CISA Domain 5B Practice Test 001

This practice test covers Domain 5 (Protection of Information Assets) Subdomain B (Security Event Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA Practice Test — 5B (Security Event Management)
10 questions • Single best answer
Question 1
An internal auditor at a government agency is evaluating the security awareness program after a series of successful phishing incidents. Management points to annual mandatory training and signed acknowledgment forms as evidence the program is effective. Which of the following would provide the BEST evidence that the awareness program is actually reducing security risk?
    Question 2
    A healthcare organization's security operations center detects ransomware actively encrypting files across several production servers in real time. The incident response team has been alerted and is assembling to respond. Which of the following should the team do FIRST to limit the immediate impact of this incident?
      Question 3
      During the investigation of a suspected data theft, an IS auditor reviews how the forensics team handled the departing employee's laptop. The auditor notes there is no documentation recording who accessed the seized device, when, and for what purpose after it was collected. Which of the following is the auditor's GREATEST concern?
        Question 4
        A financial services firm's SIEM generates thousands of alerts each day, and analysts report that the overwhelming majority are false positives, causing genuine threats to be overlooked. An IS auditor is assessing the monitoring function. Which of the following recommendations would BEST improve the effectiveness of the security monitoring process?
          Question 5
          A manufacturing company suffers a fraudulent wire transfer after an attacker impersonated the CFO in an urgent email directing finance staff to release funds immediately. An IS auditor is recommending controls to prevent recurrence. Which of the following would BEST mitigate the risk of this business email compromise attack?
            Question 6
            An IS auditor is reviewing an organization's security testing program. Management asserts that quarterly automated vulnerability scans of all external-facing systems demonstrate that the environment is secure against real attacks. Which of the following is the MOST appropriate conclusion for the auditor to reach regarding this assertion?
              Question 7
              Following a major security breach, an organization restored operations quickly and formally closed the incident. Six months later a nearly identical breach occurred through the same unpatched vulnerability. An IS auditor is reviewing the incident response process. Which of the following control weaknesses MOST likely contributed to the recurrence?
                Question 8
                An IS auditor observes a forensic investigator responding to a live compromised server that is still powered on and running. The investigator immediately shuts the system down to preserve the hard drive before collecting any other data. Which of the following is the auditor's MOST significant concern with this approach?
                  Question 9
                  During an audit of a retailer's security monitoring practices, the IS auditor finds that critical system logs are stored only locally on each server and that administrators can edit or delete them. Which of the following findings should the auditor consider the MOST significant regarding the log management process?
                    Question 10
                    An IS auditor is evaluating a company's incident response procedures. The auditor notes that all reported security events are handled in the order they are received, regardless of their nature, severity, or the systems affected. Which of the following recommendations would MOST improve the incident response process?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top