Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 5Objective 5

Security Operations and Monitoring CISA Practice Questions (Page 5)

Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.

25questions here
5free pages
3concepts
26%of the exam

Questions 21–25

  1. 21application · medium

    A security analyst notices a sudden spike in outbound network traffic from a single server, and the server is sending data to an external IP address that is not on any approved list. The server's CPU usage is also high. Which type of attack is most likely occurring?

    Select an answer first
  2. 22foundation · easy

    What is the primary purpose of a vulnerability scanner?

    Select an answer first
  3. 23expert · hard

    A security team wants to test the effectiveness of their security monitoring and incident response processes. They have a limited budget and cannot afford a full red team exercise. Which approach provides the most value for testing detection and response?

    Select an answer first
  4. 24application · medium

    An organization wants to ensure that its new web application is secure before going live. They have already run a vulnerability scanner and fixed all identified issues. What is the NEXT best step to identify logic flaws and business logic errors that scanners may miss?

    Select an answer first
  5. 25foundation · easy

    Which of the following is a key purpose of log analysis in security monitoring?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CISA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.