ExamGecko
Question list
Search
Search

Related questions











Question 624 - CISA discussion

Report
Export

An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?

A.
The system is hosted on an external third-party service provider's server.
Answers
A.
The system is hosted on an external third-party service provider's server.
B.
The system is hosted in a hybrid-cloud platform managed by a service provider.
Answers
B.
The system is hosted in a hybrid-cloud platform managed by a service provider.
C.
The system is hosted within a demilitarized zone (DMZ) of a corporate network.
Answers
C.
The system is hosted within a demilitarized zone (DMZ) of a corporate network.
D.
The system is hosted within an internal segment of a corporate network.
Answers
D.
The system is hosted within an internal segment of a corporate network.
Suggested answer: D

Explanation:

A web-based CRM system that is directly accessed by customers via the Internet should be hosted in a secure and isolated environment to protect it from external threats and unauthorized access.A web-based CRM system should also be reliable, trusted, and backed up regularly1.

Hosting the system on an external third-party service provider's servers (A) or a hybrid-cloud platform managed by a service provider (B) may not be a concern for the auditor if the service provider has adequate security measures and service level agreements in place.The auditor should verify the security controls and contractual terms of the service provider before trusting them with the CRM data23.

Hosting the system within a demilitarized zone (DMZ) of a corporate network is a common practice to provide an extra layer of security to the CRM system from untrusted networks, such as the Internet.A DMZ is a perimeter network that isolates the CRM system from the internal network and filters the incoming traffic from the external network using a security gateway4567.

Hosting the system within an internal segment of a corporate network (D) is a concern for the auditor because it exposes the CRM system and the internal network to potential attacks from the Internet. The CRM system should not be directly accessible from the Internet without a DMZ or a firewall to protect it.This could compromise the confidentiality, integrity, and availability of the CRM data and the internal network78.

asked 18/09/2024
gregory koontz
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first