Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CISM Exam - Topic 1 Question 117 Discussion

Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?
B) Cybersecurity threat intelligence groups
A) Signature-based malware detection tools
C) Penetration test findings
D) Up-to-date vulnerability scanning tools

Isaca CISM Exam - Topic 1 Question 117 Discussion

Actual exam question for Isaca's CISM exam
Question #: 117
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is B because cybersecurity threat intelligence groups provide the most effective source of information about zero-day vulnerabilities. Zero-day vulnerabilities are newly discovered or previously unknown weaknesses that may not yet have patches, signatures, or standard scanner checks. Threat intelligence sources can provide early warnings, exploit details, indicators of compromise, affected technologies, attacker tactics, and recommended mitigations. Signature-based malware detection tools are limited because they depend on known malicious patterns and may not detect new threats. Penetration testing can identify weaknesses, but it is periodic and limited to the scope of the test. Vulnerability scanning tools are useful for identifying known vulnerabilities, but they may not detect zero-day vulnerabilities until detection logic is available. In CISM risk management, organizations should maintain awareness of emerging threats and adapt controls as the threat environment changes. Therefore, cybersecurity threat intelligence groups are the best source for learning of zero-day vulnerabilities.


Contribute your Thoughts:

0/2000 characters
Danica
4 days ago
I feel like penetration test findings could reveal some vulnerabilities, but they might not be as timely as threat intelligence.
upvoted 0 times
...
Joanne
9 days ago
I'm not entirely sure, but I remember a practice question where vulnerability scanning tools were mentioned. They might not catch zero-days though, right?
upvoted 0 times
...
Wilda
14 days ago
I think option B makes the most sense since threat intelligence groups are often the first to report on zero-day vulnerabilities.
upvoted 0 times
...

Save Cancel