nerdexam
Isaca

CISA · Question #358

An IS auditor is reviewing an organization's controls for Internet of Things (IoT) devices. Which of the following should be the auditor's PRIMARY focus?

The correct answer is C. Vulnerability and patch management. Vulnerability and patch management is the primary concern for IoT devices because these devices are notoriously difficult to update, often ship with default credentials and unpatched firmware, and represent a large, distributed attack surface that can be exploited to compromise t

Submitted by carlos_mx· Apr 18, 2026Protection of Information Assets

Question

An IS auditor is reviewing an organization’s controls for Internet of Things (IoT) devices. Which of the following should be the auditor’s PRIMARY focus?

Options

  • AConfiguration management database (CMDB) coverage
  • BPower consumption and maintenance
  • CVulnerability and patch management
  • DInteroperability and integration

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    81% (50)
  • D
    11% (7)

Explanation

Vulnerability and patch management is the primary concern for IoT devices because these devices are notoriously difficult to update, often ship with default credentials and unpatched firmware, and represent a large, distributed attack surface that can be exploited to compromise the broader network. An IS auditor's primary focus is on risk - and unpatched IoT vulnerabilities are among the highest-impact, most frequently exploited risks in modern environments.

Why the distractors are wrong:

  • A (CMDB coverage): Knowing what devices exist is an inventory concern - important, but secondary to whether those known devices are secure.
  • B (Power consumption and maintenance): These are operational/facilities concerns, not IS audit priorities.
  • D (Interoperability and integration): Integration is an architecture/design concern; it matters during implementation review, but it doesn't represent the ongoing risk exposure that vulnerabilities do.

Memory tip: Think "IoT = hard to patch = high risk." In IS audit, wherever patching is hard, that's where the auditor should look hardest. The harder it is to fix, the more important it is to audit.

Topics

#IoT Security#Vulnerability Management#Patch Management#IS Audit Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice