nerdexam
Isaca

CISA · Question #353

Which of the following should be the PRIMARY focus when configuring security settings for a cloud application's infrastructure?

The correct answer is B. Protecting resources from unauthorized access. The fundamental purpose of security configuration is to protect resources from unauthorized access-controlling who can reach what. All other security activities flow from this core objective. Scalability (A) and cost minimization (D) are operational and financial concerns, not…

Submitted by tyler.j· Apr 18, 2026Protection of Information Assets

Question

Which of the following should be the PRIMARY focus when configuring security settings for a cloud application’s infrastructure?

Options

  • AMaximizing the scalability of the application
  • BProtecting resources from unauthorized access
  • CEnsuring that logs are sent to the SIEM
  • DMinimizing the cost of security infrastructure

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    89% (33)
  • C
    3% (1)
  • D
    3% (1)

Explanation

The fundamental purpose of security configuration is to protect resources from unauthorized access-controlling who can reach what. All other security activities flow from this core objective. Scalability (A) and cost minimization (D) are operational and financial concerns, not security objectives. Sending logs to a SIEM (C) is an important detective control but is secondary to the preventive control of access management. Without proper access controls in place, no other security measure is sufficient.

Topics

#Cloud security#Security configuration#Access control#Primary security objectives

Community Discussion

No community discussion yet for this question.

Full CISA Practice