ExamGecko
Question list
Search
Search

Related questions

Question 273 - CISA discussion

Report
Export

An IS auditor finds a high-risk vulnerability in a public-facing web server used to process online customer payments. The IS auditor should FIRST

A.
document the exception in an audit report.
Answers
A.
document the exception in an audit report.
B.
review security incident reports.
Answers
B.
review security incident reports.
C.
identify compensating controls.
Answers
C.
identify compensating controls.
D.
notify the audit committee.
Answers
D.
notify the audit committee.
Suggested answer: C

Explanation:

The first action that an IS auditor should take when finding a high-risk vulnerability in a public-facing web server used to process online customer payments is to identify compensating controls. Compensating controls are alternative or additional controls that provide reasonable assurance of mitigating the risk of exploiting the vulnerability. The IS auditor should assess the effectiveness of the compensating controls and determine whether they reduce the risk to an acceptable level. If not, the IS auditor should recommend remediation actions to address the vulnerability. Documenting the exception in an audit report is an important action, but it should not be the first action, as it does not address the urgency of the situation. Reviewing security incident reports is a useful action, but it should not be the first action, as it does not provide assurance of preventing future incidents. Notifying the audit committee is a necessary action, but it should not be the first action, as it does not involve taking any corrective measures.Reference:

CISA Review Manual, 27th Edition, pages 295-2961

CISA Review Questions, Answers & Explanations Database, Question ID: 260

asked 18/09/2024
Vasco Ricardo Ribeiro
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first