ExamGecko
Question list
Search
Search

Related questions











Question 966 - CISA discussion

Report
Export

Which of the following is an IS auditor's BEST recommendation to mitigate the risk of eavesdropping associated with an application programming interface (API) integration implementation?

A.
Encrypt the extensible markup language (XML) file.
Answers
A.
Encrypt the extensible markup language (XML) file.
B.
Implement Transport Layer Security (TLS).
Answers
B.
Implement Transport Layer Security (TLS).
C.
Implement Simple Object Access Protocol (SOAP).
Answers
C.
Implement Simple Object Access Protocol (SOAP).
D.
Mask the API endpoints.
Answers
D.
Mask the API endpoints.
Suggested answer: B

Explanation:

The best recommendation to mitigate the risk of eavesdropping associated with an API integration implementation is to implement Transport Layer Security (TLS). TLS is a cryptographic protocol that provides secure communication over a network by encrypting the data in transit and authenticating the parties involved. TLS can prevent unauthorized parties from intercepting, modifying or tampering with the data exchanged between the API endpoints. Encrypting the XML file, implementing SOAP, and masking the API endpoints are not sufficient to mitigate the risk of eavesdropping, as they do not provide end-to-end encryption or authentication for the API communication.Reference:IS Audit and Assurance Tools and Techniques,CISA Certification | Certified Information Systems Auditor | ISACA

asked 18/09/2024
Gregory Pollack
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first