
Certified Information Systems Auditor
Domain 5Objective 6
Incident Response and Forensics CISA Practice Questions (Page 3)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
41questions here
9free pages
12concepts
26%of the exam
Questions 11–15
- 11
During which phase of incident response is the root cause of an incident removed from affected systems?
Select an answer first - 12
An organization is developing its incident response capability. To ensure consistent and effective response to common incidents like phishing and malware, the team wants to document step-by-step procedures. What is the most appropriate approach?
Select an answer first - 13
A security analyst receives alerts for two incidents simultaneously: (1) a single workstation detected with a known malware signature, and (2) multiple servers showing signs of data exfiltration to an external IP. The analyst has limited resources and must prioritize. Which incident should be handled first?
Select an answer first - 14
What is the purpose of creating a forensic image of a storage device?
Select an answer first - 15
Which element is MOST important to include in a forensic report to ensure it is useful for legal proceedings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.