Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 5Objective 6

Incident Response and Forensics CISA Practice Questions (Page 7)

Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.

41questions here
9free pages
12concepts
26%of the exam

Questions 31–35

  1. 31expert · hard

    A forensic investigator is collecting evidence from a compromised system that is part of a criminal investigation. The investigator accidentally opens a file on the system, altering its access time. What is the most appropriate action?

    Select an answer first
  2. 32application · medium

    A malware infection is spreading across a network segment. The incident response team needs to contain the threat while preserving evidence for potential legal action. Which containment strategy best balances these needs?

    Select an answer first
  3. 33application · medium

    A forensic investigator needs to acquire the contents of a suspect's hard drive without altering the original evidence. Which method should be used?

    Select an answer first
  4. 34foundation · easy

    Which type of evidence is MOST useful for reconstructing the timeline of a security incident?

    Select an answer first
  5. 35application · medium

    After completing a forensic investigation, the lead investigator must present findings to the company's board of directors, who are non-technical. What is the most appropriate way to communicate the findings?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.