The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
Comprehensive and Detailed Step-by-Step Explanation:
Conducting vulnerability assessments only once per year, right before an audit, creates a false sense of security and leaves systems exposed between assessments.
Annual Testing Before Audit (Correct Answer -- A)
Risks undetected vulnerabilities for extended periods.
Example: A company only tests security before a compliance audit, allowing zero-day threats to persist for months.
Internal Team Conducting Assessments (Incorrect -- B)
Not ideal, but regular assessments are more critical.
Focusing on Critical Systems (Incorrect -- C)
Not perfect, but better than no testing at all.
Using Open-Source Tools (Incorrect -- D)
Open-source tools can be effective if properly configured.
References:
ISACA CISA Review Manual
NIST 800-115 (Technical Guide to Security Testing)
Fernanda
2 months agoDoretha
2 months agoAlva
1 months agoLewis
1 months agoCathrine
2 months agoSylvie
2 months agoSantos
2 months agoAllene
24 days agoYoko
29 days agoAsha
2 months agoDevorah
2 months agoGraciela
3 months agoEthan
2 months agoNida
2 months agoPaulina
3 months agoCarlton
3 months ago