ExamGecko
Question list
Search
Search

Related questions











Question 352 - CISA discussion

Report
Export

An organization has virtualized its server environment without making any other changes to the network or security infrastructure. Which of the following is the MOST significant risk?

A.
Inability of the network intrusion detection system (IDS) to monitor virtual server-lo-server communications
Answers
A.
Inability of the network intrusion detection system (IDS) to monitor virtual server-lo-server communications
B.
Vulnerability in the virtualization platform affecting multiple hosts
Answers
B.
Vulnerability in the virtualization platform affecting multiple hosts
C.
Data center environmental controls not aligning with new configuration
Answers
C.
Data center environmental controls not aligning with new configuration
D.
System documentation not being updated to reflect changes in the environment
Answers
D.
System documentation not being updated to reflect changes in the environment
Suggested answer: A

Explanation:

The most significant risk in virtualizing the server environment without making any other changes to the network or security infrastructure is the inability of the network intrusion detection system (IDS) to monitor virtual server-to-server communications. This can create blind spots for the IDS and allow malicious traffic to bypass detection. A vulnerability in the virtualization platform affecting multiple hosts is a potential risk, but not necessarily more significant than the loss of visibility. Data center environmental controls not aligning with new configuration or system documentation not being updated to reflect changes in the environment are operational issues, not security issues.Reference:ISACA, CISA Review Manual, 27th Edition, 2018, page 373

asked 18/09/2024
Andrzej Pawlus
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first