ExamGecko
Question list
Search
Search

Related questions

Question 376 - CISA discussion

Report
Export

An IS auditor reviewing security incident processes realizes incidents are resolved and closed, but root causes are not investigated. Which of the following should be the MAJOR concern with this situation?

A.
Abuses by employees have not been reported.
Answers
A.
Abuses by employees have not been reported.
B.
Lessons learned have not been properly documented
Answers
B.
Lessons learned have not been properly documented
C.
vulnerabilities have not been properly addressed
Answers
C.
vulnerabilities have not been properly addressed
D.
Security incident policies are out of date.
Answers
D.
Security incident policies are out of date.
Suggested answer: C

Explanation:

The major concern with the situation where security incidents are resolved and closed, but root causes are not investigated, is that vulnerabilities have not been properly addressed. Vulnerabilities are weaknesses or gaps in the security posture of an organization that can be exploited by threat actors to compromise its systems, data, or operations. If root causes are not investigated, vulnerabilities may remain undetected or unresolved, allowing attackers to exploit them again or use them as entry points for further attacks. This can result in repeated or escalated security incidents that can cause more damage or disruption to the organization.

The other options are not as major as the concern about vulnerabilities, but rather secondary or related issues that may arise from the lack of root cause analysis. Abuses by employees have not been reported is a concern that may indicate a lack of awareness, accountability, or monitoring of insider threats. Lessons learned have not been properly documented is a concern that may indicate a lack of improvement, learning, or feedback from security incidents. Security incident policies are out of date is a concern that may indicate a lack of alignment, review, or update of security incident processes.

ISACA CISA Review Manual 27th Edition (2019), page 254

Why Root Cause Analysis is Crucial to Incident Response (IR) - Avertium3

Root Cause Analysis Steps and How it Helps Incident Response ...

asked 18/09/2024
Adekunle Fodeke
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first