CISM Information Security Programme Practice Question
In the context of defense-in-depth, which control provides protection at the network layer to prevent unauthorized access?
⚠ Common exam trap
CISM often tests the layer at which a control operates, and candidates may pick encryption or antivirus because they sound security-related, missing that the question specifically asks for network-layer protection against unauthorized access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewalls
Firewalls operate at the network layer (Layer 3) and transport layer (Layer 4) to filter traffic based on IP addresses, ports, and protocols, preventing unauthorized network access. They are a core component of defense-in-depth at the network perimeter and internal segments. This directly matches the requirement for network-layer protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encryption of data at rest
Why it's wrong here
Encrypting data at rest protects stored volumes and objects, not traffic crossing the network, so it cannot block unauthorised access attempts. It is tempting because encryption is a core defence-in-depth control, and it would be the right answer if the question asked about protecting data confidentiality on disk or in a storage bucket.
- ✗
Antivirus software
Why it's wrong here
Antivirus software inspects files and processes on hosts, operating at the endpoint layer rather than the network layer. A firewall or network intrusion prevention system filters traffic to block unauthorised access. Antivirus is the right control for malware detection on endpoints, but it does not govern network-layer admission.
- ✓
Firewalls
Why this is correct
Firewalls inspect and filter traffic at network boundaries, enforcing rules that block unauthorised access at the network layer. Host-based or application controls operate at different layers, so firewalls uniquely satisfy the stem's network-layer protection requirement.
- ✗
Security awareness training
Why it's wrong here
Security awareness training changes human behaviour against phishing and social engineering; it enforces no network-layer rule and cannot block unauthorised access to network resources. It is tempting because defence-in-depth includes administrative controls, and it would be correct if the question asked how to reduce staff susceptibility to social engineering.
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.