
Certified Information Systems Auditor
Domain 5Objective 4
Network, Endpoint, and Data Security CISA Practice Questions (Page 3)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
35questions here
7free pages
10concepts
26%of the exam
Questions 11–15
- 11
A company issues corporate-owned laptops to employees who work remotely. The laptops contain sensitive customer data. The security team wants to ensure that if a laptop is stolen, the data cannot be read. Which control is most important?
Select an answer first - 12
A manufacturing company has deployed hundreds of IoT sensors on the factory floor. The sensors have default credentials and cannot be patched. The security team wants to reduce the risk of these devices being compromised and used to attack the corporate network. Which control is most effective?
Select an answer first - 13
A hospital allows physicians to use personal smartphones to access patient records through a web portal. The security team is concerned about data leakage if a device is lost or stolen. Which control should be implemented to best protect the patient data on these devices?
Select an answer first - 14
A small business wants to secure its office Wi-Fi network. They currently use WEP because some older printers only support it. The business is concerned about unauthorized access. Which action should they take?
Select an answer first - 15
A company runs a multi-tenant virtualized environment where different business units share the same hypervisor. The security team is concerned about the risk of one tenant sniffing another tenant's network traffic. Which control should they implement to mitigate this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.