
[Nov 22, 2023] 100% Latest Most updated Cybersecurity-Audit-Certificate Questions and Answers
Try with 100% Real Exam Questions and Answers
NEW QUESTION # 22
Which of the following presents the GREATEST challenge to information risk management when outsourcing IT function to a third party?
- A. It is difficult to know the applicable regulatory requirements when data is located on another country.
- B. Providers may be reluctant to share technical delays on the extent of their information protection mechanisms.
- C. It is difficult to determine vendor financial viability to assess their potential inability to meet contract requirements.
- D. Providers may be restricted from providing detailed ^formation on their employees.
Answer: B
Explanation:
Explanation
The GREATEST challenge to information risk management when outsourcing IT function to a third party is that providers may be reluctant to share technical details on the extent of their information protection mechanisms. This is because providers may consider their information protection mechanisms as proprietary or confidential, or may not want to reveal their weaknesses or vulnerabilities. This makes it difficult for the outsourcing organization to assess the level of security and compliance of the provider, and to monitor and audit their performance. The other options are not as challenging as providers being reluctant to share technical details, because they either involve legal or contractual aspects that can be clarified or negotiated before outsourcing (A, D), or human resource aspects that can be verified or validated by the provider C.
NEW QUESTION # 23
Which of the following is a feature of a stateful inspection firewall?
- A. It translates the MAC address to the destination IP address of each packet that enters the organization's internal network.
- B. It tracks the destination IP address of each packet that leaves the organization's internal network.
- C. It is capable of detecting and blocking sophisticated attacks
- D. It prevents any attack initiated and originated by an insider.
Answer: C
Explanation:
Explanation
A feature of a stateful inspection firewall is that it is capable of detecting and blocking sophisticated attacks. A stateful inspection firewall is a type of firewall that monitors and analyzes the state and context of network traffic. It keeps track of the source, destination, protocol, port, and session information of each packet and compares it with a set of predefined rules. A stateful inspection firewall can detect and block attacks that exploit the logic or behavior of network protocols or applications, such as fragmentation attacks, session hijacking, or application-layer attacks.
NEW QUESTION # 24
Which of the following is the MOST important consideration when choosing between different types of cloud services?
- A. Security features available on demand
- B. Emerging risk and infrastructure scalability
- C. Reputation of the cloud providers
- D. Overall risk and benefits
Answer: D
Explanation:
Explanation
The MOST important consideration when choosing between different types of cloud services is the overall risk and benefits. This is because choosing between different types of cloud services involves weighing the trade-offs between the risk and benefits of each type of cloud service, such as Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS). For example, SaaS may offer more benefits in terms of cost savings, scalability, and usability, but also more risks in terms of security, privacy, and compliance. On the other hand, IaaS may offer more benefits in terms of flexibility, customization, and control, but also more risks in terms of complexity, management, and maintenance. The other options are not the most important consideration when choosing between different types of cloud services, but rather different aspects or factors that affect the choice of cloud services, such as emerging risk and infrastructure scalability (A), security features available on demand (B), or reputation of the cloud providers (D).
NEW QUESTION # 25
Which of the following is MOST important to verify when reviewing the effectiveness of an organization's identity management program?
- A. Processes are approved by the process owner.
- B. Processes are updated and documented annually.
- C. Processes are aligned with industry best practices.
- D. Processes are centralized and standardized.
Answer: C
Explanation:
Explanation
The MOST important thing to verify when reviewing the effectiveness of an organization's identity management program is whether the processes are aligned with industry best practices. Identity management is the process of managing the identities and access rights of users across an organization's systems and resources. Industry best practices provide guidelines and standards for how to implement identity management in a secure, efficient, and compliant manner.
NEW QUESTION # 26
Which of the following is a client-server program that opens a secure, encrypted command-line shell session from the Internet for remote logon?
- A. SSH
- B. VPN
- C. IPsec
- D. SFTP
Answer: A
Explanation:
Explanation
The correct answer is C. SSH.
SSH stands for Secure Shell, a client-server program that opens a secure, encrypted command-line shell session from the Internet for remote logon. SSH allows users to remotely access and execute commands on a server without exposing their credentials or data to eavesdropping, tampering or replay attacks. SSH also supports secure file transfer protocols such as SFTP and SCP1.
VPN stands for Virtual Private Network, a technology that creates a secure, encrypted tunnel between two or more devices over a public network such as the Internet. VPN allows users to access resources on a remote network as if they were physically connected to it, while protecting their privacy and identity2.
IPsec stands for Internet Protocol Security, a set of protocols that provides security at the network layer of the Internet. IPsec supports two modes: transport mode and tunnel mode. Transport mode encrypts only the payload of each packet, while tunnel mode encrypts the entire packet, including the header. IPsec can be used to secure VPN connections, as well as other applications that require data confidentiality, integrity and authentication3.
SFTP stands for Secure File Transfer Protocol, a protocol that uses SSH to securely transfer files between a client and a server over a network. SFTP provides encryption, authentication and compression features to ensure the security and reliability of file transfers.
1: SSH (Secure Shell) 2: What is a VPN? How It Works, Types of VPN | Kaspersky 3: IPsec - Wikipedia :
[SFTP - Wikipedia]
NEW QUESTION # 27
A healthcare organization recently acquired another firm that outsources its patient information processing to a third-party Software as a Service (SaaS) provider. From a regulatory perspective, which of the following is MOST important for the healthcare organization to determine?
- A. Physical location of the data
- B. Incident escalation procedures
- C. Encryption algorithms used to encrypt the data
- D. Cybersecurity risk assessment methodology
Answer: B
Explanation:
Explanation
From a regulatory perspective, the MOST important thing for the healthcare organization to determine when outsourcing its patient information processing to a third-party Software as a Service (SaaS) provider is the incident escalation procedures. This is because incident escalation procedures define how security incidents involving patient information are reported, communicated, escalated, and resolved between the healthcare organization and the SaaS provider. This is essential for complying with regulatory requirements such as HIPAA, which mandate timely notification and response to breaches of protected health information. The other options are not as important as incident escalation procedures from a regulatory perspective, because they either relate to technical aspects that may not affect compliance (A, B), or operational aspects that may not affect patient information security (D).
NEW QUESTION # 28
Which of the following is the SLOWEST method of restoring data from backup media?
- A. Differential Backup
- B. Monthly backup
- C. Full backup
- D. Incremental backup
Answer: D
Explanation:
Explanation
The SLOWEST method of restoring data from backup media is an incremental backup. This is because an incremental backup is a type of backup that only copies the files that have been created or modified since the previous backup, whether it was a full or an incremental backup. An incremental backup makes the restoration process slower, as it requires restoring multiple backups in a specific order and sequence, starting from the last full backup and then applying each incremental backup until the desired point in time is reached. The other options are not methods of restoring data from backup media that are slower than an incremental backup, but rather different types of backup procedures that copy files based on different criteria, such as monthly backup (A), full backup (B), or differential backup C.
NEW QUESTION # 29
Security awareness training is MOST effective against which type of threat?
- A. Command injection
- B. Social engineering
- C. Social injection
- D. Denial of service
Answer: B
Explanation:
Explanation
Security awareness training is MOST effective against social engineering threats. This is because social engineering is a type of attack that exploits human psychology and behavior to manipulate or trick users into revealing sensitive or confidential information, or performing actions that compromise security. Security awareness training helps to educate users about the common types and techniques of social engineering attacks, such as phishing, vishing, baiting, etc., and how to recognize and avoid them. Security awareness training also helps to foster a culture of security within the organization and empower users to report any suspicious or malicious activities. The other options are not types of threats that security awareness training is most effective against, but rather types of attacks that exploit technical vulnerabilities or flaws in systems or applications, such as command injection (A), denial of service (B), or SQL injection (D).
NEW QUESTION # 30
Which of the following is a limitation of intrusion detection systems (IDS)?
- A. Weak passwords for the administration console
- B. Application-level vulnerabilities
- C. Lack of Interface with system tools
- D. Limited evidence on intrusive activity
Answer: B
Explanation:
Explanation
A limitation of intrusion detection systems (IDS) is that they cannot detect application-level vulnerabilities. An IDS is a tool that monitors network traffic or system activity and alerts on any suspicious or malicious events.
However, an IDS cannot analyze the logic or functionality of applications and identify vulnerabilities such as SQL injection, cross-site scripting, or broken authentication.
NEW QUESTION # 31
Which of the following cloud characteristics refers to resource utilization that can be optimized by leveraging charge-per-use capabilities?
- A. Elasticity
- B. On demand self-service
- C. Measured service
- D. Resource pooling
Answer: C
Explanation:
Explanation
The cloud characteristic that refers to resource utilization that can be optimized by leveraging charge-per-use capabilities is measured service. This is because measured service is a characteristic of cloud computing that involves monitoring, controlling, and reporting on the usage and consumption of cloud resources by cloud providers and consumers. Measured service helps to optimize resource utilization by leveraging charge-per-use capabilities, which means that cloud consumers only pay for the amount of resources that they actually use or consume, rather than paying for fixed or predetermined amounts of resources. The other options are not cloud characteristics that refer to resource utilization that can be optimized by leveraging charge-per-use capabilities, but rather different characteristics of cloud computing that describe other aspects or benefits of cloud services, such as on demand self-service (A), elasticity (B), or resource pooling (D).
NEW QUESTION # 32
Which of the following BIST enables continuous identification and mitigation of security threats to an organization?
- A. demit/ and access management (1AM)
- B. Security training and awareness
- C. Security operations center (SOC)
- D. Security information and event management (SEM)
Answer: C
Explanation:
Explanation
A security operations center (SOC) is a centralized unit that monitors, detects, analyzes, and responds to cyber threats and incidents in real time. A SOC enables continuous identification and mitigation of security threats to an organization by using various tools, processes, and expertise.
NEW QUESTION # 33
The protection of information from unauthorized access or disclosure is known as:
- A. media protect on.
- B. access control.
- C. cryptograph
- D. confidentiality.
Answer: D
Explanation:
Explanation
The protection of information from unauthorized access or disclosure is known as confidentiality. This is because confidentiality is one of the three main objectives of information security, along with integrity and availability. Confidentiality ensures that information is accessible and readable only by those who are authorized and intended to do so, and prevents unauthorized or accidental exposure of information to unauthorized parties. The other options are not the protection of information from unauthorized access or disclosure, but rather different concepts or techniques that are related to information security, such as access control (A), cryptography (B), or media protection C.
NEW QUESTION # 34
What would be an IS auditor's BEST response to an IT managers statement that the risk associated with the use of mobile devices in an organizational setting is the same as for any other device?
- A. The ability to wipe mobile devices and disable connectivity adequately mitigates additional
- B. The risk associated with mobile devices is less than that of other devices and systems.
- C. Replication of privileged access and the greater likelihood of physical loss increases risk levels.
- D. The risk associated with mobile devices cannot be mitigated with similar controls for workstations.
Answer: C
Explanation:
Explanation
The BEST response to an IT manager's statement that the risk associated with the use of mobile devices in an organizational setting is the same as for any other device is that replication of privileged access and the greater likelihood of physical loss increases risk levels. Mobile devices pose unique risks to an organization due to their portability, connectivity, and functionality. Mobile devices may store or access sensitive data or systems that require privileged access, which can be compromised if the device is lost, stolen, or hacked. Mobile devices also have a higher chance of being misplaced or taken by unauthorized parties than other devices.
NEW QUESTION # 35
What is the MAIN consideration when storing backup files?
- A. Protecting the off-site data backup copies from unauthorized access
- B. Utilizing solid slate device (SSDJ media for quick recovery
- C. Storing backup files on public cloud storage
- D. Storing copies on-site for ease of access during incident response
Answer: A
Explanation:
Explanation
The MAIN consideration when storing backup files is protecting the off-site data backup copies from unauthorized access. This is because protecting the off-site data backup copies from unauthorized access helps to ensure the confidentiality and integrity of the backup data, and prevent any unauthorized or malicious disclosure, modification, or deletion of the backup data. Protecting the off-site data backup copies from unauthorized access also helps to comply with any regulatory or contractual requirements that may apply to the backup data. The other options are not the main consideration when storing backup files, but rather different aspects or factors that affect the backup process, such as using solid state device (SSD) media (A), storing backup files on public cloud storage (B), or storing copies on-site (D).
NEW QUESTION # 36
What is the FIRST activity associated with a successful cyber attack?
- A. Exploitation
- B. Reconnaissance
- C. Maintaining a presence
- D. Creating attack tools
Answer: B
Explanation:
Explanation
The FIRST activity associated with a successful cyber attack is reconnaissance. This is because reconnaissance is a phase of the cyber attack lifecycle that involves gathering information about the target organization or system, such as its network topology, IP addresses, open ports, services, vulnerabilities, etc. Reconnaissance helps to identify potential entry points and weaknesses that can be exploited by the attackers in later phases of the attack. The other options are not the first activity associated with a successful cyber attack, but rather follow after reconnaissance in the cyber attack lifecycle, such as exploitation (A), maintaining a presence C, or creating attack tools (D).
NEW QUESTION # 37
Which of the following is the GREATEST advantage of using a virtual private network (VPN) over dedicated circuits and dial-in servers?
- A. It is more cost effective.
- B. It is more secure
- C. It is higher speed.
- D. It is more reliable
Answer: A
Explanation:
Explanation
The GREATEST advantage of using a virtual private network (VPN) over dedicated circuits and dial-in servers is that it is more cost effective. This is because a VPN is a technology that creates a secure and encrypted connection between a client and a server over an existing public network, such as the Internet. A VPN reduces the cost of establishing and maintaining a secure communication channel, as it does not require any additional hardware, software, or infrastructure, unlike dedicated circuits and dial-in servers, which require dedicated lines, modems, routers, switches, etc. The other options are not the greatest advantage of using a VPN over dedicated circuits and dial-in servers, because they either involve security (A), reliability (B), or speed C aspects that may not be significantly different or better than dedicated circuits and dial-in servers.
NEW QUESTION # 38
Which of the following is the MOST important step to determine the risks posed to an organization by social media?
- A. Review costs related to the organization's social media outages.
- B. Review access control processes for the organization's social media accounts.
- C. Review the disaster recovery strategy for the organization's social media.
- D. Review cybersecurity insurance requirements for the organization s social media.
Answer: B
Explanation:
Explanation
The MOST important step to determine the risks posed to an organization by social media is to review access control processes for the organization's social media accounts. This is because access control processes help to ensure that only authorized users can access, modify, or share the organization's social media accounts and content, and prevent unauthorized or malicious access or disclosure of sensitive or confidential information.
Access control processes also help to protect the organization's reputation and brand image from being compromised or damaged by unauthorized or inappropriate social media posts. The other options are not as important as reviewing access control processes for the organization's social media accounts, because they either relate to costs (A), insurance (B), or recovery C aspects that are not directly related to the risks posed by social media.
NEW QUESTION # 39
Which of the following is the GREATEST risk pertaining to sensitive data leakage when users set mobile devices to "always on" mode?
- A. An adversary can predict a user's login credentials.
- B. Authorization tokens could be exploited.
- C. A user's behavior pattern can be predicted.
- D. Mobile connectivity could be severely weakened.
Answer: B
Explanation:
Explanation
The GREATEST risk pertaining to sensitive data leakage when users set mobile devices to "always on" mode is that authorization tokens could be exploited. Authorization tokens are pieces of data that are used to authenticate users and grant them access to certain resources or services. Authorization tokens are often stored on mobile devices to enable seamless and convenient access without requiring users to enter their credentials repeatedly. However, if users set their mobile devices to "always on" mode, they increase the risk of losing their devices or having them stolen by attackers. Attackers can then access the authorization tokens stored on the devices and use them to impersonate the users or access their sensitive data.
NEW QUESTION # 40
Using digital evidence to provide validation that an attack has actually occurred is an example of;
- A. extraction.
- B. identification.
- C. computer forensic
- D. data acquisition.
Answer: C
Explanation:
Explanation
Using digital evidence to provide validation that an attack has actually occurred is an example of computer forensics. This is because computer forensics is a discipline that involves the identification, preservation, analysis, and presentation of digital evidence from various sources, such as computers, networks, mobile devices, etc., to support investigations of cyber incidents or crimes. Computer forensics helps to provide validation that an attack has actually occurred, by examining the digital traces or artifacts left by the attackers on the compromised systems or devices, and by reconstructing the sequence and timeline of events that led to the attack. The other options are not examples of using digital evidence to provide validation that an attack has actually occurred, but rather different techniques or processes that are related to computer forensics, such as extraction (B), identification C, or data acquisition (D).
NEW QUESTION # 41
Which type of tools look for anomalies in user behavior?
- A. Audit reduction tools
- B. Trend/variance-detection tools
- C. Attack-signature-detection tools
- D. Rootkit detection tools
Answer: B
Explanation:
Explanation
Trend/variance-detection tools are tools that look for anomalies in user behavior. These tools use statistical methods to establish a baseline of normal user activity and then compare it with current or historical data to identify deviations or outliers. These tools can help to detect unauthorized access, fraud, insider threats, or other malicious activities.
NEW QUESTION # 42
In cloud computing, which type of hosting is MOST appropriate for a large organization that wants greater control over the environment?
- A. Shared hosting
- B. Private hosting
- C. Public hosting
- D. Hybrid hosting
Answer: B
Explanation:
Explanation
In cloud computing, the type of hosting that is MOST appropriate for a large organization that wants greater control over the environment is private hosting. Private hosting is a type of cloud service model where the cloud infrastructure is dedicated to a single organization and hosted either on-premise or off-premise by a third-party provider. Private hosting offers more control over the security, performance, customization, and compliance of the cloud environment than other types of hosting.
NEW QUESTION # 43
......
New ISACA Cybersecurity-Audit-Certificate Dumps & Questions: https://www.practicetorrent.com/Cybersecurity-Audit-Certificate-practice-exam-torrent.html
Dumps to Pass your Cybersecurity-Audit-Certificate Exam with 100% Real Questions and Answers: https://drive.google.com/open?id=1AW4J_KwdpAXJggkM1D2xV-2fu0V_zEQa