Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 5Objective 6

Incident Response and Forensics CISA Practice Questions (Page 8)

Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.

41questions here
9free pages
12concepts
26%of the exam

Questions 36–40

  1. 36expert · hard

    A company has just experienced a significant security incident. The incident response team is in the containment phase and has isolated the affected systems. However, the team is under pressure from management to restore services quickly. The team suspects the attacker may have established persistence mechanisms. What is the most appropriate course of action?

    Select an answer first
  2. 37foundation · easy

    Which forensic tool is commonly used to create a forensic image of a storage device?

    Select an answer first
  3. 38foundation · easy

    Which legal consideration is MOST relevant when a forensic investigation involves data stored in another country?

    Select an answer first
  4. 39foundation · easy

    A security analyst identifies a malware infection on a single workstation and a suspected data breach of a customer database. Which incident should be prioritized for response?

    Select an answer first
  5. 40expert · hard

    A security operations center (SOC) receives an alert about a potential data breach. The alert is based on a new detection rule that has not been fully tested. The SOC manager must decide whether to escalate the alert to the incident response team. What is the most appropriate decision?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.