Which threat is greatest to an organization's entire virtual infrastructure?
Which of the following presents the GREATEST threat to an organization's entire virtual infrastructure?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the security baseline of VM provisioning; the trap is choosing a general process issue instead of the image-level control that scales across the whole virtual environment.
CISA question about the greatest threat to an organization's virtual infrastructure: the answer is a non-standardized virtual machine image. This page explains why image baseline control outweighs change management and guest authentication risks.
Choosing local authentication (C) is a common mistake because it seems like a credential-management weakness, but local authentication affects individual guest systems rather than the foundational VM image used to deploy the entire virtual environment.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The virtual machine image is the reusable baseline for creating guests. When the image is not standardized, every VM may be built with inconsistent security settings, patch levels, or applications, so a single weak image can propagate risk across all systems. In CISA's virtual-infrastructure view, this is an infrastructure-wide control failure, not just a guest-level issue. Standardizing a golden image is a foundational audit expectation, making this the greatest threat among the options.
Why the Other Options Are Wrong
Inefficient change management processes (A) create operational and audit risk, but 'inefficient' does not necessarily mean controls are absent or that the entire infrastructure is exposed. Pushing changes during business hours (B) is mainly an availability and scheduling concern, not a security threat to the whole virtual stack. Using local authentication for guest systems (C) weakens identity management at the guest OS level, yet it does not by itself expose the hypervisor or all virtual machines. These risks are narrower than leaving VM images unstandardized.
Community Comment Notes
One participant, Sibsankar, initially questioned the D key with 'D is wrong, C is correct answer,' but later apologised and confirmed D. Another commenter reinforced D by pointing out that lack of image standardization has 'wide-ranging implications for security, reliability, and operational efficiency.' The discussion therefore supports the image-control rationale, while showing why guest authentication is an easy but incorrect pick.
Exam Strategy
For 'greatest threat' questions, identify the option that affects the most components or the foundation of the environment. A non-standardized VM image is a baseline issue that can scale to every virtual machine, so weigh it before considering process or guest-level concerns.
Frequently Asked Questions
Why is an unstandardized VM image a bigger threat than local guest authentication?
Local authentication can weaken one guest's identity management, but an unstandardized image may contain insecure configurations that are copied to many VMs, spreading risk across the virtual environment.
Does inefficient change management also threaten the entire virtual infrastructure?
Yes, but inefficient change management is a process weakness, not an immediate infrastructure defect; the exam's 'greatest' threat is the non-standard image that all VMs inherit.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →