
Certified Information Systems Auditor
Domain 5Objective 6
Incident Response and Forensics CISA Practice Questions (Page 2)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
41questions here
9free pages
12concepts
26%of the exam
Questions 6–10
- 6
Which practice is essential when collecting digital evidence to preserve its integrity?
Select an answer first - 7
During which phase of the incident response lifecycle does an organization focus on establishing policies, tools, and training before an incident occurs?
Select an answer first - 8
During a major incident, the incident response team discovers that the attack originated from a compromised third-party vendor account. The vendor is critical to operations. The team needs to contain the threat, but the vendor is reluctant to cooperate. What is the most appropriate action?
Select an answer first - 9
Why are documented incident response procedures important for an organization?
Select an answer first - 10
During a forensic investigation, an investigator needs to collect evidence from a compromised server. To ensure the evidence is admissible in court, which action is most critical?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.