The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
Comprehensive and Detailed Step-by-Step Explanation:
Conducting vulnerability assessments only once per year, right before an audit, creates a false sense of security and leaves systems exposed between assessments.
Annual Testing Before Audit (Correct Answer -- A)
Risks undetected vulnerabilities for extended periods.
Example: A company only tests security before a compliance audit, allowing zero-day threats to persist for months.
Internal Team Conducting Assessments (Incorrect -- B)
Not ideal, but regular assessments are more critical.
Focusing on Critical Systems (Incorrect -- C)
Not perfect, but better than no testing at all.
Using Open-Source Tools (Incorrect -- D)
Open-source tools can be effective if properly configured.
References:
ISACA CISA Review Manual
NIST 800-115 (Technical Guide to Security Testing)
Artie
4 months agoArlette
5 months agoGraciela
5 months agoGianna
5 months agoMyong
5 months agoLeana
5 months agoDelisa
6 months agoEvangelina
6 months agoEffie
6 months agoCory
6 months agoLemuel
6 months agoTesha
6 months agoRuthann
6 months agoFernanda
1 year agoDoretha
1 year agoAlva
1 year agoLewis
1 year agoCathrine
1 year agoSylvie
1 year agoSantos
1 year agoAllene
1 year agoYoko
1 year agoAsha
1 year agoDevorah
1 year agoGraciela
1 year agoEthan
1 year agoNida
1 year agoPaulina
1 year agoCarlton
1 year ago