
Certified Information Systems Auditor
Domain 5Objective 6
Incident Response and Forensics CISA Practice Questions (Page 7)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
41questions here
9free pages
12concepts
26%of the exam
Questions 31–35
- 31
A forensic investigator is collecting evidence from a compromised system that is part of a criminal investigation. The investigator accidentally opens a file on the system, altering its access time. What is the most appropriate action?
Select an answer first - 32
A malware infection is spreading across a network segment. The incident response team needs to contain the threat while preserving evidence for potential legal action. Which containment strategy best balances these needs?
Select an answer first - 33
A forensic investigator needs to acquire the contents of a suspect's hard drive without altering the original evidence. Which method should be used?
Select an answer first - 34
Which type of evidence is MOST useful for reconstructing the timeline of a security incident?
Select an answer first - 35
After completing a forensic investigation, the lead investigator must present findings to the company's board of directors, who are non-technical. What is the most appropriate way to communicate the findings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.