ExamGecko
Question list
Search
Search

Related questions

Question 118 - CISA discussion

Report
Export

An IS auditor has been asked to assess the security of a recently migrated database system that contains personal and financial data for a bank's customers. Which of the following controls is MOST important for the auditor to confirm is in place?

A.
The default configurations have been changed.
Answers
A.
The default configurations have been changed.
B.
All tables in the database are normalized.
Answers
B.
All tables in the database are normalized.
C.
The service port used by the database server has been changed.
Answers
C.
The service port used by the database server has been changed.
D.
The default administration account is used after changing the account password.
Answers
D.
The default administration account is used after changing the account password.
Suggested answer: A

Explanation:

Changing the default configurations of a database system is a critical control for securing it from unauthorized access or exploitation. Default configurations often include weak passwords, unnecessary services, open ports, or known vulnerabilities that can be easily exploited by attackers. The other options are not as important as changing the default configurations, as they do not address the root cause of the security risks. Normalizing tables in the database is a design technique for improving data quality and performance, but it does not affect security. Changing the service port used by the database server is a form of security by obscurity, which can be easily bypassed by port scanning tools. Using the default administration account after changing the account password is still risky, as the account name may be known or guessed by attackers.Reference:CISA Review Manual (Digital Version), Chapter 5, Section 5.2.4

asked 18/09/2024
Gofaone Ncube
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first