exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1092 discussion

Actual exam question from Isaca's CISA
Question #: 1092
Topic #: 1
[All CISA Questions]

An IS auditor is performing an integrated audit covering payment processing activities using point-of-sale (POS) systems. Which of the following findings related to personal identification numbers (PINs) should be of GREATEST concern?

  • A. Cardholder PINs are encrypted and stored on the local POS terminal.
  • B. Cardholders are not required to enter their PINs.
  • C. Cardholders may select any 4-digit PIN without restrictions.
  • D. Cardholder PINs are not encrypted on the central computer.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
3008
1 month ago
Selected Answer: D
The finding of greatest concern would be option D: Cardholder PINs are not encrypted on the central computer. While all the options present potential security risks, the lack of encryption on the central computer is the most serious. This is because the central computer is likely to store the PINs of many cardholders, making it a high-value target for attackers. If an attacker were to gain access to the central computer, they could potentially obtain the PINs of all cardholders, leading to a massive data breach. In contrast, the other options, while still concerning, present less severe risks. For example, option A could lead to a data breach if an individual POS terminal is compromised, but the impact would likely be less severe than a breach of the central computer
upvoted 3 times
...
FAGFUR
1 month, 4 weeks ago
Selected Answer: A
Storing encrypted PINs locally on the POS terminal can pose a significant security risk, as it increases the likelihood of unauthorized access and potential compromise of PINs. Best practices involve avoiding the local storage of encrypted PINs, especially in a manner that could be vulnerable to exploitation. The storage of encrypted PINs on the local POS terminal is generally considered a higher risk due to the potential for direct compromise at the point of entry.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago