C Certs Club
Home
Oracle SAP Microsoft Cisco CompTIA Fortinet Salesforce Nutanix Linux Foundation Amazon View All Vendors →
Login Register

ISACA Cybersecurity-Audit-Certificate - ISACA Cybersecurity Audit Certificate Exam Certification Exam

Download Exam View Entire Exam
Page: 1 / 2
Question #1 (Topic: Demo Questions)

Which of the following would provide the BEST basis for allocating proportional protection activities when comprehensive classification is not feasible?

A.
 Single classification level allocation
B.
Business process re-engineering
C.
Business dependency assessment
D.

Comprehensive cyber insurance procurement

Correct Answer: C
Explanation:
The BEST basis for allocating proportional protection activities when comprehensive classification is not feasible is a business dependency assessment. This is because a business dependency assessment helps to identify the criticality and sensitivity of business processes and their supporting assets, based on their contribution to the organization’s objectives and value proposition. This allows for prioritizing protection activities according to the level of risk and impact. The other options are not as effective as a business dependency assessment, because they either use a single classification level allocation (A), which does not account for different levels of risk and impact; require a significant amount of time and resources to perform a business process re-engineering (B); or rely on external parties to cover potential losses without reducing the likelihood or impact of incidents (D) 
Question #2 (Topic: Demo Questions)

Availability can be protected through the use of: 

A.
 user awarenesstraining and related end-user training
B.
access controls. We permissions, and encryption. 
C.
logging, digital signatures, and write protection.
D.
redundancy, backups, and business continuity management
Correct Answer: D
Explanation:
Availability can be protected through the use of redundancy, backups, and business continuity management. This is because these measures help to ensure that systems, data, and services are accessible and functional at all times, even in the event of a disruption or disaster. The other options are not directly related to protecting availability, but rather focus on enhancing confidentiality (A), integrity C, or awareness (D).
Question #3 (Topic: Demo Questions)

The second line of defense in cybersecurity includes: 

A.
 conducting organization-wide control self-assessments
B.
risk management monitoring, and measurement of controls
C.
separate reporting to the audit committee within the organization.
D.
 performing attack and breach penetration testing. 
Correct Answer: B
Explanation:
The second line of defense in cybersecurity includes risk management monitoring, and measurement of controls. This is because the second line of defense is responsible for ensuring that the first line of defense (the operational managers and staff who own and manage risks) is effectively designed and operating as intended. The second line of defense also provides guidance, oversight, and challenge to the first line of defense. The other options are not part of the second line of defense, but rather belong to the first line of defense (A), the third line of defense C, or an external service provider (D). 
Question #4 (Topic: Demo Questions)

The "recover" function of the NISI cybersecurity framework is concerned with: 

A.
planning for resilience and timely repair of compromised capacities and service.
B.
identifying critical data to be recovered m case of a security incident.
C.
taking appropriate action to contain and eradicate a security incident.
D.
allocating costs incurred as part of the implementation of cybersecurity measures
Correct Answer: A
Explanation:
The “recover” function of the NIST cybersecurity framework is concerned with planning for resilience and timely repair of compromised capacities and service. This is because the recover function helps organizations to restore normal operations as quickly as possible after a cybersecurity incident, while also learning from the incident and improving their security posture. The other options are not part of the recover function, but rather belong to the identify (B), respond C, or protect (D) functions. 
Question #5 (Topic: Demo Questions)

Which of the following backup procedure would only copy files that have changed since the last backup was made?

A.

Incremental backup

B.

Daily backup

C.
Differential backup
D.
Full backup
Next Question
Correct Answer: A
Explanation:
The backup procedure that would only copy files that have changed since the last backup was made is an incremental backup. This is because an incremental backup is a type of backup that only copies the files that have been created or modified since the previous backup, whether it was a full or an incremental backup. An incremental backup helps to reduce the backup time and storage space, as well as the recovery time, as only the changed files need to be restored. The other options are not backup procedures that would only copy files that have changed since the last backup was made, but rather different types of backup procedures that copy files based on different criteria, such as daily backup (B), differential backup C, or full backup (D).