ExamGecko
Question list
Search
Search

Related questions

Question 225 - CISA discussion

Report
Export

During a follow-up audit, it was found that a complex security vulnerability of low risk was not resolved within the agreed-upon timeframe. IT has stated that the system with the identified vulnerability is being replaced and is expected to be fully functional in two months Which of the following is the BEST course of action?

A.
Require documentation that the finding will be addressed within the new system
Answers
A.
Require documentation that the finding will be addressed within the new system
B.
Schedule a meeting to discuss the issue with senior management
Answers
B.
Schedule a meeting to discuss the issue with senior management
C.
Perform an ad hoc audit to determine if the vulnerability has been exploited
Answers
C.
Perform an ad hoc audit to determine if the vulnerability has been exploited
D.
Recommend the finding be resolved prior to implementing the new system
Answers
D.
Recommend the finding be resolved prior to implementing the new system
Suggested answer: A

Explanation:

Requiring documentation that the finding will be addressed within the new system is the best course of action for a follow-up audit. An IS auditor should obtain evidence that the complex security vulnerability of low risk will be resolved in the new system and that there is a reasonable timeline for its implementation. The other options are not appropriate courses of action, as they may be too costly, time-consuming, or impractical for a low-risk finding.Reference:

CISA Review Manual (Digital Version), Chapter 2, Section 2.5.31

CISA Review Questions, Answers & Explanations Database, Question ID 209

asked 18/09/2024
John Doe
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first