When should systems administrators first assess the impact of applications or systems patches?
Correct Answer: B
Explanation/Reference: Systems administrators should always assess the impact of patches before installation.
Question 292
During the walk-through procedures for an upcoming audit, an IS auditor notes that the key application in scope is part of a Software as a Service (SaaS) agreement. What should the auditor do NEXT?
Which of the following BEST helps data loss prevention (DLP) tools detect movement of sensitive data m transit?
Correct Answer: B
Deep packet inspection (DPI) is a core capability of data loss prevention (DLP) tools that allows the analysis of the content of data packets in transit. This helps detect the unauthorized movement of sensitive data by examining packet-level details. * Network Traffic Logs (Option A): These provide historical data but do not actively detect data in transit. * Data Inventory (Option C): Useful for identifying where sensitive data resides but not for monitoring its movement. * Proprietary Encryption (Option D): Protects data but does not detect unauthorized transmission. Reference: ISACA CISA Review Manual, Job Practice Area 4: Protection of Information Assets.
Question 294
Which of the following findings should be of GREATEST concern to an IS auditor performing a review of IT operations?
Correct Answer: D
Changes to the job scheduler application's parameters are not approved and reviewed by an operations supervisor. This is a serious control weakness that could compromise the integrity, availability, and security of the IT operations. An IS auditor should be concerned about the lack of oversight and accountability for such changes, which could result in unauthorized, erroneous, or malicious modifications that affect the processing environment. The other options are less critical issues that may not have a significant impact on the IT operations. References: * CISA Review Manual (Digital Version), Chapter 4, Section 4.2.3.11 * CISA Review Questions, Answers & Explanations Database, Question ID 202
Question 295
Identify the payment model from description presented below: A users write an electronic check, which is digitally signed with instruction to pay. This is transferred to another user, who then deposits the electronic check with the issuer. The issuer will verify payer's signature on the payment and transfer the fund from the payer's account to the payee's account.
Correct Answer: B
Section: Information System Acquisition, Development and Implementation Explanation: Electronic check system model real-world checks quite well and thus relatively simple to understand and implement. A users write an electronic check, which is digitally signed instruction to pay. This is transferred to another user, who then deposits the electronic check with the issuer. The issuer will verify payer's signature on the payment and transfer the fund from the payer's account to the payee's account. For CISA exam you should know below information about payment systems There are two types of parties involved in all payment systems - the issuer and the user. An issuer is an entity that operates the payment service. An issuer holds the items that the payment represents. The user of the payment service performs two main functions- making payments and receiving payments - and therefore can be described as a payer or payee receptively. Electronic Money Model - The objective of electronic money systems is emulating physical cash. An issuer attempts to do this by creating digital certificates, which are then purchased by users who redeem them with the issuer at a later date. In the interim, certificates can be transferred among users to trade for goods or services. For the certificate to take on some of the attributes of physical cash, certain techniques are used so that when a certificate is deposited, the issuer can not determine the original withdrawer of the certificate. This provides an electronic certificate with unconditional uncertainty. Electronic Check Model - Electronic check system model real-world checks quite well and thus relatively simple to understand and implement. A users write an electronic check, which is digitally signed instruction to pay. This is transferred to another user, who then deposits the electronic check with the issuer. The issuer will verify payer's signature on the payment and transfer the fund from the payer's account to the payee's account. Electronic Transfer Model - Electronic systems are simplest of three payment models. The payer simply creates a payment transfer instructions, sign it digitally and send it to issuer. The issuer then verifies the signature on the request and performs the transfer. This type of systems requires payer to be on-line and not payee. The following were incorrect answers: Electronic Money Model - The objective of electronic money systems is emulating physical cash. An issuer attempts to do this by creating digital certificates, which are then purchased by users who redeem them with the issuer at a later date. In the interim, certificates can be transferred among users to trade for goods or services. For the certificate to take on some of the attributes of physical cash, certain techniques are used so that when a certificate is deposited, the issuer can not determine the original withdrawer of the certificate. This provides an electronic certificate with unconditional uncertainty. Electronic Transfer Model - Electronic systems are simplest of three payment models. The payer simply creates a payment transfer instructions, sign it digitally and send it to issuer. The issuer then verifies the signature on the request and performs the transfer. This type of systems requires payer to be on-line and not payee. Electronic Withdraw Model - Not a valid type of payment system. Reference: CISA review manual 2014 Page number 183