FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. ISACA Certification
  3. CISA Exam
  4. ISACA.CISA.v2023-03-04.q546 Dumps
  • ««
  • «
  • …
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • …
  • »
  • »»
Download Now

Question 91

An IS auditor evaluating a three-tier client/server architecture observes an issue with graphical user interface (GUI) tasks. Which layer should the auditor recommend the client address?

Correct Answer: A
Section: The process of Auditing Information System
insert code

Question 92

Which of the following statement correctly describes difference between packet filtering firewall and stateful inspection firewall?

Correct Answer: A
Explanation/Reference:
Packet Filtering Firewall
Also Known as First Generation Firewall
Do not maintain client session
The advantage of this type of firewall are simplicity and generally stable performance since the filtering rules are performed at the network layer.
Its simplicity is also disadvantage, because it is vulnerable to attack from improperly configured filters and attack tunneled over permitted services.
Some of the more common attack on packet filtering are IP Spoofing, Source Routing specification, Miniature fragment attack.
Stateful Inspection Firewall
A stateful inspection firewall keep track of the destination IP address of each packet that leaves the organization's internal network.
The session tracking is done by mapping the source IP address of incoming packet with the list of destination IP addresses that is maintained and updated
This approach prevent any attack initiated and originated by outsider.
The disadvantage includes stateful inspection firewall can be relatively complex to administer as compare to other firewall.
The following were incorrect answers:
All other choices presented were incorrect answers because they all had the proper definition.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 345 and 346
insert code

Question 93

An IS auditor is evaluating management's risk assessment of information systems. The IS auditor should FIRST review:

Correct Answer: D
Explanation/Reference:
Explanation:
One of the key factors to be considered while assessing the risks related to the use of various information systems is the threats and vulnerabilities affecting the assets. The risks related to the use of information assets should be evaluated in isolation from the installed controls. Similarly, the effectiveness of the controls should be considered during the risk mitigation stage and not during the risk assessment phase A mechanism to continuously monitor the risks related to assets should be put in place during the risk monitoring function that follows the risk assessment phase.
insert code

Question 94

Which of the following is the dominating objective of BCP and DRP?

Correct Answer: A
Section: Protection of Information Assets
Explanation:
Although the primary business objective of BCP and DRP is to mitigate the risk and impact of a business interruption, the dominating objective remains the protection of human life.
insert code

Question 95

When should reviewing an audit client's business plan be performed relative to reviewing an organization's IT strategic plan?

Correct Answer: A
Explanation/Reference:
Explanation:
Reviewing an audit client's business plan should be performed before reviewing an organization's IT strategic plan.
insert code
  • ««
  • «
  • …
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download ISACA.CISA.v2023-03-04.q546 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.