The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
Comprehensive and Detailed Step-by-Step Explanation:
Conducting vulnerability assessments only once per year, right before an audit, creates a false sense of security and leaves systems exposed between assessments.
Annual Testing Before Audit (Correct Answer -- A)
Risks undetected vulnerabilities for extended periods.
Example: A company only tests security before a compliance audit, allowing zero-day threats to persist for months.
Internal Team Conducting Assessments (Incorrect -- B)
Not ideal, but regular assessments are more critical.
Focusing on Critical Systems (Incorrect -- C)
Not perfect, but better than no testing at all.
Using Open-Source Tools (Incorrect -- D)
Open-source tools can be effective if properly configured.
References:
ISACA CISA Review Manual
NIST 800-115 (Technical Guide to Security Testing)
Artie
3 months agoArlette
3 months agoGraciela
3 months agoGianna
4 months agoMyong
4 months agoLeana
4 months agoDelisa
4 months agoEvangelina
4 months agoEffie
5 months agoCory
5 months agoLemuel
5 months agoTesha
5 months agoRuthann
5 months agoFernanda
12 months agoDoretha
12 months agoAlva
11 months agoLewis
11 months agoCathrine
1 year agoSylvie
1 year agoSantos
1 year agoAllene
11 months agoYoko
11 months agoAsha
12 months agoDevorah
12 months agoGraciela
1 year agoEthan
1 year agoNida
1 year agoPaulina
1 year agoCarlton
1 year ago