
Certified Information Systems Auditor
Domain 5Objective 4
Network, Endpoint, and Data Security CISA Practice Questions (Page 6)
Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.
35questions here
7free pages
10concepts
26%of the exam
Questions 26–30
- 26
What is the primary purpose of network segmentation in a security architecture?
Select an answer first - 27
A hospital has a wireless network for staff and a separate network for patient monitoring devices (IoT). The IoT devices are outdated and cannot support WPA3. The security team wants to ensure that a compromised IoT device cannot be used to access the staff network or the internet. Which control is most effective?
Select an answer first - 28
A company is migrating its on-premises data center to a public cloud IaaS. The compliance team requires that all data be encrypted at rest and that access to the encryption keys be logged and audited. The company also wants to minimize the administrative overhead of managing keys. Which solution should they choose?
Select an answer first - 29
What is the primary security purpose of isolating virtual networks within a hypervisor?
Select an answer first - 30
A financial services firm uses a cloud-based email service. The compliance team wants to prevent employees from accidentally sending emails that contain credit card numbers to external recipients. Which control should the firm implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.