FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. ISACA Certification
  3. CISA Exam
  4. ISACA.CISA.v2023-03-04.q546 Dumps
  • ««
  • «
  • …
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • …
  • »
  • »»
Download Now

Question 271

Which of the following is an example of a passive attack initiated through the Internet?

Correct Answer: A
Section: Protection of Information Assets
Explanation:
Internet security threats/vulnerabilities are divided into passive and active attacks. Examples of passive
attacks include network analysis, eavesdropping and traffic analysis. Active attacks include brute force
attacks, masquerading, packet replay, message modification, unauthorized access through the Internet or
web-based services, denial-of-service attacks, dial-in penetration attacks, e-mail bombing and spamming,
and e-mail spoofing.
insert code

Question 272

Which of the following would an IS auditor consider a weakness when performing an audit of an organization that uses a public key infrastructure with digital certificates for its business-to- consumer transactions via the internet?

Correct Answer: D
Explanation/Reference:
Explanation: If the certificate authority belongs to the same organization, this would generate a conflict of interest. That is, if a customer wanted to repudiate a transaction, they could allege that because of the shared interests, an unlawful agreement exists between the parties generating the certificates, if a customer wanted to repudiate a transaction, they could argue that there exists a bribery between the parties to generate the certificates, as shared interests exist. The other options are not weaknesses.
insert code

Question 273

During a follow-up audit, an IS auditor discovers that a recommendation has not been implemented.
However, the auditee has implemented a manual workaround that addresses the identified risk, through far
less efficiency than the recommended action would. Which of the following would be the auditor's BEST
course of action?

Correct Answer: D
Section: Protection of Information Assets
insert code

Question 274

An IS auditor seeks assurance that a new process for purging transactions does not have a detrimental impact on the integrity of a database. This could be achieved BEST by analyzing the:

Correct Answer: D
Section: Protection of Information Assets
insert code

Question 275

When reviewing an organization's strategic IT plan an IS auditor should expect to find:

Correct Answer: A
Section: Protection of Information Assets
Explanation:
An assessment of how well an organization's application portfolio supports the organization's business
objectives is a key component of the overall IT strategic planning process. This drives the demand side of
IT planning and should convert into a set of strategic IT intentions. Further assessment can then be made
of how well the overall IT organization, encompassing applications, infrastructure, services, management
processes, etc., can support the business objectives. Operational efficiency initiatives belong to tactical
planning, not strategic planning. The purpose of an IT strategic plan is to set out how IT will be used to
achieve or support an organization's business objectives. A listing of approved suppliers of IT contract
resources is a tactical rather than a strategic concern. An IT strategic plan would not normally include detail
ofa specific technical architecture.
insert code
  • ««
  • «
  • …
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download ISACA.CISA.v2023-03-04.q546 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.