Isaca Cybersecurity Audit Certificate Cybersecurity-Audit-Certificate Exam Questions

Page: 1 / 14
Total 134 questions
Question 1

When performing a teaming exercise, which team works to integrate the defensive tactics and controls from the defending team with the threats and vulnerabilities found by the attacking team?



Answer : C

In a teaming exercise, the purple team is responsible for integrating the defensive tactics and controls from the blue team (defensive) with the threats and vulnerabilities found by the red team (attacking). The purple team's role is to ensure that the defense mechanisms are effective against the identified threats and to improve the overall security posture of the organization.They work collaboratively with both the red and blue teams to provide a comprehensive view of the organization's security readiness1.


Question 2

The "recover" function of the NISI cybersecurity framework is concerned with:



Answer : A

The ''recover'' function of the NIST cybersecurity framework is concerned with planning for resilience and timely repair of compromised capacities and service. This is because the recover function helps organizations to restore normal operations as quickly as possible after a cybersecurity incident, while also learning from the incident and improving their security posture. The other options are not part of the recover function, but rather belong to the identify (B), respond C, or protect (D) functions.


Question 3

What is the PRIMARY purpose of creating a security architecture?



Answer : B

The PRIMARY purpose of creating a security architecture is to create a long-term information security strategy that aligns with the organization's business goals and objectives. A security architecture defines the vision, principles, standards, policies, and guidelines for how security will be implemented and managed across the organization's systems, networks, and data.


Question 4

Which of the following is MOST important to verify when reviewing the effectiveness of an organization's identity management program?



Answer : B

The MOST important thing to verify when reviewing the effectiveness of an organization's identity management program is whether the processes are aligned with industry best practices. Identity management is the process of managing the identities and access rights of users across an organization's systems and resources. Industry best practices provide guidelines and standards for how to implement identity management in a secure, efficient, and compliant manner.


Question 5

Which of the following is an attack attribute of an advanced persistent threat (APT) that is designed to remove data from systems and networks?



Answer : B

An example of an attack attribute of an advanced persistent threat (APT) that is designed to remove data from systems and networks is anexfiltration attack vector. An exfiltration attack vector is a method or channel that an APT uses to transfer data from a compromised system or network to an external location. Examples of exfiltration attack vectors include email, FTP, DNS, HTTP, or covert channels.


Question 6

Which of the following is an example of an application security control?



Answer : A

An example of an application security control issecure coding. Secure coding is the practice of developing software applications that follow security principles and standards to prevent or mitigate common vulnerabilities and risks. Secure coding involves applying techniques such as input validation, output encoding, error handling, encryption, and testing.


Question 7

Which of the following presents the GREATEST challenge to information risk management when outsourcing IT function to a third party?



Answer : B

The GREATEST challenge to information risk management when outsourcing IT function to a third party is that providers may be reluctant to share technical details on the extent of their information protection mechanisms. This is because providers may consider their information protection mechanisms as proprietary or confidential, or may not want to reveal their weaknesses or vulnerabilities. This makes it difficult for the outsourcing organization to assess the level of security and compliance of the provider, and to monitor and audit their performance. The other options are not as challenging as providers being reluctant to share technical details, because they either involve legal or contractual aspects that can be clarified or negotiated before outsourcing (A, D), or human resource aspects that can be verified or validated by the provider C.


Page:    1 / 14   
Total 134 questions