Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CGEIT Exam - Topic 5 Question 116 Discussion

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?
D) Integrate supply chain cyber risk management processes
A) Review the data classification policy and relevant documentation
B) Terminate contracts with suppliers from sanctioned regions of the world
C) Require nondisclosure agreements (NDAs) from all suppliers

Isaca CGEIT Exam - Topic 5 Question 116 Discussion

Actual exam question for Isaca's CGEIT exam
Question #: 116
Topic #: 5
[All CGEIT Questions]

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?

Show Suggested Answer Hide Answer
Suggested Answer: D

The best way to minimize intellectual property theft and sensitive information loss in IoT acquisitions is to integrate supply chain cyber risk management processes. This holistic approachincludes assessing supplier security posture, monitoring for threats, and ensuring cybersecurity is embedded into procurement, delivery, and operations.

NDAs, sanctions, and data classification are supportive, but only supply chain risk management addresses the full lifecycle risks and modern threats in globally sourced IoT ecosystems.


CGEIT Review Manual: Domain 4 -- Risk Optimization

COBIT 2019: DSS05 (Manage Security Services), APO10 (Manage Suppliers).

Contribute your Thoughts:

0/2000 characters
Selma
2 hours ago
Terminating contracts with suppliers from sanctioned regions seems extreme, but I guess it could help reduce risk. Still, I'm not sure if it's the best approach overall.
upvoted 0 times
...
Shala
5 days ago
I feel like reviewing the data classification policy is important, but I’m not convinced it directly minimizes risks related to IoT components.
upvoted 0 times
...
Markus
10 days ago
I remember practicing a question about NDAs, so option C might be a strong contender, but I wonder if it’s enough on its own.
upvoted 0 times
...
Caprice
16 days ago
I think option D sounds familiar from our discussions on supply chain risks, but I'm not entirely sure if it's the best choice here.
upvoted 0 times
...

Save Cancel