CISA - Protection of Information Assets (26% of the exam) - Section 5.1

Assess security of cloud and virtualized environments and of mobile, wireless and Internet-of-Things devices.

Describe the shared-responsibility model for cloud security and the additional attack surface introduced by virtualisation, mobile and wireless deployments. Assess the security of IoT devices and cloud-hosted environments, identifying controls that address misconfigurations, insecure communications and inadequate patching.

cloud securityvirtualizationmobile and wireless securityIoT devices

Practice question for this objective

Free sampleProtection of Information Assetshard

An IS auditor is mapping controls for a Software as a Service customer relationship management platform against an industry framework so that complementary user entity controls can be tested. Which framework is MOST appropriate for the auditor to reference when evaluating cloud-specific control coverage?

  • AThe Cloud Security Alliance Cloud Controls Matrix, which maps cloud-specific control domains across provider and customer responsibilities and aligns to multiple compliance regimes. Correct
  • BThe ISO/IEC 20000 service management standard, which prescribes service-level objectives and incident handling for outsourced operations across all hosting models.
  • CThe Payment Card Industry Data Security Standard, which sets out cardholder data protection requirements that bind every SaaS provider regardless of the data it processes.
  • DThe NIST Cybersecurity Framework Implementation Tiers, which describe organisational maturity in identifying, protecting, detecting, responding and recovering from cyber events.
Select the Cloud Security Alliance Cloud Controls Matrix as the framework that maps cloud control domains across provider and customer responsibilities. The CCM organises seventeen domains of cloud-specific controls and clearly indicates which controls are provider, customer or shared. That structure lets the IS auditor identify the complementary user entity controls that must be tested at the customer to rely on the provider's assurance report, which generic management standards do not support.

Why A is correct: The CCM is purpose-built for cloud assurance and explicitly delineates provider and customer obligations, giving the auditor a structured basis to identify complementary user entity controls during testing.

Why B is wrong: ISO/IEC 20000 covers service management generally and is not cloud-specific; the candidate may select it because SaaS feels like outsourcing, but it lacks the responsibility split the CCM provides.

Why C is wrong: PCI DSS applies only when cardholder data is in scope and is not a general cloud control framework; assuming universal applicability is a common scope error among candidates.

Why D is wrong: The CSF is a strategic risk management tool and the tiers describe maturity rather than control coverage, so it does not give the auditor the cloud-specific control catalogue required here.

See more CISA practice questions, answers explained.

Exam traps in Protection of Information Assets

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • The guest passphrase is reused across many visitors without rotation, meaning a former visitor could rejoin the guest network indefinitely without the host's knowledge.

    Why it is wrong: Tempting because passphrase reuse is a hygiene issue, but it threatens guest network availability and confidentiality rather than the corporate network and the broader segregation control.

  • Type 1 hypervisors enforce hardware-based memory isolation through virtual machine introspection agents installed inside each guest operating system at boot.

    Why it is wrong: Introspection agents are an optional security tool, not a structural property; relying on guest agents would weaken isolation rather than strengthen it as the option implies.

  • Verbose diagnostic logging on the field gateway combined with a vendor support contract that mandates physical site visits for any firmware update to the sensor estate.

    Why it is wrong: Verbose logging is an exposure but the bigger field risk is unauthenticated update paths; the candidate may overweigh logging because it is visible during walkthroughs, yet the harder issue lies elsewhere.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.