ExamGecko
Question list
Search
Search

Related questions











Question 428 - CISA discussion

Report
Export

An IS auditor has completed the fieldwork phase of a network security review and is preparing the initial following findings should be ranked as the HIGHEST risk?

A.
Network penetration tests are not performed
Answers
A.
Network penetration tests are not performed
B.
The network firewall policy has not been approved by the information security officer.
Answers
B.
The network firewall policy has not been approved by the information security officer.
C.
Network firewall rules have not been documented.
Answers
C.
Network firewall rules have not been documented.
D.
The network device inventory is incomplete.
Answers
D.
The network device inventory is incomplete.
Suggested answer: A

Explanation:

The finding that should be ranked as the highest risk is that network penetration tests are not performed. Network penetration tests are simulated cyberattacks that aim to identify and exploit the vulnerabilities and weaknesses of the network security controls, such as firewalls, routers, switches, servers, and devices. Network penetration tests are essential for assessing the effectiveness and resilience of the network security posture, and for providing recommendations for improvement and remediation. If network penetration tests are not performed, the organization may not be aware of the existing or potential threats and risks to its network, and may not be able to prevent or respond to real cyberattacks, which can result in data breaches, service disruptions, financial losses, reputational damage, and legal or regulatory penalties.The other findings are also important, but not as risky as the lack of network penetration tests, because they either do not directly affect the network security controls, or they can be addressed by documentation or approval processes.Reference:CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.4

asked 18/09/2024
Christophe RUIZ
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first