exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 96 discussion

Actual exam question from Isaca's CISA
Question #: 96
Topic #: 1
[All CISA Questions]

Which of the following is the BEST control to mitigate attacks that redirect Internet traffic to an unauthorized website?

  • A. Utilize a network-based firewall.
  • B. Conduct regular user security awareness training.
  • C. Enforce a strong password policy meeting complexity requirements.
  • D. Perform domain name system (DNS) server security hardening.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MunaM
Highly Voted 2 years, 4 months ago
I think answer should be D because if DNS is hijacked then it then DNS queries are incorrectly resolved in order to unexpectedly redirect users to malicious sites
upvoted 13 times
...
5b56aae
Most Recent 8 months, 2 weeks ago
Selected Answer: D
DNS hardening
upvoted 2 times
...
lsiau76
1 year, 4 months ago
Selected Answer: D
D. Perform domain name system (DNS) server security hardening. The best control to mitigate attacks that redirect Internet traffic to an unauthorized website is to perform domain name system (DNS) server security hardening (Option D). DNS server security hardening involves implementing measures to secure DNS infrastructure, preventing DNS attacks such as DNS spoofing, cache poisoning, and DNS redirection. By strengthening the security of DNS servers, organizations can help ensure the accuracy and integrity of DNS responses, reducing the risk of users being redirected to unauthorized websites.
upvoted 3 times
...
oldmagic
1 year, 6 months ago
Selected Answer: D
D is the correct answer here.
upvoted 3 times
...
Pakawat
1 year, 8 months ago
Selected Answer: D
D is the best answer
upvoted 3 times
...
MohamedAbdelaal
1 year, 8 months ago
Selected Answer: D
DNS hardening is the one
upvoted 3 times
...
MichaelHoang
1 year, 12 months ago
Selected Answer: D
I vote for D. This is a kind of DNS Hijacking attack. If the DNS Hijacking attack is performed successful, firewall or IDS or WAF is useless. Hence, the best practice to prevent this kind of attack is protecting your DNS Records/Server.
upvoted 2 times
...
Lilik
2 years, 2 months ago
a is correct A web application firewall is a great first line of defense for directing malicious actors away from your website. Using a WAF guards your site against the most common types of attacks, and some solutions even provide security reports that highlight important data (such as site traffic)
upvoted 4 times
...
Deeplaxmi
2 years, 3 months ago
I also think D can be correct.. DNS server hardening can prevent pharming attacks
upvoted 2 times
...
MunaM
2 years, 4 months ago
it's talking about the firewall not IDS. Are you assuming that firewall ha the IDS capabilities?
upvoted 2 times
...
NAJ_88
2 years, 4 months ago
A is correct because If a network-based IDS is placed between the Internet and the firewall, it will detect all the attack attempts, whether or not they enter the firewall. If the IDS is placed between a firewall and the corporate network, it will detect those attacks that enter the firewall (it will detect intruders). The IDS is not a substitute for a firewall, but it complements the function of a firewall.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...