nerdexam
Isaca

CISM · Question #379

An organization finds unauthorized software has been installed on a number of workstations. The software was found to contain a Trojan, which had been uploading data to an unknown external party…

The correct answer is A. Removing local administrator rights. Removing local administrator rights would have best prevented the installation of unauthorized software. This would limit the ability of users to install software without proper authorization, reducing the risk of Trojan and other malicious software being installed on…

Submitted by jakub_pl· Apr 18, 2026Information Security Risk Management

Question

An organization finds unauthorized software has been installed on a number of workstations. The software was found to contain a Trojan, which had been uploading data to an unknown external party. Which of the following would have BEST prevented the installation of the unauthorized software?

Options

  • ARemoving local administrator rights
  • BImplementing an intrusion detection system (IDS)
  • CRequiring management approval prior to installation of applications
  • DBanning executable file downloads at the internet firewall

How the community answered

(62 responses)
  • A
    77% (48)
  • B
    6% (4)
  • C
    13% (8)
  • D
    3% (2)

Explanation

Removing local administrator rights would have best prevented the installation of unauthorized software. This would limit the ability of users to install software without proper authorization, reducing the risk of Trojan and other malicious software being installed on workstations.

Topics

#Access Control#Endpoint Security#Preventive Controls#Malware Protection

Community Discussion

No community discussion yet for this question.

Full CISM Practice