IsacaIsaca
CISA · Question #426
CISA Question #426: Real Exam Question with Answer & Explanation
Sign in or unlock CISA to reveal the answer and full explanation for question #426. The question stem and answer options stay visible for context.
Submitted by packet_pusher· Apr 18, 2026Protection of Information Assets
Question
Which of the following is the GREATEST risk that could result from a contracted penetration tester attempting SQL injection techniques on the production system?
Options
- AThe tester's access could be elevated
- BProduction data could be altered
- CEvents could be improperly logged
- DSensitive data could be exfiltrated
Unlock CISA to see the answer
You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#SQL Injection#Penetration Testing#Data Integrity#Production System Risk