The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
Comprehensive and Detailed Step-by-Step Explanation:
Conducting vulnerability assessments only once per year, right before an audit, creates a false sense of security and leaves systems exposed between assessments.
Annual Testing Before Audit (Correct Answer -- A)
Risks undetected vulnerabilities for extended periods.
Example: A company only tests security before a compliance audit, allowing zero-day threats to persist for months.
Internal Team Conducting Assessments (Incorrect -- B)
Not ideal, but regular assessments are more critical.
Focusing on Critical Systems (Incorrect -- C)
Not perfect, but better than no testing at all.
Using Open-Source Tools (Incorrect -- D)
Open-source tools can be effective if properly configured.
References:
ISACA CISA Review Manual
NIST 800-115 (Technical Guide to Security Testing)
Fernanda
4 months agoDoretha
4 months agoAlva
3 months agoLewis
3 months agoCathrine
4 months agoSylvie
4 months agoSantos
4 months agoAllene
3 months agoYoko
3 months agoAsha
3 months agoDevorah
4 months agoGraciela
4 months agoEthan
4 months agoNida
4 months agoPaulina
4 months agoCarlton
5 months ago