
Certified Information Systems Auditor
Domain 5Objective 6
Incident Response and Forensics CISA Practice Questions (Page 1)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
41questions here
9free pages
12concepts
26%of the exam
Questions 1–5
- 1
An organization faces two simultaneous incidents: a low-severity phishing campaign targeting a few users, and a high-severity ransomware attack on a critical database server. The incident response team has limited staff. How should the team prioritize its response?
Select an answer first - 2
A company is responding to a data breach that involves a critical application server. The server contains volatile evidence that may be lost if the system is shut down. However, the attacker is actively using the server to exfiltrate data. What is the most appropriate containment strategy?
Select an answer first - 3
Why is timely and accurate incident reporting important?
Select an answer first - 4
What is the purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 5
What is the primary goal of the containment phase in incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.