ExamGecko
Question list
Search
Search

Related questions











Question 586 - CISA discussion

Report
Export

Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization's vulnerability scanning program''

A.
Steps taken to address identified vulnerabilities are not formally documented
Answers
A.
Steps taken to address identified vulnerabilities are not formally documented
B.
Results are not reported to individuals with authority to ensure resolution
Answers
B.
Results are not reported to individuals with authority to ensure resolution
C.
Scans are performed less frequently than required by the organization's vulnerability scanning schedule
Answers
C.
Scans are performed less frequently than required by the organization's vulnerability scanning schedule
D.
Results are not approved by senior management
Answers
D.
Results are not approved by senior management
Suggested answer: B

Explanation:

The finding that should be of greatest concern to an IS auditor assessing the effectiveness of an organization's vulnerability scanning program is that results are not reported to individuals with authority to ensure resolution. This indicates a lack of accountability and communication for vulnerability management, which may result in unresolved or delayed remediation of identified vulnerabilities. This may expose the organization to increased risk of cyberattacks or breaches. The other findings are also concerning, but not as much as this one, because they may affect the completeness, accuracy or timeliness of the vulnerability scanning process, but not necessarily its effectiveness.Reference:

ISACA, CISA Review Manual, 27th Edition, chapter 4, section 4.41

ISACA, COBIT 2019 Framework: Introduction and Methodology, section 3.2

asked 18/09/2024
Kaddy Kabuya
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first