CISA · Question #40
When evaluating the design of controls related to network monitoring, which of the following is MOST important for an IS auditor to review?
The correct answer is A. Network topology diagrams. When evaluating network monitoring controls, an IS auditor must review network topology diagrams as they provide a foundational understanding of the network's structure. This allows the auditor to identify all critical assets and network segments that require monitoring and to as
Question
When evaluating the design of controls related to network monitoring, which of the following is MOST important for an IS auditor to review?
Options
- ANetwork topology diagrams
- BReports of network traffic analysis
- CThe ISP service level agreement
- DIncident monitoring logs
How the community answered
(37 responses)- A81% (30)
- B11% (4)
- C5% (2)
- D3% (1)
Why each option
When evaluating network monitoring controls, an IS auditor must review network topology diagrams as they provide a foundational understanding of the network's structure. This allows the auditor to identify all critical assets and network segments that require monitoring and to assess if monitoring tools are adequately deployed.
Network topology diagrams are most important because they provide a comprehensive visual representation of the network's physical and logical layout, including all devices, connections, and critical segments. An auditor needs this foundational understanding to determine if monitoring controls are appropriately designed, strategically placed, and effectively cover all relevant parts of the infrastructure to detect anomalies or security events.
Reports of network traffic analysis show results of monitoring, which are important for testing effectiveness, but not for evaluating the design of the controls themselves.
The ISP service level agreement pertains to external service performance guarantees, which is relevant to network availability but not directly to the internal design of network monitoring controls.
Incident monitoring logs are records generated by monitoring systems, useful for testing operational effectiveness, but not the primary document for assessing the design and coverage of the monitoring system itself.
Concept tested: Network monitoring control design review
Source: https://www.cisecurity.org/controls/cis-controls-list/
Topics
Community Discussion
No community discussion yet for this question.