CISA Protection of Information Assets Practice Question
An IS auditor is reviewing an organization's network segmentation design. The organization states that its cardholder data environment is isolated from the corporate network. During testing, the auditor discovers that a management VLAN can reach both environments and that the firewall permits administrative protocols from the management VLAN to any host. Which of the following is the auditor's BEST conclusion?
⚠ Common exam trap
The trap here is treating management traffic as inherently trusted, when a management VLAN that spans both environments is itself the bypass that breaks segmentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Segmentation is ineffective because the management VLAN provides a path that bypasses the intended isolation.
Segmentation depends on preventing any path between environments that should not communicate. A management VLAN with administrative protocol access to any host in both the cardholder data environment and the corporate network creates exactly such a path, so the isolation claim fails. Encryption, internal origin, and presumed trust of administrative traffic do not remove the reachability that allows lateral movement, and the auditor should report the design as ineffective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Segmentation is effective because administrative traffic is trusted and exempt from segmentation controls.
Why it's wrong here
No category of traffic is inherently exempt from segmentation controls; management traffic is precisely the kind that attackers target because it carries elevated privileges. Treating administrative protocols as trusted by default contradicts the principle that segmentation must be enforced for all paths, and it would leave the cardholder data environment reachable from any compromised management host.
- ✗
The finding is not significant because the management VLAN is internal to the organization.
Why it's wrong here
Internal origin does not neutralize the risk; most breaches begin with an internal foothold that is then used to move laterally. Because the management VLAN can reach both environments, an internal compromise can cross the boundary that segmentation was designed to enforce. Dismissing the finding on the basis of network origin ignores how attackers actually escalate from a single compromised host.
- ✓
Segmentation is ineffective because the management VLAN provides a path that bypasses the intended isolation.
Why this is correct
A management VLAN that can reach both the cardholder data environment and the corporate network, with administrative protocols permitted to any host, creates a bridge that defeats the purpose of segmentation. The intended isolation no longer holds because an attacker compromising a management workstation could pivot between environments, so the auditor should conclude the control objective is not met.
- ✗
The finding is acceptable if management traffic is encrypted with strong ciphers.
Why it's wrong here
Encryption protects data in transit from interception but does not restrict who can reach a target or which commands can be issued. An attacker on the management VLAN can still authenticate to and administer hosts in both environments, so strong ciphers leave the isolation objective unmet. Confidentiality of the session is a different control from reachability, and only the latter determines whether segmentation holds.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.