ExamGecko
Question list
Search
Search

Related questions

Question 43 - CISA discussion

Report
Export

An IS auditor finds that a key Internet-facing system is vulnerable to attack and that patches are not available. What should the auditor recommend be done FIRST?

A.
Implement a new system that can be patched.
Answers
A.
Implement a new system that can be patched.
B.
Implement additional firewalls to protect the system.
Answers
B.
Implement additional firewalls to protect the system.
C.
Decommission the server.
Answers
C.
Decommission the server.
D.
Evaluate the associated risk.
Answers
D.
Evaluate the associated risk.
Suggested answer: D

Explanation:

The first step in addressing a vulnerability is to evaluate the associated risk, which involves assessing the likelihood and impact of a potential exploit. Based on the risk assessment, the appropriate mitigation strategy can be determined, such as implementing a new system, adding firewalls, or decommissioning the server.Reference:ISACA CISA Review Manual 27th Edition, page 280

asked 18/09/2024
Ahmed Khalifa
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first