Skip to main content

CYBERSECURITY-AUDIT-CERTIFICATE Real Exam Questions

ISACA Cybersecurity Audit Certificate

134 questions available · Page 1 of 14

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which of the following should an IS auditor do FIRST to ensure cyber security-related legal and regulatory requirements are followed by an organization?

  1. A

    Determine if the cybersecurity program is mapped to relevant legal and regulatory requirements.

  2. B

    Review the most recent legal and regulatory audit report conducted by an independent party.

  3. C

    Determine if there is a formal process to review changes in legal and regulatory requirements.
    D Obtain a list of relevant legal and regulatory requirements.

Show answer and explanation

Correct answer: A

Question 2 Single choice

What would be an IS auditor's BEST response to an IT managers statement that the risk associated with the use of mobile devices in an organizational setting is the same as for any other device?

  1. A

    Replication of privileged access and the greater likelihood of physical loss increases risk levels.

  2. B

    The risk associated with mobile devices is less than that of other devices and systems.

  3. C

    The risk associated with mobile devices cannot be mitigated with similar controls for workstations.

  4. D

    The ability to wipe mobile devices and disable connectivity adequately mitigates additional

Show answer and explanation

Correct answer: A

Question 3 Single choice

Which of the following is an example of an application security control?

  1. A

    Secure coding

  2. B

    User security awareness training

  3. C

    Security operations center

  4. D

    Intrusion detection

Show answer and explanation

Correct answer: A

Question 4 Single choice

Which of the following is the MOST important step to determine the risks posed to an organization by social media?

  1. A

    Review costs related to the organization's social media outages.

  2. B

    Review cybersecurity insurance requirements for the organization s social media.

  3. C

    Review the disaster recovery strategy for the organization's social media.

  4. D

    Review access control processes for the organization's social media accounts.

Show answer and explanation

Correct answer: D

Question 5 Single choice

A healthcare organization recently acquired another firm that outsources its patient information processing to a third-party Software as a Service (SaaS) provider.
From a regulatory perspective, which of the following is MOST important for the healthcare organization to determine?

  1. A

    Cybersecurity risk assessment methodology

  2. B

    Encryption algorithms used to encrypt the data

  3. C

    Incident escalation procedures

  4. D

    Physical location of the data

Show answer and explanation

Correct answer: C

Question 6 Single choice

Which of the following is the SLOWEST method of restoring data from backup media?

  1. A

    Monthly backup

  2. B

    Full backup

  3. C

    Differential Backup

  4. D

    Incremental backup

Show answer and explanation

Correct answer: D

Question 7 Single choice

At which layer in the open systems interconnection (OSI) model does SSH operate?

  1. A

    Presentation

  2. B

    Session

  3. C

    Application

  4. D

    Network

Show answer and explanation

Correct answer: C

Question 8 Single choice

One way to control the integrity of digital assets is through the use of:

  1. A

    policies.

  2. B

    hashing.

  3. C

    caching.

  4. D

    frameworks.

Show answer and explanation

Correct answer: B

Question 9 Single choice

When passwords are tied into key generation, the strength of the encryption algorithm is:

  1. A

    voided.

  2. B

    increased.

  3. C

    diminished.

  4. D

    maintained.

Show answer and explanation

Correct answer: D

Question 10 Single choice

The GREATEST benefit of using the CSA Cloud Controls Matrix is that it provides:

  1. A

    a mapping to multiple control frameworks.

  2. B

    severity rankings for identified deficiencies.

  3. C

    templates of vetted cloud auditing programs.

  4. D

    control specifications prioritized by importance.

Show answer and explanation

Correct answer: A