
Certified Information Systems Auditor
Domain 5Objective 4
Network, Endpoint, and Data Security CISA Practice Questions (Page 5)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
35questions here
7free pages
10concepts
26%of the exam
Questions 21–25
- 21
A company is moving a legacy application to a public cloud IaaS environment. The security team is concerned about the responsibility for patching the operating system of the virtual machines. According to the shared responsibility model, who is responsible for patching the OS?
Select an answer first - 22
A company is setting up a new internal PKI to issue certificates for its employees' smart cards. The security team wants to ensure that if a certificate is compromised, it can be revoked before its expiration date. Which component should they implement?
Select an answer first - 23
Which wireless security protocol is considered the most secure among the following options?
Select an answer first - 24
Which safeguard is most effective in addressing the lack of update mechanisms in IoT devices?
Select an answer first - 25
Which mobile device management (MDM) capability is most directly used to protect corporate data if a device is lost or stolen?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.