ExamGecko
Question list
Search
Search

Related questions

Question 367 - CISA discussion

Report
Export

An IS auditor has discovered that a software system still in regular use is years out of date and no longer supported the auditee has stated that it will take six months until the software is running on the current version. Which of the following is the BEST way to reduce the immediate risk associated with using an unsupported version of the software?

A.
Verify all patches have been applied to the software system's outdated version
Answers
A.
Verify all patches have been applied to the software system's outdated version
B.
Close all unused ports on the outdated software system.
Answers
B.
Close all unused ports on the outdated software system.
C.
Segregate the outdated software system from the main network.
Answers
C.
Segregate the outdated software system from the main network.
D.
Monitor network traffic attempting to reach the outdated software system.
Answers
D.
Monitor network traffic attempting to reach the outdated software system.
Suggested answer: C

Explanation:

The best way to reduce the immediate risk associated with using an unsupported version of the software is to segregate the outdated software system from the main network. An unsupported software system may have unpatched vulnerabilities that could be exploited by attackers to compromise the system or access sensitive data. By isolating the system from the rest of the network, the organization can limit the exposure and impact of a potential breach. Verifying all patches have been applied to the outdated software system, closing all unused ports on the outdated software system and monitoring network traffic attempting to reach the outdated software system are also good practices, but they do not address the root cause of the risk, which is the lack of vendor support and updates.Reference:

CISA Review Manual, 27th Edition, page 2951

CISA Review Questions, Answers & Explanations Database - 12 Month Subscription

asked 18/09/2024
Adrian Chirtoc
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first