways of conducting business (ex: benchmarking of quality, logistic efficiency) Binary Code - CORRECT ANSWER A code whose representation is limited to 0 and 1 Biometrics - CORRECT ANSWER A security technique that verifies an individual's identity by analyzing a unique physical attribute, such as a handprint. Black box testing - CORRECT ANSWER A testing approach that focuses on the functionality of the application or product and does not require knowledge of the code intervals Bridge - CORRECT ANSWER A device that connects two similar networks together Broadband - CORRECT ANSWER Multiple channels are formed by dividing the transmission medium into discrete frequency segments. Typically requires the use of a modem. Brouters - CORRECT ANSWER Devices that perform the functions of both a bridge and a router. A brouter operates at both the data link and the network layers. It connects same data link type local area network (LAN) segments as well as different data link ones, which is a significant advantage. Like a bridge, it forwards packets based on the data link layer address to a different network of the same type. Also, whenever required, it processes and forwards messages to a different data link type network based on the network protocol address. When connecting same data link type networks, it is as fast as a bridge and is able to connect different data link type networks. Buffer - CORRECT ANSWER Memory reserved to temporarily hold data to offset differences between the operating speeds of different devices, such as a printer and a computer. In a program, buffers are reserved areas of random access memory (RAM) that hold data while they are being processed Bus - CORRECT ANSWER Common path or channel between hardware devices. Can be located between components internal to a computer or between external computers in a comms network Bus Configuration - CORRECT ANSWER All devices (nodes) are linked along one communication line where transmissions are received by all attached nodes. Scope Note: This architecture is reliable in very small networks, as well as easy to use and understand. This configuration requires the least amount of cable to connect the computer together, and therefore, is less expensive than other cabling arrangements. It is also easy to extend, and 2 cables can be easily joined with a connector to make a longer cable for more computers to join the network. A repeater can also be used to extend a bus configuration. Business Case - CORRECT ANSWER Documentation of the rationale for making a business investment, used both to support a business decision on whether to proceed with the investment and as an operational tool to support management of the investment through its full economic life cycle Business Continuity Plan (BCP) - CORRECT ANSWER A plan used by an organization to respond to disruption of critical business processes. Depends on the contingency plan for restoration of critical systems Business Impact Analysis (BIA) - CORRECT ANSWER A process to determine the impact of losing the support of any resource Scope Note: The BIA assessment study will establish the escalation of that loss over time. It is predicated on the fact that senior management, when provided reliable data to document the potential impact of a lost resource, can make the appropriate decision. Business Process Reengineering (BPR) - CORRECT ANSWER The thorough analysis and redesign of business processes and management systems to establish a better performing structure, more responsive to the customer base and market conditions, while yielding material cost savings Business Risk - CORRECT ANSWER A probable situation with uncertain frequency and magnitude of loss (or gain) Bypass label processing (BLP) - CORRECT ANSWER A technique of reading a computer file while bypassing the internal file/data set label. This process could result in bypassing of the security access control system. Capability Maturity Model Integration (CMMI) - CORRECT ANSWER CMMI is a model used by many organizations to identify best practices useful in helping them assess and increase the maturity of their software development processes Capacity stress testing - CORRECT ANSWER Testing an application with large quantities of data to evaluate its performance during peak periods. Also called volume testing. Card swipe - CORRECT ANSWER A physical control technique that uses a secured card or ID to gain access to a highly sensitive location. Scope Note: If built correctly, card swipes act as a preventive control over physical access to those sensitive locations. After a card has been swiped, the application attached to the physical card swipe device logs all card users who try to access the secured location. The card swipe device prevents unauthorized access and logs all attempts to enter the secured location Central Processing Unit (CPU) - CORRECT ANSWER Computer hardware that houses the electronic circuits that control/direct all operations of the computer system Certificat (certification) Authority (CA) - CORRECT ANSWER A trusted third party that serves authentication infrastructures or organizations, and registers entities and issues them certificates Certificate Revocation List (CRL) - CORRECT ANSWER An instrument for checking the continued validity of the certificates for which the certification authority (CA) has responsibility. The CRL details digital certificates that are no longer valid. The time gap between two updates is very critical and is also a risk in digital certificates verification. Certification Practice Statement (CPS) - CORRECT ANSWER A detailed set of rules governing the certificate authority's operations. It provides an understanding of the value and trustworthiness of certificates issued by a given certificate authority (CA). In terms of the controls that an enterprise observes, the method it uses to validate the authenticity of certificate applicants and the CA's expectations of how its certificates may be used. Chain of Custody - CORRECT ANSWER A legal principle regarding the integrity and validity of the evidence. It requires accountability for anything that will be used as evidence in a legal proceeding to ensure that it can be accounted for from the time it was collected until the time it is presented in a court of law. Includes documentation as to who had access to the evidence and when, as well a the ability to identify evidence as being the exact item that was recovered or tested. Lack of control over evidence can lead to it being discredited. Depends on the ability to verify that the evidence could not have been changed, and providing a documentary record of custody to prove that the evidence was at all times under strict control and not subject to tampering. Challenge/response Token - CORRECT ANSWER A method of user authentication that is carried out through use of the Challenge Handshake Authentication Protocol (CHAP). When a user tries to log into the server using CHAP, the server sends the user a "challenge" which is a random value. The user enters a password, which is used as an encryption key to encrypt the "challenge" and return it to the server. The server is aware of the password. It, therefore, encrypts the "challenge" value and compares it with the value received from the user. If the values match, the user is authenticated. The challenge/response activity continues throughout the session and this protects the session from password sniffing attacks. Additionally, CHAP is not vulnerable to "man-in-the-middle" attacks because the challenge value is a random value that changes on each access attempt. Change Management - CORRECT ANSWER A holistic and proactive approach to managing the transition from a current to a desired organizational state, focusing specifically on the critical human or "soft" elements of change. Includes activities such as culture change (values, beliefs and attitudes), development of reward systems (measures and appropriate incentives), organizational design, stakeholder management, human resources (HR) policies and procedures, executive coaching, change leadership training, team building and communication planning and execution. Channel Service Unit/Data Service Unit (CSU/DSU) - CORRECT ANSWER Interfaces at the physical layer of the open systems interconnection (OSI) reference model, data terminal equipment (DTE) to data circuit terminating equipment (DCE), for switched carrier networks Check Digit - CORRECT ANSWER A numeric value, which has been calculated mathematically, is added to data to ensure that original data have not been altered or that an incorrect, but valid match has occurred. Scope Note: Check digit control is effective in detecting transposition and transcription errors Checklist - CORRECT ANSWER A list of items that is used to verify the completeness of a task or goal. Used in quality assurance (and, in general, in information systems audit) to check process compliance, code standardization and error prevention, and other items for which consistency processes or standards have been defined. Checkpoint restart procedures - CORRECT ANSWER A point in a routine at which sufficient information can be stored to permit restarting the computation from that point. Checksum - CORRECT ANSWER A mathematical value that is assigned to a file and used to "test" the file at a later date to verify that the data contained in the file has not been maliciously changed. Ciphertext - CORRECT ANSWER Information generated by an encryption algorithm to protect the plaintext and that is unintelligible to the unauthorized reader. Circuit-Switched Network - CORRECT ANSWER A data transmission service requiring the establishment of a circuit-switched connection before data can be transferred from source data terminal equipment (DTE) to a sink DTE. A circuit-switched data transmission service uses a connection network. Circular Routing - CORRECT ANSWER In open systems architecture, circular routing is the logical path of a message in a communication network based on a series of gates at the physical network layer in the open systems interconnection (OSI) model. Client-Server - CORRECT ANSWER A group of computers connected by a communications network, where the client is the requesting machine and the server is the supplying machine. Software is specialized at both ends. Processing may take place on either the client or the server, but it is transparent to the user. Cloud Computing - CORRECT ANSWER A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction. Coaxical Cable - CORRECT ANSWER Composed of an insulated wire that runs through the middle of each cable, a second wire that surrounds the insulation of the inner wire like a sheath, and the outer insulation which wraps the second wire. Has a greater transmission capacity than standard twisted-pair cables but has a limited range of effective distance Cohesion - CORRECT ANSWER The extent to which a system unit - subroutine, program, module, component, subsystem - performs a single dedicated function. Generally, the more cohesive are units, the easier it is to maintain and enhance a system because it is easier to determine where and how to apply a change Cold Site - CORRECT ANSWER An IS backup facility that has the necessary electrical and physical components of a computer facility, but does not have the computer equipment in place. The site is ready to receive the necessary replacement computer equipment in the event the users have to move from their main computing location to the alternative computer facility. Communication Processor - CORRECT ANSWER A computer embedded in a communications system that generally performs basic tasks of classifying network traffic and enforcing network policy functions. An example is the message data processor of a digital divide network (DDN) switching center. More advanced communications processors may perform additional functions. Comparison Program - CORRECT ANSWER A program for the examination of data, using logical or conditional tests to determine or to identify similarities or differences Compensating Control - CORRECT ANSWER An internal control that reduces the risk of an existing or potential control weakness resulting in errors and omissions Compiler - CORRECT ANSWER A program that translates programming language (source code) into machine executable instructions (object code) Completely connected (mesh) configuration - CORRECT ANSWER A network topology in which devices are connected with many redundant interconnections between network nodes (primarily used for backbone networks) Completeness Check - CORRECT ANSWER A procedure designed to ensure that no fields are missing from a record Compliance Testing - CORRECT ANSWER Tests of control designed to obtain audit evidence on both the effectiveness of the controls and their operation during the audit period Components (as in component-based development) - CORRECT ANSWER Cooperating packages of executable software that make their services available through defined interfaces. Components used in developing systems may be commercial off-the-shelf (COTS) or may be purposely built. However, the goal of component-based development is to ultimately use as many predeveloped, pretested components as possible Comprehensive Audit - CORRECT ANSWER An audit designed to determine the accuracy of financial records as well as evaluate the internal controls of a function Computer Emergency Response Team (CERT) - CORRECT ANSWER A group of people integrated at the enterprise with clear lines of reporting and responsibilities for standby support in case of an information systems emergency. This group will act as an efficient corrective control, and should also act as a single point of contact for all incidents and issues related to information systems. Computer Forensics - CORRECT ANSWER The application of the scientific method to digital media to establish factual information for judicial review. This process often involves investigating computer systems to determine whether they are or have been used for illegal or unauthorized activities. As a discipline, it combines elements of law and computer science to collect and analyze data from information systems (e.g., personal computers, networks, wireless communication and digital storage devices) in a way that is admissible as evidence in a court of law. Computer sequence checking - CORRECT ANSWER Verifies that the control number follows sequentially and that any control numbers out of sequence are rejected or noted on an exception report for further research Computer-aided software engineering (CASE) - CORRECT ANSWER The use of software packages that aid in the development of all phases of an information system. System analysis, design programming and documentation are provided. Changes introduced in one CASE chart will update all other related charts automatically. CASE can be installed on a microcomputer for easy access. Computer-assisted audit technique (CAAT) - CORRECT ANSWER Any automated audit technique, such as generalized audit software (GAS), test data generators, computerized audit programs and specialized audit utilities. Concurrency Control - CORRECT ANSWER Refers to a class of controls used in database management systems (DBMS) to ensure that transactions are processed in an atomic, consistent, isolated and durable manner (ACID). This implies that only serial and recoverable schedules are permitted, and that committed transactions are not discarded when undoing aborted transactions. Configuration Management - CORRECT ANSWER The control of changes to a set of configuration items over a system life cycle. Console Log - CORRECT ANSWER An automated detail report of computer system activity. Contingency Planning - CORRECT ANSWER Process of developing advance arrangements and procedures that enable an enterprise to respond to an event that could occur by chance or unforeseen circumstances. Continuity - CORRECT ANSWER Preventing, mitigating and recovering from disruption. The terms "business resumption planning", "disaster recovery planning" and "contingency planning" also may be used in this context; they all concentrate on the recovery aspects of continuity. Continuous Auditing Approach - CORRECT ANSWER This approach allows IS auditors to monitor system reliability on a continuous basis and to gather selective audit evidence through the computer. Continuous Improvement - CORRECT ANSWER The goals of continuous improvement (Kaizen) include the elimination of waste, defined as "activities that add cost, but do not add value", just-in-time (JIT) delivery; production load leveling of amounts and types; standardized work; paced moving lines; right-sized equipment. A closer definition of the Japanese usage of Kaizen is "to take it apart and put back together in a better way." What is taken apart is usually a process, system. product or service. -- eliminates waste in business processes Control Group - CORRECT ANSWER Members of the operations area that are responsible for the collection, logging and submission of input for the various user groups Control Objective - CORRECT ANSWER A statement of the desired result or purpose to be achieved by implementing control procedures in a particular process Control Practice - CORRECT ANSWER Key control mechanism that supports the achievement of control objectives through responsible use of resources, appropriate management of risk and alignment of IT with business. Control Risk - CORRECT ANSWER the risk that a material error exists that would not be prevented or detected on a timely basis by the system of internal controls Control Section - CORRECT ANSWER The area of the central processing unit (CPU) that executes software, allocates internal memory and transfers operations between the arithmetic-logic, internal storage and output sections of the computer Cookie - CORRECT ANSWER A message kept in the web browser for the purpose of identifying users and possibly preparing customized web pages for them. Corporate Governance - CORRECT ANSWER The system by which organizations are directed and controlled. The board of directors are responsible for the governance of their organizations. It consists of the leadership and organizational structures and processes that ensure the organization sustains and extends strategies and objectives. Corrective Control - CORRECT ANSWER Designed to correct errors, omissions and unauthorized uses and intrusions, once they are detected Countermeasure - CORRECT ANSWER Any process that directly reduces a threat or vulnerability Coupling - CORRECT ANSWER Measure of interconnectivity among structure of software programs. Coupling depends on the interface complexity between modules. This can be defined as the point at which entry or reference is made to a module, and what data pass the interface. In application software design, it is preferable to strive for the lowest possible coupling between modules. Simple connectivity among modules results in software that is easier to understand and maintain and less prone to a ripple or domino effect causes when errors occur at one location and propagate through a system. Critical Infrastructure - CORRECT ANSWER Systems whose incapacity or destruction would have a debilitating effect on the economic security of an enterprise, community or nation Critical Success Factor (CSF) - CORRECT ANSWER The most important issue or action for management to achieve control over and within its IT processes Customer Relationship Management (CRM) - CORRECT ANSWER A way to identify, acquire and retain customers. CRM is also an industry term for software solutions that help an organization manage customer relationships in an organized manner. Data Communications - CORRECT ANSWER The transfer of data between separate computer processing sites/devices using telephone lines, microwave and/or satellite links. Data Custodian - CORRECT ANSWER Individuals and departments responsible for the storage and safeguarding of computerized information. This typically is within the IS organization. Data Dictionary - CORRECT ANSWER A database that contains the name, type, range of values, source and authorization for access for each data element in a database. It also indicates which application programs use those data so that when a data structure is contemplated, a list of the affected programs can be generated. May be a stand-alone information system used for management or documentation purposes, or it may control the operation of a database. Data Diddling - CORRECT ANSWER Changing data with malicious intent before or during input into the system Data Encryption Standard (DES) - CORRECT ANSWER An algorithm for encoding binary data. It is a secret key cryptosystem published by the National Bureau of Standards (NBS), the predecessor of the US National Institute of Standards and Technology (NIST). DES was defined as a Federal Information Processing Standard (FIPS) in 1976 and has been used commonly for data encryption in the forms of software and hardware implementation Data Leakage - CORRECT ANSWER Siphoning out or leaking information by dumping computer files or stealing computer reports and tapes. Data Owner - CORRECT ANSWER Individuals, normally managers or directors, who have responsibility .for the integrity, accurate reporting and use of computerized data. Data Security - CORRECT ANSWER Those controls that seek to maintain confidentiality, integrity and availability of information Data Structure - CORRECT ANSWER The relationships among files in a database and among data items within each file Database - CORRECT ANSWER A stored collection of related data needed by organizations and individuals to meet their information processing and retrieval requirements. Database Administrator (DBA) - CORRECT ANSWER An individual or department responsible for the security and information classification of the shared data stored on a database system. This responsibility includes the design, definition and maintenance of the database. Database Management System (DBMS) - CORRECT ANSWER A software system that controls the organization, storage and retrieval of data in a database. Database Replication - CORRECT ANSWER The process of creating and managing duplicate versions of a database. Replication not only copies a database but also synchronizes a set of replicas so that changes made to one replica are reflected in all of the others. The beauty of replication is that it enables many users to work with their own local copy of a database, but have the database updated as if they were working on a single centralized database. For database applications in which, geographically users are distributed widely, replication is often the most efficient method of database access. Database Specifications - CORRECT ANSWER These are the requirements for establishing a database application. They include field definitions, field requirements, and reporting requirements for the individual information in the database. Data-oriented systems development - CORRECT ANSWER Focuses on providing ad hoc reporting for users by developing a suitable accessible database of information and to provide useable data rather than a function Decentralization - CORRECT ANSWER The process of distributing computer processing to different locations within an organization. Decision Support System (DSS) - CORRECT ANSWER an interactive system that provides the user with easy access to decision models and data, to support semi structured decision-making tasks Decryption - CORRECT ANSWER A technique used to recover the original plaintext from the ciphertext so that it is intelligible to the reader The decryption is a reverse process of the encryption. Decryption Key - CORRECT ANSWER A piece of information used to recover the plaintext from the corresponding ciphertext by decryption. Degauss - CORRECT ANSWER The application of variable levels of alternating current for the purpose of demagnetizing magnetic recording media. The process involves increasing the alternating current field gradually from zero to some maximum value and back to zero, leaving a very low residue of magnetic induction on the media. Degauss loosely means to erase. Demodulation - CORRECT ANSWER The process of converting an analog telecommunications signal into a digital computer signal. Detection Risk - CORRECT ANSWER the risk that material errors or misstatements that have occurred will not be detected by the IS auditor Detective Control - CORRECT ANSWER Exists to detect and report when errors, omissions and unauthorized uses or entries occur Dial-back - CORRECT ANSWER Used as a control over dial-up telecommunications lines. The telecommunications link established through dial-up into the computer from a remote location is interrupted so the computer can dial back to the caller. The link is permitted only if the caller is from a valid phone number or telecommunications channel. Dial-in access control - CORRECT ANSWER Prevents unauthorized access from remote users who attempt to access a secured environment. Ranges from a dial-back control to remote user authentication. Digital Certificate - CORRECT ANSWER A piece of information, a digitized form of signature, that provides sender authenticity, message integrity and nonrepudiation. A digital signature is generated using the sender's private key or applying a one-way hash function. Digital Signature - CORRECT ANSWER A piece of information, a digitized form of signature, that provides sender authenticity, message integrity and nonrepudiation. A digital signature is generated using the sender's private key or applying a one-way hash function. Disaster Recovery Plan (DRP) - CORRECT ANSWER A set of human, physical, technical and procedural resources to recover, within a defined time and cost, an activity interrupted by an emergency or disaster. Disaster Tolerance - CORRECT ANSWER The time gap during which the business can accept the non-availability of IT facilities Discovery Sampling - CORRECT ANSWER A form of attribute sampling that is used to determine a specified probability of finding at least one example of an occurrence (attribute) in a population Discretionary Access Control (DAC) - CORRECT ANSWER A means of restricting access to objects based on the identity of subjects and/or groups to which they belong. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject. Diskless Workstation - CORRECT ANSWER A workstation or PC on a network that does not have its own disk, but instead stores files on a network file server. Distributed Data Processing Network - CORRECT ANSWER A system of computers connected together by a communications network. Each computer processes its data and the network supports the system as a whole. Such a network enhances communication among the linked computers and allows access to shared files. Diverse Routing - CORRECT ANSWER The method of routing traffic through split cable facilities or duplicate cable facilities. This can be accomplished with different and/or duplicate cable sheaths. If different cable sheaths are used, the cable may be in the same conduit and, therefore, subject to the same interruptions as the cable it is backing up. The communication service subscriber can duplicate the facilities by having alternate routes, although the entrance to and from the customer premises may be in the same conduit. The subscriber can obtain diverse routing and alternate routing from the local carrier, including dual entrance facilities. However, acquiring this type of access is time-consuming and costly. Most carriers provide facilities for alternate and diverse routing, although the majority of services are transmitted over terrestrial media. These cable facilities are usually located in the ground or basement. Ground-based facilities are at great risk due to the aging infrastructures of cities. In addition, cable-based facilities usually share room with mechanical and electrical systems that can impose great risks due to human error and disastrous events. Domain Name System (DNS) - CORRECT ANSWER A hierarchical database that is distributed across the Internet that allows names to be resolved into IP addresses (and vice versa) to locate services such as web and e-mail servers Domain Name System (DNS) Poisoning - CORRECT ANSWER Corrupts the table of an Internet server's DNS, replacing an Internet address with the address of another vagrant or scoundrel address Scope Note: If a web user looks for the page with that address, the request is redirected by the scoundrel entry in the table to a different address. Cache poisoning differs from another form of DNS poisoning in which the attacker spoofs valid email accounts and floods the "n" boxes of administrative and technical contacts. Cache poisoning is related to URL poisoning or location poisoning, in which an Internet user behavior is tracked by adding an identification number to the location line of the browser that can be recorded as the user visits successive pages on the site. ALso called DNS cache poisoning or cache poisoning. Downloading - CORRECT ANSWER The act of transferring computerized information from one computer to another computer Downtime Report - CORRECT ANSWER A report that identifies the elapsed time when a computer is not operating correctly because of machine failure Dry-pipe fire extinguisher system - CORRECT ANSWER Refers to a sprinkler system that does not have water in the pipes during idle usage, unlike a fully charged fire extinguisher system that has water in the pipes at all times Scope Scope Note: The dry-pipe system is activated at the time of the fire alarm and water is emitted to the pipes from a water reservoir for discharge to the location of the fire. Dumb Terminal - CORRECT ANSWER A display terminal without processing capability. Dumb terminals are dependent on the main computer for processing. All entered data are accepted without further editing or validation. Dynamic Host Configuration Protocol (DHCP) - CORRECT ANSWER A protocol used by networked computers (clients) to obtain IP addresses and other parameters such as the default gateway, subnet mask and IP addresses of domain name system (DNS) servers from a DHCP server. The DHCP server ensures that all IP addresses are unique. Thus, IP address pool management is done by the server and not by a human network administrator. Echo Checks - CORRECT ANSWER Detects line errors by retransmitting data back to the sending device for comparison with the original transmission Ecommerce - CORRECT ANSWER The process by which enterprises conduct business electronically with their customers, suppliers and other external business partners, using the Internet as an enabling technology. Ecommerce encompasses both business-business (B2B) and business-to-consumer (B2C) ecommerce models but does not include existing non-Internet Internet ecommerce methods based on private networks, such as electronic data interchange (EDI) and Society for Worldwide Interbank Financial Telecommunication (SWIFT) Edit Control - CORRECT ANSWER Detects errors in the input portion of information that is sent to the computer for processing May be manual or automated and allow the user to edit data errors before processing. Editing - CORRECT ANSWER Ensures that data conform to predetermined criteria and enable early identification of potential errors Electronic Data Interchange (EDI) - CORRECT ANSWER The electronic transmission of transactions (information) between two organizations. EDI promotes a more efficient paperless environment. EDI transmissions can replace the use of standard documents, including invoices or purchase orders. Electronic Funds Transfer (EFT) - CORRECT ANSWER The exchange of money via telecommunications. EFT refers to any financial transaction that originates at a terminal and transfers a sum of money from one account to another. Email/interpersonal Messaging - CORRECT ANSWER An individual using a terminal, PC or an application can access a network to send an unstructured message to another individual or group of people. Embedded Audit Module (EAM) - CORRECT ANSWER Integral part of an application system that is designed to identify and report specific transactions or other information based on pre-determined criteria Identification of reportable items occurs as part of real-time processing. Reporting may be real-time online or may use store and forward methods. Also known as integrated test facility or continuous auditing module. Encapsulation (objects) - CORRECT ANSWER The technique used by layered protocols in which a lower-layer protocol accepts a message from a higher-layer protocol and places it in the data portion of a frame in the lower layer Encryption - CORRECT ANSWER The process of taking an unencrypted message (plaintext), applying a mathematical function to it (encryption algorithm with a key) and producing an encrypted message (ciphertext) Encryption Key - CORRECT ANSWER A piece of information, in a digitized form, used by an encryption algorithm to convert the plaintext to the ciphertext End-user Computing - CORRECT ANSWER The ability of end users to design and implement their own information system utilizing computer software products Enterprise Resource Planning (ERP) - CORRECT ANSWER A packaged business software system that allows an organization to automate and integrate the majority of its business processes, share common data and practices across the entire organization, and produce and access information in a real-time environment. Examples of an ERP include SAP, Oracle Financials and J.D. Edwards Escrow Agent - CORRECT ANSWER A person, agency or organization that is authorized to act on behalf of another to create a legal relationship with a third party in regards to an escrow agreement; the custodian of an asset according to an escrow agreement. As it relates to a cryptographic key, an escrow agent is the agency or organization charged with the responsibility for safeguarding the key components of the unique key. Escrow Agreement - CORRECT ANSWER A legal arrangement whereby an asset (often money, but sometimes other property such as art, a deed off title, web site, ( f software source code or a cryptographic key) is delivered to a third party (called an escrow agent) to be held in trust or otherwise pending a contingency or the fulfillment of a condition or conditions in a contract. Ethernet - CORRECT ANSWER A popular network protocol and cabling scheme that uses a bus topology and carrier sense multiple access/collision detection (CSMA/CD) to prevent network failures or collisions when two devices try to access the network at the same time. Evidence - CORRECT ANSWER The information an auditor gathers in the course of performing an IS audit; relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it is used to support. Exception Reports - CORRECT ANSWER An exception report is generated by a program that identifies transactions or data that appear to be incorrect. Exception reports may be outside a predetermined range or may not conform to specified criteria. Exclusive-OR (XOR) - CORRECT ANSWER The exclusive-OR operator returns a value of TRUE only if just one of its operands is TRUE. The XOR operation is a Boolean operation that produces a 0 if its two Boolean inputs are the same (0 and 0 or 1 and 1) and it produces a 1 if its two inputs are different (1 and 0). In contrast, an inclusive-OR operator returns a value of TRUE if either or both of its operands are TRUE. Executable Code - CORRECT ANSWER The machine language code that is generally referred to as the object or load module Expert System - CORRECT ANSWER The most prevalent type of computer system that arises from the research of artificial intelligence. An expert system has a built-in hierarchy of rules, which are acquired from human experts in the appropriate field. Once input is provided, the system should be able to define the nature of the problem and provide recommendations to solve the problem. Exposure - CORRECT ANSWER The potential loss to an area due to the occurance of an adverse event Extended Binary-coded Decimal Interchange Code (EBCDIC) - CORRECT ANSWER An 8-bit code representing 256 characters; used in most large computer systems Extensible Markup Language (XML) - CORRECT ANSWER Promulgated through the World Wide Web Consortium, XML is a web-based application development technique that allows designers to create their own customized tags, thus enabling the definition, transmission, validation and interpretation of data between applications and organizations Extranet - CORRECT ANSWER A private network that resides on the Internet and allows a company to securely share business information with customers, suppliers, or other businesses as well as to execute electronic transactions. Difference from an intranet in that it is located beyond the company's firewall. Therefore, an extranet relies on the use of securely issued digital certificates (or alternative methods of user authentication) and encryption of messages. A virtual private network (VPN) and tunneling are often used to implement extranets, to ensure security and privacy. Fallback Procedures - CORRECT ANSWER A plan of action or set of procedures to be performed if a system implementation, upgrade or modification does not work as intended. May involve restoring the system to its state prior to the implementation or change. Fallback procedures are needed to ensure that normal business processes continue in the event of failure and should always be considered in system migration or implementation. False Authorization - CORRECT ANSWER Also called false acceptance, occurs when an unauthorized person is identified as an authorized person by the biometric system False Enrollment - CORRECT ANSWER Occurs when an unauthorized person manages to enroll into the biometric system. Enrollment is the initial process of acquiring a biometric feature and saving it as a personal reference on a smart card, a PC or in a central database. Fault Tolerance - CORRECT ANSWER A system's level of resilience to seamlessly react to hardware and/or software failure Feasibility Study - C
Written for
- Institution
- CISA Practice
- Course
- CISA Practice
Document information
- Uploaded on
- March 7, 2024
- Number of pages
- 74
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
-
cisa practice exam 559 questions with answers