Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 5Objective 6

Incident Response and Forensics CISA Practice Questions (Page 4)

Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.

41questions here
9free pages
12concepts
26%of the exam

Questions 16–20

  1. 16foundation · easy

    Which factor is MOST important when prioritizing the response to multiple security incidents?

    Select an answer first
  2. 17application · medium

    A company's intrusion detection system (IDS) generates an alert for suspicious outbound traffic from a server. The security analyst on duty is unsure if this is a true positive or a false positive. According to incident detection and reporting best practices, what should the analyst do first?

    Select an answer first
  3. 18expert · hard

    A forensic investigator needs to acquire evidence from a server that is still running and cannot be shut down due to business continuity requirements. The investigator must capture volatile data and create a forensic image of the hard drive. What is the most appropriate approach?

    Select an answer first
  4. 19foundation · easy

    What is the primary purpose of forensic analysis of digital evidence?

    Select an answer first
  5. 20foundation · easy

    After an incident has been contained and eradicated, which phase involves restoring systems to normal operation and validating that they function as expected?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.