FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. ISACA Certification
  3. CISA Exam
  4. ISACA.CISA.v2023-03-04.q546 Dumps
  • ««
  • «
  • …
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • …
  • »
  • »»
Download Now

Question 181

An IS auditor recommends that an initial validation control be programmed into a credit card transaction capture application. The initial validation process would MOST likely:

Correct Answer: B
The initial validation should confirm whether the card is valid. This validity is established through the card number and PIN entered by the user. Based on this initial validation, all other validations will proceed. A validation control in data capture will ensure that the data entered is valid (i.e., it can be processed by the system). If the data captured in the initial validation is not valid (if the card number or PIN do not match with the database), then the card will be rejected or captured per the controls in place. Once initial validation is completed, then other validations specific to the card and cardholder would be performed.
insert code

Question 182

Which of the following malware technical fool's malware by appending section of themselves to files -
somewhat in the same way that file malware appends themselves?

Correct Answer: C
Section: Protection of Information Assets
Explanation/Reference:
Immunizers defend against malware by appending sections of themselves to files - sometime in the same
way Malware append themselves. Immunizers continuously check a file for changes and report changes as
possible malware behavior. Other type of Immunizers are focused to a specific malware and work by giving
the malware the impression that the malware has already infected to the computer. This method is not
always practical since it is not possible to immunize file against all known malware.
For your exam you should know below mentioned different kinds of malware Controls
A. Scanners- Look for sequences of bit called signature that are typical malware programs.
The two primary types of scanner are
1. Malware mask or Signatures - Anti-malware scanners check files, sectors and system memory for
known and new (unknown to scanner) malware, on the basis of malware masks or signatures. Malware
masks or signature are specific code strings that are recognized as belonging to malware. For polymorphic
malware, the scanner sometimes has algorithms that check for all possible combinations of a signature
that could exist in an infected file.
2. Heuristic Scanner - Analyzes the instructions in the code being scanned and decide on the basis of
statistical probabilities whether it could contain malicious code. Heuristic scanning result could indicate that
malware may be present, that is possibly infected. Heuristic scanner tend to generate a high level false
positive errors (they indicate that malware may be present when, in fact, no malware is present)
Scanner examines memory disk- boot sector, executables, data files, and command files for bit pattern that
match a known malware. Scanners, therefore, need to be updated periodically to remain effective.
B. Immunizers - Defend against malware by appending sections of themselves to files - sometime in the
same way Malware append themselves. Immunizers continuously check a file for changes and report
changes as possible malware behavior. Other type of Immunizers are focused to a specific malware and
work by giving the malware the impression that the malware has already infected to the computer. This
method is not always practical since it is not possible to immunize file against all known malware.
C. Behavior Blocker- Focus on detecting potential abnormal behavior such as writing to the boot sector or
the master boot record, or making changes to executable files. Blockers can potentially detect malware at
an early stage. Most hardware based anti-malware mechanism are based on this concept.
D. Integrity CRC checker- Compute a binary number on a known malware free program that is then stored
in a database file. The number is called Cyclic Redundancy Check (CRC). On subsequent scans, when
that program is called to execute, it checks for changes to the file as compare to the database and report
possible infection if changes have occurred. A match means no infection; a mismatch means change in the
program has occurred. A change in the program could mean malware within it. These scanners are
effective in detecting infection; however, they can do so only after infection has occurred. Also, a CRC
checker can only detect subsequent changes to files, because they assume files are malware free in the
first place. Therefore, they are ineffective against new files that are malware infected and that are not
recorded in the database. Integrity checker take advantage of the fact that executable programs and boot
sectors do not change often, if at all.
E. Active Monitors - Active monitors interpret DOS and read-only memory (ROM) BIOS calls, looking for
malware like actions. Active monitors can be problematic because they can not distinguish between a user
request and a program or a malware request. As a result, users are asked to confirm actions, including
formatting a disk or deleting a file or set of files.
The following were incorrect answers:
Scanners -Look for sequences of bit called signature that are typical malware programs.
Active Monitors - Active monitors interpret DOS and read-only memory (ROM) BIOS calls, looking for
malware like actions. Active monitors can be problematic because they can not distinguish between a user
request and a program or a malware request. As a result, users are asked to confirm actions, including
formatting a disk or deleting a file or set of files.
Behavior Blocker- Focus on detecting potential abnormal behavior such as writing to the boot sector or the
master boot record, or making changes to executable files. Blockers can potentially detect malware at an
early stage. Most hardware based anti-malware mechanism are based on this concept.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 354 and 355
insert code

Question 183

Which of the following would be the BEST way to address segregation of duties issues in an organization with budget constraints?

Correct Answer: C
Section: Protection of Information Assets
insert code

Question 184

A successful risk-based IT audit program should be based on:

Correct Answer: A
Explanation/Reference:
Explanation:
A successful risk-based IT audit program could be based on an effective scoring system. In establishing a scoring system, management should consider all relevant risk factors and avoid subjectivity. Auditors should develop written guidelines on the use of risk assessment tools and risk factors and review these guidelines with the audit committee.
insert code

Question 185

Which of the following do digital signatures provide?

Correct Answer: A
Explanation/Reference:
The primary purpose of digital signatures is to provide authentication and integrity of datA.
insert code
  • ««
  • «
  • …
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download ISACA.CISA.v2023-03-04.q546 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.