nerdexam
Isaca

CISA · Question #35

Which of the following is MOST important when planning a network audit?

The correct answer is B. Identification of existing nodes. When planning a network audit, the most important step is the identification of all existing nodes to establish a complete inventory of assets. This foundational knowledge ensures that the audit scope covers all relevant devices and systems connected to the network.

Submitted by mateo_ar· Apr 18, 2026Information System Auditing Process

Question

Which of the following is MOST important when planning a network audit?

Options

  • AIsolation of rogue access points
  • BIdentification of existing nodes
  • CAnalysis of traffic content
  • DDetermination of IP range in use

How the community answered

(68 responses)
  • A
    7% (5)
  • B
    87% (59)
  • C
    4% (3)
  • D
    1% (1)

Why each option

When planning a network audit, the most important step is the identification of all existing nodes to establish a complete inventory of assets. This foundational knowledge ensures that the audit scope covers all relevant devices and systems connected to the network.

AIsolation of rogue access points

Isolation of rogue access points is a specific security control activity that might be performed during an audit, not the primary planning step for defining scope.

BIdentification of existing nodesCorrect

Identifying existing nodes is crucial because it establishes the complete scope of the audit by providing an inventory of all devices (servers, workstations, network devices, IoT) connected to the network. Without a comprehensive list of assets, an audit cannot effectively assess security posture, vulnerabilities, or compliance across the entire network.

CAnalysis of traffic content

Analysis of traffic content is a detailed audit procedure performed after the scope and assets are identified, focusing on data inspection rather than initial planning.

DDetermination of IP range in use

Determination of IP range in use is part of network discovery, which contributes to identifying nodes, but 'identification of existing nodes' is a broader and more encompassing initial planning activity.

Concept tested: Network audit planning and scope

Source: https://www.cisecurity.org/controls/cis-controls-list/

Topics

#Network Audit Planning#Audit Scoping#Asset Identification#Audit Methodology

Community Discussion

No community discussion yet for this question.

Full CISA Practice