Published - Fri, 03 Mar 2023

CISA—Certified Information Systems Auditor - Part 114

CISA—Certified Information Systems Auditor - Part 114

1. Which of the following is NOT a disadvantage of Single Sign On (SSO)?

A) Support for all major operating system environment is difficult
B) The cost associated with SSO development can be significant
C) SSO could be single point of failure and total compromise of an organization asset
D) SSO improves an administrator's ability to manage user's account and authorization to all associated system



2. An IS auditor is reviewing the remote access methods of a company used to access system remotely. Which of the following is LEAST preferred remote access method from a security and control point of view?

A) RADIUS
B) TACACS
C) DIAL-UP
D) DIAMETER



3. There are many types of audit logs analysis tools available in the market. Which of the following audit logs analysis tools will look for anomalies in user or system behavior?

A) Attack Signature detection tool
B) Variance detection tool
C) Audit Reduction tool
D) Heuristic detection tool



4. As an IS auditor, it is very important to make sure all storage media are well protected. Which of the following is the LEAST important factor for protecting CDs andDVDs?

A) Handle by edges or by the hole in the middle
B) Store in anti-static bag
C) Avoid long term exposure to bright light
D) Store in a hard jewel case, not in soft sleeves



5. As an auditor it is very important to ensure confidentiality, integrity, authenticity and availability are implemented appropriately in an information system. Which of the following definitions incorrectly describes these parameters?1. Authenticity '' A third party must be able to verify that the content of a message has been sent by a specific entity and nobody else.2. Non-repudiation '' The origin or the receipt of a specific message must be verifiable by a third party. A person cannot deny having sent a message if the message is signed by the originator.3. Accountability '' The action of an entity must be uniquely traceable to different entities4. Availability '' The IT resource must be available on a timely basis to meet mission requirements or to avoid substantial losses.

A) All of the options presented
B) None of the options presented
C) Options number 1 and 2
D) Option number 3



1. Right Answer: D
Explanation: Single sign-on (SSO)is a Session/user authentication process that permits a user to enter one name and password in order to access multiple applications. The process authenticates the user for all the applications they have been given rights to and eliminates further prompts when they switch applications during a particular session.SSO Advantages include -Multiple passwords are no longer requiredIt improves an administrator's ability to manage user's accounts and authorization to all associated systemsIt reduces administrative overhead in resetting forgotten password over multiple platforms and applicationsIt reduces time taken by users to logon into multiple application and platformSSO Disadvantages include -Support for all major operating system is difficultThe cost associated with SSO development can be significant when considering the nature and extent of interface development and maintenance that may be necessaryThe centralize nature of SSO presents the possibility of a single point of failure and total compromise of an organization's information asset.The following reference(s) were/was used to create this question:CISA review manual 2014 Page number 332

2. Right Answer: C
Explanation: Dial-up connectivity not based on centralize control and least preferred from security and control standpoint.Remote access user can connect remotely to their organization's networks with the same level of functionality as if they would access from within their office.In connecting to an organization's network, a common method is to use dial-up lines. Access is granted through the organization's network access server (NAS) working in concert with an organization network firewall and router. The NAS handle user authentication, access control and accounting while maintaining connectivity. The most common protocol for doing this is the Remote Access Dial-In User Service (RADIUS) and Terminal Access Controller Access ControllerSystem (TACACS).Remote access Controls include:Policy and standard -Proper authorization -Identification and authentication mechanismEncryption tool and technique such as use of VPNSystem and network management -The following reference(s) were/was used to create this question:CISA Review Manual 2014 Page number 334

3. Right Answer: B
Explanation: Trend/Variance Detection tool are used to look for anomalies in user or system behavior. For example, if a user typically logs in at 9:00 am, but one day suddenly access the system at 4:30 am, this may indicate a security problem that may need to be investigated.Other types of audit trail analysis tools should also be known for your CISA examThe following were incorrect answers:Audit Reduction tool - They are preprocessor designed to reduce the volume of audit records to facilitate manual review. Before a security review, these tool can remove many audit records known to have little security significance.Attack-signature detection tool - They look for an attack signature, which is a specific sequence of events indicative of an unauthorized access attempt. A simple example would be repeated failed logon attempts.Heuristic detection tool - Heuristic analysis is an expert based analysis that determines the susceptibility of a system towards particular threat/risk using various decision rules or weighing methods. MultiCriteria analysis (MCA) is one of the means of weighing. This method differs with statistical analysis, which bases itself on the available data/statistics.The following reference(s) were/was used to create this question:CISA review manual 2014 Page number 336andhttp://en.wikipedia.org/wiki/Heuristic_analysis

4. Right Answer: B
Explanation: CDs and DVDs are least affected by static current so it is not as important to store them into anti-static bags.CDs and DVDs Storage protection recommendations:Handle by edges or by hole in the middleBe careful not to bend the CD or DVDAvoid long term exposure to bright lightStore in a hard jewel case, not is soft sleevesAlso, you should know the media storage precautions listed below in preparation for the CISA exam:USB and portable hard drive -Avoid high temperature, humidity extremes and strong magnetic fieldTape Cartridges -Store Cartridges vertically -Store cartridges in a protective container for transportWrite-protect cartridges immediatelyHard Drive -Store hard drives in anti-static bags, and be sure that person removing them from bag is static freeIf the original box and padding for the hard drive is available, use it for shippingIf the hard drive has been in a cold environment, bring it to room temperature prior to installing and using itThe following reference(s) were/was used to create this question:Reference used - CISA review manual 2014. Page number 338

5. Right Answer: D
Explanation: It is important to read carefully the question. The word 'incorrectly' was the key word. You had to find which one of the definitions presented is incorrect. The definition of Accountability was NOT properly described. Below you have the proper definition.The correct definitions are as followsAuthenticity '' A third party must be able to verify that the content of a message is from a specific entity and nobody else.Non-repudiation '' The origin or the receipt of a specific message must be verifiable by a third party. A person cannot deny having sent a message if the message is signed by the originator.Accountability '' The action of an entity must be uniquely traceable to that entityNetwork availability '' The IT resource must be available on a timely basis to meet mission requirements or to avoid substantial losses.The following reference(s) were/was used to create this question:CISA review manual 2014 Page number 34

Comments (0)

Search
Popular categories
Latest blogs
CA Foundation Business Economics Questions 2023 - Part 32
CA Foundation Business Economics Questions 2023 - Part 32
Questions 1. Generally an economy is considered under developed ifA) The standard of living of people & Productivity is low.B) Agriculture is the main occupation of the peopleC) The production techniques are backward.D) All of the above.2. Which of the following statement is correct?A) Agriculture occupies 10 per cent population of India.B) Nearly 5 per cent population of India is below the poverty line.C) The production techniques in agriculture are backward.D) None of the above.3. Which of the statements is correct?A) The tertiary sector contributes the maximum to the GDP.B) India is basically a socialist economy.C) The distribution of income and wealth is quite equitable.D) None of the above.4. In perfect competition in the short run there will be __________ possibilitiesA) Normal profits.B) Supernormal profits.C) LossD) All of above5. ______________ measure generally gives the lowest estimate of unemployment especially for poor economy.A) Usual status.B) CWS.C) CDS.D) CMS. Right Answer and Explanation: 1. Right Answer: DExplanation: 2. Right Answer: CExplanation: 3. Right Answer: AExplanation: 4. Right Answer: DExplanation: 5. Right Answer: AExplanation: .col-md-12 { -webkit-user-select: none; -ms-user-select: none; user-select: none; } .flash-sale-container{background:#134981;text-align:center;padding:2%;} p.flash-sale-text{ font-size:24px;font-family:"Poppins";letter-spacing:2px;line-height:1.4em; } span.flash-break{ display:block; } .flash-sale-text { -webkit-animation-name:flash; animation: blink 1.5s infinite; } @keyframes blink{ 0% { color: #D3585F; } 20% { color: #D3585F; } 40% { color: #FFF; } 60% { color: #FFF; } 80% { color: #D3585F; } 100% { color: #D3585F; } } @-webkit-keyframes blink{ 0% { color: #D3585F; } 20% { color: #D3585F; } 40% { color: #FFF; } 60% { color: #FFF; } 80% { color: #D3585F; } 100% { color: #D3585F; } }

Fri, 03 Mar 2023

CA Foundation Business Economics Questions 2023 - Part 31
CA Foundation Business Economics Questions 2023 - Part 31
Questions 1. When the price of a complementary of commodity X falls, the demand for X-A) FallsB) RisesC) Remains unchangedD) any of the above2. Which of the following is the method of measuring elasticity of demand when change in price of a commodity is substantial?A) Arc methodB) Point methodC) Percentage methodD) none of the above3. FERA stands for -A) Foreign Exchange Recommendation ActB) Foreign Exchange Regulation ActC) Finance and Export Regulation AssociationD) Funds Export Revaluation Act4. Nearly _____percent of working population is engaged in the service sector.A) 23 per centB) 45 per centC) 80 per centD) 50 per cent5. ACRP stands for â??A) Agro-Commodity Regional PlanningB) Agro-Climatic Rational PlanningC) Agro-Climatic Regional PlanningD) Allied-Climatic Regional Planning Right Answer and Explanation: 1. Right Answer: BExplanation: 2. Right Answer: AExplanation: 3. Right Answer: BExplanation: 4. Right Answer: AExplanation: 5. Right Answer: CExplanation: .col-md-12 { -webkit-user-select: none; -ms-user-select: none; user-select: none; } .flash-sale-container{background:#134981;text-align:center;padding:2%;} p.flash-sale-text{ font-size:24px;font-family:"Poppins";letter-spacing:2px;line-height:1.4em; } span.flash-break{ display:block; } .flash-sale-text { -webkit-animation-name:flash; animation: blink 1.5s infinite; } @keyframes blink{ 0% { color: #D3585F; } 20% { color: #D3585F; } 40% { color: #FFF; } 60% { color: #FFF; } 80% { color: #D3585F; } 100% { color: #D3585F; } } @-webkit-keyframes blink{ 0% { color: #D3585F; } 20% { color: #D3585F; } 40% { color: #FFF; } 60% { color: #FFF; } 80% { color: #D3585F; } 100% { color: #D3585F; } }

Fri, 03 Mar 2023

CA Foundation Business Economics Questions 2023 - Part 30
CA Foundation Business Economics Questions 2023 - Part 30
Questions 1. Literacy rate calculated considering total population into account is known asA) Crude Literacy RateB) Total Literacy RateC) Mean Literacy RateD) None of the above2. In order to encourage investment in the economy, the RBI mayA) Increase Bank RateB) Sell securities in the open marketC) Buy securities in the open marketD) None of above3. Most of unemployment in India is __________A) VoluntaryB) StructuralC) FrictionalD) Technical4. Under a Command economy â??A) State plays a major roleB) Market plays major roleC) Both a & bD) Neither a nor b5. _______is the apex bank for agriculture credit in India.A) RBIB) SIDBIC) NABARDD) ICICI Right Answer and Explanation: 1. Right Answer: AExplanation: 2. Right Answer: CExplanation: 3. Right Answer: BExplanation: 4. Right Answer: AExplanation: 5. Right Answer: CExplanation: .col-md-12 { -webkit-user-select: none; -ms-user-select: none; user-select: none; } .flash-sale-container{background:#134981;text-align:center;padding:2%;} p.flash-sale-text{ font-size:24px;font-family:"Poppins";letter-spacing:2px;line-height:1.4em; } span.flash-break{ display:block; } .flash-sale-text { -webkit-animation-name:flash; animation: blink 1.5s infinite; } @keyframes blink{ 0% { color: #D3585F; } 20% { color: #D3585F; } 40% { color: #FFF; } 60% { color: #FFF; } 80% { color: #D3585F; } 100% { color: #D3585F; } } @-webkit-keyframes blink{ 0% { color: #D3585F; } 20% { color: #D3585F; } 40% { color: #FFF; } 60% { color: #FFF; } 80% { color: #D3585F; } 100% { color: #D3585F; } }

Fri, 03 Mar 2023

All blogs