ExamGecko
Question list
Search
Search

Related questions

Question 29 - CISA discussion

Report
Export

An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor's NEXT course of action?

A.
Report the mitigating controls.
Answers
A.
Report the mitigating controls.
B.
Report the security posture of the organization.
Answers
B.
Report the security posture of the organization.
C.
Determine the value of the firewall.
Answers
C.
Determine the value of the firewall.
D.
Determine the risk of not replacing the firewall.
Answers
D.
Determine the risk of not replacing the firewall.
Suggested answer: D

Explanation:

The IS auditor's next course of action after finding that firewalls are outdated and not supported by vendors should be to determine the risk of not replacing the firewall. Outdated firewalls may have known vulnerabilities that can be exploited by attackers to bypass security controls and access the network. They may also lack compatibility with newer technologies or standards that are required for optimal network performance and protection. Not replacing the firewall could expose the organization to various threats, such as data breaches, denial-of-service attacks, malware infections, or regulatory non-compliance. The IS auditor should assess the likelihood and impact of these threats and quantify the risk level for management to make informed decisions.

asked 18/09/2024
Danyail Storey
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first