Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which control mechanism is used to detect the unauthorized modification of key configuration settings?
The control mechanism that is used to detect the unauthorized modification of key configuration settings isfile integrity. File integrity is the property of ensuring that files are not altered or corrupted by unauthorized users or processes. File integrity can be monitored by using tools that compare the current state of files with a baseline or checksum and alert on any changes.
The most common use of asymmetric algorithms is to:
Asymmetric algorithms are commonly used to securely distribute symmetric keys. The asymmetric encryption process involves a public key for encryption and a private key for decryption. This method ensures that even if the public key is intercepted, the encrypted data cannot be decrypted without the corresponding private key. Symmetric keys are then used for the bulk encryption of data due to their efficiency in processing large volumes of information.
An information security procedure indicates a requirement to sandbox emails. What does this requirement mean?
An information security procedure that indicates a requirement to sandbox emails means that the emails need to be isolated and tested for malicious content. This is because sandboxing is a technique that creates a virtual or isolated environment, where suspicious or untrusted emails can be executed or analyzed without affecting the rest of the system or network. Sandboxing helps to detect and prevent malware, phishing, or spam attacks that may be embedded in emails, and protect the users and the organization from potential harm. The other options are not what sandboxing emails means, but rather different concepts or techniques that are related to information security, such as encryption and nonrepudiation (A), backup and recovery (B), or firewall and delivery (D).
Availability can be protected through the use of:
Availability can be protected through the use of redundancy, backups, and business continuity management. This is because these measures help to ensure that systems, data, and services are accessible and functional at all times, even in the event of a disruption or disaster. The other options are not directly related to protecting availability, but rather focus on enhancing confidentiality (A), integrity C, or awareness (D).
Which of the following backup procedures would only copy files that have changed since the last backup was made?
An incremental backup is a type of backup that only copies the files that have changed since the last backup was made. This means that after a full backup, subsequent incremental backups will only include the data that has been altered or newly created since the previous backup, making it a more efficient way to save storage space and reduce backup time.
134 questions covering all exam domains, starting from $20
Exam domains verified against: Official Isaca Cybersecurity-Audit-Certificate exam guide, last checked September 2026.
Covers threat and vulnerability management, incident response and management, and disaster recovery and business continuity planning. Also addresses security monitoring and logging, identity and access management, data protection and cryptography, and network security to ensure understanding of core operations required to maintain a secure environment.
Assesses knowledge of cloud security, mobile security, and Internet of Things security, along with industrial control systems security and application security. Also examines endpoint security and Security Information and Event Management to ensure awareness of current technology landscape.
Sample question from this domain above: Q2
Tests ability to manage cybersecurity risks, develop and enforce policies, standards and procedures, and ensure compliance with regulatory requirements. Covers security awareness and training, third-party risk management, and the use of metrics and reporting in governance.
Sample question from this domain above: Q5
Focuses on the audit process including planning and scoping, evidence gathering and documentation, and reporting and communication. Covers audit follow-up and remediation, emphasizing the critical role of audit in verifying cybersecurity effectiveness and compliance.
Common questions about the exam itself