Courseiva
mediumMultiple ChoiceObjective-mapped

CISA Practice Question: During a security audit, it is discovered that a…

During a security audit, it is discovered that a database containing customer credit card numbers is not encrypted at rest. The database is used by a legacy application that cannot be modified. Which compensating control most effectively reduces the risk?

⚠ Common exam trap

A common mix-up: candidates choose audit logging or masking because they seem technical, but they fail to recognize that only network segmentation actively prevents direct access to the unencrypted data at rest, while the others are either detective or require application changes that are impossible in this scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolating the database server on a separate network segment with strict firewall rules

Isolating the database server on a separate network segment with strict firewall rules (e.g., using VLANs and ACLs to restrict traffic to only the legacy application’s IP and port) prevents unauthorized network-level access to the unencrypted data. This compensating control reduces the attack surface by ensuring that even if the database lacks encryption at rest, an attacker cannot reach it without first compromising the network segmentation, which is a critical defense-in-depth layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Isolating the database server on a separate network segment with strict firewall rules

    Why this is correct

    Segmentation reduces the attack surface and limits access.

  • Enabling detailed audit logging for all database access

    Why it's wrong here

    Logging is detective, not preventive.

  • Requiring all users to sign a nondisclosure agreement (NDA)

    Why it's wrong here

    NDA is a legal control, not technical.

  • Implementing dynamic data masking at the application level

    Why it's wrong here

    Masking hides data from users but data remains unencrypted in storage.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.