Free Certified Information Systems Auditor practice — 6 questions on Protection of Information Assets, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 5: Protection of Information Assets
An IS auditor is reviewing an organization's PKI implementation used to secure business-to-business transactions. The auditor discovers that relying applications validate certificates only against a Certificate Revocation List (CRL) that is published every 24 hours, with no OCSP stapling or real-time checking in place. Which risk should the auditor MOST prominently cite in the finding?
CRLs are only as current as their publication interval; a 24-hour refresh window means a revoked (e.g., compromised or stolen) certificate can still be accepted as valid by relying systems for up to a full day, creating a real window of exposure that OCSP or OCSP stapling would substantially reduce.
Question 2 of 6 · Domain 5: Protection of Information Assets
During a review of an organization's privileged access management (PAM) solution, an IS auditor finds that database administrators check out shared root-level credentials from a password vault, and all vaulted sessions are recorded. However, the auditor notes that the vault automatically rotates the checked-out password only after the credential is manually returned, with no enforced maximum checkout duration. What is the MOST significant control weakness this represents?
Without an enforced maximum checkout time-to-live, a credential can be held open indefinitely, defeating the purpose of just-in-time privileged access and creating an extended window during which the credential's password is static and known to whoever checked it out — increasing the risk of misuse or lateral compromise going undetected.
Question 3 of 6 · Domain 5: Protection of Information Assets
An organization's security policy requires that a symmetric Data Encryption Key (DEK) be used to encrypt large volumes of data at rest, while a separate Key Encryption Key (KEK) protects the DEK itself. An IS auditor reviewing this envelope encryption architecture should confirm which control is in place to ensure the design is effective?
Envelope encryption's security depends on protecting the KEK at a higher assurance level than the DEK; storing it in an HSM or dedicated key management service, separate from the data and the DEK, ensures that compromise of the encrypted data store or the DEK alone does not expose the KEK.
Question 4 of 6 · Domain 5: Protection of Information Assets
An IS auditor is evaluating the use of digital signatures on financial transaction messages exchanged between a bank and a corporate client. Management states the signatures were implemented specifically to prevent the sender from later denying they submitted a transaction. Which security objective does this control PRIMARILY address?
Non-repudiation ensures that the originator of a message cannot later deny having sent it, which is achieved by digital signatures because only the sender's private key could have produced a valid signature verifiable with their public key.
Question 5 of 6 · Domain 5: Protection of Information Assets
A financial services company's security operations center (SOC) uses a SIEM to correlate logs from firewalls, endpoint detection tools, and authentication systems. An IS auditor wants to test the operating effectiveness of the SIEM's alerting capability for detecting a multi-stage attack (initial phishing compromise followed by lateral movement). Which testing approach would provide the BEST evidence of control effectiveness?
Testing operating effectiveness requires evidence that the control actually functions as intended in practice; a controlled simulation of the specific attack pattern, followed by verification that the SIEM detects, correlates, and escalates the alert within SLA, provides direct substantive evidence rather than relying on design documentation or inquiry alone.
Question 6 of 6 · Domain 5: Protection of Information Assets
An organization classifies data into Public, Internal, Confidential, and Restricted tiers. During a review of cross-border data transfers, an IS auditor discovers that a customer analytics dataset classified as Confidential (containing pseudonymized personal data) is being transferred to a third-party processor in a country without an adequacy decision or equivalent legal safeguard recognized by the data's originating jurisdiction. Which recommendation should the auditor make FIRST?
Most data privacy regulations (e.g., GDPR-style frameworks) require a recognized legal transfer mechanism — such as standard contractual clauses (SCCs) or binding corporate rules (BCRs) — for transfers to jurisdictions lacking an adequacy determination, regardless of pseudonymization; the auditor's first recommendation should be to establish this legal safeguard.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.