ExamGecko
Question list
Search
Search

Related questions











Question 424 - CISA discussion

Report
Export

Which of the following should an IS auditor ensure is classified at the HIGHEST level of sensitivity?

A.
Server room access history
Answers
A.
Server room access history
B.
Emergency change records
Answers
B.
Emergency change records
C.
IT security incidents
Answers
C.
IT security incidents
D.
Penetration test results
Answers
D.
Penetration test results
Suggested answer: D

Explanation:

The IS auditor should ensure that penetration test results are classified at the highest level of sensitivity, because they contain detailed information about the vulnerabilities and weaknesses of the IT systems and networks, as well as the methods and tools used by the testers to exploit them. Penetration test results can be used by malicious actors to launch cyberattacks or cause damage to the organization if they are disclosed or accessed without authorization. Therefore, they should be protected with the highest level of confidentiality, integrity and availability.The other options are not as sensitive as penetration test results, because they either do not reveal as much information about the IT security posture, or they are already known or reported by the organization.Reference:CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.4

asked 18/09/2024
Anand Prakash
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first