What Best Identifies Threats in Proposed Virtualization Techniques?

Information Security Governance & Management
Answer Correct answer: C — Conduct a formal risk assessment to proactively evaluate security threats before implementing the proposed virtualization technique.

Which of the following BEST enables an organization to identify potential security threats associated with a virtualization technique proposed by the vendor of a popular virtual machine (VM) system?

  1. Architecture design
  2. Functional specifications
  3. Risk assessment Correct Answer
  4. Hypervisor logs

Community Votes

C
56%
D
44%

56% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between pre-implementation planning and post-deployment monitoring, with the common trap being the selection of operational logs before the system exists.

This CISA question tests proactive risk identification during the planning phase of new virtualization technologies. Community consensus confirms that conducting a formal risk assessment is the only viable method when a solution remains unimplemented.

Candidates frequently choose hypervisor logs because they appear highly specific to VM environments, overlooking that logs cannot be analyzed until after deployment.

Community Discussion (7 comments)

Enig 👍 2
C If implement = D, it is only proposed therefore Risk assessment, C
RS66 👍 4 Selected: C
Those who are saying D can you explain how do you check logs of a system that doesn't exist yet? This system is proposed by the vendor, not implemented yet. Answer is C.
46080f2 👍 1 Selected: D
C. is only to confuse. The question of what is best for a narrowly described area. A typical ISACA question and typically the answer specific to the narrowed area is the correct one. For example, C. is far too general, whereas D. is very specific in relation to the limited context of the question. So D. is the correct answer from my ISACA experience.
shalota2 👍 1
D is only to confuse. I think is C the right answer
Swallows 👍 1 Selected: D
Hypervisor logs provide detailed information about the activities and events occurring within the virtualized environment. By analyzing these logs, an organization can identify potential security threats associated with a virtualization technique proposed by the vendor of a popular virtual machine (VM) system. Hypervisor logs record various activities such as virtual machine creation, deletion, resource allocation, network traffic, and system configuration changes. Analyzing these logs allows organizations to detect unauthorized access, unusual behaviors, and potential security vulnerabilities within the virtualized environment, enabling them to take proactive measures to mitigate security risks. While risk assessment (option C) is important for identifying and prioritizing security threats, hypervisor logs provide real-time data that directly relates to the operation of the virtualization technique and can reveal specific security issues within the VM system.
a84n 👍 1 Selected: C
Correct Answer is C option D may not proactively identify potential security threats associated with a proposed virtualization technique.
hermfrancis 👍 2 Selected: D
For ISACA's logic about the questions, D should be the answer because C is not only for VM environments.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A risk assessment is the most appropriate control when evaluating a vendor-proposed virtualization technique before any infrastructure is deployed. It systematically identifies, analyzes, and prioritizes potential security threats, allowing the organization to implement mitigations proactively. Since the technology is merely proposed, forward-looking evaluation frameworks like risk assessments align perfectly with CISA’s emphasis on preventive governance.

Why the Other Options Are Wrong

Architecture design and functional specifications focus on structural and operational requirements rather than threat identification. Hypervisor logs record historical events within an active environment, making them impossible to utilize during the proposal phase. Selecting implementation artifacts prematurely violates the fundamental principle that controls must match the project lifecycle stage.

Community Comment Notes

Multiple candidates highlight the critical timeline constraint, noting that logs do not exist for systems that have not yet been built [1]. Several users emphasize that while log analysis is valuable operationally, it fails the "proposed" condition in the prompt [2]. Others acknowledge ISACA’s tendency toward specificity but agree that temporal feasibility overrides technical narrowness in this scenario [4].

Official Reference

Exam Strategy

Always anchor your choice to the project lifecycle stage mentioned in the stem. If a technology is proposed or planned, prioritize governance and assessment activities over technical controls that require existing infrastructure.

Frequently Asked Questions

Why are hypervisor logs incorrect for a proposed system?

Logs only capture data after deployment; they cannot analyze threats for unimplemented vendor proposals.

Does architecture design cover security threats?

Architecture design focuses on structural components and workflows, not systematic threat identification or mitigation planning.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide