The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
Comprehensive and Detailed Step-by-Step Explanation:
Conducting vulnerability assessments only once per year, right before an audit, creates a false sense of security and leaves systems exposed between assessments.
Annual Testing Before Audit (Correct Answer -- A)
Risks undetected vulnerabilities for extended periods.
Example: A company only tests security before a compliance audit, allowing zero-day threats to persist for months.
Internal Team Conducting Assessments (Incorrect -- B)
Not ideal, but regular assessments are more critical.
Focusing on Critical Systems (Incorrect -- C)
Not perfect, but better than no testing at all.
Using Open-Source Tools (Incorrect -- D)
Open-source tools can be effective if properly configured.
References:
ISACA CISA Review Manual
NIST 800-115 (Technical Guide to Security Testing)
Artie
7 months agoArlette
8 months agoGraciela
8 months agoGianna
8 months agoMyong
8 months agoLeana
9 months agoDelisa
9 months agoEvangelina
9 months agoEffie
9 months agoCory
9 months agoLemuel
9 months agoTesha
9 months agoRuthann
9 months agoFernanda
1 year agoDoretha
1 year agoAlva
1 year agoLewis
1 year agoCathrine
1 year agoSylvie
1 year agoSantos
1 year agoAllene
1 year agoYoko
1 year agoAsha
1 year agoDevorah
1 year agoGraciela
1 year agoEthan
1 year agoNida
1 year agoPaulina
1 year agoCarlton
1 year ago