Isaca Certified Information Systems Auditor CISA Question # 237 Topic 24 Discussion
CISA Exam Topic 24 Question 237 Discussion:
Question #: 237
Topic #: 24
An organization has virtualized its server environment without making any other changes to the network or security infrastructure. Which of the following is the MOST significant risk?
A.
Inability of the network intrusion detection system (IDS) to monitor virtual server-lo-server communications
B.
Vulnerability in the virtualization platform affecting multiple hosts
C.
Data center environmental controls not aligning with new configuration
D.
System documentation not being updated to reflect changes in the environment
The most significant risk in virtualizing the server environment without making any other changes to the network or security infrastructure is the inability of the network intrusion detection system (IDS) to monitor virtual server-to-server communications. This can create blind spots for the IDS and allow malicious traffic to bypass detection. A vulnerability in the virtualization platform affecting multiple hosts is a potential risk, but not necessarily more significant than the loss of visibility. Data center environmental controls not aligning with new configuration or system documentation not being updated to reflect changes in the environment are operational issues, not security issues. References: ISACA, CISA Review Manual, 27th Edition, 2018, page 373
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit