2009 CISA PRACTICE QUESTION ALL.doc_第1页
2009 CISA PRACTICE QUESTION ALL.doc_第2页
2009 CISA PRACTICE QUESTION ALL.doc_第3页
2009 CISA PRACTICE QUESTION ALL.doc_第4页
2009 CISA PRACTICE QUESTION ALL.doc_第5页
已阅读5页,还剩260页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

2009 cisa practice question all(800) questions: 1、which of the following antispam filtering techniques would best prevent a valid, variable-length e-mail message containing a heavily weighted spam keyword from being labeled as spam? a、heuristic (rule-based) b、signature-based c、pattern matching d、bayesian (statistical) answer:d note:bayesian filtering applies statistical modeling to messages, by performing a frequency analysis on each word within the message and then evaluating the message as a whole. therefore, it can ignore a suspicious keyword if the entire message is within normal bounds. heuristic filtering is less effective, since new exception rules may need to be defined when a valid message is labeled as spam. signature-based filtering is useless against variable-length messages, because the calculated md5 hash changes all the time. finally, pattern matching is actually a degraded rule-based technique, where the rules operate at the word level using wildcards, and not at higher levels. 2、an offsite information processing facility with electrical wiring, air conditioning and flooring, but no computer or communications equipment, is a: a、cold site. b、warm site. c、dial-up site. d、duplicate processing facility. answer:a note:a cold site is ready to receive equipment but does not offer any components at the site in advance of the need. a warm site is an offsite backup facility that is partially configured with network connections and selected peripheral equipmentsuch as disk and tape units, controllers and cpusto operate an information processing facility. a duplicate information processing facility is a dedicated, self-developed recovery site that can back up critical applications. 3、which of the following is most directly affected by network performance monitoring tools? a、integrity b、availability c、completeness d、confidentiality answer:b note:in case of a disruption in service, one of the key functions of network performance monitoring tools is to ensure that the information has remained unaltered. it is a function of security monitoring to assure confidentiality by using such tools as encryption. however, the most important aspect of network performance is assuring the ongoing dependence on connectivity to run the business. therefore, the characteristic that benefits the most from network monitoring is availability. 4、an is auditor invited to a development project meeting notes that no project risks have been documented. when the is auditor raises this issue, the project manager responds that it is too early to identify risks and that, if risks do start impacting the project, a risk manager will be hired. the appropriate response of the is auditor would be to: a、stress the importance of spending time at this point in the project to consider and document risks, and to develop contingency plans. b、accept the project managers position as the project manager is accountable for the outcome of the project. c、offer to work with the risk manager when one is appointed. d、inform the project manager that the is auditor will conduct a review of the risks at the completion of the requirements definition phase of the project. answer:a note:the majority of project risks can typically be identified before a project begins, allowing mitigation/avoidance plans to be put in place to deal with these risks. a project should have a clear link back to corporate strategy and tactical plans to support this strategy. the process of setting corporate strategy, setting objectives and developing tactical plans should include the consideration of risks. appointing a risk manager is a good practice but waiting until the project has been impacted by risks is misguided. risk management needs to be forward looking; allowing risks to evolve into issues that adversely impact the project represents a failure of risk management. with or without a risk manager, persons within and outside of the project team need to be consulted and encouraged to comment when they believe new risks have emerged or risk priorities have changed. the is auditor has an obligation to the project sponsor and the organization to advise on appropriate project management practices. waiting for the possible appointment of a risk manager represents an unnecessary and dangerous delay to implementing risk management. 5、in a public key infrastructure, a registration authority: a、verifies information supplied by the subject requesting a certificate. b、issues the certificate after the required attributes are verified and the keys are generated. c、digitally signs a message to achieve nonrepudiation of the signed message. d、registers signed messages to protect them from future repudiation. answer:a note:a registration authority is responsible for verifying information supplied by the subject requesting a certificate, and verifies the requestors right to request certificate attributes and that the requestor actually possesses the private key corresponding to the public key being sent. certification authorities, not registration authorities, actually issue certificates once verification of the information has been completed; because of this, choice b is incorrect. on the other hand, the sender who has control of their private key signs the message, not the registration authority. registering signed messages is not a task performed by registration authorities. 6、which of the following should be of most concern to an is auditor reviewing the bcp? a、the disaster levels are based on scopes of damaged functions, but not on duration. b、the difference between low-level disaster and software incidents is not clear. c、the overall bcp is documented, but detailed recovery steps are not specified. d、the responsibility for declaring a disaster is not identified. answer:d note:if nobody declares the disaster, the response and recovery plan would not be invoked, making all other concerns mute. although failure to consider duration could be a problem, it is not as significant as scope, and neither is as critical as the need to have someone invoke the plan. the difference between incidents and low-level disasters is always unclear and frequently revolves around the amount of time required to correct the damage. the lack of detailed steps should be documented, but their absence does not mean a lack of recovery, if in fact someone has invoked the plan. 7、which of the following is the key benefit of control self-assessment (csa)? a、management ownership of the internal controls supporting business objectives is reinforced. b、audit expenses are reduced when the assessment results are an input to external audit work. c、improved fraud detection since internal business staff are engaged in testing controls d、internal auditors can shift to a consultative approach by using the results of the assessment. answer:a note:the objective of control self-assessment is to have business management become more aware of the importance of internal control and their responsibility in terms of corporate governance. reducing audit expenses is not a key benefit of control self-assessment (csa). improved fraud detection is important, but not as important as ownership, and is not a principal objective of csa. csa may give more insights to internal auditors, allowing them to take a more consultative role; however, this is an additional benefit, not the key benefit. 8、an is auditor evaluating logical access controls should first: a、document the controls applied to the potential access paths to the system. b、test controls over the access paths to determine if they are functional. c、evaluate the security environment in relation to written policies and practices. d、obtain an understanding of the security risks to information processing. answer:d note:when evaluating logical access controls, an is auditor should first obtain an understanding of the security risks facing information processing by reviewing relevant documentation, by inquiries, and by conducting a risk assessment. documentation and evaluation is the second step in assessing the adequacy, efficiency and effectiveness, thus identifying deficiencies or redundancy in controls. the third step is to test the access pathsto determine if the controls are functioning. lastly, the is auditor evaluates the security environment to assess its adequacy by reviewing the written policies, observing practices and comparing them to appropriate security best practices. 9、the logical exposure associated with the use of a checkpoint restart procedure is: a、denial of service. b、an asynchronous attack. c、wire tapping. d、computer shutdown. answer:b note:asynchronous attacks are operating system-based attacks. a checkpoint restart is a feature that stops a program at specified intermediate points for later restart in an orderly manner without losing data at the checkpoint. the operating system saves a copy of the computer programs and data in their current state as well as several system parameters describing the mode and security level of the program at the time of stoppage. an asynchronous attack occurs when an individual with access to this information is able to gain access to the checkpoint restart copy of the system parameters and change those parameters such that upon restart the program would function at a higher-priority security level. 10、many organizations require an employee to take a mandatory vacation (holiday) of a week or more to: a、ensure the employee maintains a good quality of life, which will lead to greater productivity. b、reduce the opportunity for an employee to commit an improper or illegal act. c、provide proper cross-training for another employee. d、eliminate the potential disruption caused when an employee takes vacation one day at a time. answer:b note:required vacations/holidays of a week or more in duration in which someone other than the regular employee performs the job function is often mandatory for sensitive positions, as this reduces the opportunity to commit improper or illegal acts. during this time it may be possible to discover any fraudulent activity that was taking place. choices a, c and d could all be organizational benefits from a mandatory vacation policy, but they are not the reason why the policy is established. 11、to determine how data are accessed across different platforms in a heterogeneous environment, an is auditor should first review: a、business software. b、infrastructure platform tools. c、application services. d、system development tools. answer:c note:projects should identify the complexities of the it infrastructure that can be simplified or isolated by the development of application services. application services isolate system developers from the complexities of the it infrastructure and offer common functionalities that are shared by many applications. application services take the form of interfaces, middleware, etc. business software focuses on business processes, whereas application services bridge the gap between applications and the it infrastructure components. infrastructure platform tools are related to core hardware and software components required for development of the it infrastructure. systems development tools represent development components of the it infrastructure development. 12、an integrated test facility is considered a useful audit tool because it: a、is a cost-efficient approach to auditing application controls. b、enables the financial and is auditors to integrate their audit tests. c、compares processing output with independently calculated data. d、provides the is auditor with a tool to analyze a large range of information. answer:c note:an integrated test facility is considered a useful audit tool because it uses the same programs to compare processing using independently calculated data. this involves setting up dummy entities on an application system and processing test or production data against the entity as a means of verifying processing accuracy. 13、an is auditor evaluates the test results of a modification to a system that deals with payment computation. the auditor finds that 50 percent of the calculations do not match predetermined totals. which of the following would most likely be the next step in the audit? a、design further tests of the calculations that are in error. b、identify variables that may have caused the test results to be inaccurate. c、examine some of the test cases to confirm the results. d、document the results and prepare a report of findings, conclusions and recommendations. answer:c note:an is auditor should next examine cases where incorrect calculations occurred and confirm the results. after the calculations have been confirmed, further tests can be conducted and reviewed. report preparation, findings and recommendations would not be made until all results are confirmed. 14、the primary objective of performing a postincident review is that it presents an opportunity to: a、improve internal control procedures. b、harden the network to industry best practices. c、highlight the importance of incident response management to management. d、improve employee awareness of the incident response process. answer:a note:a postincident review examines both the cause and response to an incident. the lessons learned from the review can be used to improve internal controls. understanding the purpose and structure of postincident reviews and follow-up procedures enables the information security manager to continuously improve the security program. improving the incident response plan based on the incident review is an internal (corrective) control. the network may already be hardened to industry best practices. additionally, the network may not be the source of the incident. the primary objective is to improve internal control procedures, not to highlight the importance of incident response management (irm), and an incident response (ir) review does not improve employee awareness. 15、when conducting a penetration test of an organizations internal network, which of the following approaches would best enable the conductor of the test to remain undetected on the network? a、use the ip address of an existing file server or domain controller. b、pause the scanning every few minutes to allow thresholds to reset. c、conduct the scans during evening hours when no one is logged-in. d、use multiple scanning tools since each tool has different characteristics. answer:b note:pausing the scanning every few minutes avoids overtaxing the network as well as exceeding thresholds that may trigger alert messages to the network administrator. using the ip address of a server would result in an address contention that would attract attention. conducting scans after hours would increase the chance of detection, since there would be less traffic to conceal ones activities. using different tools could increase the likelihood that one of them would be detected by an intrusion detection system. 16、an organization has implemented a disaster recovery plan. which of the following steps should be carried out next? a、obtain senior management sponsorship. b、identify business needs. c、conduct a paper test. d、perform a system restore test. answer:c note:a best practice would be to conduct a paper test. senior management sponsorship and business needs identification should have been obtained prior to implementing the plan. a paper test should be conducted first, followed by system or full testing. 17、this question refers to the following diagram. e

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论