IsacaIsaca
CISA · Question #308
CISA Question #308: Real Exam Question with Answer & Explanation
Sign in or unlock CISA to reveal the answer and full explanation for question #308. The question stem and answer options stay visible for context.
Submitted by cyberguy42· Apr 18, 2026Protection of Information Assets
Question
An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet. Which of the following should be a concern for the auditor?
Options
- AThe system is hosted within a demilitarized zone (DMZ) of a corporate network
- BThe system is hosted in a hybrid-cloud platform managed by a service provider
- CThe system is hosted within an internal segment of a corporate network
- DThe system is hosted on an external third-party service provider's servers
Unlock CISA to see the answer
You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Network Security#DMZ#Network Segmentation#Security Architecture