Isaca Certified Information Systems Auditor CISA Question # 360 Topic 37 Discussion
CISA Exam Topic 37 Question 360 Discussion:
Question #: 360
Topic #: 37
Which of the following is the MOST important consideration when implementing a Zero Trust strategy for mobile, wireless, and Internet of Things (IoT) devices?
A.
Ensuring the latest firmware updates are applied regularly to all devices
B.
Validating the identity of all devices and users before granting access to resources
C.
Focusing on user training and awareness to prevent phishing attacks
D.
Implementing strong encryption protocols for data in transit and at rest
Zero Trustis based on the principle of " never trust, always verify, " makingidentity validationthe most critical aspect.
Option A (Incorrect):Firmware updatesare important for security but are onlyone partof aZero Trustapproach.
Option B (Correct):Device and user identity validationensures that onlyauthorizedentities can accesscritical resources, reducing the risk of unauthorized access.
Option C (Incorrect):User awarenessis important but does not enforce access control, which isfundamentalto Zero Trust.
Option D (Incorrect):Encryptionsecures data but does not controlwho can access resources, which is the primary focus of Zero Trust.
[Reference:ISACA CISA Review Manual –Domain 5: Protection of Information Assets– CoversZero Trust security models and access control best practices., , , , , , , ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit