Medium1 markMultiple Choice
Area II: SecurityCIS ControlsFrameworksArea II

CPA · Question 36 · Area II: Security

According to the CIS Controls v8, what is Control 1 (the most foundational control)?

Answer options:

A.

Data Protection

B.

Inventory and Control of Enterprise Assets

C.

Account Management

D.

Malware Defenses

How to approach this question

Recall the very first step in security: You can't protect what you don't know you have.

Full Answer

B.Inventory and Control of Enterprise Assets✓ Correct
CIS Control 1 is 'Inventory and Control of Enterprise Assets'. You must actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) connected to the infrastructure.

Common mistakes

Thinking software inventory (Control 2) comes first.

Practice the full CPA ISC Practice Exam 5

82 questions · hints · full answers · grading

More questions from this exam