exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1800 discussion

Actual exam question from Isaca's CISA
Question #: 1800
Topic #: 1
[All CISA Questions]

An IS auditor is reviewing an organization’s cloud access security broker (CASB) solution. Which of the following is MOST important for the auditor to verify?

  • A. Cloud services are classified.
  • B. Users are centrally managed.
  • C. Cloud processes are resilient.
  • D. Users are periodically recertified.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cisagroup
3 months ago
Selected Answer: A
A Cloud Access Security Broker (CASB) is used to monitor and enforce security policies for cloud applications. The most important aspect for an IS auditor to verify is whether cloud services are classified based on risk, sensitivity, and criticality
upvoted 1 times
...
46080f2
3 months, 2 weeks ago
Selected Answer: A
Among the options, classifying cloud services (A) stands out as the most important for the auditor to verify. It underpins the CASB’s ability to provide visibility, enforce risk-based policies, and protect the organization’s cloud environment effectively. Without proper classification, the CASB cannot prioritize its security measures, potentially leaving critical services vulnerable or over-restricting benign ones. While central user management, resilient processes, and periodic recertification contribute to overall security, they are either supplementary to or outside the CASB’s primary role. Industry best practices, such as those from Gartner, also highlight service discovery and classification as foundational to CASB deployments, reinforcing this conclusion.
upvoted 1 times
...
thusharaj
4 months, 3 weeks ago
Selected Answer: A
Answer A, When reviewing a Cloud Access Security Broker (CASB) solution, it is most important to ensure that cloud services are classified because the CASB's primary role is to monitor, control, and secure cloud usage. Proper classification of cloud services ensures that the organization understands the risks associated with different types of services (e.g., IaaS, SaaS, PaaS) and can enforce appropriate policies, such as data security, compliance, and user access.
upvoted 1 times
...
blehbleh
8 months ago
Selected Answer: B
You need centralized management. A just assumes you need classification in your cloud services which is not always the case.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...