The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
Comprehensive and Detailed Step-by-Step Explanation:
Conducting vulnerability assessments only once per year, right before an audit, creates a false sense of security and leaves systems exposed between assessments.
Annual Testing Before Audit (Correct Answer -- A)
Risks undetected vulnerabilities for extended periods.
Example: A company only tests security before a compliance audit, allowing zero-day threats to persist for months.
Internal Team Conducting Assessments (Incorrect -- B)
Not ideal, but regular assessments are more critical.
Focusing on Critical Systems (Incorrect -- C)
Not perfect, but better than no testing at all.
Using Open-Source Tools (Incorrect -- D)
Open-source tools can be effective if properly configured.
References:
ISACA CISA Review Manual
NIST 800-115 (Technical Guide to Security Testing)
Artie
6 months agoArlette
6 months agoGraciela
6 months agoGianna
7 months agoMyong
7 months agoLeana
7 months agoDelisa
7 months agoEvangelina
7 months agoEffie
8 months agoCory
8 months agoLemuel
8 months agoTesha
8 months agoRuthann
8 months agoFernanda
1 year agoDoretha
1 year agoAlva
1 year agoLewis
1 year agoCathrine
1 year agoSylvie
1 year agoSantos
1 year agoAllene
1 year agoYoko
1 year agoAsha
1 year agoDevorah
1 year agoGraciela
1 year agoEthan
1 year agoNida
1 year agoPaulina
1 year agoCarlton
1 year ago