ExamGecko
Question list
Search
Search

Related questions

Question 110 - CISA discussion

Report
Export

An IS audit reveals that an organization is not proactively addressing known vulnerabilities. Which of the following should the IS auditor recommend the organization do FIRST?

A.
Verify the disaster recovery plan (DRP) has been tested.
Answers
A.
Verify the disaster recovery plan (DRP) has been tested.
B.
Ensure the intrusion prevention system (IPS) is effective.
Answers
B.
Ensure the intrusion prevention system (IPS) is effective.
C.
Assess the security risks to the business.
Answers
C.
Assess the security risks to the business.
D.
Confirm the incident response team understands the issue.
Answers
D.
Confirm the incident response team understands the issue.
Suggested answer: C

Explanation:

If an IS audit reveals that an organization is not proactively addressing known vulnerabilities, the IS auditor should recommend that the organization assess the security risks to the business first, as this would help to prioritize the vulnerabilities based on their impact and likelihood, and determine the appropriate mitigation strategies.Verifying the disaster recovery plan (DRP) has been tested, ensuring the intrusion prevention system (IPS) is effective, and confirming the incident response team understands the issue are important steps, but they are not as urgent as assessing the security risks to the business.Reference:CISA Review Manual (Digital Version), Chapter 5, Section 5.6

asked 18/09/2024
Filippo Panarella
24 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first