nerdexam
Isaca

CISA · Question #308

An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet. Which of the following should be a…

The correct answer is C. The system is hosted within an internal segment of a corporate network. Hosting a web-based CRM system within the internal segment of a corporate network poses significant security risks. Direct access from the Internet to the internal network increases the attack surface and exposes internal systems to potential external threats. A more secure…

Submitted by cyberguy42· Apr 18, 2026Protection of Information Assets

Question

An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet. Which of the following should be a concern for the auditor?

Options

  • AThe system is hosted within a demilitarized zone (DMZ) of a corporate network
  • BThe system is hosted in a hybrid-cloud platform managed by a service provider
  • CThe system is hosted within an internal segment of a corporate network
  • DThe system is hosted on an external third-party service provider's servers

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    79% (19)
  • D
    4% (1)

Explanation

Hosting a web-based CRM system within the internal segment of a corporate network poses significant security risks. Direct access from the Internet to the internal network increases the attack surface and exposes internal systems to potential external threats. A more secure architecture would involve hosting such systems in a demilitarized zone (DMZ) or on a cloud platform with appropriate security controls to isolate the internal network from direct exposure.

Topics

#Network Security#DMZ#Network Segmentation#Security Architecture

Community Discussion

No community discussion yet for this question.

Full CISA Practice