What Best Identifies Threats in Proposed Virtualization Techniques?
Which of the following BEST enables an organization to identify potential security threats associated with a virtualization technique proposed by the vendor of a popular virtual machine (VM) system?
Community Votes
56% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between pre-implementation planning and post-deployment monitoring, with the common trap being the selection of operational logs before the system exists.
This CISA question tests proactive risk identification during the planning phase of new virtualization technologies. Community consensus confirms that conducting a formal risk assessment is the only viable method when a solution remains unimplemented.
Candidates frequently choose hypervisor logs because they appear highly specific to VM environments, overlooking that logs cannot be analyzed until after deployment.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A risk assessment is the most appropriate control when evaluating a vendor-proposed virtualization technique before any infrastructure is deployed. It systematically identifies, analyzes, and prioritizes potential security threats, allowing the organization to implement mitigations proactively. Since the technology is merely proposed, forward-looking evaluation frameworks like risk assessments align perfectly with CISA’s emphasis on preventive governance.Why the Other Options Are Wrong
Architecture design and functional specifications focus on structural and operational requirements rather than threat identification. Hypervisor logs record historical events within an active environment, making them impossible to utilize during the proposal phase. Selecting implementation artifacts prematurely violates the fundamental principle that controls must match the project lifecycle stage.Community Comment Notes
Multiple candidates highlight the critical timeline constraint, noting that logs do not exist for systems that have not yet been built [1]. Several users emphasize that while log analysis is valuable operationally, it fails the "proposed" condition in the prompt [2]. Others acknowledge ISACA’s tendency toward specificity but agree that temporal feasibility overrides technical narrowness in this scenario [4].Official Reference
Exam Strategy
Always anchor your choice to the project lifecycle stage mentioned in the stem. If a technology is proposed or planned, prioritize governance and assessment activities over technical controls that require existing infrastructure.
Frequently Asked Questions
Why are hypervisor logs incorrect for a proposed system?
Logs only capture data after deployment; they cannot analyze threats for unimplemented vendor proposals.
Does architecture design cover security threats?
Architecture design focuses on structural components and workflows, not systematic threat identification or mitigation planning.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →